inqelo
Features How it works Pricing Support
Login Start free
Login Start free
Compliance

Privacy Policy

Last updated: 24 August 2026

This policy applies when Inqelo acts as controller of personal data, including for website visitors, prospective customers, contact-form submitters, sales and support correspondents, trial users, account holders, invited users and people identified as contractual or DPA contacts.

What this policy does not cover. When you use Inqelo to capture and process enquirers' data through calls, forms or email, you are the controller or a processor acting for your own client; Inqelo is your processor or Sub-processor under our Data Processing Agreement. This policy is about the data we hold about you in your own dealings with us.

1. Who we are and how to contact us

JoPaJoEm Pty Ltd (ACN 125 834 184) as trustee for the JoPaJoEm Family Trust (ABN 98 473 397 086), trading as "Inqelo", of 167 Flinders Street, Adelaide SA 5000, Australia. Privacy contact: admin@inqelo.com.

Representative

We value your privacy and your rights as a data subject and have therefore appointed Prighter Group with its local partners as our privacy representative and your point of contact for the following regions:

  • European Union (EU)
  • United Kingdom (UK)

Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative, Prighter, or make use of your data subject rights, please visit the following website: https://app.prighter.com/portal/19935887204

Please add the following subject to all correspondence: ID-19935887204

The appointed entities are Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria (EU GDPR Article 27) and Prighter Ltd, 20 Mortlake High Street, London SW14 8JN, United Kingdom (UK GDPR Article 27).

We have assessed the Article 37 criteria and do not currently consider appointment of a Data Protection Officer to be mandatory. We review that assessment as the nature and scale of our processing changes.

2. What we collect, why, and on what legal basis

What Why Legal basis (GDPR Art. 6)
Your name, email address, password (stored only as a secure hash) and short-lived security tokens Create and secure your account, sign you in, verify your address and process invitations Contract (6(1)(b)); legitimate interests in securing the service (6(1)(f))
Your company membership and access role Control who can see and do what in your company Contract
The date and time you accepted our Terms and acknowledged this policy Prove the agreement existed Legal obligation (6(1)(c)); legitimate interests in evidencing the agreement (6(1)(f))
Billing references: identifiers linking your company to our payment provider, plan and usage state Charge for the service Contract
Integration identifiers and credentials that you authorise for connected services Deliver configured integrations to your accounts Contract
Company details: company name, website, tracking phone numbers, the account owner's email Operate your company workspace Contract
Contracting details: legal entity name, registered address, country of establishment, and DPA contact name, position and email Complete and administer the Terms, DPA and incorporated transfer safeguards for the company Contract; legitimate interests in administering and evidencing the agreement (6(1)(f))
Minimal records of completed deletion requests, kept for 6 years Demonstrate that we honoured deletion requests Legitimate interests (6(1)(f)) in demonstrating compliance and, where necessary, establishing, exercising or defending legal claims
Support messages you send us Help you Contract; legitimate interests in answering your request (6(1)(f))
Your account email address Send mandatory Service, legal, privacy and Sub-processor change notices to every active account Contract (6(1)(b)); legal obligation (6(1)(c)); legitimate interests in maintaining an evidenced compliance record (6(1)(f))
Contact and demo enquiries you send us: your name, work email, company name and website, the monthly enquiry volume and current call-tracking arrangements you choose to tell us, and your message Answer your enquiry, arrange a demo, and prepare a proposal Steps at your request before entering a contract (6(1)(b)); legitimate interests in responding to a business enquiry you started (6(1)(f))
Meeting bookings you make with us: your name, email address, the time you choose and any notes you add when booking Schedule and hold the meeting you asked for Steps at your request before entering a contract (6(1)(b)); legitimate interests in holding a meeting you booked (6(1)(f))
Sales correspondence: the emails, calls and notes from our discussions with you about the service Progress the discussion and keep a record of what was said Steps at your request before entering a contract (6(1)(b)); legitimate interests in pursuing a business relationship you started (6(1)(f))
Support enquiries from people who do not hold an account: your name, email address and what you tell us in your message Answer your question Legitimate interests in answering the request you sent us (6(1)(f))
Marketing-site request and network data, including IP address, browser information, page requested and time Serve the site, keep it available, and detect and investigate abuse Legitimate interests in the security and availability of our site (6(1)(f))
Event and trade-show contacts: the business contact details you give us in person Follow up the conversation you asked us to follow up Legitimate interests in following up a business contact you started (6(1)(f))
Trial accounts: the same account and company details as above, plus the trial start and end dates and the usage counted against the trial Run the free trial and tell you when it ends Contract (6(1)(b))

We run no marketing or analytics tracking on your account and make no automated decisions about you that produce legal or similarly significant effects.

