How AIR Fusion collects, uses, stores, shares, and protects information on the Platform.
Last updated: August 6, 2026
This Privacy Policy describes how SUPPORT PARTNERS USA, INC. (“Support Partners”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects information in connection with the AIR Fusion platform, including the website at https://airfusion.ai/, its subpages and content, the AIR Fusion web and client applications, and the associated application programming interfaces and integrations (collectively, the “Platform”). This Privacy Policy applies to the Platform. Support Partners maintains a separate privacy policy for its corporate website at https://support-partners.com/. This Privacy Policy applies globally, to every user of the Platform, wherever in the world that user is located. It is designed to comply with the EU General Data Protection Regulation, the UK GDPR and the Data Protection Act 2018, the comprehensive privacy laws of the United States and its individual states, the EU Artificial Intelligence Act, and applicable artificial intelligence transparency legislation. Where a law that applies to you grants you a right or protection greater than the one stated here, that law prevails and we will honour it. We are committed to protecting the privacy of your information. We believe it is a good business practice to disclose to you how your personal information may be used. This Privacy Policy is intended to describe in a straight-forward and easily understandable manner:
As noted in the customer agreement or Standard Terms and Conditions applicable to the Platform (the “Agreement”), by accessing or using the Platform you accept and acknowledge that you are bound by this Privacy Policy. Accordingly, we encourage you to read this Privacy Policy carefully. If you have questions or concerns regarding this Privacy Policy, you may e-mail us at privacy@support-partners.com, or send mail to Support Partners USA, Inc., Attn: Privacy Dept., 8776 E. Shea Blvd #106-325, Scottsdale, Arizona, 85260.
This summary is provided for convenience. It does not replace the full text of this Privacy Policy.
The Platform is provided to organizations. It is important to understand which information we determine the use of, and which information we merely hold and process on a Customer’s behalf, because your rights differ accordingly.
We act as the controller (or “business”, under United States state privacy laws) in respect of information we collect to create and administer accounts, authenticate users, provide support, bill for the Platform, secure the Platform, and communicate with you. We determine the purposes and means of that processing, and this Privacy Policy governs it.
We act as a processor (or “service provider”) in respect of the files, documents, media, metadata, and other material that a Customer or its Authorized Users upload to, import into, or generate within a Customer tenant (collectively, “Customer Content”, each item being an “Asset”). The Customer is the controller of Customer Content. We process Customer Content only on the Customer’s documented instructions, as set out in the Agreement and the data processing addendum entered into with that Customer, and for no independent purpose of our own.
We may create aggregated or deidentified data derived from Customer Content, and use it to operate, secure, analyse, and improve the Platform, provided that such data cannot reasonably be used to identify any individual, Customer, or Asset, and is not disclosed to any third party in a form that could be attributed to a Customer. We maintain that data in deidentified form and do not attempt to reidentify it. Google user data is excluded from this permission, and is used only as described in the section titled “Google Drive Integration and Google User Data”.
If you are an Authorized User and you wish to access, correct, export, or delete Customer Content, you should in the first instance contact the Customer that operates your tenant. We will assist that Customer in responding to your request as required by the Agreement and by applicable law. If you contact us directly, we will refer your request to the relevant Customer unless applicable law requires otherwise.
When an account is created, we collect information such as name, business e-mail address, telephone number, job title or role, employer or organization name, mailing address, and authentication credentials or single sign-on identifiers. Where a Customer provisions accounts on behalf of its personnel, we receive this information from the Customer.
We collect and store the Customer Content that you or your organization choose to upload to, or import into, your tenant, together with associated metadata such as file name, file type, size, provenance, content credentials, version history, and the identity of the Authorized User who created or modified an Asset. Customer Content may itself contain personal information; we do not control what a Customer chooses to place within its tenant.
Where you connect a third-party service to your tenant, we collect the information necessary to operate that connection and the material you choose to bring across. Our handling of information obtained from Google APIs is described separately, and governs over anything to the contrary in this Privacy Policy, in the section titled “Google Drive Integration and Google User Data”. Our handling of information obtained from the Microsoft Graph API is likewise described separately, and governs over anything to the contrary in this Privacy Policy, in the section titled “OneDrive Integration and Microsoft User Data”.
