Privacy Policy
How Resulticks Solution Inc protects and manages your personal data across the Collab Service.
This Privacy Policy explains how Resulticks Solution Inc (“Resulticks,” “we,” “us,” or “our”), part of the Resulticks group, with its office at 607 Third Avenue, New York, NY 10017, United States (“Company”), collects, uses, discloses, and protects personal data in connection with Collab, a Resulticks product — our enterprise team-collaboration platform (messaging, voice/video calls and meetings, screen-share, file sharing, tasks, calendar, and related features), including the Collab web application, desktop application, and mobile applications for iOS and Android (together, the “Service”).
Collab is one of the products in the Resulticks portfolio. Your use of the Collab Service is also subject to the overarching Resulticks Privacy Policy; this Policy supplements that policy with details specific to the Collab Service, and in the event of a direct conflict on a Collab-specific matter, this Policy controls for that matter.
This Policy reflects the requirements of the EU/UK GDPR, the California Consumer Privacy Act (“CCPA/CPRA”), and India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) as a general baseline. Resulticks participates in the EU-U.S. Data Privacy Framework and the UK Extension to the EU-U.S. DPF, as described in the Resulticks Privacy Policy. Where a right or obligation applies only under a specific law, this is noted.
By creating an account, being provisioned an account by your organization, or otherwise using the Service, you acknowledge that you have read and understood this Policy.
1. Definitions
- “Organization” — the company, team, or workspace an individual User belongs to within Collab.
- “Admin” — an individual granted administrative rights over an Organization’s Collab workspace.
- “User” / “you” — any individual who accesses or uses the Service, whether self-registered or provisioned by an Admin.
- “Content” — messages, files, recordings, calendar entries, tasks, reactions, and any other data a User submits, uploads, or generates through the Service.
- “Personal Data” — any data that identifies or is reasonably capable of identifying a natural person.
2. Our Role: Who Controls Your Data
Collab is operated by Resulticks as the data controller for account, billing, and platform-usage data. For Content submitted within an Organization’s workspace, your Organization’s Admin sets workspace-level policies (retention, security settings, member access, integrations) — Resulticks processes that Content to provide the Service and in accordance with your Admin’s configuration. If you were provisioned an account by an employer or other organization, that organization may also independently control how it uses information it can access through the Service (see Section 12 — Notice to Employees / Organization Members).
3. Data We Collect
We collect the following categories of data to provide the Service: account and identity data; communications content; calls and meetings data; presence and activity data; device and technical data; organization data; and support data. This data is provided by you, generated automatically as you use the Service, or supplied by your Organization’s Admin or identity provider.
We do not knowingly collect sensitive personal data (e.g., health, financial account, or biometric data) except where a User voluntarily includes it in Content, which is that User’s — and their Organization’s — responsibility.
4. How We Use Data
We use Personal Data to provide and maintain the Service, authenticate and secure accounts, provide customer support, improve reliability and performance, comply with legal obligations and lawful Admin-configured policies, and — where separately enabled by your Organization — provide optional AI-assisted features (Section 5).
Legal bases (GDPR): performance of a contract (providing the Service to your Organization), legitimate interests (security, service improvement), legal obligation, and consent (for optional features such as AI summaries or non-essential cookies). Under the DPDP Act, processing is based on your consent at account creation/provisioning or another legally recognized ground (e.g., an existing employment relationship where your Organization directs use of the Service).
5. Optional AI-Assisted Features
Collab includes AI-assisted features (e.g., conversation/message summarization) that are disabled by default and must be explicitly enabled by your Organization’s Admin. When enabled, the relevant message content is sent to large-language models to generate the requested output. Content sent for this purpose is transmitted over encrypted connections but, consistent with Section 8 below, is not end-to-end encrypted at the point it is processed by the AI provider. If your Organization has not enabled this feature, no Content is sent to an AI provider. Your Admin can confirm current status in workspace settings.
6. Cookies & Similar Technologies
The Service uses strictly necessary session/authentication cookies or tokens (e.g., login sessions, SSO/PKCE flow, CSRF protection) and local device storage required for core functionality (e.g., push-notification subscriptions). We do not use third-party advertising trackers. Where any non-essential analytics or tracking technology is introduced in the future, we will update this Policy and obtain consent where required.
7. Sharing & Disclosure
We do not sell Personal Data. We share data only as follows:
- Sub-processors / infrastructure providers who process data solely to operate the Service on our behalf, under contractual confidentiality and security obligations, including: real-time media routing, object storage, push notification delivery (Web Push), and, if enabled by your Organization, GIF search (Giphy — search queries only, no message content) and AI summarization providers (Section 5).
- Your Organization’s Admins, who — depending on workspace configuration — may access workspace membership, audit logs, and, where retention/eDiscovery policies permit, message and file content within their own Organization.
- Identity providers, when your Organization uses Single Sign-On, for authentication only.
- Legal & safety disclosures, where required to comply with law, valid legal process, or to protect the rights, property, or safety of Resulticks, our Users, or the public.
- Corporate transactions (merger, acquisition, financing, or sale of assets), subject to standard confidentiality protections and, where legally required, notice to affected Users.
