Secure Chat Privacy Policy
At a Glance
This Privacy Policy explains how MIS Solutions, Inc collects, uses, discloses, stores, and protects information when you use Secure Chat.
Secure Chat is a messaging and collaboration software service. Depending on your account type, your organization may control your workspace, users, messages, files, retention settings, exports, and related account data.
1. Scope of This Privacy Policy
This Privacy Policy applies to Secure Chat, including our websites, applications, software, APIs, administrative portals, support services, and related features, collectively, the "Service."
This Privacy Policy does not apply to third-party websites, applications, integrations, or services that we do not own or control. Those services are governed by their own privacy policies and terms.
If you use Secure Chat through your employer, customer, school, managed service provider, reseller, or another organization, that organization may have its own privacy policy, terms, retention practices, and administrative controls that apply to your use of the Service.
2. Important Definitions
Personal Information Information that identifies, relates to, describes, can reasonably be associated with, or could reasonably be linked to an identifiable person or household. The meaning of this term may vary under applicable law.
Customer Content Messages, files, attachments, contacts, conversations, profile details, workspace configurations, and other content submitted to, transmitted through, stored in, or processed by the Service by or on behalf of a customer or user.
Customer The person, company, organization, or other entity that subscribes to or administers a Secure Chat workspace or account.
User An individual who accesses or uses the Service, including account owners, administrators, invited users, guests, and end users.
Administrator A user or organization representative with permission to configure, manage, monitor, export, retain, or delete data within a workspace or account.
Service Provider A vendor, contractor, or third party that processes information for us or for our customers under contractual restrictions.
3. Our Role: Controller, Business, Processor, or Service Provider
Our privacy role depends on the context in which information is processed.
- Customer-controlled workspace data. For Customer Content and user account data inside an
organization-managed workspace, MIS Solutions, Inc. generally acts as a service provider, processor, or similar role on behalf of the Customer. The Customer decides why and how that data is processed, subject to the applicable agreement.
- Our own business data. For information we collect to operate our website, manage subscriptions,
bill customers, market the Service, communicate with prospects, run security operations, and manage our business, MIS Solutions, Inc. generally acts as a controller, business, or similar role.
- Your organization controls many settings. If your account is organization-managed, your
organization may control retention, deletion, exports, access permissions, audit logs, identity management, integrations, and other administrative features.
If a separate data processing agreement, business associate agreement, or similar privacy addendum applies, that document controls to the extent it conflicts with this Privacy Policy for the subject matter it covers.
4. Information We Collect
We collect information in the categories below. The specific information collected depends on how you use the Service, your plan, your settings, your organization settings, and the integrations you enable.
4.1 Information You Provide
- Account information. Name, email address, phone number, username, password or
authentication information, profile photo, job title, organization name, workspace name, and user preferences.
- Customer Content. Messages, channels, chats, files, attachments, reactions, mentions, contacts,
groups, conversation participants, and other content you choose to submit or transmit through the Service.
- Administrative information. Workspace settings, user roles, permissions, security settings,
retention settings, audit configurations, billing contacts, and subscription details.
- Billing and transaction information. Payment method details, billing address, tax information,
invoices, receipts, plan selections, transaction history, and subscription records. Payment card information may be processed by our payment processor rather than stored directly by us.
- Support and communications. Support tickets, troubleshooting details, feedback, survey
responses, call or meeting details, emails, chat communications with us, and related records.
- Marketing and event information. Contact details, lead information, webinar or event registration,
product interests, and communications preferences.
4.2 Information Collected Automatically
- Device and browser information. IP address, device identifiers, browser type, operating system,
device type, language settings, and similar technical information.
- Usage information. Pages or features viewed, messages sent, files uploaded, actions taken, time
and date of activity, referral URLs, session duration, clicks, and performance data.
- Log and security information. Authentication events, access logs, audit logs, error logs, crash
data, security telemetry, suspicious activity signals, and system diagnostics.
- Approximate location. General location derived from IP address or other technical signals. We do
not intentionally collect precise geolocation unless disclosed at the point of collection or enabled by your settings.
- Cookies and similar technologies. Cookies, pixels, local storage, SDKs, and similar technologies
used to operate, secure, remember preferences, analyze, and improve the Service.
4.3 Information From Third Parties
- Customers and administrators. Your organization or administrator may provide your name, email
address, role, group membership, permissions, directory information, or other data needed to create and manage your account.
- Identity and authentication providers. If you sign in using single sign-on or another identity
provider, we may receive authentication tokens, email address, name, groups, profile information, and related account attributes.
