Privacy Policy

Last updated: July 14, 2026. This version replaces the version dated December 1, 2024. Prior versions are available on request.

Who we are and what this policy covers

Abloomify Inc. ("Abloomify", "we", "us") is a company based in Toronto, Ontario, Canada. We provide an AI productivity management platform for businesses, available at app.abloomify.com (US region) and app-eu.abloomify.com (EU region), together with device agents, a browser extension, and integrations (collectively, the "Platform"), and we operate the marketing website www.abloomify.com (the "Website").

This policy explains what personal information we collect, why we collect it, who we share it with, where it is stored, and the rights you have. For privacy questions or requests, contact us at legal@abloomify.com.

We do not sell personal information.

Our roles: when we are a controller and when we are a processor

We handle personal information in two distinct roles, and different rules apply to each:

  • Abloomify as a controller. We decide how and why to process personal information about Website visitors, sales prospects and marketing contacts, and the business contact and account information of our customers' authorized users. This policy describes that processing in full.
  • Abloomify as a processor. When a customer uses the Platform, data about the customer's employees and other end users (for example, work-activity telemetry from device agents, data from integrations the customer connects, documents the customer uploads, and conversations with our AI assistant) is processed on the customer's behalf and under the customer's instructions. The customer is the controller of that data; Abloomify is a processor. That processing is governed by our agreement with the customer, including our Data Processing Addendum (DPA), which incorporates the European Commission's Standard Contractual Clauses where applicable.

If your employer uses Abloomify and you have questions or requests about data processed through your employer's deployment, please contact your employer first. Your employer decides what is collected and why, and is responsible for informing you. We assist our customers in responding to such requests as required by our DPA and applicable law.

Information we collect

Website visitors

  • Usage and device data, collected automatically: IP address, approximate location derived from IP, browser and device type, pages viewed, referring pages, and interactions with the Website. Some of this is collected through cookies and similar technologies described in the cookies section below, which you can control through our consent banner.
  • Visitor identification (not in the EEA or UK). Outside the European Economic Area and the United Kingdom, we use a visitor-identification service that uses the IP address of a Website visit to identify the organization the visit likely comes from and, in some cases, publicly available business contact details associated with it, so that our sales team can prioritize outreach. This service is not loaded for visitors in regions where the GDPR applies.
  • Form submissions, provided by you: name, work email address, company, phone number, and the content of your message when you request a demo, contact us, download a resource, apply to our partner program, or join a waitlist. Forms are protected by Google reCAPTCHA, which involves data processing by Google, and meetings booked with us are scheduled through Cal.com.
  • Information from other sources: we may receive business contact information about prospective customers from publicly available sources and third-party business data providers, which we use for business-to-business outreach.

Customers and their authorized users

  • Account information: name, work email address, role, and authentication identifiers. Sign-in is handled through AWS Cognito and, where enabled by your company, Google sign-in or your company's single sign-on provider (for example, Okta).
  • Business and billing contact information needed to manage the customer relationship.
  • Product usage and support data: how authorized users interact with the Platform, including through product analytics and session replay used to diagnose problems and improve the product, and the content of support requests.

Platform data we process on behalf of customers

The following categories are processed with Abloomify acting as a processor for the customer, as described in the roles section above:

  • Device agent telemetry: work-activity signals such as application and website usage patterns from the Abloomify desktop agents (macOS and Windows) and browser extension. Administrators define an application allowlist centrally and the agent enforces it at the moment of capture, so activity outside the approved list is never recorded and never transmitted. The agents cannot capture screenshots, keystrokes, or the content of communications in any configuration.
  • Integration data: data from workplace tools the customer chooses to connect, such as project management, source code hosting, communication, HR, and calendar and email systems. What is collected depends on the integrations the customer enables and the permissions it grants.
  • Uploaded content: documents and files the customer or its users add to the Platform's knowledge base.
  • AI assistant content: conversations with our AI assistant "Bloomy" and the results it produces.

