1. Who this policy covers
This policy covers visitors, account holders, collaborators, prospective users, and people who interact with public proposals, contracts, invoices, project portals, meetings, or other pages created through Centralee.
When a Centralee customer enters information about their own clients or prospects, that customer is responsible for deciding why the information is used. Centralee processes it to provide the service on the customer’s instructions.
2. Information we collect
Account information may include your name, email address, authentication provider, profile details, avatar, business details, and account preferences.
Workspace content may include client and prospect details, notes, proposals, contracts, signatures, projects, tasks, meetings, invoices, financial records, files, communications, and other information you choose to enter.
Billing information may include your plan, billing country, subscription or order identifiers, transaction amount, currency, status, and renewal dates. Payment-card, bank, UPI, or other payment instrument credentials are handled by the payment provider and are not stored by Centralee.
Technical information may include IP and request information, browser and device characteristics, authentication and security events, device fingerprints used to protect public actions, application logs, usage data, and approximate country derived from network information.
Support information includes messages, attachments, and account details you provide when contacting us.
3. Our responsible processing commitments
We process personal information responsibly, fairly, transparently, and with respect for the people to whom it relates. In practical terms, we identify a legitimate purpose before processing, seek to collect only what is reasonably needed, take steps to keep important records accurate, limit access, apply proportionate security, retain information only for justified periods, and remain accountable for the providers and systems used to deliver Centralee.
Responsible processing does not mean that every field or record is reviewed by a person. It means that product design, access controls, provider selection, retention decisions, incident response, and rights handling are governed by documented purposes and appropriate safeguards. We periodically reconsider whether a category remains necessary and whether the same outcome can reasonably be achieved with less information.
We do not sell personal information. We do not use customer workspace content to advertise third-party products. We do not permit a provider to use workspace content for its independent advertising merely because it processes that content for Centralee. If an optional integration gives a provider an independent relationship with you, its own notice will govern that separate processing.
4. How we use information
We use information to create and secure accounts; provide requested features; process subscriptions; deliver emails and notifications; operate public client workflows; provide support; prevent fraud and abuse; diagnose errors; enforce plan limits; maintain audit records; improve product reliability; and comply with legal obligations.
We may combine related account, workspace, billing, and technical records when necessary to answer a request, diagnose an entitlement, detect abuse, or investigate an incident. Access is limited according to the task and the information should not be used for an unrelated purpose.
5. Legal grounds
Depending on the context and applicable law, we process information to perform our contract with you, take requested steps before entering that contract, comply with legal obligations, pursue legitimate interests such as security and service improvement, and act on consent where consent is required. You may withdraw consent for consent-based processing, but this does not affect earlier lawful processing.
Where we rely on legitimate interests, we consider the purpose, necessity, reasonable expectations, sensitivity, and potential effect on individuals. We apply safeguards and do not rely on that ground where the person's rights and interests should prevail. A customer may have its own legal ground for client data that Centralee processes on its instructions.
6. Detailed data inventory
This inventory describes information that may be processed across Centralee. A particular account or visitor will not necessarily generate every category.
Identity and profile data. This category may include name, profile image, business identity, role, and optional profile details. We obtain it from account settings, information you enter, and an authentication provider. We process it to create and personalise an account, identify workspace participants, and support recipient-facing business pages. We seek to limit processing to information reasonably connected to those purposes and restrict access where appropriate. Whether a field is mandatory depends on the feature. Missing or inaccurate information may make a function unavailable or incomplete. The account holder controls optional workspace content and should not submit excessive, unlawful, or irrelevant information.
Contact data. This category may include email address and contact details supplied for you, clients, prospects, collaborators, signers, or recipients. We obtain it from you, another workspace user, a customer, or a recipient interaction. We process it to deliver the requested service, address communications, authenticate users, and support legitimate business relationships. We seek to limit processing to information reasonably connected to those purposes and restrict access where appropriate. Whether a field is mandatory depends on the feature. Missing or inaccurate information may make a function unavailable or incomplete. The account holder controls optional workspace content and should not submit excessive, unlawful, or irrelevant information.
