Privacy Policy
Last updated: July 14, 2026
This Privacy Policy explains how Declogger B.V. ("Declogger", "we", "us"), a private limited company incorporated in the Netherlands, collects and processes personal data when you use the Declogger application and related websites (together, the "Service"). It applies alongside our Terms & Conditions.
1. Our role
Declogger acts as a data controller for personal data we collect about account holders and billing contacts (for example, your name, email, and subscription details). Declogger acts as a data processor on behalf of your organization for the content your team uploads into the Service — the decisions, documents, and reasoning that make up the workspace. Your organization is the controller of that content and decides what to put in, who can access it, and when to delete it.
2. What we collect
- Account data: name, email address, hashed password, organization membership, role.
- Organization & billing data: company name, address, VAT number, invoices, payment metadata (we do not store full card numbers).
- Customer Content: the two workspaces your team uses — Task Boards (tasks and their titles, descriptions, due dates, assignees, board and lane placements, task comments and @mentions, archived tasks, and mention-based sharing metadata) and the Knowledge Base (logged decisions with alternatives, reasoning, and "Discussed with" participants; uploaded documents; external resources including their URLs and fetched snapshots; and the Tasks archive of completed and archived tasks) — along with any attachments and personal data they happen to contain.
- Inbound integration content: content routed into Declogger from the sources a Client Admin connects — Microsoft Teams meeting transcripts and chat messages, WhatsApp messages (text and voice notes) sent to the Declogger Twilio number, Slack channel messages, tickets and comments from Jira, Linear, and Asana, and payloads sent to inbound webhook endpoints you configure. For each item we store the message body and any media attached, the sender's identifier for that source (phone number, Teams / Slack / ticketing user id, or webhook client id), and, for ticketing sources, the external issue key and URL so we can link back to the original record.
- Workflow & accountability metadata: per-decision Decision-maker assignments, acknowledgement state, approval requests submitted by Contributors and the approvers they select (including permission-scoped re-runs of conflict and opportunity analysis), notification read and archive state, and audit-trail entries (who did what, when, and to which record).
- Usage & device data: log files, IP address, browser and device information, timestamps, and feature usage.
- Cookies and similar technologies: essential cookies needed to keep you signed in, and limited analytics where you have consented.
3. Why we process it and our legal bases
We process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and, for AI-assisted features, the EU Artificial Intelligence Act (Regulation (EU) 2024/1689, the "AI Act" — see section 4). We rely on the following legal bases under Article 6 GDPR:
- Performance of a contract — to provide the Service to you and your organization, manage accounts, and process payments.
- Legitimate interests — to keep the Service secure, prevent abuse, debug issues, and improve the product. We balance these interests against your rights.
- Legal obligation — to comply with tax, accounting, and other legal requirements.
- Consent — for non-essential analytics cookies and marketing communications, where applicable. You may withdraw consent at any time.
4. AI-assisted features
Some features — including conflict and opportunity detection between decisions, Organization Insights surfaced across the workspace (cooperation opportunities, conflicts, and knowledge gaps), summarization, document and image content extraction, extraction of decisions from Microsoft Teams meeting transcripts and chat messages, transcription of WhatsApp voice notes and extraction of decisions from WhatsApp messages, and auto-capture triage of inbound messages from Slack, Jira, Linear, Asana, and inbound webhooks — are powered by Google Gemini 2.5 Flash (used for conflict and opportunity detection, document analysis, decision extraction, the Ask bar, and auto-capture triage) and Google Gemini 3 Flash Preview (used for Organization Insights), accessed through the Lovable AI Gateway. When you use these features, the relevant Customer Content is transmitted to the gateway and on to the model provider for processing. Both the gateway and the underlying model provider contractually commit, in their data-processing terms, not to use Customer Content to train any AI model. AI output can be incomplete or inaccurate; you remain responsible for reviewing it before acting on it, and it must not be treated as legal, financial, medical, or other professional advice.
Auto-capture triage. When a Client Admin turns on auto-capture for a given inbound source, the incoming message content is sent to the AI Gateway for classification, a proposal is created in the Knowledge Base for Client-Admin review, and Declogger may post a reply back in that same source — a Slack message, a Teams reply, a WhatsApp response, a ticket comment on the originating Jira / Linear / Asana issue, or a webhook callback — containing related knowledge from your workspace and any conflicts we detected. Decisions marked Confidential are excluded from that cross-user comparison and are never referenced in these replies. Auto-capture is off by default for every source and is controlled per source on each Inbound integration card.
Each of these AI flows — Teams transcript processing, WhatsApp message processing, and auto-capture triage — can be disabled by a Client Admin: transcript and WhatsApp flows under Settings → Privacy, and auto-capture per source under Settings → Integrations → Inbound. When a flow is disabled, inbound content for that channel is not sent to the model, no proposal is created, and no in-channel reply is posted.
Under the EU AI Act (Regulation (EU) 2024/1689), Declogger's AI-assisted features qualify as a limited-risk AI system and are not a high-risk AI system under Annex III of that Regulation. In line with Article 50, AI-generated content in Declogger (analysis findings, transcripts, decisions extracted from inbound messages, and auto-capture proposals and their in-channel replies) is presented as such, and the underlying general-purpose AI model is disclosed above. AI output is advisory only; a human user always remains the decision-maker. You may contact us at the address in section 13 to request information about AI-assisted processing that affects you.
5. Sharing and sub-processors
We share personal data only with service providers acting on our instructions, including:
- our cloud hosting and database provider;
- our email and transactional-messaging provider;
- our payment processor;
- our AI model providers (for the features described above);
- analytics and error-monitoring tools.