How we use information and our legal bases

Where we act as a controller, we use personal information for the following purposes. For individuals in the European Economic Area, the United Kingdom, and Switzerland, the legal basis for each purpose is noted:

  • Providing and operating the Platform and Website(creating and administering accounts, authentication, support): performance of a contract.
  • Responding to inquiries and managing sales relationships (demo requests, contact forms, company identification for business-to-business outreach): our legitimate interests in operating and growing a business-to-business company. Where company identification relies on cookies or similar technologies, those are subject to the consent choices described in the cookies section.
  • Marketing communications (emails about our products and services): your consent, or as otherwise permitted by applicable law. Every marketing email includes an unsubscribe link, and you can opt out at any time.
  • Analytics and advertising on the Website (measuring Website performance and our own advertising campaigns): your consent where required by law, collected through our cookie banner, and otherwise our legitimate interests in measuring and improving our marketing.
  • Product analytics on the Platform (understanding how the Platform is used so we can improve it and fix problems): our legitimate interests in improving our services.
  • Security, fraud prevention, and abuse prevention: our legitimate interests in protecting our services and users.
  • Legal compliance (tax, accounting, and responding to lawful requests): compliance with legal obligations.

You are not required to provide personal information, but without it we may be unable to respond to your inquiry, provide the Platform, or manage your account.

We do not rely on employee consent as a basis for workforce analytics. Our customers, as employers and controllers, determine their own legal basis for using the Platform with their workforce in accordance with the employment and data protection laws that apply to them, and we support them with documentation as described below.

Cookies, analytics, and advertising on our website

The Website uses cookies and similar technologies in the following categories:

  • Necessary: technologies required for the Website to function, including the consent banner itself.
  • Analytics: services that help us understand how the Website is used and how it performs.
  • Advertising: tags from the advertising platforms we use to advertise our own services. These measure the performance of our campaigns and may be used by those platforms as described in their own privacy policies. For the collection and transmission of data through these tags on our Website, we and the relevant platform act as joint controllers.
  • Visitor identification: the identification service described in the collection section above, which uses the IP address of a visit. It is not loaded for visitors in regions where the GDPR applies.

The specific providers, cookies, and durations in each category are listed in the cookie table of our consent banner settings, which is kept current through periodic scans.

Where required by law, non-essential cookies and tags load only with your consent, collected through our cookie consent banner: you can accept, reject, or customize categories there. You can change or withdraw your choices at any time using the Cookie Settings link in the Website footer, or by contacting us at legal@abloomify.com.

AI features and how they process data

  • Model providers. Abloomify's AI features run by default on AWS Bedrock using foundation models from Anthropic (Claude) and Amazon (Nova). A customer's administrators can additionally enable optional models from OpenAI and Google, which are served through those providers' APIs; like every external provider on the platform, these are disabled by default and used only after an administrator enables them. Under our agreements with all of these providers, prompts and outputs are not used to train their models, and Abloomify does not use customer data to train AI models.
  • In-region inference. AI processing on the default models happens in the same geography as the customer's instance: US-region customers' AI processing stays in the United States, and EU-region customers' AI processing runs on AWS Bedrock EU inference and stays in the European Union. If a customer's administrators enable the optional external model providers, requests to those models are served through the providers' own APIs.
  • Stored results. Model providers do not use prompts or outputs to train models. Conversation history with Bloomy and results derived from it are stored in the customer's region so users can return to them, and users can delete their chat history at any time from within the app.
  • External AI access. Customers can create scoped API keys that let their own AI tools query their Abloomify knowledge base over the Model Context Protocol (MCP). Keys are limited to the creator's own access, every call is audited, and keys can be revoked at any time.
  • Insights, not automated decisions. Abloomify's AI features generate analytics and insights for review by our customers. Abloomify does not make automated decisions that produce legal or similarly significant effects about individuals. How insights are used within a customer's organization is determined by the customer as controller.

Google user data access and use

This section describes the personal Google account connection an individual user can make through our AI assistant "Bloomy". When you connect your Google account to Abloomify through Bloomy, we access certain Google user data to provide our services. This section describes what data we access, how we use it, and how we protect it. Abloomify's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Google data we access

  • Gmail Data: Email messages, threads, drafts, and labels. We read email content to help you search, summarize, and respond to emails. We create and update drafts on your behalf but never send emails automatically.
  • Google Calendar Data: Calendar events, schedules, and meeting details. We access this to help you view your schedule, create events, and manage meetings.
  • Google Contacts Data: Contact names and email addresses. We access this to help you find recipients when composing emails.
  • Google Meet Data: Meeting conference information and transcripts. We access this to help you retrieve information about past meetings.
  • Basic Profile Information: Your name and email address associated with your Google account for authentication purposes.