When you interact with the Platform we automatically collect certain information (“Automatically-Collected Data”) about or from your computer, phone, or mobile device (“Devices”), such as, without limitation, your IP address, browser type and version, browser language, country and time zone, the URLs that refer visitors to the Platform, dates and times of access, page views and navigation, approximate geographic location derived from IP address, cookie information, the pages you requested, duration of activity, searches performed within the Platform, hardware model, operating system version, unique device identifiers, and mobile network information. We use this information to operate, secure, troubleshoot, and improve the Platform.
We do not use Automatically-Collected Data to deliver targeted or interest-based advertising, and we do not permit third parties to collect Automatically-Collected Data through the Platform for that purpose.
We do not collect or process payment card numbers, bank account numbers, or other payment instrument details through the Platform. Fees for the Platform are invoiced and settled outside the Platform, in accordance with the Agreement, and we hold only the billing contact details and transaction records necessary to administer your subscription and to meet our accounting and tax obligations. If in-Platform payment processing is introduced in a future release, it will be operated by a third-party payment processor to which payment details are submitted directly, that processor will be added to the list of subprocessors below, and this Privacy Policy will be updated before the feature becomes available.
We do not collect social security numbers of Customers, Authorized Users, or other individuals, and you should not provide such information to Support Partners. Nonetheless, if Support Partners comes into possession of social security numbers or collects such information in the future, the information will be treated confidentially and not shared with third parties unless allowed by law. Additionally, Support Partners will take reasonable steps to limit access to such social security numbers and take legally required steps to secure the transmission of data containing them.
If you enable features that detect, recognize, identify, group, search, or tag faces, the Platform may derive facial geometry, facial embeddings, or similar biometric information from images or video solely to provide the functionality you request. We do not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information. We disclose such information only as permitted by applicable law and obtain any notice, consent, or authorization required before collecting, processing, or disclosing it.
We retain biometric identifiers only for as long as necessary for the disclosed purpose. For Illinois residents, biometric identifiers and biometric information are permanently destroyed when the initial purpose for their collection has been satisfied or within three years of the individual’s last interaction with us, whichever occurs first. For Colorado consumers, biometric identifiers are deleted no later than the earliest of: (i) satisfaction of the initial collection purpose; (ii) twenty-four months after the consumer’s last interaction with us; or (iii) within the period required by Colorado law after our periodic review determines that continued retention is no longer necessary, adequate, or relevant. We maintain appropriate safeguards and an incident-response protocol for biometric information as required by applicable law.
For individuals in the European Economic Area, where biometric data are processed for the purpose of uniquely identifying a natural person and we act as controller, we process such data only where permitted under Article 9 of the GDPR, including on the basis of explicit consent where required.
The Platform is a business product, meant for adults and those who have reached the age of majority as defined by the laws of their domicile. It is not meant for individuals under the age of eighteen (18) or those defined by the laws of their domicile as minors. This Privacy Policy is designed to comply with the Children’s Online Privacy Protection Act (“COPPA”) to the extent COPPA applies. Accordingly, we do not knowingly collect or retain any personal information about users under the age of sixteen (16). If we obtain actual knowledge that we collected or retained personal information about a child under the age of sixteen (16), that information will be promptly deleted from our active systems, and purged from encrypted backups in accordance with our backup rotation schedule. Since we do not collect information from users under sixteen (16) years old, no such information is disclosed to third parties.
We use the information described above only for the purposes set out below. We do not use it for any incompatible purpose.
We do not use personal information, Customer Content, or Google user data for advertising of any kind, including targeted, personalized, interest-based, or retargeted advertising. We do not share it with advertising networks, advertising platforms, data brokers, or information resellers. We do not use it to determine credit-worthiness or for lending purposes.
