Privacy Policy

What we collect, how we use it, and the choices you have — whether you are a visitor, a customer, or someone who has been asked to answer a conversation.

Effective October 5, 2026

1. Who we are and what this policy covers

Acquainto Inc., a Delaware corporation (“Acquainto”, “we”), provides a service that lets organizations create conversational surveys and intake flows, called eFlows, and collect responses through a widget on their own website or a link we host. This policy explains what personal information we collect, how we use it, and the choices you have. It covers acquainto.com, the Acquainto application at app.acquainto.com, our API, the eFlow widget and hosted links, and email we send.

It applies to three kinds of people:

  • Visitors to acquainto.com
  • Customers: organizations that sign up for Acquainto, and the people who use it on their behalf
  • Respondents: people who answer an eFlow that one of our customers has published

Effective date: October 5, 2026. Contact: privacy@acquainto.com, Acquainto Inc., 18117 Biscayne Blvd, Suite 61395, Miami, FL 33160, USA.

2. Our two roles

For visitors and customers, Acquainto decides how and why data is processed, so we are the controller (or “business” under US state laws) of that data.

For respondents, the organization that published the eFlow (our customer) decides what to ask, why, who sees your answers, and how long they are kept. Acquainto processes your answers only to run that eFlow for them, on their instructions, as their processor (or “service provider”). The one exception is a small amount of technical information, such as IP addresses and security logs, which we use ourselves to keep the service secure and to count usage in aggregate.

If you answered an eFlow, in short:

The organization that asked youAcquainto
Decides what is asked and whyYesNo
Sees your answersYes, and anyone they share them withOur systems process them to run the conversation. Our staff do not read them in the ordinary course of operating the service
Decides how long answers are keptYes, within the limits in section 8Deletes on their instructions and on the schedule in section 8
Answers your requests to see, correct, or delete your dataYesPasses your request to them and helps them respond
Keeps your answers secureYesYes, as described in section 9

The organization’s own privacy notice governs how it uses your answers. You can reach it from the eFlow, usually through the “How your answers are handled” link.

What we promise respondents, whatever the organization instructs:

  • The eFlow always tells you that you are talking with an AI assistant and which organization sees your answers
  • We never sell your answers, use them for advertising, or combine them with answers you give to other organizations
  • We do not use your answers to train AI models unless the organization has opted in, and then only in de-identified form
  • We apply the security and deletion practices in this policy to every eFlow
  • If you contact us about your data, we forward your request to the organization, and tell you if we cannot identify it
  • Anyone can report an eFlow that seems deceptive or abusive to privacy@acquainto.com, and we can disable it
  • We do not follow instructions we believe are unlawful

3. Information we collect

WhoWhatHow we get it
VisitorsPages viewed, IP address, browser and device type, referring pageAutomatically, from our web server logs
CustomersName, work email, password (stored as a hash), organization name, logo and brand settings, plan and billing statusYou provide it when you sign up and use the app
CustomerseFlow content you author: questions, instructions, branding, images, webhook and integration settingsYou create it in the app
CustomersUsage: pages visited in the app, actions taken, API calls, IP address, timestampsAutomatically, from application logs
CustomersGoogle account connection, if you connect Google Sheets: an access token and the sheet you chooseYou authorize it through Google
CustomersSupport requests and files you attach to themYou send them to us
RespondentsYour answers to an eFlow, including free-text answersYou provide them in the conversation
RespondentsSession data: a random session identifier, timestamps, the page the widget is embedded on, browser type, IP addressAutomatically, when the widget or hosted link loads
RespondentsContact details, if the customer’s eFlow asks you for them, or if the customer attached them to your personalized linkYou provide them in the conversation, or the customer provides them when they create the link

We do not knowingly collect precise location, biometric data, or data from device sensors. Respondents may be asked about sensitive topics by a customer, for example health or employment; the customer is responsible for having a lawful basis to ask, and we process those answers only on their instructions.

4. How we use information

We use information to:

  • Provide the service: run eFlows, store and display responses, deliver results to customers, send invitations and notifications
  • Operate customer accounts: sign-in, billing, support, and service announcements
  • Keep the service secure: detect abuse, rate-limit traffic, investigate incidents, and keep audit logs
  • Improve the service using aggregated usage statistics that do not identify individuals
  • Meet legal obligations and enforce our terms

AI processing. eFlows are conversational. To decide what to ask next and to interpret answers, the service sends the conversation to a large language model run by a third-party AI provider (see section 6). Only the content needed for that conversation is sent. We send an instruction with every request that the content not be retained and not be used to train models. We do not commit to a particular provider, and which one serves a given request may change.