Authentication data. This category may include provider identifiers, verification state, sign-in method, session information, recovery events, and security signals. We obtain it from Firebase, Google sign-in where chosen, your browser, and our security systems. We process it to authenticate access, maintain sessions, prevent account takeover, and investigate suspicious activity. We seek to limit processing to information reasonably connected to those purposes and restrict access where appropriate. Whether a field is mandatory depends on the feature. Missing or inaccurate information may make a function unavailable or incomplete. The account holder controls optional workspace content and should not submit excessive, unlawful, or irrelevant information.
Consent records. This category may include accepted policy versions, acceptance time, signup method, account or email reference, and limited request metadata. We obtain it from the signup control and the request used to create an account. We process it to demonstrate agreement, administer policy changes, answer disputes, and meet accountability obligations. We seek to limit processing to information reasonably connected to those purposes and restrict access where appropriate. Whether a field is mandatory depends on the feature. Missing or inaccurate information may make a function unavailable or incomplete. The account holder controls optional workspace content and should not submit excessive, unlawful, or irrelevant information.
Business and workspace data. This category may include business name, branding, timezone, currency, preferences, templates, and workspace configuration. We obtain it from account owners and authorised workspace users. We process it to configure the service and present consistent documents and pages. We seek to limit processing to information reasonably connected to those purposes and restrict access where appropriate. Whether a field is mandatory depends on the feature. Missing or inaccurate information may make a function unavailable or incomplete. The account holder controls optional workspace content and should not submit excessive, unlawful, or irrelevant information.
Client and lead data. This category may include names, contact information, status, source, tags, notes, activity, preferences, and commercial context. We obtain it from workspace users, imports, and recipient interactions. We process it to provide customer relationship and lead-management functions on the account holder's instructions. We seek to limit processing to information reasonably connected to those purposes and restrict access where appropriate. Whether a field is mandatory depends on the feature. Missing or inaccurate information may make a function unavailable or incomplete. The account holder controls optional workspace content and should not submit excessive, unlawful, or irrelevant information.
Proposal data. This category may include scope, deliverables, prices, assumptions, validity, recipient details, viewing activity, choices, and acceptance status. We obtain it from workspace users and intended recipients. We process it to create, deliver, administer, and evidence proposal workflows. We seek to limit processing to information reasonably connected to those purposes and restrict access where appropriate. Whether a field is mandatory depends on the feature. Missing or inaccurate information may make a function unavailable or incomplete. The account holder controls optional workspace content and should not submit excessive, unlawful, or irrelevant information.
Contract data. This category may include contract terms, party details, signature information, timestamps, status, and related activity. We obtain it from workspace users, signers, and technical event records. We process it to provide document, signature, completion, and recordkeeping functions. We seek to limit processing to information reasonably connected to those purposes and restrict access where appropriate. Whether a field is mandatory depends on the feature. Missing or inaccurate information may make a function unavailable or incomplete. The account holder controls optional workspace content and should not submit excessive, unlawful, or irrelevant information.
Project data. This category may include projects, milestones, tasks, due dates, assignments, statuses, notes, and client-facing updates. We obtain it from workspace users and invited recipients. We process it to organise work and provide selected project information to authorised participants. We seek to limit processing to information reasonably connected to those purposes and restrict access where appropriate. Whether a field is mandatory depends on the feature. Missing or inaccurate information may make a function unavailable or incomplete. The account holder controls optional workspace content and should not submit excessive, unlawful, or irrelevant information.
Meeting data. This category may include availability, purpose, date, time, timezone, attendees, calendar references, and meeting links. We obtain it from workspace users, attendees, and connected Google services when enabled. We process it to schedule meetings, prevent conflicts, send notices, and support optional calendar connections. We seek to limit processing to information reasonably connected to those purposes and restrict access where appropriate. Whether a field is mandatory depends on the feature. Missing or inaccurate information may make a function unavailable or incomplete. The account holder controls optional workspace content and should not submit excessive, unlawful, or irrelevant information.