A current list of sub-processors is available on request from privacy@resulticks.com.
8. Data Security
We apply technical and organizational measures appropriate to the risk, including:
- Encryption in transit (TLS) for all client-server and client-media communications;
- Role-based access control and organization-scoped data isolation (each Organization’s data is logically segregated);
- Optional multi-factor authentication and Single Sign-On (OIDC/PKCE);
- Optional end-to-end encryption (“E2EE”) for messages and file attachments is a supported, configurable capability of the Service. E2EE must be enabled by your Organization’s Admin and is not active by default. When E2EE is not enabled for your Organization, message and file content is encrypted in transit and protected by access controls, but is stored and processed in a form accessible to our backend systems (for example, to support server-side search). We do not represent that all communications on the Service are end-to-end encrypted; you can confirm your Organization’s current E2EE status with your Admin.
- Ongoing internal security review of authentication, storage, and real-time communication paths.
No method of transmission or storage is 100% secure. We will notify affected Organizations and, where required by applicable law (including the DPDP Act and GDPR), affected individuals and regulators, without undue delay in the event of a personal data breach materially affecting them.
9. Data Retention & Deletion
Content is retained according to the retention policy configured by your Organization’s Admin, or until your Organization’s account is terminated, whichever is applicable. Deleted Content is logically removed from active systems (soft-deleted) and purged from backups within our standard backup-rotation window. Account and billing records may be retained longer where necessary to comply with legal, tax, or audit obligations.
Account deletion. You may delete your individual Collab account and associated Personal Data directly within the app at Settings → Account → Delete Account, or via the web at https://collab.resulticks.com/account/delete. You may also request deletion by contacting your Organization’s Admin or us directly at privacy@resulticks.com. Where a workspace is Admin-managed, deletion of certain workspace Content may be governed by your Organization’s retention policy and may need to be routed through your Admin. We will action verified deletion requests within the timeframe required by applicable law.
10. International Data Transfers
Collab infrastructure may be hosted in the United States, Singapore, India, and/or other regions selected for your deployment, consistent with Resulticks’ global operations. Where Personal Data is transferred across borders, we rely on appropriate safeguards, including the EU-U.S. Data Privacy Framework and its UK Extension for transfers of EEA/UK personal data to Resulticks in the United States, standard contractual clauses where applicable, and, for EEA/UK data, GDPR Chapter V transfer mechanisms. We also comply with the DPDP Act’s cross-border transfer provisions.
11. Your Rights
Subject to applicable law and any verification requirements, you may have the right to:
- Access the Personal Data we hold about you;
- Correct inaccurate or incomplete data;
- Erase your Personal Data (subject to legal/contractual retention needs);
- Withdraw consent for processing based on consent (e.g., optional AI features), without affecting prior lawful processing;
- Port your data in a structured, machine-readable format, where technically feasible;
- Object to or restrict certain processing (GDPR);
- Nominate a representative to exercise your rights on your behalf, including after death (DPDP Act); and
- Lodge a complaint with the relevant supervisory authority (e.g., India’s Data Protection Board, an EU/UK Data Protection Authority, or, for California residents, the California Privacy Protection Agency).
To exercise these rights, contact our Grievance Officer (Section 15). We will respond within the timeframe required by applicable law.
12. Notice to Employees / Organization Members
Collab is typically provisioned to you by an employer or organization (“your Organization”). Your Organization’s Admin(s) may be able to view your workspace activity, access message/file Content (where E2EE is not enabled and workspace policy permits), configure retention and export data, and enforce workplace policies through the Service. Resulticks does not control, and is not responsible for, how your Organization uses this administrative capability; questions about workplace monitoring should be directed to your employer’s HR/IT policies.
13. Children’s Privacy
The Service is a business/enterprise product intended for use by individuals aged 18 and older (or the applicable age of majority) acting on behalf of an organization. We do not knowingly collect Personal Data from children. If we learn a child’s data has been collected without appropriate consent, we will delete it.
14. Automated Decision-Making
We do not use Personal Data to make decisions producing legal or similarly significant effects about Users without human involvement. Optional AI summarization (Section 5) generates informational content only and is not used for automated decision-making about individuals.
15. Grievance Officer / Contact
For privacy questions, requests, or complaints, contact:
Grievance Officer / Data Protection Contact
Resulticks Solution Inc
Email: privacy@resulticks.com
Address: 607 Third Avenue, New York, NY 10017, United States
Tel: +1 (212) 400-3350
(Required designation under the DPDP Act, Section 8(9)/13. The named individual holding this office should be inserted by Resulticks before publication.)
16. Changes to This Policy
We may update this Policy from time to time. Material changes will be notified to Organization Admins and/or Users via the Service or email at least 30 days before taking effect, except where a shorter period is required for legal or security reasons. Continued use of the Service after the effective date constitutes acceptance.
17. Governing Law
This Policy is governed by the laws of Singapore, consistent with the Resulticks Terms and Conditions, without regard to conflict-of-law principles, and subject to mandatory local data-protection law applicable to you (including the DPDP Act, GDPR, and CCPA/CPRA where relevant).