Training. We do not use your eFlow content or respondent conversations to train or improve models unless you opt in. Opting in is a setting in your account, off by default; when it is on, we may use de-identified content from your account to improve Acquainto’s features, and you can turn it off at any time, which stops further use. We improve the service for everyone using aggregated usage statistics that do not identify anyone. We do not attempt to re-identify de-identified data, and we require the same of anyone we share it with.

Quality evaluation. We measure how well the conversation engine performs — whether a question was understood, whether a follow-up was warranted — and we publish the results. Those measurements run against a fixed set of test conversations we wrote ourselves, not against your content, and they do not train models. If you flag a turn in your own account as wrong, you can export it as a test case; that export stays inside your account.

No automated decisions about people. eFlows adapt their questions to your answers, and can summarize responses for the organization that asked. They do not make decisions that have legal or similarly significant effects on anyone; any such decisions are made by the organization.

Our staff and your content. Our staff do not view your eFlow titles, questions, or respondent data in the course of operating the service. Staff access is restricted by role, requires multi-factor authentication, and administrative actions are recorded in an audit trail.

We send customers transactional email (verification, invitations, password resets, results notifications). Marketing email, if any, can be unsubscribed from with one click. We never send marketing email to respondents.

5. Cookies and similar technologies

The Acquainto application uses cookies that are necessary to sign you in and keep your session secure. They are set only for app.acquainto.com and console.acquainto.com and are not shared with other sites.

The eFlow widget stores a random session identifier in the respondent’s browser so a conversation can be resumed if the page is reloaded. It is not used to track respondents across websites.

The widget runs on our customers’ own websites. Consent for any cookies those sites set is managed by the customer’s own consent tool, not by ours — we do not place a consent banner on someone else’s site, and we do not read the choices made in theirs.

acquainto.com, our marketing site, sets no cookies. It runs no analytics and no advertising tags— there is nothing to consent to and nothing to opt out of. If that changes we will say so here first. We do not use advertising cookies or sell data to ad networks, and we honor the Global Privacy Control signal where the law requires it.

One thing the marketing site does do. If you arrive with a campaign or referral code in the address bar — from an advertisement, or from a link a partner shared — the buttons that take you to signup carry that code onward, along with the page you clicked from and the address of the site that sent you, so that if you do create an account we can tell which advertisement or partner brought you. It is written into the link and nowhere else: nothing is stored in your browser, nothing is sent to anyone while you read, and if you never click through to signup nothing about your visit is recorded anywhere at all.

6. How we share information

We share personal information only with the service providers below, who process it on our behalf for the purpose stated, and in the other situations listed.

What the provider doesWhat it can seeWhere
Runs the application and the APIEverything. All data passes through the running application, and encryption terminates hereUnited States
Holds the database, its backups and file storageAll customer and respondent data, at restUnited States
Routes each AI request to a language modelConversation content: the question text and the answers given so farVaries with the model provider the router selects
Delivers our emailEmail addresses and message content — a completion notification contains the full question-and-answer table, so this provider can see answersUnited States
Provides sign-in with Google, and the Sheets export when a customer connects itSign-in identity, and the response data that customer chooses to exportUnited States
Monitors errorsOperational metadata only — never answers or respondent identifiersUnited States

This table names functions rather than companies on purpose. Which company performs each one can change without this policy changing, and a policy that carries vendor names goes stale quietly. The current names, what each one sees, the region it runs in and the gaps we know about are all at acquainto.com/subprocessors, which is the authoritative list.

There is no payment row, because we process no payment data. Billing runs against a mock provider today and no card details reach us or any provider acting for us. The row appears here, naming the processor, in the same change that turns real billing on.

We notify every customer at least 30 days before a new provider begins processing their data,so there is time to object or to leave before it happens. Changes are recorded on acquainto.com/subprocessors with the date each one took effect.

We also share information:

  • With the customer who published an eFlow. Respondent answers belong to that customer, who can see, export, and delete them
  • Through integrations a customer turns on, such as webhooks or Google Sheets, which send response data to systems the customer controls
  • When required by law, such as a subpoena or court order, in which case we notify the affected customer unless legally prohibited
  • In a business transfer, such as a merger or acquisition, under the same protections as this policy

We do not sell personal information and have not done so in the past 12 months.

7. Where data is stored

We store and process data in the United States. Section 6 and acquainto.com/subprocessors name each provider and the region it runs in; where we have not independently confirmed a region against the running deployment, that page says so rather than stating one.

If you use the service from outside the United States, your data is transferred to and processed in the United States. We do not publish a standard data processing agreement; if your legal review requires one, write to privacy@acquainto.com and we will handle the request individually.