Invoice data. This category may include invoice identifiers, parties, addresses, line items, quantities, rates, tax fields, due dates, status, and notes. We obtain it from workspace users, clients, and recorded transaction activity. We process it to create, present, track, and administer invoices. We seek to limit processing to information reasonably connected to those purposes and restrict access where appropriate. Whether a field is mandatory depends on the feature. Missing or inaccurate information may make a function unavailable or incomplete. The account holder controls optional workspace content and should not submit excessive, unlawful, or irrelevant information.
Subscription data. This category may include plan, entitlement, price, currency, billing interval, renewal date, cancellation state, and provider customer references. We obtain it from checkout selections, our systems, Razorpay, and Dodo Payments where applicable. We process it to activate paid features, administer recurring access, prevent duplicate entitlements, and answer billing enquiries. We seek to limit processing to information reasonably connected to those purposes and restrict access where appropriate. Whether a field is mandatory depends on the feature. Missing or inaccurate information may make a function unavailable or incomplete. The account holder controls optional workspace content and should not submit excessive, unlawful, or irrelevant information.
Transaction metadata. This category may include provider order, payment, and subscription identifiers, amount, currency, status, timestamps, and verification outcome. We obtain it from payment providers and verified webhooks. We process it to verify payment events, reconcile access, investigate failures or duplicates, and maintain financial records. We seek to limit processing to information reasonably connected to those purposes and restrict access where appropriate. Whether a field is mandatory depends on the feature. Missing or inaccurate information may make a function unavailable or incomplete. The account holder controls optional workspace content and should not submit excessive, unlawful, or irrelevant information.
Files and media. This category may include documents, attachments, avatars, logos, images, and other content intentionally uploaded. We obtain it from workspace users and authorised upload interfaces. We process it to store, deliver, display, and secure user-requested content. We seek to limit processing to information reasonably connected to those purposes and restrict access where appropriate. Whether a field is mandatory depends on the feature. Missing or inaccurate information may make a function unavailable or incomplete. The account holder controls optional workspace content and should not submit excessive, unlawful, or irrelevant information.
Google Drive data when connected. This category may include the connected Google account's authorised Drive access, files or folders selected in Centralee, and the minimal metadata needed to operate the connection. We obtain it from the workspace user who connects Google Drive and Google services. We process it to create and manage Centralee folders, upload files selected by the user, and display Drive files the user asks Centralee to access; Centralee does not sell Google user data. We seek to limit processing to information reasonably connected to those purposes and restrict access where appropriate. Whether a field is mandatory depends on the feature. Missing or inaccurate information may make a function unavailable or incomplete. The account holder controls optional workspace content and should not submit excessive, unlawful, or irrelevant information.
Communications data. This category may include transactional email details, delivery events, support correspondence, notices, and recipient messages. We obtain it from users, recipients, ZeptoMail, Brevo, and support channels. We process it to send requested communications, provide support, diagnose delivery, and maintain an appropriate business record. We seek to limit processing to information reasonably connected to those purposes and restrict access where appropriate. Whether a field is mandatory depends on the feature. Missing or inaccurate information may make a function unavailable or incomplete. The account holder controls optional workspace content and should not submit excessive, unlawful, or irrelevant information.
Public-page activity. This category may include link identifier, viewed resource, action, timestamp, device or browser signals, and abuse-prevention state. We obtain it from recipient browsers, request logs, and customer-directed pages. We process it to deliver intended public workflows, show relevant activity, enforce link controls, and deter repeated or fraudulent actions. We seek to limit processing to information reasonably connected to those purposes and restrict access where appropriate. Whether a field is mandatory depends on the feature. Missing or inaccurate information may make a function unavailable or incomplete. The account holder controls optional workspace content and should not submit excessive, unlawful, or irrelevant information.
Device and network data. This category may include IP address, browser type, operating environment, language, request headers, approximate region, and identifiers used for protection. We obtain it from your browser, network requests, Cloudflare, and application infrastructure. We process it to deliver content, secure sessions, route traffic, prevent abuse, and diagnose compatibility. We seek to limit processing to information reasonably connected to those purposes and restrict access where appropriate. Whether a field is mandatory depends on the feature. Missing or inaccurate information may make a function unavailable or incomplete. The account holder controls optional workspace content and should not submit excessive, unlawful, or irrelevant information.