Where the EU General Data Protection Regulation (“GDPR”) or the UK GDPR and the Data Protection Act 2018 (together, “UK data protection law”) applies to our processing as controller, we rely on the legal bases set out below. Where we process as processor on a Customer’s behalf, the Customer determines the legal basis.
| Purpose | Categories of personal data | Legal basis |
|---|---|---|
| Creating and administering accounts; authenticating users; providing the Platform | Identity, contact, employment, credentials | Article 6(1)(b) — performance of a contract; or Article 6(1)(f) — legitimate interests in providing the Platform to the Customer that employs or engages you |
| Customer support and responding to requests | Identity, contact, correspondence, support metadata | Article 6(1)(b) and Article 6(1)(f) — legitimate interests in supporting our Customers |
| Security, fraud and abuse prevention, incident investigation | Usage, device, log, access data | Article 6(1)(f) — legitimate interests in securing the Platform; Article 6(1)(c) where a legal obligation applies |
| Service continuity, backup and disaster recovery | All categories held | Article 6(1)(b) and Article 6(1)(f) — legitimate interests in operating a reliable service |
| Billing, accounting, audit and tax | Identity, contact, billing and transaction records | Article 6(1)(b) and Article 6(1)(c) — compliance with legal obligations |
| Service, security and administrative notices | Identity, contact | Article 6(1)(b) — necessary to perform the contract |
| Marketing communications | Identity, contact, preferences | Article 6(1)(a) — consent, where required; otherwise Article 6(1)(f) — legitimate interests in business-to-business marketing, subject to opt-out |
| Analysing and improving Platform performance and functionality | Aggregated or deidentified usage data wherever practicable | Article 6(1)(f) — legitimate interests in improving our product |
| Establishing, exercising or defending legal claims; regulatory compliance | Any category relevant to the claim | Article 6(1)(c) and Article 6(1)(f) |
Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that our interests are not overridden by your interests, rights, and freedoms. You may request a summary of that assessment, and you may object to the processing, at privacy@support-partners.com. Where we rely on consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.
We do not intentionally collect special categories of personal data under Article 9 GDPR, and you should not submit such data to us other than as Customer Content that the Customer has a lawful basis to process. Where Customer Content contains special category data, the Customer is responsible for identifying an Article 9 condition.
Providing account and identity information is necessary to enter into and perform the contract under which the Platform is made available. If it is not provided, we cannot create an account or provide the Platform. Providing marketing preferences is optional, and there is no consequence to declining.
Where we do not collect personal data from you directly, we obtain it from: the Customer that operates your tenant, which provisions and administers accounts; the identity provider you or your Customer uses to authenticate; a third-party service you connect to your tenant, such as Google Drive or OneDrive, in respect of material you select; and our payment processor, in respect of transaction records. We do not acquire personal data from data brokers, list vendors, or public-data aggregators.
The Platform offers features that use artificial intelligence and machine learning, which may include content analysis, media and video analysis, search and retrieval, classification, tagging, transcription, summarisation, and automated workflows (“AI Features”). This section explains how AI Features handle your information, and how we meet the transparency obligations that apply to them.
Regulation (EU) 2024/1689 (the “AI Act”) applies to AI systems placed on the Union market or whose output is used in the Union. Where we make AI Features available under our own name, we act as a provider of an AI system. Where a Customer uses those features under its own authority, the Customer acts as a deployer, and certain obligations fall on the Customer rather than on us. We give the following information so that both roles can be discharged.
The United Kingdom has not enacted a statute equivalent to the AI Act. Our processing of personal data by AI Features in the United Kingdom is governed by UK data protection law, and we apply the transparency, fairness, accuracy, data minimisation, and accountability requirements of that law, together with the guidance issued by the Information Commissioner’s Office on artificial intelligence and data protection. The commitments in this section, including the restriction on model training and the transparency measures described above, are applied to United Kingdom users on the same basis as to users in the European Union.
AI-specific obligations in the United States are set by individual jurisdictions. We apply the commitments in this section nationwide, and we note the following in particular.
Which AI Features are available within a tenant, and to which Authorized Users, is configured for each Customer and is agreed with that Customer. If you are an Authorized User and you wish to know which AI Features are enabled in your tenant, or to have them changed, please contact your Customer administrator. If you believe an AI Feature has produced an inaccurate output about you, you may contact privacy@support-partners.com, and you may exercise the rights set out in the section titled “Your Privacy Rights and Choices”.
If you connect Google Drive to AIR Fusion, we access only the files you yourself select, use them only to complete the import you initiated, store them within your own tenant, and never use them for advertising or to train artificial intelligence models. This section applies to all users worldwide.
