• About
  • Pricing
  • Ready team blueprintsStart from a proven business outcome, then match real specialists.
  • Partnership
  • Signals
  • Insights
  • Login →Create account +Client Office →Team Studio →Pro Workspace →
    My account Upgrade $Support Sign out ×
Main/
InsightsArticles & newsSignalsPeople & project graphPartnershipCollaborate with usAboutWhat is Collty?PricingPlans and capacity
Login →Create account +Client Office →Team Studio →Pro Workspace →My account Upgrade $Support Sign out ×
PrivacyTermsCookiesGDPREU AI Act
Privacy and data protection

Privacy Policy

This policy explains what personal information Collty processes, why it is needed, how private workspace data is separated from public discovery data, and which choices and rights are available to you.

Effective date

July 29, 2026

Version

2.2

Privacy contact

privacy@collty.com

01

Private work stays private

Private chats, direct messages, tasks, files, billing records and non-public profiles are limited to authorized participants and are excluded from public discovery resources.

02

AI remains purpose-limited

AI features process only the context needed for the feature you or an authorized workspace member uses. Collty does not use private workspace content to train public or shared models.

03

No sale of personal information

Collty does not sell personal information and does not use personal information for cross-context behavioral advertising.

Contents
  • 1. Scope and Collty
  • 2. Our data protection roles
    • When Collty acts as controller
    • When Collty acts as processor
  • 3. Information we process
    • Account, access and identity information
    • Professional, organization and relationship information
    • Project and workspace information
    • Communications, community and support
    • AI and agent data
    • Technical, usage and security information
  • 4. Where information comes from
  • 5. Why we use information
  • 6. Legal bases
  • 7. AI, recommendations and automated features
  • 8. Visibility and disclosure
    • Public, community and private surfaces
    • Recipients
  • 9. Cookies and local technologies
  • 10. Retention and deletion
  • 11. Security and confidentiality
  • 12. International transfers
  • 13. Data-protection operations and evidence
  • 14. Your choices and privacy rights
  • 15. Regional notices
    • EEA, United Kingdom and Switzerland
    • California and other United States privacy laws
  • 16. Age requirement
  • 17. Changes to this policy
  • 18. Contact and complaints

Readable format: this policy is intentionally layered. The summaries help orientation, while the complete sections below control if a summary and the detailed text differ. A PDF version is available for accessibility and record keeping.

Cookie PolicyRequest a prior version
01

Scope and Collty

This Privacy Policy applies when you visit collty.com, create or use a Collty account, participate in a workspace, use Collty applications or AI-enabled features, publish or interact in Signals, contact support, request access, or otherwise use the Collty cloud software and platform service (the "Service").

"Collty," "we," "us," or "our" means Collty, which operates collty.com and provides the Service. Collty can be contacted using the details in Section 17.

This policy does not govern independent services linked to or integrated with Collty. Those providers process information under their own notices. If an organization gives you access to Collty, that organization may also have its own privacy obligations for information it controls.

02

Our data protection roles

When Collty acts as controller

Collty generally acts as controller for account registration, access administration, subscriptions, product usage, security, support, public profiles, Signals, platform communications, service improvement, and compliance. This means Collty determines why and how that information is processed.

When Collty acts as processor

For private project, team, client, task, file, message, invoice, expense, analytics, and workspace content submitted and controlled by a customer organization, Collty may act as that organization's processor or service provider. The customer is responsible for its instructions, permissions, legal basis, notices, and the data it places in the Service. A data processing addendum may apply where agreed.

Workspace permissions are the boundary

A workspace role does not make all data public. Access is scoped by workspace, project, team, participant, and feature permissions. Workspace owners and administrators control membership and may access or manage content according to those permissions.

03

Information we process

Account, access and identity information

  • name, email address, authentication credentials and session records;
  • date of birth or age-confirmation data, phone number, city, country and language where provided;
  • invite codes, inviter and invitee relationships, access requests and email-confirmation status;
  • organization, workspace, role, membership, permission and administrator records;
  • information returned by an identity provider, such as Google, when you choose that sign-in method.

Professional, organization and relationship information

  • professional biography, roles, skills, industries, experience, education, rates, availability, portfolio cases and links;
  • client, partner, company and team profile information, including operational and commercial settings;
  • collaboration graph entries, recommendations, connections, achievements, reputation signals and profile completeness;
  • photos and other profile media you upload.