Usage and diagnostics. This category may include feature events, page and API activity, response status, error details, performance timing, and aggregated usage. We obtain it from applications, infrastructure, logs, and support investigations. We process it to operate, troubleshoot, secure, understand, and improve the reliability of the service. We seek to limit processing to information reasonably connected to those purposes and restrict access where appropriate. Whether a field is mandatory depends on the feature. Missing or inaccurate information may make a function unavailable or incomplete. The account holder controls optional workspace content and should not submit excessive, unlawful, or irrelevant information.
Security and audit data. This category may include login events, significant changes, signature or recipient events, webhook verification, fraud indicators, and investigation notes. We obtain it from service activity, providers, affected users, and our security review. We process it to protect users, establish accountability, enforce terms, and respond to incidents or disputes. We seek to limit processing to information reasonably connected to those purposes and restrict access where appropriate. Whether a field is mandatory depends on the feature. Missing or inaccurate information may make a function unavailable or incomplete. The account holder controls optional workspace content and should not submit excessive, unlawful, or irrelevant information.
Support data. This category may include the issue description, account context, attachments, troubleshooting details, and communications. We obtain it from the person contacting us and relevant service records. We process it to answer requests, reproduce problems, restore access, handle grievances, and improve support. We seek to limit processing to information reasonably connected to those purposes and restrict access where appropriate. Whether a field is mandatory depends on the feature. Missing or inaccurate information may make a function unavailable or incomplete. The account holder controls optional workspace content and should not submit excessive, unlawful, or irrelevant information.
Feedback and research data. This category may include product feedback, survey answers, interview notes, and voluntary suggestions. We obtain it from users who choose to participate. We process it to understand user needs, prioritise improvements, and communicate about submitted feedback. We seek to limit processing to information reasonably connected to those purposes and restrict access where appropriate. Whether a field is mandatory depends on the feature. Missing or inaccurate information may make a function unavailable or incomplete. The account holder controls optional workspace content and should not submit excessive, unlawful, or irrelevant information.
Legal and compliance data. This category may include complaints, rights requests, notices, dispute records, required verification, and official correspondence. We obtain it from users, claimants, advisers, authorities, and our records. We process it to establish, exercise, or defend rights and comply with applicable obligations. We seek to limit processing to information reasonably connected to those purposes and restrict access where appropriate. Whether a field is mandatory depends on the feature. Missing or inaccurate information may make a function unavailable or incomplete. The account holder controls optional workspace content and should not submit excessive, unlawful, or irrelevant information.
Marketing preference data. This category may include product communication choices and evidence of opt-in or opt-out where relevant. We obtain it from the preference control or direct request. We process it to respect communication choices and send permitted product information. We seek to limit processing to information reasonably connected to those purposes and restrict access where appropriate. Whether a field is mandatory depends on the feature. Missing or inaccurate information may make a function unavailable or incomplete. The account holder controls optional workspace content and should not submit excessive, unlawful, or irrelevant information.
Derived and aggregate data. This category may include summaries, counts, trends, risk indicators, and statistics produced from other service data. We obtain it from calculation from the categories described above. We process it to provide dashboards, apply plan limits, detect abuse, and improve service performance. We seek to limit processing to information reasonably connected to those purposes and restrict access where appropriate. Whether a field is mandatory depends on the feature. Missing or inaccurate information may make a function unavailable or incomplete. The account holder controls optional workspace content and should not submit excessive, unlawful, or irrelevant information.
7. Roles and customer instructions
For account registration, subscription administration, direct support, security, policy acceptance, and Centralee's own operations, Centralee determines the relevant purposes and means of processing. For personal information placed in a workspace by a customer about its clients, prospects, signers, collaborators, or other contacts, the customer generally determines the business purpose and Centralee acts to provide the service on its instructions.
Customer instructions include ordinary configuration and use of documented features, these contractual terms, and lawful support requests. We will not knowingly follow an instruction that requires unlawful processing. A customer is responsible for its own privacy notices, permissions, legal grounds, data accuracy, rights responses, and decisions about what is entered, shared, exported, or deleted.
