Legal
Privacy Policy
This Privacy Policy explains how Control Roam ("Control Roam," "we," "us," or "our") collects, uses, discloses, and safeguards information in connection with our management and analytics service for Roam virtual offices (the "Service").
Last updated
1.Scope & our roles
This Policy applies to information we process through the Service, our website, and related communications. It does not apply to third-party products, including Roam or any workspace you connect, which are governed by their own privacy policies.
We act in two capacities. For account, billing, website, and marketing information, we are a controller and determine how that information is processed. For the workspace data you direct us to synchronize and analyze on your behalf (see Section 3), we act as a processor (or "service provider") that handles data under your instructions. Where you are an organization's administrator, you are responsible for your users' information and for having the necessary rights and notices to permit our processing.
2.Information we collect
We collect the following categories of information:
- Account information. Your name, work email address, organization name, role, and authentication metadata. We support passwordless sign-in; we do not store account passwords.
- Credentials you provide. API keys, tokens, and connection settings you enter to link a workspace. These are stored in encrypted form and used only to operate the Service for you.
- Usage and device data. Log data, approximate location derived from IP address, browser and device type, pages viewed, features used, timestamps, and diagnostic information, collected to secure and improve the Service.
- Support and communications. Information you share when you contact us, respond to a survey, or otherwise correspond with us.
- Billing information. Where paid features apply, limited transaction details. Card numbers are handled by our payment processor and are not stored by us.
3.Workspace data we process
When you connect a workspace, you may direct the Service to synchronize and store data from that workspace so it can be searched, analyzed, exported, and retained. Depending on the features you enable, this may include directory and membership records, meeting and session metadata, recordings and transcripts, chat and message content (including direct and private conversations where your plan and permissions allow), events, presence and audit logs, and related attachments and metadata.
This data may include personal information and, in some cases, sensitive or regulated information about your personnel and their communications. You are responsible for determining that your collection and use of this data is lawful, for configuring the scope of synchronization, and for providing any notices or obtaining any consents required in your jurisdiction. We process this data solely to provide the Service to you and as otherwise permitted in Section 4.
4.How we use information
We use information to:
- provide, operate, maintain, and secure the Service;
- authenticate users and manage accounts, organizations, and permissions;
- synchronize, index, store, analyze, and present workspace data as you configure it;
- generate reports, insights, alerts, and exports you request;
- provide support, respond to inquiries, and send service, security, and administrative messages;
- monitor, detect, investigate, and prevent fraud, abuse, security incidents, and violations of our terms;
- develop, test, and improve features and models, using aggregated or de-identified data where practicable;
- comply with law and enforce our agreements.
We do not sell personal information, and we do not use workspace data for advertising or to train externally shared machine-learning models.
5.Legal bases for processing (EEA/UK)
Where the GDPR or UK GDPR applies and we act as a controller, we rely on the following legal bases: performance of a contract with you; our legitimate interests in operating, securing, and improving the Service (balanced against your rights); compliance with legal obligations; and, where required, your consent (which you may withdraw at any time). Where we act as a processor, the relevant controller is responsible for the legal basis of processing.
7.Sub-processors
We use a limited set of infrastructure and communications providers to deliver the Service. We impose data-protection terms on each and remain responsible for their performance of the services they provide to us. A current list of sub-processor categories is available on request at privacy@controlroam.com. Where required by contract, we will provide advance notice of material changes so you may object.
8.Data retention
We retain information for as long as needed to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Workspace data is retained according to your configuration and plan; you can delete data or disconnect a workspace to remove it, subject to routine backup cycles. Upon termination, we will delete or return workspace data as described in our Terms and applicable data-processing terms, except where retention is required by law.
9.Security
We maintain administrative, technical, and organizational measures designed to protect information, including encryption of credentials, access controls, network protections, and logical isolation between customers. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your account, managing your users' access, and promptly notifying us of any suspected unauthorized use at support@controlroam.com.
10.International data transfers
We may process and store information in countries other than where you are located, including the United States. Where we transfer personal information subject to the GDPR or UK GDPR across borders, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum) or another lawful transfer mechanism. A copy of the relevant safeguards is available on request.
11.Your privacy rights
Depending on your location, you may have rights to access, correct, delete, port, or restrict processing of your personal information, to object to certain processing, and to withdraw consent. To exercise a right, contact us at privacy@controlroam.com. Where we process workspace data as a processor, we will refer your request to the responsible organization and assist them as required. We will respond within the timeframes required by applicable law and may need to verify your identity. You may also lodge a complaint with your local supervisory authority.
12.U.S. state privacy rights
Residents of certain U.S. states (including California, Virginia, Colorado, Connecticut, and Utah) may have rights to know, access, correct, and delete personal information, and to opt out of "sales" or "sharing" and certain targeted advertising and profiling. We do not sell personal information or share it for cross-context behavioral advertising as those terms are defined under applicable law. To exercise your rights, contact us at privacy@controlroam.com; we will not discriminate against you for doing so. You may use an authorized agent where permitted.
14.Children's privacy
The Service is intended for use by businesses and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will take appropriate steps to delete it.
15.Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
16.Contact us
For privacy questions or requests, contact privacy@controlroam.com, or write to us at Control Roam, Legal Department (address available on request). If you are in the EEA or UK, you may also contact our data protection contact at privacy@controlroam.com.