Project and workspace information

  • project briefs, team composition, roles, availability, operating models, sprint settings, milestones and roadmaps;
  • tasks, dependencies, comments, Team Pulse responses, analytics, status history and collaboration signals;
  • documents, files, links, canvas objects, diagrams, proposals, generated plans and workspace settings;
  • invoices, expenses, time, rates, budgets, payment-status records and other commercial workflow data when those features are enabled.

Communications, community and support

  • private chats, direct messages, project comments and meeting-related information;
  • Signals posts, replies, reactions, follows, accepted answers, saved items and collaboration interests;
  • support requests, feedback, reports, moderation appeals and related correspondence;
  • service, security and notification preferences.

AI and agent data

  • prompts, instructions, selected project context and files intentionally supplied to an AI feature;
  • generated outputs, team recommendations, summaries, scores, agent settings, actions, approval state and execution history;
  • provider, model, feature, token, cost, latency, error and safety telemetry used to operate and account for AI usage.

Technical, usage and security information

  • IP address, browser, device, operating system, time zone, approximate location derived from IP and language;
  • pages, features, interactions, searches, timestamps, navigation, performance, diagnostics and crash information;
  • session, authentication, rate-limit, anti-abuse, audit and security-event records;
  • essential cookies, local storage and similar technologies needed to authenticate, secure and remember the Service.
04

Where information comes from

  • Directly from you when you register, complete a profile, create content, configure a project or communicate.
  • From your organization, team members, clients, partners or other users when they invite you, add you to authorized work, recommend you or interact with you.
  • Automatically from your device and use of the Service.
  • From identity, communication, security and integration providers you choose or that are required to operate the Service.
  • From public professional sources only where permitted by law and relevant to a user-requested discovery, verification or enrichment function.

If you provide information about another person, you must have authority to do so and provide any notice or obtain any permission required by law.

05

Why we use information

PurposeTypical informationWhy it is necessary
Provide the ServiceAccount, profile, workspace, content and configuration dataCreate accounts, run workspaces, enable collaboration and deliver requested features.
AI and recommendationsSelected prompts, project context, profile and usage dataGenerate plans, assemble and analyze teams, run authorized agents and provide decision support.
Security and integritySession, device, access, audit and abuse signalsAuthenticate users, prevent fraud, investigate incidents and enforce permissions.
Communication and supportContact, notification, support and interaction dataSend operational notices, answer requests and provide assistance.
Subscriptions and administrationPlan, usage, invoice and account recordsAdminister access, limits, usage accounting and financial records.
Improve the platformFeature usage, diagnostics, feedback and de-identified metricsMeasure reliability, fix defects and improve workflows and models.
ComplianceRelevant account, transaction, content and audit recordsMeet legal obligations, respond to lawful requests and resolve disputes.

We do not repurpose private workspace content for unrelated advertising. If we plan a materially different use that requires notice or consent, we will provide it before that processing begins.

06

Legal bases

Where the GDPR, UK GDPR or comparable law applies, Collty relies on one or more of the following bases. The applicable basis depends on the feature and relationship.

Legal basisExamples
ContractCreating and administering your account, providing subscribed features, collaboration tools and requested AI functions.
Legitimate interestsSecuring and improving the Service, preventing abuse, supporting users, measuring reliability and operating Collty, balanced against your rights.
ConsentOptional communications, non-essential technologies or a specific optional data use where consent is required.
Legal obligationTax, accounting, sanctions, lawful requests, record keeping and regulatory compliance.
Protection of rightsEstablishing, exercising or defending legal claims and protecting users, Collty or others.

When Collty acts as processor, the customer controller determines the legal basis for its workspace content and Collty follows the customer's documented lawful instructions.

07

AI, recommendations and automated features

Collty uses AI and algorithmic systems for team assembly, team intelligence, project planning, canvas assistance, summaries, professional discovery, moderation support, analytics, smart console signals and configurable agents. Inputs may include information you supply, authorized workspace context and relevant profile or project records.

