1. Who we are and what this covers
AImagineThat ("AImagineThat", "we", "us") provides an agentic AI CRM platform. This policy covers:
- the marketing website at aimaginethat.com;
- the CRM application at app.aimaginethat.com (the "Service"); and
- third-party mailboxes and accounts you choose to connect to the Service, such as Gmail and Microsoft Outlook.
When a business ("Customer") uses the Service to manage its own contacts, leads and deals, the Customer is the controller of that business data and we process it on the Customer's instructions under our Terms of Service. For account data, website data and billing we act as the controller.
2. Data we collect
Data you give us
- Account data: name, work email, company, role, password hash or Google sign-in identity, and team membership.
- CRM data: contacts, companies, leads, deals, quotations, tasks, notes, activities, files and call records that you or your team enter or import.
- Enquiry and booking data: details submitted through website forms or the meeting scheduler.
- Billing data: plan, invoices and payment status. Card details are handled by our payment processor and never stored by us.
Data collected automatically
- Usage and device data: pages visited, features used, browser type, approximate location derived from IP address, and timestamps.
- Logs and diagnostics: error reports, security events and API request metadata needed to run and protect the Service.
Data from connected services
When you connect a mailbox, calendar, telephony or messaging provider, we receive the data described in section 3 under the permissions you grant. You can revoke these permissions at any time.
3. Connected Gmail and Outlook mailboxes
The Service lets each user optionally connect their own Gmail or Microsoft 365 / Outlook.com mailbox so that email conversations with customers appear alongside CRM records and follow-ups can be sent from the CRM.
What we access
- Your email address and basic profile so we can label the connection.
- Message metadata and content in the folders being synchronised: sender, recipients, subject, date, body, labels or folders, read and flag state, and attachments.
- The ability to create drafts, send messages, reply, forward, move messages between folders, and mark them read or flagged, only when you or an automation you configured explicitly asks for it.
Permissions requested
- Google:
openid,emailandhttps://www.googleapis.com/auth/gmail.modify. We do not request permanent-delete permission or access to your full Google account. - Microsoft: delegated
User.Read,Mail.ReadWrite,Mail.Send,offline_accessand OpenID identity scopes. We never request organisation-wide or application-level mailbox access.
How mailbox data is used
- To display your email threads inside the CRM and match them to contacts, leads and deals.
- To let you compose, reply, forward and send email from the CRM using your own mailbox as the sender.
- To run email-based automations that you configure, such as reminding you when a customer has not replied.
- To generate optional AI summaries, sentiment and suggested next actions for a conversation, as described in section 6.
Mailbox data is never used for advertising, sold, shared with data brokers, or used to train general-purpose AI models. Access tokens are encrypted at rest with a key held separately from the database.
Disconnecting
You can disconnect a mailbox from Settings → Email in the Service at any time. Disconnecting revokes our stored tokens, cancels pending sync and send jobs, and removes the mailbox from your team's shared views. You can also revoke access from your Google Account permissions or Microsoft account permissions page.
4. Google API Services User Data Policy
AImagineThat's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We only use Google user data to provide and improve the user-facing mailbox features described in section 3.
- We do not transfer Google user data to third parties except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with prior notice.
- We do not use Google user data to serve advertisements.
- Humans do not read Google user data unless you give explicit permission for a specific message, it is necessary for security or to comply with law, or the data has been aggregated and anonymised for internal operations.
5. How we use data
- To provide, operate, secure and support the Service and this website.
- To authenticate users and manage teams, roles and permissions.
- To send transactional messages such as invitations, password resets, quotations you choose to send, and service notices.
- To respond to enquiries and schedule demos you request.
- To bill Customers and prevent fraud or abuse.
- To analyse aggregated usage so we can improve reliability and features.
- To comply with legal obligations.
Where GDPR or similar law applies, our legal bases are performance of a contract, our legitimate interests in running and securing the Service, your consent where we ask for it, and compliance with law.
6. AI processing
Some features send CRM content, and where connected, email content, to large language model providers to produce summaries, sentiment, win-probability estimates, drafted follow-ups, lead scores or voice-agent responses. These providers are engaged as processors on our behalf. Under our agreements with them, content is used only to generate the requested output and is not used to train their models. AI output is a suggestion; a human in your team remains responsible for what is sent or saved.
7. Sharing and sub-processors
We share personal data only with:
- Your team: data you store in a shared workspace is visible to teammates according to the roles the Customer configures.
- Sub-processors that host or help deliver the Service, currently including Microsoft Azure (hosting, database and AI models), Cloudflare (file storage and networking), Resend (transactional email), our telephony and voice providers when you use calling features, and our payment processor for billing.
- Providers you connect, such as Google or Microsoft, when we act on your instruction to send an email or update a message.
- Authorities when required by law, or to protect the rights, safety or property of AImagineThat, our Customers or others.
- A successor in a merger, acquisition or asset sale, with notice to you.
We do not sell personal data.
8. Retention and deletion
- Account and CRM data is kept for as long as the Customer's subscription is active and for up to 90 days afterwards so it can be exported, then deleted or anonymised.
- Mailbox data is deleted when the mailbox is disconnected or the account is deleted, subject to short-lived backups that expire within 35 days.
- Enquiry data is kept for up to 24 months from the last contact.
- Logs are kept for up to 12 months for security and diagnostics.
- Billing records are retained for the period required by tax and accounting law.
9. Security
We use encryption in transit (TLS) and at rest, encrypted storage of provider tokens with a separately managed key, role-based access control, per-workspace data isolation, audit logging, least-privilege infrastructure access and regular dependency and vulnerability review. No system is perfectly secure; if we become aware of a breach affecting your data we will notify you and the relevant authorities as required by law.
10. Your rights
Depending on where you live, including under the EU/UK GDPR and India's Digital Personal Data Protection Act, you may have the right to access, correct, delete, restrict or object to processing of your personal data, to data portability, and to withdraw consent. You can exercise most of these directly in the Service, or by contacting us using the details in section 15. If you are a user of a Customer's workspace, we may direct your request to that Customer. You may also lodge a complaint with your local supervisory authority.
11. Cookies
This website stores a single preference (your light or dark theme) in your browser's local storage and uses no advertising or cross-site tracking cookies. The Service uses strictly necessary cookies for sign-in sessions and security. You can clear these at any time from your browser.
12. International transfers
Our infrastructure is hosted on Microsoft Azure and may be located in the United States, the European Union or India depending on the Customer's configured data residency. Where data is transferred across borders we rely on standard contractual clauses or equivalent safeguards.
13. Children
The Service is intended for business use and is not directed to anyone under 18. We do not knowingly collect data from children.
14. Changes to this policy
We may update this policy from time to time. Material changes will be announced in the Service or by email before they take effect. The effective date at the top of this page shows the current version.
15. Contact
Questions, requests or complaints about privacy can be sent to neal@aimaginethat.com. You can also reach the team at bob@aimaginethat.com.