Private work stays private
Private chats, direct messages, tasks, files, billing records and non-public profiles are limited to authorized participants and are excluded from public discovery resources.
This policy explains what personal information Collty processes, why it is needed, how private workspace data is separated from public discovery data, and which choices and rights are available to you.
Private chats, direct messages, tasks, files, billing records and non-public profiles are limited to authorized participants and are excluded from public discovery resources.
AI features process only the context needed for the feature you or an authorized workspace member uses. Collty does not use private workspace content to train public or shared models.
Collty does not sell personal information and does not use personal information for cross-context behavioral advertising.
Readable format: this policy is intentionally layered. The summaries help orientation, while the complete sections below control if a summary and the detailed text differ. A PDF version is available for accessibility and record keeping.
This Privacy Policy applies when you visit collty.com, create or use a Collty account, participate in a workspace, use Collty applications or AI-enabled features, publish or interact in Signals, contact support, request access, or otherwise use the Collty cloud software and platform service (the "Service").
"Collty," "we," "us," or "our" means Collty, which operates collty.com and provides the Service. Collty can be contacted using the details in Section 17.
This policy does not govern independent services linked to or integrated with Collty. Those providers process information under their own notices. If an organization gives you access to Collty, that organization may also have its own privacy obligations for information it controls.
Collty generally acts as controller for account registration, access administration, subscriptions, product usage, security, support, public profiles, Signals, platform communications, service improvement, and compliance. This means Collty determines why and how that information is processed.
For private project, team, client, task, file, message, invoice, expense, analytics, and workspace content submitted and controlled by a customer organization, Collty may act as that organization's processor or service provider. The customer is responsible for its instructions, permissions, legal basis, notices, and the data it places in the Service. A data processing addendum may apply where agreed.
If you provide information about another person, you must have authority to do so and provide any notice or obtain any permission required by law.
| Purpose | Typical information | Why it is necessary |
|---|---|---|
| Provide the Service | Account, profile, workspace, content and configuration data | Create accounts, run workspaces, enable collaboration and deliver requested features. |
| AI and recommendations | Selected prompts, project context, profile and usage data | Generate plans, assemble and analyze teams, run authorized agents and provide decision support. |
| Security and integrity | Session, device, access, audit and abuse signals | Authenticate users, prevent fraud, investigate incidents and enforce permissions. |
| Communication and support | Contact, notification, support and interaction data | Send operational notices, answer requests and provide assistance. |
| Subscriptions and administration | Plan, usage, invoice and account records | Administer access, limits, usage accounting and financial records. |
| Improve the platform | Feature usage, diagnostics, feedback and de-identified metrics | Measure reliability, fix defects and improve workflows and models. |
| Compliance | Relevant account, transaction, content and audit records | Meet legal obligations, respond to lawful requests and resolve disputes. |
We do not repurpose private workspace content for unrelated advertising. If we plan a materially different use that requires notice or consent, we will provide it before that processing begins.
Where the GDPR, UK GDPR or comparable law applies, Collty relies on one or more of the following bases. The applicable basis depends on the feature and relationship.
| Legal basis | Examples |
|---|---|
| Contract | Creating and administering your account, providing subscribed features, collaboration tools and requested AI functions. |
| Legitimate interests | Securing and improving the Service, preventing abuse, supporting users, measuring reliability and operating Collty, balanced against your rights. |
| Consent | Optional communications, non-essential technologies or a specific optional data use where consent is required. |
| Legal obligation | Tax, accounting, sanctions, lawful requests, record keeping and regulatory compliance. |
| Protection of rights | Establishing, exercising or defending legal claims and protecting users, Collty or others. |
When Collty acts as processor, the customer controller determines the legal basis for its workspace content and Collty follows the customer's documented lawful instructions.
Collty uses AI and algorithmic systems for team assembly, team intelligence, project planning, canvas assistance, summaries, professional discovery, moderation support, analytics, smart console signals and configurable agents. Inputs may include information you supply, authorized workspace context and relevant profile or project records.
Collty does not sell personal information. Collty does not share personal information for cross-context behavioral advertising. Service providers may process information only for contracted services and subject to applicable restrictions.
Collty uses essential cookies, local storage and similar technologies for sign-in, session continuity, fraud prevention, security, preferences, feature state and performance. Optional analytics or communication technologies, if introduced, are used with the notice and choice required in your region.
You can control browser storage through your browser or available preference controls. Blocking essential technologies may prevent authentication, saved preferences or protected workspace features from functioning. The Collty Cookie Policy at collty.com/cookies provides the current technology list, purposes, providers and retention periods.
We keep personal information only for as long as reasonably necessary for the purpose collected, the active account or workspace relationship, contractual commitments, security, dispute resolution, and legal, tax or accounting requirements. Retention varies by category and context.
Deletion from active systems may be followed by deletion from protected backups according to normal backup rotation, unless retention is legally required.
Collty applies administrative, technical and organizational safeguards designed for the nature of the data and risk. These include authenticated workspaces, role and project authorization, secure transport, audit and abuse controls, environment separation, access limitation and incident-response processes.
Sensitive fields protected by Collty's secure-field layer use application-level AES-256-GCM authenticated encryption. Deterministic matching of protected identifiers uses keyed HMAC-SHA256 lookup values rather than exposing plaintext identifiers. Public discovery data is separated from private workspace data by server-side access boundaries.
No system is completely secure. You are responsible for protecting credentials, using appropriate workspace permissions and promptly reporting suspected unauthorized access to privacy@collty.com.
Collty and its service providers may process information in countries other than where you live. Where required, Collty uses lawful safeguards such as adequacy decisions, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, and supplementary technical and organizational measures.
You may contact privacy@collty.com for information about the transfer safeguards applicable to your information, subject to confidentiality and security limitations.
Collty maintains versioned technical records for processing activities, data-protection impact assessments, service providers, international transfer reviews, retention rules, data-subject requests, privacy incidents and accountability controls. These records are protected from public and ordinary authenticated access and are available to authorized operators through service-role controls.
Depending on your location and subject to legal exceptions, you may have rights to access, correct, delete, restrict or object to processing, receive a portable copy, withdraw consent, and complain to a supervisory authority. You may also have rights concerning automated decision-making.
If Collty processes workspace information only on behalf of your organization, we may direct the request to that organization or assist it as required by contract and law.
You may contact the competent data protection authority where you live or work. Before doing so, we invite you to contact privacy@collty.com so we can try to resolve the concern. Where required, Collty will identify an applicable representative or data protection contact in the relevant account or regional notice.
Where applicable, residents may request to know or access categories and specific pieces of personal information, correct inaccurate information, delete information, obtain portability, and opt out of sale, sharing or targeted advertising. Collty does not sell personal information and does not share it for cross-context behavioral advertising.
The categories described in Section 3 are collected for the business purposes in Section 5 and disclosed to the recipient categories in Section 8. Collty does not knowingly sell or share personal information of users under 18. Requests are subject to verification and applicable exceptions.
Collty is a professional service intended only for people aged 18 or older and legally able to enter an agreement. We do not knowingly permit children to create accounts. If you believe a person under 18 provided personal information, contact privacy@collty.com.
We may update this policy as the Service, processing or law changes. The effective date identifies the current version. If a change materially affects how we use personal information, we will provide notice through the Service, email or another legally appropriate method before the change takes effect where required.
Prior versions are available on reasonable request. Continued use after an update does not replace any consent required by law.
privacy@collty.com
privacy@collty.com
office@collty.com
Please do not send passwords, full payment credentials or unnecessary sensitive information by email. We may request additional information through a secure channel to verify and complete a request.