Data Use
Last updated October 1, 2026
Scope
This page describes how Refline Technologies LLP ("Refline") handles the data your workspace and its agents touch: room content, memory, connected-tool records and credentials. It complements the Privacy Policy, which covers personal data, and forms part of the Terms of Service.
Room-scoped access
Agents can only see the tools and context connected to their room. A room connected to HubSpot and Gmail does not gain access to your LinkedIn or Notion unless you connect those too. Agents inherit the minimum scopes you grant per tool, per room, and cannot expand them on their own.
Room memory, briefs, learned context, decisions and history, belongs to the room that produced it. It is not shared across workspaces and is only readable by the people and agents you place in that room.
No training on your data
Your workspace content, room messages, account briefs, connected CRM records, sent and received outreach, memory and credentials, is never used to train models shared across customers. Where we use model providers to run agents, prompts and outputs are processed to serve your workspace, under provider terms that do not retain your data for their own model training.
Connected tools and credentials
OAuth tokens and API keys you connect are stored encrypted and used only to perform the actions your agents and approvals call for. You can revoke a connection at any time from workspace settings; the tokens are then destroyed and the data stops flowing.
Subprocessors
We use a small list of infrastructure, hosting, model and communication providers to run the Service. Each processes data only to deliver the Service and is bound by contractual data-protection terms no weaker than these. A current list of subprocessors is available on request, and we will give notice before adding one that materially changes how your data is handled.
Audit trail
Every agent action records its actor, inputs, outputs, approver and timestamp, and the activity feed for a room is the same trail the agents write to. Approval decisions are stored with the name of the human who made them.
Deletion
Disconnect a tool and its tokens are revoked and its data stops flowing. Delete a room and its memory is destroyed. Delete the workspace and everything goes with it, within 30 days, permanently, except records we must keep for legal, tax or accounting reasons, which are held no longer than required and never used for any other purpose.
Data Processing Agreements
If your organisation needs a signed DPA for compliance (GDPR or equivalent), contact us and we will provide our standard processor terms covering subject matter, duration, confidentiality, security measures, subprocessor consent, audit rights and deletion on termination.
Contact
Data questions or DPA requests:
Refline Technologies LLP
332, A Wing, Om 9 Square, 150 Feet Ring Rd, Circle,
Nana Mava, Rajkot, Gujarat 360003, India
data@reflineai.com