  • Only context needed for the selected feature is sent to an applicable model or AI service provider.
  • Private chats and direct messages are not used as public discovery material and are not used to train public or shared models.
  • AI providers act as service providers for the requested processing under applicable contractual and security controls.
  • AI outputs can be incomplete or inaccurate. Users must review material decisions, generated content, staffing choices, financial actions and external communications.
  • Agent actions follow configured permissions, project state, pause controls and approval requirements; users remain responsible for authorized use.
  • Team scores, matching and recommendations support human decisions. Collty does not use them as the sole basis for decisions producing legal or similarly significant effects about a person.
  • Before first publication, Collty asks you to expressly acknowledge the current Terms and Privacy Policy and to instruct Collty to process the permitted profile and professional work evidence needed for discovery, matching, ranking, team recommendations and profile-quality guidance. The acknowledgement is versioned and recorded. It is not consent to unrelated AI use; a separate optional use that legally requires consent will use a separate request.
  • If you do not want an available professional profile to be considered for discovery or AI-assisted matching, use the available visibility controls or request profile deletion. You can update inaccurate or outdated profile evidence at any time, subject to account and record-integrity requirements.
  • Verified project work can affect future relevance and ranking through role, task, outcome, reliability, availability, capacity and permission-scoped collaboration signals. Private unrelated content, protected attributes and unsupported claims are outside the ranking contract.
  • A displayed match may include a concise explanation of the professional evidence that supported it. Collty does not expose hidden candidate pools, another person's private information or proprietary ranking weights.
  • You may correct your own professional profile evidence or report that an AI-assisted ranking used inaccurate or unsupported evidence. Collty may investigate and correct the system or source record, but does not adjudicate or overturn a customer's independent team choice. Result ratings are learning feedback and do not replace this correction process.
  • Collty maintains product-specific AI system classifications, risk and data-governance controls, provenance, monitoring and incident records. The applicable role and legal obligations depend on the intended purpose and use of each feature.

No hidden public-model training

Collty does not use private workspace content to train public or shared foundation models. Any future optional training program involving identifiable or private content would require a separate, explicit notice and choice.

08

Visibility and disclosure

Public, community and private surfaces

  • Public profile, portfolio, team or organization information is visible only when the applicable visibility setting and product flow make it public.
  • Signals publication metadata or previews may be discoverable where configured, while the full community experience and private interactions may require an account.
  • Private chats, direct messages, project tasks, files, billing data, non-public profiles and workspace records are limited to authorized participants and excluded from public sitemaps, public feeds and AI discovery resources.
  • Workspace owners and administrators may access content and activity within the scope of their organizational role and permissions.

Recipients

  • Authorized users, workspace members and people you choose to interact with, according to permissions and visibility settings.
  • Vendors that provide infrastructure, communications, authentication, security, support, file, analytics or AI processing needed to operate the Service.
  • Professional advisers, auditors and insurers subject to confidentiality duties.
  • Authorities or other parties when disclosure is required by law or reasonably necessary to protect rights, safety, security or the integrity of the Service.
  • A successor in a merger, financing, reorganization, acquisition or sale, subject to appropriate safeguards and notice where required.
  • Other recipients at your direction or with your consent.

Collty does not sell personal information. Collty does not share personal information for cross-context behavioral advertising. Service providers may process information only for contracted services and subject to applicable restrictions.

09

Cookies and local technologies

Collty uses essential cookies, local storage and similar technologies for sign-in, session continuity, fraud prevention, security, preferences, feature state and performance. Optional analytics or communication technologies, if introduced, are used with the notice and choice required in your region.

You can control browser storage through your browser or available preference controls. Blocking essential technologies may prevent authentication, saved preferences or protected workspace features from functioning. The Collty Cookie Policy at collty.com/cookies provides the current technology list, purposes, providers and retention periods.

10

Retention and deletion

We keep personal information only for as long as reasonably necessary for the purpose collected, the active account or workspace relationship, contractual commitments, security, dispute resolution, and legal, tax or accounting requirements. Retention varies by category and context.

  • Account and subscription records are generally retained while the account is active and for a reasonable period afterward.
  • Workspace content follows customer instructions, account controls and applicable contractual retention settings, subject to legal holds and backup cycles.
  • Security, audit and abuse records may be retained longer where needed to protect the Service and users.
  • Public content may remain visible until deleted, made private or removed under platform rules; cached copies may take time to expire.
  • De-identified information may be retained where it cannot reasonably be linked back to an individual and is maintained in de-identified form.

Deletion from active systems may be followed by deletion from protected backups according to normal backup rotation, unless retention is legally required.

11

Security and confidentiality

Collty applies administrative, technical and organizational safeguards designed for the nature of the data and risk. These include authenticated workspaces, role and project authorization, secure transport, audit and abuse controls, environment separation, access limitation and incident-response processes.

Sensitive fields protected by Collty's secure-field layer use application-level AES-256-GCM authenticated encryption. Deterministic matching of protected identifiers uses keyed HMAC-SHA256 lookup values rather than exposing plaintext identifiers. Public discovery data is separated from private workspace data by server-side access boundaries.

