Privacy Policy

Last updated: March 29, 2026

1. Scope and Applicability

This Privacy Policy describes how RowsnColumns AI collects, uses, stores, and discloses personal data when you access our website, authentication flows, workspace features, support channels, and related services. It applies to customer users, trial users, visitors, and authorized administrators acting on behalf of an organization.

2. Categories of Data We Process

We may process account identifiers (name, email, user ID), authentication and session data, workspace metadata, prompts, workbook-level operations, generated outputs, audit trails, usage telemetry, and support communications. If your organization connects external systems, we may also process integration metadata required to complete requested actions.

3. Purposes of Processing

We process data to provide and secure the service, authenticate users, execute spreadsheet workflows, maintain auditability, prevent abuse, support billing and service operations, and improve reliability. We do not sell personal data.

4. Lawful Bases

Depending on jurisdiction, our lawful bases may include performance of a contract, legitimate interests (for security and service operations), compliance with legal obligations, and consent where required.

5. Sharing and Subprocessors

We may share data with hosting, infrastructure, analytics, authentication, and support vendors acting under contractual confidentiality and data protection obligations. Data may also be disclosed where required by law, court order, or valid government request.

6. Retention and Deletion

Data retention depends on account configuration, operational needs, and legal requirements. Workflow artifacts and logs are retained only as long as needed for service delivery, audit, security, and compliance, then deleted or de-identified in accordance with internal controls.

7. Security

We implement administrative, technical, and organizational safeguards designed to protect data against unauthorized access, loss, misuse, or alteration. No method of transmission or storage is fully risk-free, so we encourage customers to apply access controls and review policies within their own environments.

8. International Data Transfers

If data is transferred across borders, we use appropriate legal and contractual mechanisms required by applicable privacy laws.

9. Your Rights

Subject to local law, you may request access, correction, deletion, objection, restriction, or portability of your personal data, and may appeal decisions where applicable. Requests are handled in accordance with identity verification and legal requirements.

10. Children’s Data

The service is intended for business and professional use and is not directed to children under the age required by applicable law.

11. Policy Updates

We may revise this Policy from time to time. Material updates will be reflected by the "Last updated" date and, where required, additional notice.

12. Contact and Legal Requests

Privacy and legal requests can be sent to [email protected]. Please include your organization, request type, and relevant account identifier to help us process your request.