- Integrations and connected services. If you enable integrations, we may receive information from
those services as needed to provide the requested functionality.
- Payment processors. We may receive payment status, transaction identifiers, billing details, fraud
signals, and limited payment method information.
- Business partners and public sources. We may receive business contact details, company
information, and marketing-related information from partners, lead sources, public websites, or professional directories.
5. Customer Content, Messages, and Metadata
Secure Chat is designed to transmit and store communications and collaboration data. Customer Content may include personal information, business information, confidential information, and other information that users choose to submit.
We process Customer Content to provide, secure, maintain, support, troubleshoot, and improve the Service; comply with law; enforce our agreements; and perform obligations under applicable customer contracts.
Message metadata may include sender, recipient, timestamps, workspace, channel or conversation identifiers, message status, device, IP address, file metadata, and similar operational information.
Metadata may be needed to deliver, secure, troubleshoot, retain, search, export, or audit communications.
Administrators may be able to access, review, preserve, export, delete, or restrict Customer Content and related metadata depending on the Customer plan, settings, permissions, and applicable agreements.
Unless expressly stated in a separate written agreement, Secure Chat is not intended for protected health information, payment card data, government classified data, export-controlled technical data, children's data, or other regulated information requiring specialized handling.
6. How We Use Information
- Provide and operate the Service. Create accounts, authenticate users, deliver messages, store
files, enable search, manage workspaces, process payments, and provide requested features.
- Secure the Service. Detect, prevent, investigate, and respond to fraud, abuse, malware, spam,
unauthorized access, policy violations, security incidents, and technical issues.
- Administer accounts and subscriptions. Manage billing, invoicing, renewals, plan changes,
customer communications, user permissions, and support requests.
- Support and troubleshoot. Respond to inquiries, diagnose problems, perform maintenance,
improve reliability, and provide customer success services.
- Improve and develop the Service. Analyze usage, performance, reliability, errors, feature adoption,
and user feedback to improve existing features and develop new features.
- Communicate with you. Send transactional notices, security alerts, administrative messages,
product updates, support responses, billing notices, and marketing communications where permitted.
- Personalize user experience. Remember preferences, display relevant account information, and
tailor features based on role, settings, and usage.
- Comply with law and enforce agreements. Meet legal, tax, accounting, compliance, dispute
resolution, audit, and contractual obligations.
7. Artificial Intelligence and Automated Processing
The Service may include or later add features that use automation, machine learning, artificial intelligence, or similar technologies, such as search, summarization, routing, security monitoring, spam detection, abuse detection, analytics, or productivity features.
We do not use Customer Content for third-party advertising. We do not use Customer Content to train third-party artificial intelligence models unless you or your organization expressly enable that feature or authorize that use in a separate written agreement.
If AI-enabled features are offered, we may provide additional disclosures, settings, terms, or opt-in controls that explain how the feature works and what data is processed.
8. How We Disclose Information
We disclose information only as described in this Privacy Policy, as directed by the Customer, as necessary to provide the Service, or as otherwise permitted or required by law.
- Customers and administrators. If you use an organization-managed account, Customer Content,
account information, usage data, logs, and settings may be disclosed to or accessible by the Customer and its authorized administrators.
- Other users. Information you share in messages, channels, groups, profiles, reactions, files, or
collaboration features may be visible to other users according to your settings and workspace permissions.
- Service providers. We disclose information to vendors that provide hosting, infrastructure,
security, storage, analytics, payment processing, customer support, communications, email delivery, identity services, logging, monitoring, and other services.
- Integrations. When you connect or use third-party integrations, we disclose information to those
services as needed to provide the integration or as directed by you or your organization.
- Professional advisers. We may disclose information to auditors, lawyers, insurers, banks,
consultants, and other professional advisers.
- Legal, compliance, and safety. We may disclose information to comply with law, legal process,
government requests, court orders, security obligations, or to protect rights, safety, users, customers, third parties, or the Service.
- Business transactions. We may disclose information in connection with a merger, acquisition,
financing, corporate transaction, reorganization, bankruptcy, or sale of assets.
- Aggregated or de-identified information. We may disclose information that has been aggregated
or de-identified so it does not reasonably identify you, subject to applicable law.
9. No Sale of Customer Content; Advertising
We do not sell Customer Content. We do not use Customer Content for third-party advertising. We do not sell personal information or share personal information for cross-context behavioral advertising. If our practices change, we will update this Privacy Policy and provide opt-out controls where required by law before those changes apply.