An up-to-date list of sub-processors is available on request. We do not sell personal data, and we do not share Customer Content with third parties for their own purposes.
5a. Outbound integrations
A Client Admin can configure outbound destinations so that, when a decision reaches the accepted status, a copy of that decision is automatically pushed to a third-party service. The payload typically includes the decision's title, the "chosen / not chosen / reason" content fields, the author's name, tags, implementation date, and a link back to the decision in Declogger. Currently supported destination kinds are generic outbound webhooks, Microsoft Teams (Incoming Webhook), Slack (Incoming Webhook), Jira, Linear, and Asana.
These destinations are chosen and controlled by your organization, not by Declogger. They are not Declogger sub-processors: once a payload leaves Declogger, the receiving service processes it under its own terms and privacy notice, and the customer organization remains responsible for what is configured, who can read the destination channel, board, or endpoint, and whether the pushed decisions contain confidential or personal data. A Client Admin can pause or remove any destination at any time in Integrations settings, after which no further payloads are sent to it.
5b. Inbound integrations
A Client Admin can connect inbound sources so that content created outside Declogger is brought into the workspace and turned into proposals or draft decisions. Currently supported sources are Microsoft Teams (meeting transcripts and chat messages forwarded by your Teams admin), WhatsApp via a Declogger Twilio number (text messages and voice notes, the latter transcribed by the AI flow described in section 4), Slack, Jira, Linear, and Asana (channel messages or tickets and comments, via OAuth workspace connections the customer authorizes), and inbound webhooks (endpoints the customer's own systems post to, using a shared-secret signature that Declogger verifies before accepting the payload).
Auto-capture is off by default for every source and is controlled per source under Settings → Integrations → Inbound. When it is off, an inbound message is stored as raw incoming source only; when it is on, the AI flow described in section 4 runs and Declogger may post a reply back in that source. Turning auto-capture off for a source stops both proposal generation and in-channel replies for that source.
The customer organization is responsible for telling meeting participants, channel members, ticket authors, and message senders that content routed to Declogger will be stored and processed, and for obtaining any consent required under local law — including, where applicable, consent to record and transcribe meetings. Phone numbers, Teams / Slack / ticketing user ids, and webhook client ids are stored only to attribute the resulting decision to the right person, to support disambiguation replies for users who belong to more than one organization, and to post any in-channel reply back to the correct thread. Inbound ingestion can be turned off at any time by removing the connector in Integrations settings, or by disabling the relevant AI toggle in Privacy settings or the per-source auto-capture toggle on the Inbound card.
6. Data location and international transfers
Customer Content and account data are currently stored in the European Union (Frankfurt, Germany). Additional storage regions (United Kingdom, United States, Asia-Pacific) are on our roadmap and will only be activated for an organization with explicit configuration. Where personal data is transferred outside the European Economic Area — for example, to AI model providers when AI features are used — we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, supplementary measures where required, or an adequacy decision. Where a customer organization configures outbound integrations (see section 5a), payloads may be transmitted outside the EEA depending on where the receiving service is hosted; the customer organization is responsible for assessing transfer safeguards for the destinations it configures. Where a customer organization uses inbound integrations (see section 5b), WhatsApp messages are received via Twilio, Teams content via Microsoft, and Slack, Jira, Linear, and Asana content via those respective providers, each of which may process the data outside the EEA under its own terms before it reaches Declogger.
7. Retention
We retain account data for as long as the account is active and for a limited grace period after closure. Customer Content is retained for as long as your organization keeps it in the workspace; after termination of the subscription it remains available for export for a limited window (typically 30 days) before being deleted from our active systems. Audit-trail entries (who did what, when, and to which record) are retained for the life of the workspace to support compliance, accountability, and dispute resolution, and can be exported by Client Admins on Standard and above. Backups are rotated on a defined schedule. Invoices and other records required by law are retained for the statutory period.
8. Your rights
Subject to applicable law, you have the right to access, rectify, erase, restrict, or port your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time. You may also lodge a complaint with a supervisory authority — in the Netherlands, the Autoriteit Persoonsgegevens. To exercise your rights, contact us at the address below. If your data is part of Customer Content controlled by your organization, we will refer your request to them.
9. Security
We use industry-standard technical and organizational measures to protect personal data, including encryption in transit and at rest, role-based access controls, multi-factor authentication for administrative access, audit logging, and regular review of our security posture. Credentials for outbound integrations (webhook signing secrets, API tokens, incoming-webhook URLs) are stored in a restricted server-side vault, kept separate from the destination's public configuration, and are not returned to the browser after creation. No system is perfectly secure; if a personal data breach affects your data, we will notify you and the relevant authorities as required by law.
10. Cookies
We use two categories of cookies and similar browser storage:
- Strictly necessary: required to operate the Service — for example, to keep you signed in and to remember your theme preference. These are always on and cannot be disabled.
- Non-essential: optional analytics or product-improvement cookies. These are only set after you give consent via our cookie banner.
When you first visit the site you'll see a cookie banner asking you to Accept or Reject non-essential cookies. You can change your choice at any time via the Cookie preferences link in the website footer, or by clearing your browser's site data for Declogger.
11. Children
The Service is not directed to individuals under the age of 16, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us so we can delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you in advance by email or through the Service. The "Last updated" date at the top of this page indicates when the policy was last revised.
13. Contact
For privacy questions or to exercise your rights, contact us at compliance@declogger.com.