If a person asks us about customer-controlled workspace content, we may direct the request to the relevant customer because it is best positioned to identify the relationship and decide the response. We may assist the customer with available tools and reasonable technical information, subject to security, confidentiality, proportionality, and applicable law.
8. Service providers
We share information only as needed with service providers that help operate Centralee, including Cloudflare for application delivery and security; Google Firebase and Google Cloud for authentication and data storage; Razorpay and Dodo Payments for billing; ZeptoMail or Brevo for transactional email; ImageKit for image and file delivery; and Google services for optional sign-in, Drive, and calendar features.
When you choose to connect Google Drive, Centralee uses the access you grant only to create and manage Centralee folders, upload files you select, and display Drive files you ask to access. We do not sell Google user data. You can disconnect Google Drive at any time.
We assess providers according to the nature of their role, the information involved, security and reliability needs, contractual protections, location, and available alternatives. We seek commitments appropriate to the service and limit provider access to what is needed for its function. Providers may process information in India and other countries where they or their infrastructure operate.
A provider can change its infrastructure, subprocessors, or legal terms. We monitor material operational changes through reasonable commercial processes and may replace a provider, modify a feature, or introduce additional safeguards when appropriate. A provider's independent services, such as a bank account, Google account, or payment instrument that you separately maintain, remain governed by that provider's direct relationship with you.
9. International processing
Centralee is operated from India and uses service providers with infrastructure and personnel in multiple countries. Personal information may therefore be processed outside the country where a user or recipient is located. Privacy, government-access, and procedural laws can differ between locations.
Where applicable law requires a transfer safeguard, we use a lawful mechanism and proportionate contractual, organisational, or technical measures. We also consider data location, access needs, encryption in transit, provider security, and the nature of the information. No transfer mechanism eliminates every risk, but international access is not authorised merely because it is technically possible.
10. Public and customer-directed sharing
Information is shared with recipients when you intentionally send or publish a proposal, contract, invoice, project portal, meeting link, or other public link. You control the content and intended recipient of those pages. A person with a valid link may be able to view the associated content, so links should be treated as confidential where the underlying material is confidential.
Workspace owners may share information with collaborators and configure recipient experiences. Recipients may provide information or take actions that become visible to the customer. Centralee does not decide the customer's underlying relationship with those people.
We may disclose information when required by law, to respond to valid legal process, to protect rights and safety, or as part of a merger, financing, acquisition, reorganisation, insolvency, or transfer of the service subject to appropriate safeguards. We review demands for apparent validity and scope and may challenge or narrow a demand where lawful and appropriate.
11. Cookies and local storage
Centralee uses browser storage and similar technologies for authentication, security, preferences, session continuity, and short-lived application caching. Payment and authentication providers may set their own essential technologies when their services are used.
Some storage is essential for a requested login or application function. Clearing it may sign you out, remove a local preference, interrupt an email-link flow, or require data to be fetched again. Browser controls can manage local technologies, but disabling essential storage may prevent the service from working.
We do not currently use third-party behavioural advertising cookies. If that changes, this policy and any required consent controls will be updated before such use.
12. Retention framework
We keep personal information only for a period that is reasonably connected to service delivery, customer instructions, security, legitimate business records, or law. The schedule below describes the factors and typical approach rather than promising a single deletion date for every record.
Active account records. We generally retain this information while the account remains active and for a limited administrative period after closure. The purpose is to operate the account, support reactivation where offered, resolve closure issues, and meet contractual obligations. We consider sensitivity, legal duties, expected disputes, security risk, provider dependencies, and whether aggregated information can serve the purpose. Expiry may not remove every protected backup immediately, but retained copies remain restricted from ordinary use. We may delete sooner when information is no longer needed or retain a limited record longer where law, fraud prevention, safety, or legal claims justify it.