This section applies to every user of the AIR Fusion Google Drive integration, wherever in the world that user is located, and regardless of which other provisions of this Privacy Policy apply to that user. It applies in addition to the remainder of this Privacy Policy. Where any other provision of this Privacy Policy conflicts with this section in respect of Google user data, this section prevails. In this section, “Google user data” means any data we obtain from Google APIs about you or your Google Account, including the content of files you import from Google Drive.
We request access to Google user data only when you choose to connect your Google Account to AIR Fusion, and we obtain data only when you take an action that requires it. We collect:
We do not request or receive any other Google scopes.
We use Google user data for one purpose only: to fulfill the import you initiated — retrieving the file you selected and creating a copy of it as an Asset within your tenant — and to display and manage the connected Google Account as described above.
We use Google user data for no other purpose. In particular, and notwithstanding anything to the contrary elsewhere in this Privacy Policy, we do not use Google user data for advertising of any kind, including targeted, personalized, interest-based, or retargeted advertising; to build marketing or behavioral profiles; for general product analytics, usage-trend analysis, or benchmarking; to determine credit-worthiness or for lending purposes; or to create, train, or improve any machine learning or artificial intelligence model. The artificial-intelligence features described in this Privacy Policy operate on an imported Asset only where you expressly direct them to do so in respect of that Asset, and in no case is Google user data used to create, train, or improve any model beyond your own personalized model for that user-facing feature.
We do not sell, rent, license, or trade Google user data, and we do not share it with any third party other than the subprocessors strictly necessary to operate the integration, being WorkOS, Inc. (custody, encryption, and refresh of Google OAuth tokens) and Microsoft Corporation, through Microsoft Azure (hosting and storage of imported file content and metadata). No advertising network, advertising platform, data broker, information reseller, or analytics provider receives Google user data. Notwithstanding any other provision of this Privacy Policy, Google user data is never shared, transferred, or made available for advertising, marketing, or measurement purposes.
AIR Fusion’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
(a) Prominent user-facing use. We limit our use of Google user data to providing or improving user-facing features that are prominent in the requesting application’s user interface.
(b) Restrictions on transfer. We do not transfer Google user data except: (i) to provide or improve user-facing features that are prominent in the requesting application’s user interface, and only with your consent; (ii) for security purposes, for example investigating abuse; (iii) to comply with applicable laws; or (iv) as part of a merger, acquisition, or sale of assets of the developer, after obtaining your explicit prior consent.
(c) Prohibited uses. We do not transfer or sell Google user data to third parties such as advertising platforms, data brokers, or information resellers. We do not transfer, sell, or use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising. We do not transfer, sell, or use Google user data to determine credit-worthiness or for lending purposes.
(d) No human reading. We do not allow humans to read Google user data, unless: (i) we have obtained and documented your explicit consent or affirmative agreement to view specific messages, files, or other data; (ii) the data, including derivations of it, is aggregated and anonymized and used for internal operations in accordance with applicable privacy and other jurisdictional legal requirements; (iii) it is necessary for security purposes, for example investigating a bug or abuse; or (iv) it is necessary to comply with applicable laws or regulations.
(e) No artificial intelligence or machine learning training. We do not transfer, sell, or use Google user data to create, train, or improve a machine learning or artificial intelligence model, beyond that specific user’s personalized model for the appropriate use case or user-facing feature.
You control both our access to your Google Account and the copy of any file you have imported.
Content imported through a third-party integration (Google Drive or OneDrive) is expressly excepted from any fixed retention period stated elsewhere in this Privacy Policy. Once a file is imported it becomes an Asset within your tenant, and is retained for as long as your tenant retains it — that is, according to the Customer’s own configured data-retention settings and its own decisions to delete — and not according to any fixed period set by us. We retain it until it is deleted by a user, until the Customer’s configured retention policy causes it to be deleted, until you disconnect the relevant integration and ask us to delete it, or until the tenant is terminated, whichever occurs first, after which it is deleted as described above.
If you connect OneDrive to AIR Fusion, we access only the files you yourself select, use them only to complete the import you initiated, store them within your own tenant, and never use them for advertising or to train artificial intelligence models. This section applies to all users worldwide.