No system is completely secure. You are responsible for protecting credentials, using appropriate workspace permissions and promptly reporting suspected unauthorized access to privacy@collty.com.

12

International transfers

Collty and its service providers may process information in countries other than where you live. Where required, Collty uses lawful safeguards such as adequacy decisions, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, and supplementary technical and organizational measures.

You may contact privacy@collty.com for information about the transfer safeguards applicable to your information, subject to confidentiality and security limitations.

13

Data-protection operations and evidence

Collty maintains versioned technical records for processing activities, data-protection impact assessments, service providers, international transfer reviews, retention rules, data-subject requests, privacy incidents and accountability controls. These records are protected from public and ordinary authenticated access and are available to authorized operators through service-role controls.

  • The processing register records purposes, data categories, data subjects, recipients, legal-basis assessments, expected transfers, retention references and accountable roles.
  • Technical DPIAs cover AI-assisted team assembly, Signals applicant ranking, Team Intelligence and task allocation. Legal approval and any required supervisory consultation remain separate recorded statuses.
  • The provider and transfer registers track public documentation, contract review, processing-region verification, transfer mechanism and transfer impact assessment status. Collty does not mark a contract, region or safeguard verified until evidence has been checked.
  • The retention register separates active-system rules, protected-backup rotation, legal holds and deletion methods. Enforcement status distinguishes implemented controls from work that still requires verification.
  • Authenticated privacy requests receive a recorded due date, status history and protected response. Collty normally responds without undue delay and within one month, subject to lawful verification, extension and exceptions.
  • Privacy incidents are recorded with confidentiality, integrity and availability impact, risk assessment and a 72-hour supervisory-notification clock where notification may be required.
  • DPO and EU-representative requirements are assessed against Collty's actual establishment, monitoring scale, processing and target markets. A role is not presented as appointed until the legal assessment and appointment are complete.

Evidence, not a certification claim

These controls support accountable GDPR operation and audit readiness. They do not by themselves constitute regulator approval, a legal opinion or formal certification. Entity details, contracts, regions, transfer safeguards and role appointments must remain accurate and are subject to documented review.

14

Your choices and privacy rights

Depending on your location and subject to legal exceptions, you may have rights to access, correct, delete, restrict or object to processing, receive a portable copy, withdraw consent, and complain to a supervisory authority. You may also have rights concerning automated decision-making.

  • Use profile, workspace and notification controls where available.
  • Submit and track an authenticated access, portability, rectification, erasure, restriction or objection request in My Account under Privacy & data.
  • Use the unsubscribe link for optional marketing; essential account, security and service messages will continue.
  • Contact privacy@collty.com with the account email and a clear request.
  • Use the in-product correction or report path, where available, to identify an AI-system error or inaccurate professional evidence associated with your own account.
  • An authorized agent may submit a request where permitted, but Collty may verify identity, authority and account ownership.
  • Collty will not discriminate against you for exercising a privacy right.

If Collty processes workspace information only on behalf of your organization, we may direct the request to that organization or assist it as required by contract and law.

15

Regional notices

EEA, United Kingdom and Switzerland

You may contact the competent data protection authority where you live or work. Before doing so, we invite you to contact privacy@collty.com so we can try to resolve the concern. Where required, Collty will identify an applicable representative or data protection contact in the relevant account or regional notice.

California and other United States privacy laws

Where applicable, residents may request to know or access categories and specific pieces of personal information, correct inaccurate information, delete information, obtain portability, and opt out of sale, sharing or targeted advertising. Collty does not sell personal information and does not share it for cross-context behavioral advertising.

The categories described in Section 3 are collected for the business purposes in Section 5 and disclosed to the recipient categories in Section 8. Collty does not knowingly sell or share personal information of users under 18. Requests are subject to verification and applicable exceptions.

16

Age requirement

Collty is a professional service intended only for people aged 18 or older and legally able to enter an agreement. We do not knowingly permit children to create accounts. If you believe a person under 18 provided personal information, contact privacy@collty.com.

17

Changes to this policy

We may update this policy as the Service, processing or law changes. The effective date identifies the current version. If a change materially affects how we use personal information, we will provide notice through the Service, email or another legally appropriate method before the change takes effect where required.

Prior versions are available on reasonable request. Continued use after an update does not replace any consent required by law.

18

Contact and complaints

Privacy requests

privacy@collty.com

Security and privacy reports

privacy@collty.com

General and legal notices

office@collty.com

Please do not send passwords, full payment credentials or unnecessary sensitive information by email. We may request additional information through a secure channel to verify and complete a request.