10. Cookies and Similar Technologies
We and our service providers may use cookies, pixels, local storage, SDKs, and similar technologies to operate, secure, analyze, and improve the Service.
Essential cookies Used for login, authentication, security, fraud prevention, session management, load balancing, and core Service functionality.
Preference cookies Used to remember language, display, notification, and other user preferences. Analytics cookies Used to understand usage, performance, feature adoption, errors, and service reliability. Marketing cookies Not used in campaign measurement or advertising cookies You can control cookies through your browser settings. Blocking some cookies may affect Service functionality. Where required by law, we will provide additional cookie consent or preference controls.
If we engage in activities subject to browser-based opt-out requirements, we will honor legally required opt-out preference signals, such as Global Privacy Control, in accordance with applicable law.
11. Legal Bases for Processing for EEA, UK, and Similar Jurisdictions
If privacy laws in the European Economic Area, United Kingdom, Switzerland, or similar jurisdictions apply, we process personal information under one or more legal bases, depending on the context.
Contract To provide the Service, create accounts, deliver messages, process payments, administer subscriptions, and perform agreements.
Legitimate interests To secure the Service, prevent abuse, improve functionality, support customers, analyze performance, communicate about the Service, and manage our business, where those interests are not overridden by privacy rights.
Consent For activities that require consent, such as certain cookies, marketing communications, or optional features.
Legal obligation To comply with applicable law, legal process, tax, accounting, regulatory, security, and compliance obligations.
Vital interests or public interest Where necessary in limited circumstances to protect safety or comply with important public interest obligations.
12. International Data Transfers
We may process and store information in the United States and other countries where we, our affiliates, customers, or service providers operate. These countries may have privacy laws that differ from those in your jurisdiction.
Where required, we use appropriate transfer mechanisms, safeguards, or contractual protections for international transfers, such as standard contractual clauses, data processing agreements, or other lawful mechanisms.
13. Data Retention
We retain information for as long as reasonably necessary to provide the Service, fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support legitimate business needs.
Retention periods vary depending on the type of information, Customer settings, account status, plan, legal requirements, backup cycles, and operational needs.
- Customer Content. Retained according to Customer instructions, workspace settings,
subscription status, retention policies, deletion requests, and applicable agreements.
- Account information. Retained while your account is active and for a reasonable period after
closure for legal, security, audit, tax, accounting, and business purposes.
- Logs and security records. Retained for security, fraud prevention, troubleshooting, compliance,
and audit purposes according to our internal retention schedules.
- Backups. Deleted or overwritten according to our backup lifecycle, unless earlier deletion is
legally required and technically feasible.
14. Security
We use commercially reasonable administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction.
Security measures may include access controls, encryption in transit, authentication controls, logging, monitoring, vulnerability management, vendor review, employee training, backup controls, and incident response processes.
No system, software, network, or transmission method is completely secure. You are responsible for using strong credentials, protecting your devices, managing user permissions, enabling available security features, and promptly notifying us of suspected unauthorized access.
15. Your Choices and Controls
- Account settings. You may be able to update profile details, preferences, notifications,
integrations, and security settings through the Service.
- Organization-managed accounts. If your account is managed by an organization, direct access,
correction, deletion, export, and retention requests to your organization or administrator unless the Service provides self-service controls.
- Marketing communications. You may opt out of marketing emails by using the unsubscribe link
or contacting us. We may still send transactional, security, billing, legal, or administrative messages.
- Cookies. You can manage cookies through browser settings or, where available, our cookie
preference tools.
- Integrations. You may be able to disconnect integrations through account settings or by
contacting your administrator.
16. Privacy Rights
Depending on where you live and how your information is processed, you may have rights regarding your personal information. These rights may include:
- Accessing or confirming whether we process your personal information;
- Receiving a copy of personal information in a portable format;
- Correcting inaccurate personal information;
- Deleting personal information, subject to exceptions;
- Opting out of sale, sharing, targeted advertising, or certain profiling where applicable;
- Limiting use or disclosure of sensitive personal information where applicable;
- Objecting to or restricting certain processing where applicable;
- Withdrawing consent where processing is based on consent;
- Appealing a decision regarding a privacy request where required by law;
- Lodging a complaint with a privacy regulator where applicable. If your information is controlled by a Customer, we may forward your request to the Customer, direct you
to contact the Customer, or process the request according to the Customer's instructions.
17. Notice for California Residents
This section applies to California residents to the extent the California Consumer Privacy Act, as amended, applies to our processing of personal information.
The chart below describes categories of personal information we may collect, use, and disclose. Not every category applies to every user.