What you must provide. Your name and email are required to create an account. When creating a company, its legal entity, registered address, country of establishment and DPA contact are required to complete the company agreement and incorporated data-protection documents. A billing address and a business tax ID (for example an EU VAT number or an Australian ABN) are required by our payment provider at checkout. Other fields are optional or generated by use.

Data we get from someone other than you. If a teammate invites you, we receive your email address (and the inviter's identity) from them before you first log in.

3. Who we share it with

A small set of providers under contract, each listed with what they do:

  • Stripe (Stripe Payments Europe, Ltd): payment and subscription processing. Stripe receives the billing and account details needed to provide those services. Your card details and billing address live with Stripe, not in our systems.
  • Twilio SendGrid (EU region) sends our service emails to you.
  • Amazon Web Services (Frankfurt) and DigitalOcean (Amsterdam): hosting and storage.
  • Cloudflare provides edge delivery, network security and domain services for relevant Inqelo services.
  • Microsoft hosts, through Microsoft 365, the mailboxes that receive the contact, sales and support messages you send to our published addresses.
  • Calendly (Calendly LLC, USA) provides the booking pages behind our "book a time" buttons and holds the details you enter when scheduling a meeting with us.

Security and error logging is operated on Inqelo infrastructure, minimised and retained only for a short, bounded period. We never sell personal data.

4. Where your data is processed, and transfers

Your account data is hosted in the EU (Amsterdam and Frankfurt). Because Inqelo is an Australian company, your data is available to us from Australia; that transfer is protected by the EU Standard Contractual Clauses and our documented transfer assessment, copies of which you can request via the privacy contact. Providers with a non-EU leg (Stripe, Cloudflare, Calendly) are covered by their own Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

Enquiries and correspondence you email us are stored in Microsoft 365 and may be processed outside the EEA. Those transfers are covered by Microsoft's data protection terms, which incorporate the EU Standard Contractual Clauses. Infrastructure and security providers process limited request and network data to deliver and protect the Services as described in section 3.

5. How long we keep it

Data Kept
Account, company, billing-reference and integration records Life of the account or company, subject to applicable legal retention requirements
Security and invitation tokens Until use, revocation or expiry
Deletion receipts 6 years. Retained for Inqelo's legitimate interests in demonstrating compliance and, where necessary, establishing, exercising or defending legal claims
Contact, demo, sales and support enquiries, including from people without an account, and meeting bookings held in Calendly While the enquiry or relationship remains active and for three years after our last meaningful contact, then deleted. Ask us sooner and we will delete them
Event and trade-show contacts As for enquiries above: three years after our last meaningful contact, then deleted, or sooner on request
Marketing-site request and network records Retained only for the period reasonably necessary to operate and secure the site
Trial accounts As for account and company records above
Records held by Stripe (invoices, tax) Stripe's statutory retention

6. Your rights

You can ask us for a copy of your data, to correct it, delete it, restrict or object to its processing, or receive it in a portable form (Articles 15–21 GDPR) by contacting the privacy contact. We respond within one month. For complex or numerous requests we may extend this by up to two further months, and we will tell you within the first month if we need to and why.

None of the processing described in this policy relies on consent, so there is no consent to withdraw; if that changes we will say so here first.

You can complain to your local supervisory authority: for EU residents, the authority of your Member State; for UK residents, the Information Commissioner's Office. Our representative (see section 1) can also receive correspondence on our behalf at https://app.prighter.com/portal/19935887204, reference ID-19935887204.

7. Cookies and similar technologies

We use strictly necessary authentication, security and service-delivery technologies. We do not use advertising or analytics cookies on the Platform or marketing site. Relevant infrastructure providers may process limited request and network data when delivering these technologies.

On the marketing site and public Platform pages we use the Cookiebot consent management tool by Usercentrics A/S (Denmark, EU). It sets a first-party cookie ("CookieConsent") that records your consent choices for 12 months; this cookie is strictly necessary for consent management. When these pages load, Usercentrics receives your IP address and browser information to deliver the banner and maintain the consent record we are required to keep.

8. Security

We use encryption in transit and at rest, role-based access, company isolation, protected credentials and minimised security logging. The full technical and organisational measures schedule is available to customers in the Data Processing Agreement.

9. Changes and required notices

We will update this policy as the Service changes. Material legal, privacy and Sub-processor changes are sent by email to every active account as required Service notices. They do not have a separate subscription or opt-out.

Features How it works Pricing Support Compliance Privacy Policy Terms of Service Customer Data Responsibilities
© 2026 Inqelo
inqelo