1. Our roles
Cain Family Insurance operates CleanIQ. For account, billing, product-usage, security, and support data, CleanIQ generally decides why and how the data is used. For CRM data a customer connects, CleanIQ acts on that customer’s instructions as a service provider or processor.
2. Data we collect
We collect account and team information; authentication and security events; organization and subscription records; device, IP, and request logs; encrypted connector credentials; CRM identifiers and data needed for scans; findings, approvals, write-back, audit and job history; support tickets; and Calia conversations, proposed actions, and approvals. Stripe provides billing identifiers and status; CleanIQ does not store full payment-card numbers.
3. Sources
Data comes from you and your team, connected CRM providers, authentication providers, Stripe, service logs, and communications with support or Calia.
4. Why we use data and lawful bases
We use data to create and secure accounts; connect CRMs; run scans and approved corrections; enforce plan limits; process billing; send transactional messages; provide support; investigate incidents; prevent fraud and abuse; comply with law; and improve and develop reliability and customer experience. Where GDPR or similar law applies, the lawful basis may be performance of a contract, steps requested before entering a contract, compliance with a legal obligation, or legitimate interests such as securing, operating, supporting, and improving the service. Consent is used where required and may be withdrawn without affecting prior lawful processing.
5. Service providers and integrations
We disclose only the data reasonably necessary to providers listed on the Subprocessor List. Customer-selected CRMs are customer-directed integrations. We may also disclose data when legally required, to protect rights or safety, or during a business transaction subject to appropriate safeguards.
6. Calia and OpenAI
Calia sends a limited, credential-free task context and recent conversation to the OpenAI API. CleanIQ requests that Responses API content not be stored by setting
store: false. OpenAI states that API inputs and outputs are not used to train its models by default unless the customer opts in, although limited abuse-monitoring retention may apply under OpenAI’s terms. Do not place secrets or restricted data in Calia prompts.7. Sale, sharing, and advertising
CleanIQ does not sell personal information and does not share it for cross-context behavioral advertising. CleanIQ does not use third-party advertising cookies. Necessary cookies and similar storage support authentication, security, preferences, and checkout flow.
8. Retention and deletion
CleanIQ retains data only as reasonably necessary for the service, security, audit, billing, dispute, and legal purposes. Retention varies by record type and contract. A verified account-deletion request removes or de-identifies eligible data, subject to legal obligations, security logs, payment records, active disputes, and customer instructions. Audit and security logs may be retained after account deletion when reasonably necessary for security, fraud prevention, legal compliance, or dispute evidence. The CRM remains the system of record.
9. Security
CleanIQ uses TLS in transit, server-side encryption for connector credentials, access controls, tenant-scoped authorization, audit logging, rate controls, approval gates, secure cookies, and secret-management practices. No security measure eliminates all risk. See the Security Overview.
10. Privacy rights
Depending on where you live and applicable law, you may request access, correction, deletion, or portability; object to or restrict certain processing; appeal a denied request; or opt out of sale, sharing, or targeted advertising. CleanIQ does not currently sell or share data for targeted advertising. We may verify identity and authority before acting and will not discriminate for exercising applicable rights.
11. California notice
California residents may have rights to know, correct, delete, and receive information about categories of collection and disclosure. CleanIQ does not sell or share personal information as those terms are used for cross-context behavioral advertising. Authorized agents may submit requests subject to identity and authority verification.
12. Children
CleanIQ is a business service for users 18 and older and is not directed to children. Do not connect or submit children’s data unless you have first obtained written confirmation that the use is supported and lawful.
13. International transfers
CleanIQ and its providers may process data in the United States and other locations where they operate. Where applicable and available, CleanIQ may use recognized transfer mechanisms such as the European Commission’s Standard Contractual Clauses or another lawful safeguard. Customers are responsible for determining whether their use requires a Data Processing Addendum or additional transfer terms.
14. Requests and changes
Send privacy requests to [email protected]. We may update this Notice as the service or law changes and will post the updated date and provide additional notice when legally required.