Identifiers Examples: Name, email address, phone number, username, IP address, account ID, device identifiers, organization name, billing contact details.
Categories of recipients: Service providers; Customers and administrators; integrations; professional advisers; legal or compliance recipients; business transaction parties.
Customer records information Examples: Billing address, payment status, transaction records, support records, subscription details, and similar customer account records.
Categories of recipients: Service providers; payment processors; professional advisers; legal or compliance recipients.
Commercial information Examples: Subscription plan, purchases, invoices, renewals, product interests, usage of paid features, and transaction history.
Categories of recipients: Service providers; payment processors; professional advisers; business transaction parties.
Internet or network activity Examples: Log data, usage data, device data, browser data, pages viewed, features used, authentication events, audit logs, and security telemetry.
Categories of recipients: Service providers; Customers and administrators; security vendors; integrations;
legal or compliance recipients.
Approximate geolocation Examples: General location inferred from IP address or account information. Categories of recipients: Service providers; security vendors; Customers and administrators where enabled.
Audio, electronic, visual, or similar information Examples: Support call recordings, meeting recordings, profile images, uploaded files, or message content if you choose to provide it.
Categories of recipients: Service providers; Customers and administrators; other users based on workspace settings; legal or compliance recipients.
Professional or employment-related information Examples: Job title, company name, department, role, permissions, organization directory details, and business contact information.
Categories of recipients: Service providers; Customers and administrators; integrations; business partners where applicable.
Inferences Examples: Preferences, product interests, feature usage patterns, support needs, and account risk signals.
Categories of recipients: Service providers; Customers and administrators where applicable; business transaction parties.
Sensitive personal information Examples: Account login credentials, security information, precise content of communications, and any sensitive information users choose to submit in Customer Content.
Categories of recipients: Service providers; Customers and administrators; other users based on workspace settings; legal or compliance recipients. We do not use sensitive personal information to infer characteristics except as permitted by law.
Sources of personal information include you, your organization, administrators, other users, devices and browsers, identity providers, integrations, payment processors, service providers, business partners, and public sources.
Business and commercial purposes include providing the Service, account administration, billing, support, security, fraud prevention, analytics, product improvement, communications, legal compliance, and business operations.
We do not sell Customer Content. We do not sell personal information or share personal information for cross-context behavioral advertising. We do not knowingly sell or share personal information of children under 16.
California residents may have the right to know, access, correct, delete, opt out of sale or sharing, limit certain uses of sensitive personal information, and not be discriminated against for exercising privacy rights. Submit requests by emailing info@mis-solutions.com.
18. Notice for Other U.S. State Residents
Residents of certain U.S. states may have rights under state privacy laws, subject to scope, applicability, exceptions, and verification requirements. These rights may include access, deletion, correction, portability, opt-out of sale, opt-out of targeted advertising, opt-out of certain profiling, and appeal.
To exercise applicable state privacy rights, contact info@mis-solutions.com. If required, we will provide an appeal process in our response to your request.
19. Notice for EEA, UK, and Swiss Users
If you are located in the European Economic Area, United Kingdom, Switzerland, or a jurisdiction with similar laws, you may have additional rights regarding your personal information, including rights to access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority.
Where we act as a processor or service provider for a Customer, we process personal information according to the Customer's instructions. You should contact the Customer or administrator to exercise rights regarding Customer-controlled data.
20. Children's Privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information to us, contact info@mis-solutions.com.
If you are a parent, guardian, school, or organization using Secure Chat in a context involving minors, you are responsible for ensuring that your use complies with applicable law and that all required consents, notices, and agreements are in place before using the Service for that purpose.
21. Third-Party Links and Integrations
The Service may contain links to third-party websites or allow you to connect third-party applications and integrations. We are not responsible for the privacy, security, or content practices of third parties. Review their policies before providing information to them or enabling integrations.
22. Do Not Track and Preference Signals
Some browsers transmit "Do Not Track" signals. There is not a uniform industry standard for responding to these signals. We respond to legally required opt-out preference signals where applicable and technically feasible. Hers
23. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through the Service, by email, by posting an updated policy, or by another reasonable method.
The updated Privacy Policy will be effective as of the date stated at the top of the policy unless otherwise required by law. Your continued use of the Service after the effective date means that the updated policy applies to your use of the Service.
24. Contact Us
Questions, concerns, or privacy requests may be sent to: Company: MIS Solutions, Inc. Attn: Privacy Department Email: Info@mis-solutions.com Mailing Address: 4485 Tench Rd STE 440 Suwanee GA 30024