8. Retention and deletion

DataKept for
Respondent conversationsUntil the customer deletes them, or deletes their account. There is no automatic expiry on response content
Customer account and eFlow contentFor the life of the account
Deleted accountsAll account data removed within 7 days of deletion
Audit events: sign-in, administrative actions, exportsUp to 400 days, for security investigation and compliance
Audit events: conversation, integration and model activity90 days
Billing recordsAs required by tax and accounting law

The periods above are for the live service. Encrypted database backups are retained for 35 days and then expire automatically, so complete removal from all systems takes up to that long after removal from the live service; there is no restore-and-scrub path into a backup.

Response content delivered to a destination you connect — your own Google Sheet, your webhook endpoint, your inbox — is a copy in a system we have no access to. Deleting it here does not delete it there.

9. Security

All data is encrypted in transit (TLS 1.2 or later) and at rest. Access by our staff requires a company account with multi-factor authentication, and administrative actions are logged. Passwords are stored hashed; API keys are stored only as digests, so reading our database cannot recover a usable key. Each customer’s data is separated in the application layer, with an automated test suite that verifies one account cannot reach another’s records. Changes to the infrastructure itself are recorded in an audit log that is cryptographically signed and stored write-protected, so an entry cannot be altered or removed after the fact.

The database sits in a private network segment with no route to the internet and no public address. Nothing outside our own application servers can reach it. acquainto.com/trust lists the rest of what we do and do not do, in the same terms.

We are not SOC 2 certified and no audit is in progress. Our Type I process begins in Q1 2027.No system is perfectly secure; if we learn of a breach affecting your data we will notify affected customers without undue delay and as required by law.

10. Your rights and choices

Customers can view and update account details in the app, export their data, delete responses, and close their account, which deletes their organization’s data as described in section 8. Email privacy@acquainto.com for anything the app does not cover.

Respondents should contact the organization that published the eFlow, since it controls your answers. If you reached this page from an eFlow’s privacy link, the organization’s name and privacy contact appear at the top of the page.

If you don’t know who the organization is, email privacy@acquainto.com and include as much of the following as you have:

  • If you can, start from the eFlow itself: its privacy link opens this page with the eFlow already identified, and a request sent from the same device and browser you answered on lets us find your answers directly
  • The link you used, or the website where the eFlow appeared, and roughly when you answered
  • The email address you gave in the eFlow, if any

To protect you, we verify your request before acting on it, for example by sending a confirmation link to the email address you gave. When you email us, we may reply with a link to a short form so we can identify and verify your request. Until your request is verified, we will not confirm whether we hold any answers from you. Once verified, we forward your request to the organization within 5 business days and tell you which organization it went to. The organization then responds within the time the law gives it. If an organization does not act on a forwarded request within 30 days, we may delete or restrict the answers concerned. If the organization’s account has already been closed, its data is deleted on the schedule in section 8.

Residents of California, Colorado, Connecticut, Virginia, and other US states with privacy laws have the right to know what personal information we hold, to access, correct, or delete it, to opt out of sale or targeted advertising (we do neither), and not to be discriminated against for exercising these rights. Submit a request to privacy@acquainto.com; we may ask you to verify your identity. You can appeal a decision by replying to our response. We respond within 45 days.

Residents of the EU, UK, and Switzerland additionally have the rights to restrict or object to processing, to data portability, and to lodge a complaint with a supervisory authority: in the EU, the authority in your country; in the UK, the Information Commissioner’s Office; in Switzerland, the Federal Data Protection and Information Commissioner. For respondent data, the organization that published the eFlow is the controller and chooses its own legal basis; we process your answers only on its instructions.

Our own legal bases are:

PurposeLegal basis
Providing the service, customer accounts, billing, supportPerformance of our contract with the customer
Security, abuse prevention, security logs, aggregated usage statisticsOur legitimate interest in operating and protecting the service
Marketing email to customersConsent, or legitimate interest where the law allows, with one-click unsubscribe
Using de-identified content to improve the serviceThe customer’s opt-in
Tax, accounting, and legal obligationsLegal obligation

Residents of Canada may also complain to the Office of the Privacy Commissioner of Canada, or in Quebec, to the Commission d’accès à l’information. We store data outside Canada, in the United States, as described in section 7.

11. Children

Acquainto is a business service. We do not knowingly collect personal information from children under 13, and customers may not use the service to collect it from children under 13 without the parental consent the law requires. If you believe a child has provided us information, email privacy@acquainto.com and we will delete it.

12. Changes and contact

We will post changes to this policy on this page and update the effective date. For changes that materially reduce your rights, we will email customers at least 30 days before they take effect.

Questions or requests: privacy@acquainto.com, or Acquainto Inc., 18117 Biscayne Blvd, Suite 61395, Miami, FL 33160, USA. Our privacy officer is our Chief Technology Officer, reachable at the same address.