Services Privacy Policy
This policy describes how SuperApp, Inc. collects, uses, discloses, transfers, retains and protects personal information in connection with its technical support, hosted and other services.
Introduction
SuperApp, Inc. (“SuperApp,” “we,” “us,” or “our”) provides this Services Privacy Policy to explain how we collect, use, disclose, transfer, retain, and protect personal information in connection with the technical support services, hosted services, and other services that we provide to SuperApp customers (collectively, the “Services”).
If you have questions about our use of your personal information, please contact us using the details provided below.
We may update this Services Privacy Policy from time to time. When we do, we will revise the effective date shown at the beginning of the policy and provide any additional notice required by applicable law. We encourage you to review this policy periodically. You may request notice of updates by emailing trust@superapp.chat.
Website privacy. This Services Privacy Policy does not describe our collection, use, or disclosure of personal information when visitors access our website at superapp.chat. For information about our website practices, please review the Website Privacy Policy posted on our website.
Who We Are
SuperApp provides an AI collaboration platform that brings real-time group messaging, leading AI models, and collaborative content creation into one shared workspace. SuperApp is headquartered in San Francisco, California, and operates globally. For more information, visit superapp.chat.
If you are located in the European Economic Area (“EEA”), the United Kingdom (“UK”), or Switzerland, SuperApp, Inc. is the controller of the personal information described in this policy, except where we process personal information solely on behalf of a customer.
What This Policy Covers
This Services Privacy Policy explains how we use your personal information for our own business purposes in connection with the Services.
This policy applies, for example, if you use the Services as an authorized user under a customer account, typically an account maintained by your employer (a “User”). It also applies to the limited extent that we process personal information appearing in text, images, files, data, or other content submitted through the Services (“Content”) for our own purposes, as permitted by our agreements and applicable law.
This policy does not apply to the practices of organizations that we do not own or control. It also does not govern personal information that we process solely as a processor or service provider on behalf of a customer, or personal information processed exclusively within a customer’s systems and environments.
When a customer submits Content in connection with the Services, we generally process that Content under the customer’s instructions and on the customer’s behalf. Questions or requests concerning such processing should be directed to the relevant customer and will be governed by that customer’s privacy notices and policies.
We are not responsible for the privacy practices of our customers or other third parties, which may differ from the practices described here.
Information We Collect Through the Services
Depending on how you interact with the Services, we may collect personal information that you provide directly, information provided by customers or other third parties, and information collected automatically through cookies and similar technologies.
Information that you provide
If you are a User, you may provide personal information when you create an account, contact customer support, send us an email or otherwise communicate with us. Categories include:
- Business contact information, such as your name, job title, organization, email address, and company;
- Account login credentials, such as an email address or username and password;
- Troubleshooting and support data, including information submitted with support requests and the content of communications with us;
- Payment information, such as credit card numbers, associated identifiers and billing address;
- Marketing information, such as contact and marketing preferences; and
- Inquiries and feedback, including contact information and communications with us.
We use this information to provide, operate, maintain, secure, and improve the Services; administer accounts; communicate with you; respond to requests; and, where permitted by law, send information about products and services that may be of interest to you.
You may choose which personal information to provide, but certain information may be necessary for us to perform our contractual obligations or provide the requested Services.
Information from customers and other sources
We may receive personal information from the SuperApp customer that administers your account, from other Users, from identity and integration providers, and from service providers that help us operate the Services. This information may include account, organizational, authentication, support, and integration-related information.
Our use and transfer of information received from Google APIs to any other application will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
Information collected automatically
When you use the Services, we may automatically collect information relating to performance, configuration, and usage, including:
- Log data, such as IP address, browser or device type, operating system, domain name, device identifiers and referring website addresses;
- Usage data, such as timestamps, pages viewed, searches and other actions, features used and interaction metrics; and
- Location data, which may be inferred from an IP address.
We use this information to provide, support, secure, and operate the Services; diagnose and resolve technical issues; understand usage; and analyze, develop, and improve our products and services.
Information processed on behalf of customers
Customers may submit Content to us for processing. We do not control the Content customers choose to submit. It may include:
- Identification and contact data, such as names, addresses, titles and contact details;
- Financial data, such as information in bank statements, pay slips and financial or tax documents; and
- Health data, such as information in health records, lab reports, x-rays and insurance claims.
We generally process Content under our customers’ instructions and in accordance with our agreements with them. Customers are responsible for the Content they submit, including correcting, deleting, or updating that Content and providing any notices or obtaining any consents required by applicable law.