This section applies to every user of the AIR Fusion OneDrive integration, wherever in the world that user is located, and regardless of which other provisions of this Privacy Policy apply to that user. It applies in addition to the remainder of this Privacy Policy. Where any other provision of this Privacy Policy conflicts with this section in respect of Microsoft user data, this section prevails. In this section, “Microsoft user data” means any data we obtain from the Microsoft Graph API about you or your Microsoft account, including the content of files you import from OneDrive.
We request access to Microsoft user data only when you choose to connect your Microsoft account to AIR Fusion, and we obtain data only when you take an action that requires it. We collect:
We do not request or receive any other Microsoft Graph scopes.
The OneDrive integration supports connecting either a personal Microsoft account or a work or school (Microsoft 365) account. If you connect a work or school account, the file structure accessed is that account’s OneDrive for Business, which is provisioned and governed by your employer or institution — not by the Customer that operates your AIR Fusion tenant. Your organization’s Microsoft 365 administrator may need to consent to, or may restrict or revoke, third-party application access to that account under its own IT policies, independently of anything described in this Privacy Policy.
We use Microsoft user data for one purpose only: to fulfil the import you initiated — retrieving the file you selected and creating a copy of it as an Asset within your tenant — and to display and manage the connected Microsoft account as described above.
We use Microsoft user data for no other purpose. In particular, and notwithstanding anything to the contrary elsewhere in this Privacy Policy, we do not use Microsoft user data for advertising of any kind, including targeted, personalized, interest-based, or retargeted advertising; to build marketing or behavioral profiles; for general product analytics, usage-trend analysis, or benchmarking; to determine credit-worthiness or for lending purposes; or to create, train, or improve any machine learning or artificial intelligence model. The artificial-intelligence features described in this Privacy Policy operate on an imported Asset only where you expressly direct them to do so in respect of that Asset, and in no case is Microsoft user data used to create, train, or improve any model beyond your own personalized model for that user-facing feature.
Microsoft Corporation is both the infrastructure provider that hosts the Platform, through Microsoft Azure, and, where you connect OneDrive, the source of the Microsoft user data you import. These are separate roles: hosting the Platform does not give Microsoft any greater access to, or rights in, Microsoft user data than it has as our infrastructure subprocessor generally, as described in the section titled “How We Share Information.”
We do not sell, rent, license, or trade Microsoft user data, and we do not share it with any third party other than the subprocessors strictly necessary to operate the integration, being WorkOS, Inc. (custody, encryption, and refresh of Microsoft OAuth tokens) and Microsoft Corporation, through Microsoft Azure (hosting and storage of imported file content and metadata). No advertising network, advertising platform, data broker, information reseller, or analytics provider receives Microsoft user data. Notwithstanding any other provision of this Privacy Policy, Microsoft user data is never shared, transferred, or made available for advertising, marketing, or measurement purposes.
AIR Fusion’s access to and use of Microsoft user data through the Microsoft Graph API adheres to the Microsoft APIs Terms of Use. This Privacy Policy, including this section, is intended to be at least as protective of your information as the Microsoft Privacy Statement, as that Terms of Use requires. Specifically:
(a) No advertising or marketing use. We do not use or transfer Microsoft user data, or any data aggregated, anonymized, or derived from it, for advertising or marketing purposes, including targeting or serving advertisements.
(b) No use beyond the permissions you grant. We do not request, use, or make available Microsoft user data outside the permissions you expressly grant when you connect your Microsoft account, and we do not scrape, build databases from, or otherwise copy Microsoft user data except as necessary to fulfil the import you initiated.
(c) No human reading beyond what the feature requires. We do not have personnel read Microsoft user data other than as necessary to provide the import feature, investigate security incidents or abuse, or comply with applicable law.
(d) Deletion on disconnection or account closure. We implement the retention and deletion practices described below, including deleting Microsoft user data when you disconnect the integration or close your account with us.
You control both our access to your Microsoft account and the copy of any file you have imported.
Content imported from OneDrive is subject to the same retention treatment as content imported from Google Drive, described in the section titled “Retention of imported content” above.
We share information only as described in this section. We do not share it for any other purpose.
We engage a limited number of service providers to operate the Platform. Each is bound by written contract to process information only on our documented instructions, to apply appropriate technical and organizational security measures, to assist us with data subject requests and security incidents, and to delete or return the information at the end of the engagement. Our subprocessors as at the date of this Privacy Policy are:
An up-to-date list of subprocessors is available upon request by emailing privacy@support-partners.com. Customers may subscribe to notifications of changes to that list as provided in the Agreement and the data processing addendum.
