Privacy Notice
Effective 11 October 2026 · Last updated 11 October 2026
1. Scope and Exado’s role
“Exado,” “we,” “us” and “our” refer to the Exado service and its operator. This notice applies to personal information handled through exado.app, the Exado portal, communications with Exado, and any future Exado products or features that link to this notice. A customer organization may control the personal information it places in its workspace. In that case, Exado processes that information to provide the service under the customer’s instructions and agreement. Exado separately acts as a controller for its own account administration, security, support and business-contact records.
2. Personal information we may process
- Identity and contact: first and last name, business email, mobile number and country calling code, job title, organization, and contact messages.
- Account and access: Firebase user identifier, account status, email-verification status, authenticator enrollment and sign-in security metadata. Exado does not ask for or store your password in readable form or your authenticator secret.
- Invitation and tenant records: one-time invitation-token hash, invited email, workspace role, expiry and redemption events; tenant name and type; user-to-tenant membership; and administrator decisions.
- Workspace content: goals, tasks, approvals, comments, records and audit/activity entries that a customer or user chooses to place in the portal. Customers should avoid entering information they do not have authority to submit.
- Technical and security data: service logs, approximate connection details, browser/device information, timestamps, error diagnostics, and events needed to authenticate, prevent abuse, investigate incidents and maintain the service. Providers may collect additional technical data under their own notices.
- AI and integration data, when enabled: prompts, context selected for an AI request, generated plans and outputs, integration account identifiers, authorized scopes, configuration and action history. Exado will describe enabled providers and material data flows in product settings or a customer agreement before activation.
3. Purposes and instructions
We use information to create and secure accounts; verify email; support authenticator MFA; issue and redeem invitations; provision and separate internal, customer and partner workspaces; display and administer business workflows; maintain access and activity records; provide support; prevent fraud, misuse and security incidents; operate, debug and improve Exado; comply with legal obligations; and communicate service, security and policy updates. We do not sell personal information or use workspace content to target advertising.
Where an organization controls workspace data, its administrators choose who is invited and what data is entered. Exado processes that workspace information to provide the configured service and follows the applicable customer agreement and documented instructions. Exado does not currently connect this preview to Microsoft, Jira or other customer systems, and the preview’s Mangi panel is not connected to a live AI model or external tools.
4. Legal grounds and required fields
Exado handles information only for specified service, security, support and business purposes and as permitted by applicable law. Where the GDPR or similar law applies, Exado relies as appropriate on performance of a contract or steps requested before a contract, legitimate interests such as account security and service reliability, legal obligations, or consent where required. The Israeli Privacy Protection Law, 5741-1981, including Amendment 13, and applicable regulations govern processing in Israel. Amendment 13 took effect on 14 August 2025 and revised, among other matters, the information-database framework. See the Israeli Privacy Protection Authority’s Amendment 13 guidance and official legal-information collection. A field marked required is needed for the stated account or feature; if you do not provide it, Exado may be unable to create the account or provide that feature. Consent to contractual terms is recorded separately from this notice.
5. Service providers and disclosures
Exado currently uses Google Firebase services for authentication, static hosting and Cloud Firestore storage. Google acts as a service provider under its applicable terms. Firestore is configured in the European multi-region location `eur3`; this describes Firestore storage only and does not promise that every authentication, hosting, support or network operation remains in that region. See Google’s Privacy Policy and Firebase service terms for provider details. Exado may disclose information to other service providers who support hosting, email, AI, monitoring or integrations only as needed to provide a feature and subject to appropriate contractual and security controls. We may disclose information where required by law, to protect people or the service, or during a corporate transaction subject to applicable law. We do not make workspace data public.
6. International processing
Exado and its providers may process information in Israel, the European Economic Area, the United States or other locations where providers operate. Where information is transferred across borders, Exado will use a transfer mechanism and safeguards required by applicable law, including applicable Israeli transfer rules and, where relevant, standard contractual clauses or another lawful GDPR transfer mechanism. The specific locations and safeguards can depend on the service feature and provider selected.
7. Retention and deletion
We keep personal information for the time reasonably needed for the purposes above, the active workspace relationship, security and audit needs, dispute resolution, and legal obligations. Invitation tokens expire after seven days and can be redeemed only once; unused token records and redeemed-token audit metadata may be retained for security and recordkeeping. Workspace administrators control membership and content within their tenant, subject to available product controls and applicable agreements. The current preview does not provide self-service account export or deletion. To request access, correction or deletion, contact info@exado.app; Exado will verify the request and respond under applicable law. Some records may be retained where the law permits or requires it. Backup deletion timing depends on the provider and applicable retention configuration.
8. Security
Exado’s portal is designed to use verified email, authenticator-app MFA, TLS connections, tenant-scoped authorization rules, restricted invitations, least-privilege access and activity records. Security controls are reviewed as the product develops. No internet service can promise absolute security. The private preview is not a certified compliance service; customers must assess suitability for their data and environment. If you suspect unauthorized account or workspace access, email info@exado.app promptly. Exado will investigate and notify affected parties and authorities when required by law.
9. Your rights and requests
Depending on applicable law and Exado’s role, you may ask to access, correct, delete or restrict personal information, object to certain processing, receive a copy, withdraw consent where processing relies on consent, or complain to the relevant regulator. If Exado processes your workspace information for an organization, direct the request to that organization first; Exado will assist the organization as required by the applicable agreement and law. For information Exado controls, contact info@exado.app. We may request reasonable information to confirm your identity and protect another person’s data.
10. Children, changes and contact
Exado is a business service and is not directed to children. We do not knowingly invite a child to create an account. We may revise this notice when Exado’s products, providers or legal obligations change. Material changes will be dated here and, where appropriate, communicated to workspace administrators or users. Privacy contact: info@exado.app. This notice does not replace a data-processing agreement or a customer’s own notice to its employees and users.