Skip to main content

Legal & Privacy

Privacy Policy

Effective Date: August 30, 2026Last Updated: August 30, 2026

infiSet (“infiSet”, “we”, “us”, or “our”) respects your privacy. This Privacy Policy explains how personal information is collected, used, stored, disclosed, and protected when you visit or use the infiSet website, application, workspaces, client portals, scheduling tools, document and signature features, integrations, and related services (collectively, the “Service”).

By using the Service, you acknowledge the practices described in this Privacy Policy.

1. Information We Collect

We collect information that you provide to us, information generated through your use of the Service, and information received from services you choose to connect.

Information you provide

Depending on the features you use, this may include:

  • name and email address;
  • phone number;
  • organization and business information;
  • account and profile information;
  • workspace and role information;
  • CRM contacts, leads, clients, projects, notes and related records;
  • scheduling and meeting information;
  • documents and files you upload or create;
  • information contained in documents you ask the Service to process;
  • electronic-signature information and signing evidence;
  • messages and support communications;
  • billing and transaction information;
  • information submitted through forms;
  • information provided when you request or use integrations; and
  • other information you voluntarily provide.

Information concerning other people

Customers may enter information about their own customers, clients, prospects, employees, contractors, meeting participants, signers, or other contacts.

When a customer uses infiSet to process such information on its behalf, the customer is responsible for determining the purposes of that processing and for providing any notices, obtaining permissions, and fulfilling any legal obligations applicable to that processing. infiSet processes such information only as necessary to provide the Service and according to the customer's instructions and applicable agreements.

Automatically collected information

We may automatically collect technical and usage information, including:

  • IP address and network information;
  • browser type and version;
  • operating system;
  • device type;
  • language and locale;
  • referring and exit pages;
  • dates and times of requests;
  • pages, routes, and features accessed;
  • authentication and security events;
  • error and diagnostic information;
  • performance information; and
  • identifiers used to maintain sessions and security.

2. How We Use Information

We use information as reasonably necessary to:

  • provide, operate, maintain, and improve the Service;
  • create and administer accounts and workspaces;
  • authenticate users and enforce authorization;
  • provide CRM, project, document, portal, scheduling, meeting, and workflow functionality;
  • synchronize information with integrations that you authorize;
  • create and update calendar events when requested;
  • send confirmations, reminders, service messages, and other transactional communications;
  • process subscriptions, payments, refunds, and related transactions;
  • provide electronic-signature functionality and maintain signing evidence;
  • provide AI-assisted features that you request;
  • provide customer support;
  • detect, investigate, and prevent fraud, abuse, unauthorized access, and security incidents;
  • monitor reliability and diagnose errors;
  • maintain backups and disaster-recovery systems;
  • comply with applicable legal obligations;
  • establish, exercise, or defend legal claims; and
  • protect the rights, safety, and security of infiSet, our users, and others.

We do not sell personal information.

3. Cookies and Similar Technologies

infiSet may use cookies, local storage, session storage, and similar technologies.

Some technologies are necessary for authentication, session management, security, request protection, application functionality, and service operation.

We may also use security and diagnostic technologies for abuse prevention, reliability, and performance.

Where non-essential analytics, advertising, or similar technologies are used, their use is subject to applicable law and any controls provided by the Service.

4. Cloudflare and Turnstile

infiSet uses Cloudflare services for infrastructure, application delivery, security, access protection, object storage, database-related infrastructure, asynchronous processing, and bot/abuse protection.

We may use Cloudflare Turnstile to help distinguish legitimate users from automated or abusive traffic. Turnstile may process information and security signals necessary for this purpose.

When Invisible Turnstile is used, Cloudflare requires reference to its Turnstile Privacy Addendum. The applicable addendum is available here: https://www.cloudflare.com/turnstile-privacy-policy/

Cloudflare Privacy Policy: https://www.cloudflare.com/privacypolicy/

5. Cloudflare Access

Certain environments and administrative areas may be protected by Cloudflare Access using email-based one-time passcodes.

When Access is used, information such as an email address, authentication event, session information, IP/network information, and security signals may be processed to authenticate and protect access.

Passing Cloudflare Access authentication does not by itself grant application-level administrator privileges.

6. Cloudflare R2, D1, Queues, Workers and Hyperdrive

Cloudflare Workers may execute application requests and related server-side processing.

Cloudflare R2 may be used for application objects, generated files, media, and encrypted production backup storage.

Cloudflare D1 and Queues may be used for supporting application data and asynchronous processing.

Cloudflare Hyperdrive may be used to provide optimized connectivity between the application and the applicable PostgreSQL database environment.

Separate infrastructure is maintained for staging and production. Local development may use local emulation rather than production infrastructure.

7. Neon PostgreSQL

Neon PostgreSQL is used as the application's PostgreSQL database infrastructure.

Depending on the Service and your use of it, information stored in the database may include account records, workspace information, CRM records, projects, meetings, documents and file metadata, payment metadata, permissions, integrations, audit records, configuration, and workflow information.