We do not sell personal information or Customer Content, and we do not share personal information for cross-context behavioral advertising or targeted advertising, as those terms are defined under applicable United States state privacy laws. We have not done so in the preceding twelve (12) months.
We do not sell Google user data under any circumstances. This includes any merger, acquisition, change of control, or sale of substantially all of our assets or business, in connection with which Google user data will be transferred only after obtaining your explicit prior consent. We do not sell, and do not create for sale, aggregated or deidentified information derived from Google user data.
From time to time, Support Partners may be required to respond to a subpoena, a court order, or a similar investigative demand from law enforcement, a government agency, or a private litigant. Support Partners reserves all rights to defend, within its sole discretion, against such legal requests, demands, and claims. For instance, Support Partners may raise or waive legal objections or rights. Support Partners also reserves the right to disclose your information, as allowed by applicable law, when we believe it is reasonably appropriate based on the situation. Such disclosure may occur, but is not limited to, disclosing your information in connection with efforts to: (i) investigate, prevent, or commence other actions regarding suspected illegal activity or other wrongdoing; (ii) protect or defend the rights, property, or safety of our company, our users, our employees, or others; (iii) comply with applicable law or cooperate with law enforcement; or (iv) enforce the Agreement or other agreements or policies between you and us related to the Platform.
Where we are legally permitted to do so, and where we act as processor for a Customer, we will notify the relevant Customer before disclosing Customer Content in response to a legal demand, so that the Customer may seek protective relief.
This Privacy Policy does not cover any third party’s use or handling of your information once it is shared at your direction. Instead, the privacy policies of the third party or parties will govern. We encourage you to visit the websites of those third parties and fully read and understand their privacy policies. Some of these entities or their servers may be located outside the United States.
The Platform may contain links to other websites. Support Partners disclaims any responsibility for the privacy practices of third parties that may have links to or from the Platform, or any framed content within it. We encourage you to review the privacy policies and statements of every website that you visit that collects personally identifiable information.
The Platform is operated from, and information is stored in, the locations described in the Agreement or the applicable order form. Information may be transferred to, stored in, and processed in the United States and in other countries in which we or our subprocessors operate. The laws of those countries may differ from the laws of your country.
Where we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland to a country that has not been the subject of an adequacy decision, we rely on appropriate safeguards, being the European Commission’s Standard Contractual Clauses, and for United Kingdom transfers the UK International Data Transfer Addendum to those clauses, together with any supplementary measures required following a transfer impact assessment. A copy of the safeguards applicable to your information is available on request from privacy@support-partners.com.
Customers with data residency requirements should refer to the Agreement or contact us; regional hosting may be available.
We retain Customer Content, including Assets imported from a connected third-party service, for as long as the Customer’s tenant retains it. Retention of Customer Content is determined by the Customer through its own configured data-retention settings and its own decisions to delete, and not by any fixed period set by us. We do not apply an independent retention clock to Customer Content.
Nothing in this section prevents us from deleting Customer Content where the Agreement permits or requires it, including on non-payment, on expiry of a trial or evaluation period, on termination of the Agreement, or where a tenant has been inactive for the period stated in the Agreement. Where we propose to delete Customer Content on grounds of inactivity, we will give the Customer prior notice and a reasonable opportunity to retrieve it.
When an Asset is deleted, it is removed from active systems within three (3) months and purged from encrypted backups within a further three (3) months, in accordance with our backup rotation schedule. On termination or expiry of a tenant, Customer Content is deleted, or returned to the Customer and then deleted, in accordance with the Agreement, and in any event within three (3) months of the end of any agreed retrieval period, with backups purged within a further three (3) months. These are outer limits rather than targets; in practice deletion is normally completed sooner.
We may store account and identity information, and the Automatically-Collected Data we hold about you, for more than one (1) year from the time of initial submission: for as long as an account remains active, and thereafter for the period necessary to resolve disputes, enforce our agreements, and comply with our legal, tax, and accounting obligations. Security, audit, and access logs are retained for the period necessary for the security purposes described in this Privacy Policy. Billing records are retained for the period required by applicable tax law. Aggregated and deidentified information, which cannot reasonably be used to identify you, may be retained indefinitely.