Workspace content. We generally retain this information while the customer maintains the workspace and through a reasonable deletion or export window following account closure. The purpose is to provide customer-controlled workflows and allow orderly account administration. We consider sensitivity, legal duties, expected disputes, security risk, provider dependencies, and whether aggregated information can serve the purpose. Expiry may not remove every protected backup immediately, but retained copies remain restricted from ordinary use. We may delete sooner when information is no longer needed or retain a limited record longer where law, fraud prevention, safety, or legal claims justify it.
Backups. We generally retain this information until the relevant protected backup cycles expire or are securely overwritten. The purpose is to support resilience, disaster recovery, and service continuity. We consider sensitivity, legal duties, expected disputes, security risk, provider dependencies, and whether aggregated information can serve the purpose. Expiry may not remove every protected backup immediately, but retained copies remain restricted from ordinary use. We may delete sooner when information is no longer needed or retain a limited record longer where law, fraud prevention, safety, or legal claims justify it.
Billing and transaction records. We generally retain this information for the period required by tax, accounting, payment, anti-fraud, and dispute obligations. The purpose is to reconcile payments, demonstrate financial activity, address charge questions, and comply with recordkeeping law. We consider sensitivity, legal duties, expected disputes, security risk, provider dependencies, and whether aggregated information can serve the purpose. Expiry may not remove every protected backup immediately, but retained copies remain restricted from ordinary use. We may delete sooner when information is no longer needed or retain a limited record longer where law, fraud prevention, safety, or legal claims justify it.
Consent and policy records. We generally retain this information for the life of the account and an appropriate period afterward. The purpose is to demonstrate which terms were accepted and respond to legal or contractual questions. We consider sensitivity, legal duties, expected disputes, security risk, provider dependencies, and whether aggregated information can serve the purpose. Expiry may not remove every protected backup immediately, but retained copies remain restricted from ordinary use. We may delete sooner when information is no longer needed or retain a limited record longer where law, fraud prevention, safety, or legal claims justify it.
Authentication and session records. We generally retain this information for short operational periods, with significant security events retained longer where justified. The purpose is to maintain sessions, investigate account takeover, and protect users. We consider sensitivity, legal duties, expected disputes, security risk, provider dependencies, and whether aggregated information can serve the purpose. Expiry may not remove every protected backup immediately, but retained copies remain restricted from ordinary use. We may delete sooner when information is no longer needed or retain a limited record longer where law, fraud prevention, safety, or legal claims justify it.
Security and abuse records. We generally retain this information for a risk-based period that may extend beyond account closure. The purpose is to detect repeated attacks, enforce restrictions, protect other users, and establish or defend claims. We consider sensitivity, legal duties, expected disputes, security risk, provider dependencies, and whether aggregated information can serve the purpose. Expiry may not remove every protected backup immediately, but retained copies remain restricted from ordinary use. We may delete sooner when information is no longer needed or retain a limited record longer where law, fraud prevention, safety, or legal claims justify it.
Public-page activity. We generally retain this information for the period needed to operate the workflow and maintain relevant document or abuse-prevention records. The purpose is to show intended activity, support signatures or acceptance records, and investigate misuse. We consider sensitivity, legal duties, expected disputes, security risk, provider dependencies, and whether aggregated information can serve the purpose. Expiry may not remove every protected backup immediately, but retained copies remain restricted from ordinary use. We may delete sooner when information is no longer needed or retain a limited record longer where law, fraud prevention, safety, or legal claims justify it.
Support records. We generally retain this information for a reasonable period after the request is resolved. The purpose is to maintain continuity, measure support quality, and address recurring or disputed issues. We consider sensitivity, legal duties, expected disputes, security risk, provider dependencies, and whether aggregated information can serve the purpose. Expiry may not remove every protected backup immediately, but retained copies remain restricted from ordinary use. We may delete sooner when information is no longer needed or retain a limited record longer where law, fraud prevention, safety, or legal claims justify it.
Privacy requests and grievances. We generally retain this information for an appropriate compliance and limitation period after completion. The purpose is to demonstrate response, avoid repeated verification, and establish or defend legal rights. We consider sensitivity, legal duties, expected disputes, security risk, provider dependencies, and whether aggregated information can serve the purpose. Expiry may not remove every protected backup immediately, but retained copies remain restricted from ordinary use. We may delete sooner when information is no longer needed or retain a limited record longer where law, fraud prevention, safety, or legal claims justify it.