Neon Privacy Policy: https://neon.tech/privacy-policy

8. Google OAuth, Google Calendar and Google Drive

infiSet may allow you to connect Google services, including Google authentication, Google Calendar, and Google Drive.

When you connect a Google account, we receive and process the information made available through the permissions you authorize. Depending on the integration, this may include basic account/profile information, calendar availability and event information, and Drive files or folders that the authorized integration is permitted to access.

We request permissions appropriate to the functionality being used and aim to use the minimum access reasonably necessary.

Google information is used to provide the Google-connected functionality you request. We do not sell Google user data.

We do not use Google user data for unrelated advertising.

We do not intentionally use Google user data for purposes unrelated to the feature for which you granted access.

You may revoke Google's access through your Google account controls and/or disconnect the integration from infiSet.

Google API Services User Data Policy: https://developers.google.com/terms/api-services-user-data-policy

Google OAuth policies: https://developers.google.com/identity/protocols/oauth2/policies

9. Scheduling and Calendar Data

infiSet provides its own scheduling interface and may communicate with connected calendar providers to determine availability and create, update, or cancel calendar events when requested.

Scheduling information may include meeting title, participants, date and time, timezone, availability information, calendar event identifiers, meeting status, and related workflow information.

Third-party calendar providers may independently change or cancel events or experience outages. Such provider activity may affect the information available to infiSet.

10. Google Drive and External Storage

Where external-storage functionality is enabled, infiSet may connect to storage controlled by you.

The external provider remains responsible for its own storage service, availability, security, and policies.

Depending on the feature, infiSet may store identifiers, metadata, permissions information, OAuth credentials/tokens, or other integration information necessary to operate the connection. We do not intentionally copy an entire connected storage account into infiSet unless a feature expressly requires such copying.

11. Resend and Email

infiSet uses email infrastructure, including Resend, to deliver transactional and service-related communications.

Depending on the message and configuration, email processing may involve sender and recipient addresses, names, message content, attachments, timestamps, delivery status, bounce information, complaint information, and related delivery metadata.

Email may be used for account and authentication messages, scheduling confirmations and reminders, document and signing notifications, payment messages, security notices, support communications, and other service communications.

12. Razorpay and Payments

Paid features may use Razorpay for payment processing.

Razorpay and its payment partners may process payment information necessary to authorize and complete transactions. infiSet may receive transaction and billing information such as customer/order identifiers, payment identifiers, amount, currency, payment status, timestamps, refund status, subscription information, and payment-method metadata.

Unless expressly stated otherwise, infiSet does not intentionally store complete card numbers, CVV/CVC values, UPI PINs, banking passwords, or other payment authentication secrets in its ordinary application database.

Payment-provider terms and privacy practices apply to payment processing performed by the provider.

Razorpay Privacy Policy: https://razorpay.com/privacy-policy/

13. AI-Assisted Features

infiSet may provide AI-assisted functionality for drafting, summarization, extraction, classification, document processing, communication assistance, workflow assistance, and other features.

When you use an AI feature, the information sent to the applicable AI service may include your prompt, selected records, document excerpts, relevant application context, and other information reasonably necessary to provide the requested result.

AI requests are designed to use only information necessary for the requested operation.

The exact AI provider and model used may vary by feature. AI services are subject to their applicable terms and privacy practices.

AI output may be inaccurate, incomplete, outdated, or unsuitable for a particular purpose. Users should review important AI-generated information before relying on it.

14. Bring Your Own Key

Where infiSet supports BYOK functionality, credentials supplied by you are treated as confidential credentials and are intended to be used only for the integration you authorize.

We take reasonable measures to prevent credentials from being unnecessarily exposed through the user interface or ordinary logs. You remain responsible for having the right to use the credential and for charges imposed by the applicable provider.

15. Electronic Signatures and Timestamping

Where electronic-signature functionality is provided, infiSet may process signer names, email addresses, documents, signature actions, timestamps, IP addresses, browser/device information, authentication information, and audit-trail information necessary to provide and evidence the signing workflow.

Where an RFC 3161 timestamp authority is used, timestamping may process the cryptographic hash or other information required to create timestamp evidence.

An RFC 3161 timestamp does not by itself establish every fact concerning the identity, authority, consent, or legal validity of an underlying transaction.

16. Lark

infiSet may use Lark for internal operational communication, notifications, alerts, and incident workflows.

Information sent through such systems is intended to be limited to information reasonably necessary for internal operations, including event identifiers, technical diagnostics, operational metadata, alerts, and limited account or workspace identifiers.

We configure operational notifications to avoid unnecessarily sending customer content.

17. Sentry

infiSet may use Sentry for error monitoring, diagnostics, and performance monitoring.

Depending on configuration, diagnostic information may include technical identifiers, account identifiers, browser/device information, request metadata, error messages, stack traces, route information, performance information, and timestamps.

We configure diagnostic systems to minimize unnecessary personal information and to avoid exposing passwords, authentication secrets, payment credentials, and other sensitive secrets through ordinary telemetry.

Sentry legal information: https://sentry.io/legal/

18. Better Stack

infiSet may use Better Stack for production availability, monitoring, and operational incident management.