Where permitted by applicable law and expressly authorized by the relevant customer, we may use certain Content to improve or develop Service functionality. To the extent that such Content constitutes personal information, we process it in accordance with this policy and applicable law.
How We Use Your Personal Information
We use personal information to provide, administer, secure, support, and improve the Services; communicate with you; comply with legal obligations; and conduct legitimate business activities, including analyzing product usage. If you are located in the EEA or UK, the legal basis for processing depends on the information involved and the context in which it is processed.
Depending on the circumstances, we process personal information as necessary to enter into or perform a contract; to pursue our or a third party’s legitimate interests, where those interests are not overridden by your rights and interests; to comply with legal obligations; or with your consent.
| Personal information | Business purpose | Legal basis in EEA / UK |
|---|---|---|
| Business contact information; account credentials; inquiries and feedback | Provide the Services; create, administer, and manage accounts; and provide requested features and functionality | Performance of a contract; legitimate interests; consent, where applicable |
| Business contact information | Respond to inquiries and support requests and send technical notices, service updates, security alerts, and administrative messages | Performance of a contract; legitimate interests; consent, where applicable |
| Payment information | Process payments and maintain transaction and billing records | Performance of a contract; compliance with legal obligations |
| Business contact information; marketing information; inquiries and feedback; location data | Send marketing communications in accordance with your preferences; conduct marketing research, contests, surveys, and sweepstakes; and, where permitted, present relevant offers | Legitimate interests; consent, where required |
| Troubleshooting and support data | Understand, diagnose, and resolve issues with the Services | Performance of a contract; legitimate interests |
| Business contact information; account credentials; payment information | Enforce applicable terms and policies; detect and prevent fraud or abuse; and establish, exercise, or defend legal claims | Legitimate interests; compliance with legal obligations |
| Log, usage, and location data | Analyze usage and trends; secure, improve, and develop the Services; and use aggregated or de-identified information to develop features, capabilities, or products | Legitimate interests; consent, where required |
| Content | Provide the Services and perform activities authorized by the relevant customer | Performance of a contract; legitimate interests; compliance with legal obligations |
How We Disclose Personal Information
We may disclose personal information to the following categories of recipients for the purposes described in this policy:
- Affiliates, service providers, and partners. We may disclose information to our affiliates and to third-party service providers and partners, including subprocessors listed in superapp-subprocessors.document, that provide hosting, infrastructure, support, payment processing, security, analytics, communications, or other services. This may include third-party AI or cognitive service providers used to process user-initiated requests. Information provided to those providers is limited to what is reasonably necessary for the applicable purpose, subject to customer configuration, applicable agreements, and law;
- Legal and safety recipients. We may disclose information to law-enforcement bodies, regulators, government agencies, courts, professional advisers, or other third parties when disclosure is required or permitted by law, necessary to establish, exercise, or defend legal claims, or necessary to protect the rights, property, safety, or vital interests of any person;
- Transaction participants. We may disclose information to an actual or potential buyer, investor, lender, and their respective agents and advisers in connection with a proposed or completed financing, reorganization, sale, merger, acquisition, or other transfer of all or part of our business or assets, subject to appropriate confidentiality and use restrictions; and
- Other recipients at your direction. We may disclose information to any other person at your direction or with your consent.
SuperApp does not sell personal information. We contractually require service providers that process personal information on our behalf to use it only for specified purposes and to protect it in accordance with applicable law.
International Data Transfers, Security, and Retention
Data transfers
SuperApp is headquartered in the United States. The Services may be provided and hosted in the United States and in other countries where SuperApp, our affiliates, service providers, and partners operate. Your personal information may therefore be transferred to and processed in countries whose privacy laws differ from, and may provide a different level of protection than, the laws in your country.
When SuperApp transfers personal information across borders, we take appropriate steps to protect it in accordance with this policy and applicable privacy and data-protection laws.
These measures may include standard contractual clauses approved by the European Commission, applicable UK transfer mechanisms, additional safeguards where necessary, and comparable contractual and organizational protections with service providers and partners.
Information security
We maintain administrative, technical, and organizational safeguards designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Data retention
We retain personal information for as long as we have an ongoing legitimate business need to do so—for example, to provide the Services, comply with legal, tax or accounting requirements, resolve disputes, or as otherwise permitted or required by law.
When there is no ongoing legitimate need to process personal information, we will delete or anonymize it. If deletion is not immediately possible, such as when information is stored in backup archives, we will securely store and isolate the information from further processing until deletion is possible. We may retain aggregated or de-identified information that cannot reasonably be used to identify you.