We take reasonable security measures to protect information against unauthorized access, loss, alteration, or destruction. These measures include encryption of data in transit and at rest, tenant isolation, role-based access control, the principle of least privilege for personnel access, logging and monitoring, vulnerability management, personnel confidentiality obligations, and the use of reputable third-party vendors. Despite these reasonable measures, we cannot guarantee that our security measures are impenetrable. Therefore, although we take reasonable steps to secure your information, we cannot and do not promise or warrant that your information will always remain secure.
The Platform is hosted on Microsoft Azure. Microsoft maintains an independent audit and certification programme for the Azure platform, including ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, and SOC 2 Type II, and our security programme is built on and assessed against those platform controls. Certifications held by Microsoft in respect of the Azure platform attest to the security of that platform; they do not constitute an assessment of the AIR Fusion application itself.
If we become aware of a personal data breach affecting your information, we will notify you, or the Customer that operates your tenant, without undue delay and as required by applicable law and the Agreement.
We extend the following rights to all users of the Platform, wherever they are located, to the extent permitted by, and subject to the conditions, limitations, and exemptions available under, applicable law, and subject to verification of your identity. Where a right is not recognised in your jurisdiction, we extend it as a matter of policy rather than as a legal entitlement, and we may decline a request that is manifestly unfounded, excessive, or repetitive. Where we hold information as a processor on a Customer’s behalf, we will refer your request to that Customer and assist them in responding.
To exercise any of these rights, e-mail privacy@support-partners.com, or write to Support Partners USA, Inc., Attn: Privacy Dept., 8776 E. Shea Blvd #106-325, Scottsdale, Arizona, 85260. We will respond within the period required by applicable law. You may also authorize an agent to make a request on your behalf, subject to verification.
If you are in the European Economic Area, the United Kingdom, or Switzerland, you also have the right to lodge a complaint with your local supervisory authority. We would appreciate the opportunity to address your concerns first.
Unless you opt out, we may use your information to communicate with you about the Platform. You may opt out of marketing communications at any time using the unsubscribe link in any such message, or by contacting privacy@support-partners.com. You cannot opt out of service, security, and administrative notices while you hold an account, as these are necessary to provide the Platform. Please note that changing your opt-out preference will only affect future communications from us.
In some states, users may be entitled to know how we respond to “Do Not Track” browser settings. There is little consensus in the industry about what “Do Not Track” means; however, at this time we recognize “Do Not Track” signals, and the Global Privacy Control signal, as an opt-out for the sharing of your data with third parties. Because we do not use the Platform to deliver advertising, and do not permit third-party advertising technologies on it, no advertising-related tracking occurs on the Platform in any event.
The disclosures in this section (and linked Supplemental Privacy Policy) apply only to individual residents of California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, as applicable. The Supplemental Policy provides additional information about how we collect, use, disclose, and otherwise process personal information within the scope of the California Consumer Privacy Act of 2018, as amended (“CCPA”), Colorado Privacy Act (“CPA”), Connecticut Data Privacy Act (“CTDPA”), Delaware Personal Data Privacy Act (“DPDPA”), Florida Digital Bill of Rights (“FLDBOR”), Indiana Consumer Data Protection Act (“INCDPA”), Iowa Consumer Data Protection Act (“ICDPA”), Kentucky Consumer Data Protection Act (“KCDPA”), Maryland Online Data Privacy Act (“MODPA”), Minnesota Consumer Data Privacy Act (“MCDPA”), Montana Consumer Data Privacy Act (“MTCDPA”), Nebraska Data Privacy Act (“NDPA”), New Hampshire Privacy Act (“NHPA”), New Jersey Data Privacy Act (“NJDPA”), Oregon Consumer Data Privacy Act (“OCPA”), Rhode Island Data Transparency and Privacy Protection Act (“RIDTPPA”), Tennessee Information Protection Act (“TIPA”), Texas Data Privacy and Security Act (“TDPSA”), Utah Consumer Privacy Act (“UCPA”), and Virginia Consumer Data Protection Act (“VCDPA”). Residents of California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia can review the Supplemental Privacy Policy at https://airfusion.ai/legal/privacy-policy-supplement.
