Who we are
StreamlineOS is a SaaS platform for HR, projects, CRM, chat, and analytics. We operate at www.streamlineos.in. When you sign up for an account, your organization is the controller of the data you put into StreamlineOS — we're the processor. When you visit our marketing site or talk to us through this site's forms, we're the controller.
The two roles are governed differently. This policy covers both — and we'll flag which is which when the answer depends on it.
What we collect
Plain English
The boring stuff you'd expect: an account email, your name, what you do inside the product, and the content you create. Nothing creepy, no hidden trackers.We collect three categories of information:
- Account data: name, work email, company, phone (optional), role. Provided by you at signup or when invited into a workspace.
- Content you create: employee records, projects, leads, messages, files, payroll runs — whatever you put into the product. This is your customer data; you own it. We hold it on your behalf.
- Operational data: IP address, browser, login timestamps, audit events, and the kind of feature-usage metrics we need to keep the platform fast and to debug issues. We don't use this for advertising.
We don't buy personal data from third parties, and we don't build behavioural ad profiles. The only third-party data we touch is what you choose to import (CSV uploads, Google Calendar events, etc.).
How we use it
Six purposes — that's the whole list.
- Run the product. Authenticate you, render your dashboard, deliver chat messages, generate payslips — the things you signed up for.
- Bill correctly. Track seat counts and invoice usage where the plan requires it.
- Support you. When you write to us, our team reads the message and replies. We don't outsource support to data brokers.
- Keep it secure. Detect suspicious logins, rate-limit abuse, run audit logs.
- Improve the product. Aggregate, de-identified usage stats — never individual user behaviour matched to a name.
- Comply with the law. When we have to.
We do not sell personal data. Full stop. No carve-outs, no “sharing for valid business purposes” that means selling, no behavioural ad networks.
Legal bases (GDPR)
If you're in the EU/UK, here are the GDPR Article 6 legal bases we rely on, mapped to each purpose:
- Contract — running the product, supporting you, billing you.
- Legitimate interest — security, fraud prevention, debugging. We've documented our LIA (legitimate interest assessment) and it's available on request.
- Legal obligation — responding to lawful requests, tax records, etc.
- Consent — only where required, e.g. optional analytics cookies and marketing emails. You can withdraw consent any time.
Subprocessors
We use a small, deliberate list of subprocessors. Adding one is a decision, not a default.
| Vendor | Purpose | Region |
|---|---|---|
| Neon (Postgres) | Primary database | AP Southeast 1 / your region |
| Cloudflare R2 | File storage (avatars, attachments, payslips) | Global |
| Zoho ZeptoMail | Transactional email (auth, notifications) | India |
| Ably | Realtime chat and presence | Global edge |
| Inngest | Background jobs and scheduled reports | US / EU |
| Upstash Redis | Rate limiting and session cache | Your region |
| OpenAI / Google AI | Optional AI features (you can disable) | US |
| Vercel | Hosting and edge delivery | Global |
We notify customers at least 30 days before adding a new subprocessor with access to customer data. Enterprise customers receive the notice via email; everyone else gets it from the changelog of this page.
How long we keep it
- Active accounts: as long as you're a customer plus the duration needed to fulfil legal obligations (typically 7 years for invoices in India).
- Closed accounts: all customer content is permanently deleted 90 days after account closure, unless legally required to keep it longer. You can request immediate deletion in writing.
- Operational logs: 13 months, then automatically purged.
- Contact form submissions: 24 months from your last interaction.
- Backups: 30 days rolling, automatically expired.
International transfers
Our primary region is AP Southeast 1 (Singapore). For customers in the EU, UK, or requiring data residency in their region, we offer dedicated infrastructure on the Enterprise plan.
Where personal data is transferred out of the EU/UK to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (2021) and supplementary measures described in our security documentation.
Your rights
Wherever you are, you can ask us to do the following with your personal data. If you're an end-user of one of our customers, we'll forward your request to the controller (your employer) since they hold the relationship with you.
- Access — get a copy of the data we hold about you.
- Correct — fix anything that's wrong.
- Delete — “right to be forgotten” subject to legal retention obligations.
- Port — export in a machine-readable format.
- Object — to any processing based on legitimate interest.
- Withdraw consent — wherever we relied on consent.
Email support@streamlineos.in with your request. We respond within 30 days, usually within 5.
How we protect it
A short summary lives here; the full picture is in our Security page. In brief: TLS 1.2+ in transit, AES-256 at rest, MFA available on every account, role-based access throughout, audited dependencies, and we don't store plaintext passwords (bcrypt with cost-factor 12).
Children
StreamlineOS is not intended for anyone under 16. We don't knowingly collect data from children. If a parent or guardian discovers their child has created an account, contact us and we'll delete it.
AI features
Several features (lead scoring, smart summaries, email drafts, attrition risk) call third-party LLM APIs — currently OpenAI and Google. When you use them:
- Prompts are scoped to the minimum context required for the feature. We don't send your whole database every time you ask for a summary.
- We've elected not to allow the provider to use submitted data to train their models, where the provider offers that option.
- AI features can be disabled at the organization level from Settings → AI.
- Enterprise customers may bring their own API key (BYOK) so the model traffic never traverses our infrastructure beyond proxying.
Changes to this policy
When we make a material change to this policy we'll email account owners at least 14 days before it takes effect. Minor edits (typo fixes, restructuring) are published silently, but you can always check the “effective” date at the top of the page.
Contact
Privacy questions, requests, complaints — write to support@streamlineos.in. For formal data protection enquiries, address them “Attn: Data Protection Officer.” If you're in the EU and unhappy with our response, you have the right to complain to your local supervisory authority.