Privacy Policy
Last updated:
This Privacy Policy describes what data Driftless collects, how we use it, how long we keep it, the rights you have over your data under GDPR and CCPA, where your data is processed, and how to reach us with privacy questions.
Data we collect
Driftless is an agentic product delivery platform provided by Iron Flank Inc. (“Driftless”, “we”, “us”, “our”). This Privacy Policy explains how we collect, use, and protect personal data when you use the Driftless website at godriftless.ai, the Driftless application at app.godriftless.ai, the Driftless REST API, and the Driftless MCP endpoint (collectively, the “Service”).
We collect the following categories of data:
Account information
When you create an account, we collect your name, email address, organization name, and authentication credentials. This information is necessary to provision and manage your account and to identify you within the Service.
- Identity: name and display name associated with your account.
- Contact: email address used for account verification, notifications, and support.
- Organization: organization name and membership role within your team.
[Pending review: any additional account fields collected at signup, e.g., phone number, job title]Usage data
We collect operational and usage data about how you interact with the Service. This includes log data (IP address, browser type, timestamps), feature usage (projects created, tasks completed, agent runs), and performance metrics. Usage data helps us operate, secure, and improve the Service.
- Log data: IP address, request timestamps, user-agent string, and referral URLs.
- Activity data: actions you take within the Service — creating projects, initiatives, tasks, comments, and media.
- Analytics: aggregate, pseudonymized usage metrics used to understand feature adoption and service health.
[Pending review: specify analytics provider and exact data points collected, e.g., Google Analytics 4 event parameters]Customer-provided API keys
You may provide third-party API keys (for example, keys for version-control platforms or CI services) to enable integrations within Driftless. These keys are stored encrypted at rest and are used solely to execute the integrations you configure. We do not use your API keys for any purpose other than operating the integrations you have authorized.
[Pending review: encryption method for stored API keys and key-rotation policy]Customer data
You submit projects, initiatives, tasks, comments, media, and other content to the Service (“Customer Data”). You own your Customer Data; we process it only to provide the Service to you, as described in this Privacy Policy and our Terms of Service.
How we use your data
We use the data we collect for the following purposes:
- Service delivery. Operating, maintaining, and providing the features of the Service — account provisioning, project and task management, agent automation, and integrations.
- Improvement. Analyzing usage patterns to improve existing features, develop new features, and optimize performance. Improvements are based on aggregate or pseudonymized data wherever possible.
- Security. Detecting, preventing, and responding to fraud, abuse, security incidents, and other violations of our Terms of Service. This includes monitoring access logs and automated threat detection.
- Communication. Sending service notifications, security alerts, and support responses. Marketing communications are sent only with your consent where required by applicable law.
- Legal compliance. Meeting legal obligations, resolving disputes, and enforcing our agreements.
We process your data only for the purposes described in this Privacy Policy, or as otherwise described to you at the point of collection. We do not sell your personal data. [Pending review: any secondary use that requires separate consent under applicable law]
Legal bases for processing (GDPR)
For users in the European Economic Area, United Kingdom, and Switzerland, we process personal data on the following legal bases:
- Performance of a contract — providing the Service you requested, including account management and feature delivery.
- Legitimate interests — security monitoring, service improvement, and fraud prevention, balanced against your privacy rights.
- Legal obligation — complying with applicable laws and regulatory requirements.
- Consent — for optional analytics or marketing communications, where consent is required.
[Pending review: confirm the specific legitimate-interest assessments and document them if required by your DPO]Data retention and deletion
We retain your personal data only as long as necessary to fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce our agreements.
Retention periods
- Account information: retained for the lifetime of your account. When you close your account, we delete your account information within
[Pending review: account-deletion period, e.g., 30 days], except where retention is required by law. - Customer Data: retained for the lifetime of your account. You can export or delete your Customer Data at any time using the tools available in the Service. When you delete Customer Data, it is removed from active systems within
[Pending review: data-deletion period, e.g., 30 days]and from backups within[Pending review: backup-retention period, e.g., 90 days]. - Usage and log data: retained for
[Pending review: log-retention period, e.g., 12 months]for security and operational purposes, then automatically deleted or anonymized. - API keys: retained for the lifetime of the integration you configured. When you remove an integration, the associated API key is deleted immediately.
Deletion
You can request deletion of your personal data at any time by contacting privacy@godriftless.ai. We will process your request in accordance with applicable law. In some cases, we may need to retain certain data to comply with legal obligations or protect our legal rights; such data will be deleted once the retention obligation expires.