Information for California Consumers
This section applies to California residents and supplements the other provisions of this policy. “Personal information” has the meaning given by the California Consumer Privacy Act of 2018, as amended (the “CCPA”), and does not include information that is exempt from the CCPA.
During the preceding 12 months, depending on how individuals interacted with the Services, we may have collected the following CCPA categories from individuals, from a SuperApp customer or other third party, or automatically from a device:
- Identifiers, such as name, job title, organization, email address, company, username, and IP address;
- Commercial information, such as marketing information, troubleshooting and support data, inquiries, and feedback;
- Internet or other electronic network activity information, such as browser or device type, operating system, domain name, device identifiers, referring website addresses, and usage data;
- Financial information, such as payment and billing information;
- Geolocation data, such as city, state, and country inferred from an IP address; and
- Sensitive personal information, such as account login credentials and payment-card information, where applicable.
We use and retain these categories for the business and commercial purposes described in “How We Use Your Personal Information,” and we disclose them for business purposes to the categories of recipients described in “How We Disclose Personal Information.” We retain each category only for as long as reasonably necessary and proportionate for the disclosed purposes, subject to the considerations described in “International Data Transfers, Security, and Retention.”
SuperApp does not sell personal information. If any activity constitutes “sharing” under the CCPA, California residents may exercise the applicable opt-out right by contacting us as described in “How to Exercise Your Rights.”
Your Rights
You may have rights and choices regarding your personal information. Available rights depend on your location and applicable law and may include rights of access, correction, deletion, objection or opt-out, restriction, withdrawal of consent, and portability.
EEA, UK, and Swiss privacy rights
If you are located in the EEA, UK, or Switzerland, your rights may include:
- Access: request information about personal information we process and a copy of that information;
- Correction: request correction or updating of inaccurate or incomplete information;
- Deletion: request deletion of some or all personal information from our systems;
- Objection: object in certain circumstances to processing based on legitimate interests or for direct marketing purposes;
- Withdraw consent: withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing;
- Restriction: ask us to restrict processing in certain circumstances; and
- Portability: request a machine-readable copy and, where applicable and technically feasible, transmission to another controller.
If you are not satisfied with how we process personal information or handle a request, you may lodge a complaint with the data-protection or supervisory authority in your country or region.
California rights
If you are a California resident, rights under the CCPA may include:
- Right to know and access: request information about the categories and specific pieces of personal information we have collected, the sources of that information, the purposes for collecting or disclosing it, and the categories of recipients to which it was disclosed;
- Right to delete: request deletion of personal information collected from you, subject to applicable exceptions;
- Right to correct: request correction of inaccurate personal information that we maintain about you;
- Right to opt out: opt out of the sale or sharing of personal information, if applicable;
- Right to limit: limit certain uses and disclosures of sensitive personal information, if applicable; and
- Right to non-discrimination: receive equal service and pricing and not be retaliated against for exercising your privacy rights.
SuperApp does not sell personal information. We will not discriminate or retaliate against you for exercising a privacy right. We do not offer financial incentives related to the collection, use, or disclosure of personal information unless the material terms are separately disclosed as required by law.
How to exercise your rights
To exercise rights under applicable data protection laws, or if you are an authorized agent acting on another person’s behalf, contact trust@superapp.chat. We will respond in accordance with applicable legal requirements.
We may verify your identity using a method appropriate to the nature of the request. An authorized agent may be required to provide evidence of authority, and we may contact you directly to confirm your identity and permission. We may deny or limit a request where permitted by law, including if we cannot verify the requester’s identity or locate the relevant person in our systems.
Where we process personal information as a processor or service provider for a customer rather than as a controller, please direct the request to the relevant customer. Questions about your rights may be sent to trust@superapp.chat.
Children’s Privacy and Contact Information
Children’s privacy
The Services are not directed to or intended for use by children under 18. If you are under 18, do not attempt to register for the Services or send us personal information.
If a parent or guardian becomes aware that a child has provided personal information to us, please contact trust@superapp.chat. If we learn that a child under 18 has provided personal information in violation of this policy, we will take appropriate steps to delete it, subject to applicable law.
Privacy inquiries and requests
To ask a question, raise a concern, or submit a privacy-rights request, contact the SuperApp Privacy Team at trust@superapp.chat. Please do not include passwords, payment-card numbers, health information, or other sensitive information in an unencrypted email.