Email delivery records. We generally retain this information for a limited diagnostic period, with important transactional notices retained where needed. The purpose is to confirm sending, diagnose delivery, suppress invalid destinations, and maintain required notices. We consider sensitivity, legal duties, expected disputes, security risk, provider dependencies, and whether aggregated information can serve the purpose. Expiry may not remove every protected backup immediately, but retained copies remain restricted from ordinary use. We may delete sooner when information is no longer needed or retain a limited record longer where law, fraud prevention, safety, or legal claims justify it.
Application logs. We generally retain this information for short, risk-based operational periods unless an event requires longer investigation. The purpose is to diagnose errors, monitor reliability, prevent abuse, and investigate incidents. We consider sensitivity, legal duties, expected disputes, security risk, provider dependencies, and whether aggregated information can serve the purpose. Expiry may not remove every protected backup immediately, but retained copies remain restricted from ordinary use. We may delete sooner when information is no longer needed or retain a limited record longer where law, fraud prevention, safety, or legal claims justify it.
Aggregated statistics. We generally retain this information for as long as they remain useful and no longer identify a person. The purpose is to understand product performance, capacity, adoption, and reliability. We consider sensitivity, legal duties, expected disputes, security risk, provider dependencies, and whether aggregated information can serve the purpose. Expiry may not remove every protected backup immediately, but retained copies remain restricted from ordinary use. We may delete sooner when information is no longer needed or retain a limited record longer where law, fraud prevention, safety, or legal claims justify it.
Files pending deletion. We generally retain this information until active copies and scheduled backup copies are removed through normal system cycles. The purpose is to complete a reliable deletion without undermining backup integrity or security. We consider sensitivity, legal duties, expected disputes, security risk, provider dependencies, and whether aggregated information can serve the purpose. Expiry may not remove every protected backup immediately, but retained copies remain restricted from ordinary use. We may delete sooner when information is no longer needed or retain a limited record longer where law, fraud prevention, safety, or legal claims justify it.
Records under legal hold. We generally retain this information until the relevant hold, investigation, proceeding, or binding preservation duty ends. The purpose is to comply with law and preserve information needed for a dispute or official process. We consider sensitivity, legal duties, expected disputes, security risk, provider dependencies, and whether aggregated information can serve the purpose. Expiry may not remove every protected backup immediately, but retained copies remain restricted from ordinary use. We may delete sooner when information is no longer needed or retain a limited record longer where law, fraud prevention, safety, or legal claims justify it.
13. Security governance
We use reasonable administrative, technical, and organisational safeguards designed to protect information, including authenticated access, provider security controls, encrypted network transport, access restrictions, webhook verification, and audit or abuse-prevention records. Safeguards are selected with regard to the nature of the system, sensitivity, credible threats, implementation cost, and available technology.
Security is a shared responsibility. You should protect your email and Google accounts, use a strong unique password where applicable, secure devices, review collaborators, verify recipients, avoid exposing public links, and report suspected unauthorised access promptly. We will never ask for a password, card credential, one-time password, CVV, UPI PIN, or bank password through ordinary support.
We investigate suspected incidents to determine scope, contain risk, restore safe operation, preserve relevant evidence, and make notifications where applicable law requires them. Not every unsuccessful attack, blocked request, service error, or provider alert is a personal-data breach. No online service can guarantee absolute security.
14. Individual choices and rights
Subject to applicable law, you may request access to or information about your personal information, correction of inaccurate or incomplete information, deletion, restriction or objection, withdrawal of consent, portability where it applies, and review of certain automated decisions. You may also raise a grievance or complain to an appropriate authority. Rights vary by location and circumstances and may be subject to exemptions.
Many account and workspace details can be reviewed or changed directly in the application. For other requests, email hello@centralee.com with the subject Privacy Request and describe the information, account, relationship, and requested outcome. Do not send identity documents unless we ask for a proportionate verification method.