Monitoring may involve hostnames, domains, timestamps, status information, technical/network information, and monitoring metadata.

Better Stack is not intended to receive ordinary customer document content merely as a result of service availability monitoring.

Better Stack legal information: https://betterstack.com/legal/

19. GitHub and CI/CD

GitHub is used for source control, code review, deployment automation, and operational workflows.

GitHub Actions may execute application deployment and production backup workflows.

GitHub may process repository information, source code, commits, pull requests, workflow logs, deployment metadata, and encrypted repository/environment secrets.

Production secrets are not intended to be committed to the source repository.

GitHub Privacy Statement: https://docs.github.com/en/site-policy/privacy-policies/github-privacy-statement

20. Backups

Production data may be backed up through automated workflows.

Production database backups may be encrypted before being stored in dedicated Cloudflare R2 backup storage. Backup storage is separate from ordinary active application storage.

Because backups exist for disaster recovery, a record deleted from active systems may remain temporarily in an encrypted backup until that backup reaches the applicable retention/deletion lifecycle.

Backups are protected using access controls and are not intended to be publicly accessible.

21. Security

We use reasonable technical and organizational safeguards appropriate to the nature of the information processed.

These measures may include encryption in transit, access controls, least-privilege permissions, environment separation, protected CI/CD environments, secret management, authentication controls, security monitoring, audit logs, backup encryption, and restricted administrative access.

No internet-based service can guarantee absolute security.

22. Data Sharing

We do not sell personal information.

We may disclose information to:

  • infrastructure and hosting providers;
  • payment processors;
  • email delivery providers;
  • authentication, calendar, and storage providers that you authorize;
  • AI providers when required for an AI feature you use;
  • security, monitoring, and abuse-prevention providers;
  • electronic-signature and timestamping providers;
  • professional advisers;
  • authorities or other parties when legally required or permitted;
  • parties involved in a merger, acquisition, restructuring, financing, or sale of relevant assets; and
  • other parties when you direct or authorize us to do so.

We expect service providers processing information on our behalf to use appropriate contractual and security safeguards.

23. International Processing

Our service providers may process information in countries other than the country in which you reside.

Where required by applicable law, we use appropriate contractual or other safeguards for international transfers.

24. Data Retention

We retain information for as long as reasonably necessary to provide the Service, maintain security, complete transactions, meet legal and accounting obligations, resolve disputes, prevent fraud, enforce agreements, and maintain appropriate disaster-recovery systems.

Different information may have different retention periods.

Account and Customer Data are generally retained while an account or applicable customer relationship remains active, subject to deletion controls and contractual terms.

Payment, accounting, security, audit, legal, and backup records may be retained for longer where reasonably necessary or legally required.

25. Deletion

You may request deletion of personal information by contacting us at the privacy contact associated with your infiSet account or using available account controls.

Deletion may be delayed or limited where information must be retained for legal, accounting, security, fraud-prevention, dispute-resolution, contractual, or backup purposes.

Encrypted disaster-recovery backups may retain deleted information until their normal lifecycle expires.

26. Privacy Rights

Depending on where you live and applicable law, you may have rights to:

  • request access to personal information;
  • request correction of inaccurate information;
  • request deletion;
  • request restriction of processing;
  • object to certain processing;
  • withdraw consent where processing is based on consent;
  • request portability of certain information; and
  • receive information about how your information is processed.

Requests may require reasonable identity verification.

27. Customer Responsibilities

If you use infiSet to process information about other people, you are responsible for:

  • collecting and using information lawfully;
  • providing required privacy notices;
  • obtaining required consent or other authorization where applicable;
  • configuring user and workspace permissions correctly;
  • responding to requests from individuals where you are the responsible organization;
  • maintaining appropriate internal security; and
  • not submitting information that you are prohibited from processing.

28. Sensitive Information

Unless a particular feature expressly supports it, you should not intentionally submit passwords, payment authentication secrets, private encryption keys, government authentication secrets, or other highly sensitive information that is unnecessary for the Service.

29. Children's Privacy

infiSet is intended primarily for business and professional use and is not directed to children.

We do not knowingly seek to collect children's personal information in violation of applicable law.

30. Third-Party Websites

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of third parties that operate independently from infiSet.

31. Business Transfers

If infiSet is involved in a merger, acquisition, financing, restructuring, or sale of assets, information may be transferred as part of that transaction subject to applicable law.

32. Legal Disclosures

We may disclose information where reasonably necessary to comply with law, respond to lawful requests, enforce agreements, investigate fraud or security incidents, protect users or the public, or protect our rights and property.

33. Changes to this Privacy Policy

We may update this Privacy Policy when our Service, integrations, processing activities, legal obligations, or security practices change.

The “Last Updated” date will be changed when an update is published.

Where required by law, we will provide additional notice or obtain consent.

34. Contact

For privacy questions, requests, or complaints, please contact us through the privacy or support contact information provided on the infiSet website.

Privacy contact: privacy@infiset.com

Website: https://infiset.com

Third-Party Privacy Resources