If you are a Nevada resident, you may opt out of the sale of your personal information. We do not sell personal information. To submit a request in any event, please contact us at privacy@support-partners.com and title the subject of your e-mail “Nevada Privacy Rights Opt-Out Request”. In response, we will request information from you to verify your identity. We will attempt to respond to your request, once verified, as required and in accordance with applicable law.
If the General Data Protection Regulation (“GDPR”) applies to our processing of your personal data, We are the controller for the processing described in this Privacy Policy. Our EU representative and Data Protection Officer, if applicable, may be contacted at harry.grinling@support-partners.com.
We process personal data as necessary to perform a contract with you, comply with applicable law, pursue our legitimate interests where those interests are not overridden by your rights and interests, or with your consent where consent is required. Our legitimate interests include operating, securing, supporting, and improving the Platform and our business. Where processing is based on consent, you may withdraw your consent at any time without affecting processing that occurred before withdrawal.
Personal data may be transferred to and processed in countries outside the European Economic Area, including the United States. Where required, we rely on an applicable adequacy decision, the EU-U.S. Data Privacy Framework where applicable, Standard Contractual Clauses, or another lawful transfer mechanism. You may contact us for information regarding the safeguards applicable to such transfers.
Subject to applicable law, you may request access to, correction or deletion of, or restriction of processing of your personal data; object to certain processing; and request portability of your personal data. You may withdraw consent where processing is based on consent and may object at any time to processing for direct marketing. You may exercise these rights at privacy@support-partners.com. You also have the right to lodge a complaint with the supervisory authority in the EU Member State of your habitual residence, place of work, or the location of an alleged infringement.
We retain personal data for the periods described in this Privacy Policy or for as long as reasonably necessary for the purposes for which it was collected, taking into account applicable legal requirements, contractual obligations, and legitimate business needs.
We collect personal data from you and, where applicable, from Customers, integrations, service providers, publicly available sources, and other sources identified in this Privacy Policy. The categories of personal data we collect are described elsewhere in this Privacy Policy.
Certain personal data may be required to enter into or perform a contract with us or to receive particular services. If required information is not provided, we may be unable to provide the applicable service.
We do not use personal data to make decisions based solely on automated processing, including profiling, that produce legal effects or similarly significant effects concerning you. Our use of artificial intelligence is described in the section titled “Artificial Intelligence: Data Handling, Transparency and Governance.”
This Privacy Policy may be updated from time to time. When changes are made, we will revise the “Last Updated” date at the top of this Privacy Policy. If we make any material change in the way we collect, use, or share personal information, we will post notice of the change on the Platform and, where we hold your e-mail address, notify you by e-mail in advance of the change taking effect. We will not apply a material change retroactively to information already collected without your consent, or the consent of the Customer that operates your tenant, where consent is required. Your continued use of the Platform after a change takes effect indicates your agreement to the revised Privacy Policy.
If you wish to retain a copy of this Privacy Policy, you should print or save a copy for your records.
If any term of this Privacy Policy is held invalid or unenforceable by a court of law or a competent jurisdiction, the remaining provisions of this Privacy Policy shall remain in full force and effect.
The adoption or publication of this Privacy Policy does not subject Support Partners to any stricter duty in its collection, handling, storage, and disclosure of nonpublic information than otherwise applies to Support Partners under applicable law. Except in respect of the commitments made in the section titled “Google Drive Integration and Google User Data” and the section titled “OneDrive Integration and Microsoft User Data”, which we give as binding undertakings, and except where applicable data protection law provides otherwise, no person or entity shall have any right or recourse against Support Partners nor any of its affiliates, agents, sponsors, or other related parties based on any alleged violation of or noncompliance with this Privacy Policy. This Privacy Policy is subject to applicable law as well as any separate contract that may be signed between Support Partners and you or the Customer that operates your tenant.
If you have questions, concerns, or requests relating to this Privacy Policy or to our handling of your information, you may contact us as follows.
Until the address of establishment of our European Union representative is published above, individuals in the European Economic Area may address any request or communication that would otherwise be directed to the representative to privacy@support-partners.com, or to our Data Protection Officer, and it will be handled without delay. This does not affect your right to lodge a complaint with your local supervisory authority.
Questions? Contact privacy@support-partners.com.