[Pending review: describe any data that must be retained for legal, tax, or regulatory reasons and the applicable retention period]Your rights under GDPR
If you are in the European Economic Area, United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) gives you the following rights over your personal data:
- Right of access. You can request a copy of the personal data we hold about you and information about how we process it.
- Right to rectification. You can request that we correct any inaccurate or incomplete personal data we hold about you.
- Right to erasure. You can request that we delete your personal data, subject to legal retention obligations. This is also known as the “right to be forgotten.”
- Right to data portability. You can request a machine-readable copy of the personal data you provided to us, in a structured, commonly used format, and you have the right to transmit that data to another controller.
- Right to object. You can object to our processing of your personal data that is based on legitimate interests or for direct marketing. We will stop processing your data for the objected purpose unless we can demonstrate compelling legitimate grounds that override your rights.
How to exercise your GDPR rights
To exercise any of these rights, contact us at privacy@godriftless.ai. We will respond to your request within one month of receipt, as required by GDPR. If we need more time, we will inform you of the reason and extension period within that month.
Right to lodge a complaint
You have the right to lodge a complaint with your local data protection authority if you believe our processing of your personal data violates GDPR. [Pending review: name and contact details of the supervisory authority in your primary jurisdiction]
Your rights under CCPA
If you are a resident of California, the California Consumer Privacy Act (CCPA) gives you the following rights over your personal data:
- Right to know. You can request that we disclose the categories of personal data we collect about you, the specific pieces of data, the business purpose for collecting it, and the categories of third parties with whom we share it.
- Right to delete. You can request that we delete the personal data we have collected from you, subject to exceptions under CCPA (for example, data needed to complete a transaction or comply with legal obligations).
- Right to opt out of sale. Driftless does not sell personal data. You have the right to opt out of any future sale of your personal data. Because we do not sell your data, no action is needed; this right is included for completeness and future protection.
How to exercise your CCPA rights
To exercise any of these rights, contact us at privacy@godriftless.ai. We will verify your identity before processing your request and will respond within the timeframe required by CCPA. [Pending review: describe identity-verification method, e.g., matching email address and account details]
Non-discrimination
We will not discriminate against you for exercising your CCPA rights. We will not deny you service, charge different prices, or provide a different level of service because you exercised your rights under CCPA.
Data processing location and sub-processors
Processing location
Your personal data and Customer Data are processed and stored in [Pending review: primary data-processing region, e.g., the United States (us-east-2)]. We may transfer data to other regions for operational purposes only where permitted by applicable law and with appropriate safeguards in place.
For users in the European Economic Area, United Kingdom, or Switzerland, any transfer of personal data outside those regions is made using appropriate legal mechanisms, such as [Pending review: transfer mechanism, e.g., Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework].
Sub-processors
We use third-party service providers (sub-processors) to help operate the Service. Each sub-processor is bound by written agreements that require them to protect personal data consistent with this Privacy Policy and applicable law. Our current sub-processors include:
- Cloud hosting:
[Pending review: cloud provider name, e.g., Amazon Web Services]— infrastructure hosting and data storage. - Analytics:
[Pending review: analytics provider, e.g., Google Analytics 4]— aggregate usage measurement on the marketing site. - Email delivery:
[Pending review: email provider, e.g., Amazon SES]— transactional and notification email.
[Pending review: complete sub-processor list with provider name, purpose, and processing location; update when sub-processors change]Data sharing
We do not share your personal data with third parties for their own marketing purposes. We share data only with sub-processors as described above, with law enforcement or government authorities when legally required, and with your consent where required by applicable law.
Privacy contact and changes to this policy
Privacy contact
If you have questions about this Privacy Policy or want to exercise your data protection rights, contact us:
- Email: privacy@godriftless.ai
- General support: support@godriftless.ai
[Pending review: postal address for privacy correspondence and name of Data Protection Officer if appointed]
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above. If we make material changes that affect your rights, we will notify you using commercially reasonable means — for example, by email or an in-app notice — before the changes take effect. Your continued use of the Service after a change constitutes acceptance of the revised policy.
Children’s privacy
The Service is a B2B product and is not directed at children. We do not knowingly collect personal data from anyone under the age of [Pending review: minimum age, e.g., 16]. If you believe we have collected personal data from a child, please contact us and we will delete it.