§Legal
Privacy Policy.
Please read this policy carefully before using our service.
✓Summary
Your Data
You own your data. We never sell it to third parties.
Security
We use industry-standard encryption to protect your information.
Transparency
We are transparent about what data we collect and why.
Your Rights
You can access, export, or delete your data at any time.
This summary is for reference only and does not replace the full privacy policy.
1. Information We Collect
Information You Provide
- Account Information — Name, email, password
- Business Data — Company details, contacts, deals
- Payment Information — Billing details (processed by Stripe)
- Communications — Support messages, feedback
Information We Collect Automatically
- Usage Data — Features used, time spent
- Device Information — Browser, OS, IP address
- Cookies — Session and preference cookies
- Server Logs — Access logs, error logs
Location Data
With your permission, the ILORA mobile app may collect your device's precise and approximate location to validate attendance, record work-session metadata, and enable location-based features. You can revoke this permission at any time in your device settings.
2. How We Use Your Information
We use your information for the following purposes:
- Provide and maintain the Service
- Process transactions and send notifications
- Improve and personalize user experience
- Analyze usage patterns and trends
- Communicate updates and marketing
- Detect and prevent fraud
- Comply with legal obligations
- Provide customer support
3. How We Share Your Information
We do not sell your personal information. We may share your data in the following circumstances:
- Service Providers — Third-party vendors who help us operate the Service (e.g., hosting, payment processing).
- Legal Requirements — When required by law or to protect our rights.
- Business Transfers — In connection with a merger, acquisition, or sale of assets.
- With Your Consent — When you explicitly agree to share your information.
4. Data Security
We implement industry-standard security measures to protect your data:
- Encryption — Data is encrypted in transit (TLS) and at rest (AES-256).
- Access Control — Strict role-based access controls for employees.
- Regular Audits — Frequent security assessments and vulnerability scans.
Important Note: No system is 100% secure. We continuously work to improve our security measures.
5. Your Privacy Rights
You have the following rights regarding your personal data:
- Access — Request a copy of your personal data.
- Rectification — Correct inaccurate or incomplete data.
- Erasure — Request deletion of your data.
- Portability — Export your data in a structured format.
- Restriction — Limit how we process your data.
- Objection — Object to certain data processing.
6. Data Retention
We retain your data as follows:
- After Cancellation — 30 days for data export, then deleted
- Backups — Up to 90 days in encrypted backups
- Legal Requirements — Retained as required by law
- Analytics Data — Anonymized data retained indefinitely
7. International Data Transfers
Your data may be transferred to and processed in countries outside your residence.
We ensure appropriate safeguards are in place to protect your data in accordance with this Privacy Policy.
8. Cookies & Tracking
We use cookies and similar technologies:
- Essential Cookies — Required for the Service to function
- Analytics Cookies — Help us improve the Service
9. Children's Privacy
Our Service is not intended for children under 18. We do not knowingly collect data from children.
10. Changes to This Policy
We may update this policy. Changes will be communicated via:
- Email notification
- In-app notification
- Update notice on this page
11. Contact Us
If you have questions about this Privacy Policy, please contact us:
- Email — privacy@ilora.app
- Data Protection Officer — dpo@ilora.app
We will respond to your inquiry within 30 days.
12. AI Usage & Data Governance
As a forward-looking Enterprise platform, ILORA integrates Artificial Intelligence to accelerate workflows. Our AI Governance model ensures that convenience never compromises privacy.
- OpenAI Zero Data Retention — Your data is processed ephemerally and is NOT used to train AI models.
- Live AI Data Masking (PII Scrubbing) — Automatic redaction of personal information before AI processing.
- EU AI Act Compliance & Audit Logging — Human-In-The-Loop authorization for high-risk AI with full audit trails.
13. Regulatory Compliance
- GDPR — Full compliance with EU General Data Protection Regulation.
- CCPA — California Consumer Privacy Act compliant.
?FAQ