How we use Google user data

We use Google user data solely to provide and improve our AI assistant functionality:

  • Email Management: Searching emails, reading message content to answer your questions, creating draft replies, and organizing your inbox by modifying labels (archive, mark as read/unread).
  • Calendar Management: Displaying your schedule, creating new events, and updating existing meetings based on your requests.
  • Contact Lookup: Finding email addresses when you ask to send emails to specific people.
  • Meeting Intelligence: Retrieving meeting transcripts to answer questions about past discussions.
  • Inbox Manager (optional): If you turn on the Inbox Manager, we process incoming email messages on an ongoing basis while it is enabled, to categorize them and prepare draft replies for your review. Drafts are never sent without your action, and you can turn the Inbox Manager off at any time in Bloomy.

We do not use Google user data for advertising, marketing to third parties, or training AI models, or for any purpose unrelated to providing our services to you.

Google data sharing and transfer

We do not sell, rent, or share your Google user data with third parties except as necessary to provide our services:

  • Service Providers: We use trusted subprocessors to securely connect to Google APIs and process data on our behalf. A full list of our subprocessors is available in our Trust Center.
  • AI Processing: Email and calendar content may be processed by our AI systems to generate responses to your queries. Model providers do not use this content to train models, and the processing happens in your region. Results you ask Bloomy to produce are saved to your chat history in your region until you delete them.

We do not transfer Google user data to third parties for targeted advertising, data brokering, credit assessment, or any other purpose unrelated to providing our services.

Your control over Google data

You have full control over your data. We access Google data when you request it and, if you have enabled the Inbox Manager, on an ongoing basis while that feature is on. Any information derived from your emails or calendar is stored solely to provide the functionality you requested or enabled.

  • You may delete your entire chat history and any derived information at any time from within the Abloomify app.
  • You may disconnect your Google account at any time in Bloomy under My Connectors, which will revoke our access.
  • You may also revoke access directly from your Google Account at https://myaccount.google.com/permissions.

Microsoft user data

If you connect a Microsoft Outlook account to Bloomy, we access mailbox and calendar data to provide the same assistant features described above for Google, under the same restrictions: no use for advertising, no sale of your data, no use to train AI models, and the same optional Inbox Manager behavior and controls. You can disconnect your Microsoft account at any time in Bloomy under My Connectors, or revoke access from your Microsoft account settings.

How we share information

We share personal information only as described here. We do not sell personal information for money, and outside of the Website advertising tags described in the cookies section, we do not share it with third parties for their own marketing. Some US state laws treat the use of advertising tags as "sharing" or a "sale" of personal information; you can opt out of these through the cookie banner settings or by contacting us.

  • Service providers and subprocessors that help us run our services: cloud infrastructure (AWS), analytics and session replay (PostHog), AI model providers via AWS Bedrock, payment processing (Stripe), productivity and email systems, email delivery and notification services, scheduling, and customer relationship tools. Our current subprocessor list is published in our Trust Center.
  • Advertising and analytics partners for the Website, as described in the cookies section and subject to your consent choices.
  • Legal reasons: when required by law or legal process, or where reasonably necessary to protect our rights, our users, or the public.
  • Business transfers: if we are involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to this policy.

Where data is stored and international transfers

Abloomify runs two production environments: a US environment hosted in AWS us-east-1 (N. Virginia) at app.abloomify.com, and an EU environment hosted in AWS eu-central-1 (Frankfurt) at app-eu.abloomify.com. Each customer is provisioned in exactly one region.

EU data residency. For customers on the EU environment, Platform data is stored and processed inside the European Union: telemetry collected by device agents and integrations, the application database, product analytics (hosted on PostHog's EU cloud), and AI processing on the default AWS Bedrock EU models all reside in the EU, and installers generated for EU companies are configured with EU endpoints only. Optional external providers (such as the optional AI models described in the AI section) are disabled by default and used only if a customer's administrators enable them. EU companies also start with device-agent collection disabled by default, as described in the employee monitoring section below. The service providers involved in delivering the service are listed in our Trust Center.

Where personal information for which Abloomify is the controller (for example, Website, marketing, and account data) is transferred across borders, we rely on recognized safeguards: for transfers to Abloomify Inc. in Canada, the European Commission's adequacy decision for Canada (covering commercial organizations subject to PIPEDA); and for transfers to service providers in the United States, the European Commission's Standard Contractual Clauses, with supplementary measures where appropriate (a number of our providers additionally hold their own certifications, such as the EU-US Data Privacy Framework). For transfers from the United Kingdom and Switzerland, we rely on the UK and Swiss recognized versions of these safeguards. You can request a copy of the relevant safeguards at legal@abloomify.com.