We may verify identity and authority before disclosing or changing information. Verification protects the person concerned and may use the account email, an authenticated session, relevant transaction context, or other limited evidence. An agent must demonstrate authority where law permits an authorised agent.
We will respond within the period required by applicable law. Complex, numerous, unclear, or third-party-dependent requests may require clarification or an extension where allowed. We may refuse or limit a request where an exemption applies, the request would adversely affect another person's rights, identity cannot be verified, retention is legally required, or the request is manifestly unfounded or excessive. We will explain the applicable reason when required.
Withdrawing consent does not invalidate earlier lawful processing. Objecting to necessary contractual processing may mean the relevant service cannot continue. Deletion from active systems may not immediately remove protected backup copies, de-identified statistics, records needed for security, or information another customer independently controls.
15. Automated processing and fairness
Centralee may use rules and automated signals to authenticate requests, prevent repeated actions, enforce plan limits, route traffic, identify suspicious behaviour, and calculate dashboard or billing states. These tools support service operation and security. We do not currently use customer workspace content to make decisions that produce legal or similarly significant effects about the subject on Centralee's own behalf.
Automated controls can make mistakes. If a security or entitlement control materially affects access, contact support with relevant context so the matter can be reviewed. We assess signals in context and may ask for verification before restoring access or changing a protected record.
We seek to avoid unjustified discrimination in our own processing. Customers remain responsible for decisions they make using their records, reports, proposals, contracts, invoices, or other workspace content and must not use Centralee to make unlawful discriminatory decisions.
16. Accuracy, minimisation, and access
We design fields and workflows around identifiable product purposes and seek not to require information that is unnecessary for the requested function. Optional fields should be used with the same restraint. Customers should periodically review stored client information, remove obsolete details, and restrict sensitive notes to people with a legitimate need.
People can correct many account details directly, while customers control most workspace content. We may correct system records when reliable evidence shows an error. We do not guarantee that customer-supplied information is accurate and ordinarily do not independently verify the facts in proposals, contracts, invoices, profiles, or notes.
Access by Centralee personnel is limited to legitimate operational needs such as support, security, reliability, billing administration, or legal compliance. Access may be logged or controlled through provider and application systems. Confidentiality duties and role expectations apply to people authorised to handle information.
17. Account closure and deletion
An account holder may request closure through available settings or support. Before closure, the customer should export any records it is required to keep and resolve active subscriptions, recipient workflows, collaborator access, and outstanding business obligations. Account closure does not cancel or rewrite the customer's external contracts, invoices, or legal duties.
Following a valid closure request, active access is disabled and information enters applicable deletion and retention processes. Some records remain where needed for payment reconciliation, tax, consent evidence, fraud prevention, security, disputes, provider settlement, backup integrity, or other legal obligations. Retained information remains subject to this policy and is not used to continue ordinary workspace operations.
Public links may stop working when their underlying record or workspace is disabled, but recipients may have downloaded, printed, forwarded, or independently retained information. Centralee cannot delete copies outside systems it controls.
18. Children
Centralee is intended for business users aged 18 or older and is not directed to children. Customers must not knowingly use the service to build profiles about children or collect children's information unless they have a lawful, necessary, and appropriately safeguarded business purpose that is compatible with the service.
If you believe a child has created an account or personal information about a child has been submitted inappropriately, contact us with sufficient context so we can review and take proportionate action. We may coordinate with the relevant customer where it controls the record.
19. Changes and contact
We may update this policy when our services, providers, or legal obligations change. Material changes will be posted here and, where appropriate, communicated through the service or email. The last-updated date identifies the current version, and the signup record stores the version accepted when an account is created.
For privacy questions, rights requests, or grievances, email hello@centralee.com with the subject Privacy Request. Include the relevant account email and a clear description, but never include passwords, payment credentials, one-time passwords, CVV, UPI PINs, or bank passwords. We will acknowledge and address requests within a reasonable period consistent with applicable law.
If a response does not resolve a concern, reply with the reasons and ask for grievance review. This internal route does not limit any right to contact a competent regulator, court, payment provider, or other authority available under applicable law.