Employee monitoring: what our agents do and do not collect

We design the Platform to minimize data at the point of collection:

  • Collection is an explicit administrator choice with three states per platform: collect activity, collect only an approved allowlist of applications or domains, or collect nothing.
  • Companies on the EU environment start in the collect-nothing state on every platform: device agents collect and transmit no usage telemetry until an administrator approves specific applications or domains or explicitly enables collection.
  • Allowlists are enforced at capture on the device, so activity outside the approved list is never recorded and never transmitted. In the collect-nothing state, agents transmit no usage telemetry at all; only basic device enrollment information (such as hostname, operating system version, device username, and agent version) and periodic configuration checks flow.
  • The agents have no capability to capture screenshots, keystrokes, or the content of communications, in any configuration. Window title collection is off by default and requires an explicit administrator opt-in, with browser tab titles behind a further opt-in of their own.
  • Telemetry awaiting transmission is held in a bounded in-memory queue on the device, is not written to disk, and is discarded beyond the queue's limit or on restart.
  • The employer, as controller, configures what is collected, informs its employees, and determines its legal basis under the laws that apply to it, including local employment law requirements such as works council agreements or collective consultation where applicable.

Documentation supporting Data Protection Impact Assessments (DPIAs), works council review, and employee notices is available on request at legal@abloomify.com.

How long we keep information

  • Customer account and billing data: for the duration of the customer relationship, and afterwards as required by law (for example, tax and accounting requirements).
  • Platform data processed for customers: retained per the customer's configuration and agreement, and deleted or returned following termination of the customer agreement in accordance with the DPA.
  • Marketing contacts: until you unsubscribe or ask us to delete your details, or after 24 months without any engagement from you, whichever comes first.
  • Website analytics and advertising data: for the durations shown per cookie in the cookie consent banner settings.
  • Logs and backups: for limited periods appropriate to security, reliability, and disaster recovery, after which they are deleted or overwritten in the ordinary course.

How we protect information

Although no system can be guaranteed 100% secure, we use reasonable and appropriate physical, organizational, and technical measures to protect personal information against unauthorized use, loss, access, modification, destruction, or disclosure. These include encryption in transit and at rest, network and system security monitoring, and access controls that limit access to personal information to those who have a business need to know. More detail about our security practices is available in our Trust Center.

Your rights

Depending on where you live, you may have some or all of the following rights over personal information for which Abloomify is the controller:

  • to access the personal information we hold about you;
  • to have inaccurate information corrected;
  • to have your information deleted;
  • to restrict or object to our processing of your information;
  • to object at any time to the use of your information for direct marketing, and to unsubscribe from marketing emails using the link in every message;
  • to receive a copy of information you provided to us in a portable format;
  • to withdraw consent at any time where processing is based on consent (including via the cookie banner settings), without affecting processing that happened before you withdrew it.

To exercise any of these rights, contact us at legal@abloomify.com. We may need to verify your identity before acting on a request. We respond within one month; where a request is complex or we receive many requests, we may extend this by up to two further months, and we will tell you within the first month if so. If we cannot fulfill a request (for example, because it would reveal personal information about someone else), we will explain why.

If your employer uses Abloomify, requests about data processed through your employer's deployment should be directed to your employer, who controls that data; we will assist them in responding.

If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local data protection supervisory authority. In Canada, complaints may be directed to the Office of the Privacy Commissioner of Canada. Residents of certain US states may have additional rights under their state's privacy law, which you can exercise through the contact above.

Children

Our Website and Platform are intended for business use and are not directed to children under 16. We do not knowingly collect personal information from children.

Changes to this policy

We update this policy as our services and legal requirements evolve. When we do, we update the date at the top of this page. If a change is material, we will provide more prominent notice, such as a notice on the Website or an email to registered users. Prior versions are available on request.

Questions and contact information

For questions, concerns, or requests relating to personal information at Abloomify, contact us at legal@abloomify.com (for general inquiries, hello@abloomify.com). Abloomify Inc. is based in Toronto, Ontario, Canada. We have not appointed a Data Protection Officer, as we are not required to do so; privacy inquiries are handled through the contact above.

Privacy Policy | Abloomify - AI Productivity Management