Who is responsible
Triway Technologies LLC, Dubai, United Arab Emirates, operates the service. For the records your company puts into its workspace, your company decides what is held and why, and Triway processes it on your instructions. For your sign-in account, Triway is the controller. Questions to akshay@triwaytechnologies.com.
What the service holds
- Companies: name, domain, relationship, industry, location, tax registration number, brand assets, owner, and when a rep last opened the record.
- Contacts: name, email, phone numbers with labels and extensions, title, LinkedIn URL, company, owner, and when a rep last opened the record.
- Opportunities: name, stage, amount and currency, expected close, lead source, quotation links, billing cadence, and reasons recorded for lost or on hold.
- Activity: notes, calls, meetings, tasks and stage changes written by your people, and the enrichment entries the agent writes.
- Agent evidence: facts about contacts with their source and a confidence band, accepted or rejected by your people.
- Accounts: the name, email and role of each person in your workspace, and their sessions.
- Usage: agent sessions and model usage per workspace, and an audit trail of setting changes with who made them.
No mailbox or calendar is connected: the service does not read correspondence. Card photographs are sent to the model for one extraction and are not stored.
Who can see it
Only the people in your workspace, according to the role your admins give them: admins see and change everything, members work records, viewers read. Every record carries your workspace's identity and the database refuses to show one workspace another's rows. Triway staff reach a workspace's data only as operators through the database when support requires it, never through the application as a user, and every such action is recorded.
Providers and what each receives
- Vercel (Frankfurt): Runs the app, the API and the agent; sees data in transit and in logs without request bodies.
- Supabase (Frankfurt): The database; holds every record at rest.
- Resend (EU): Sends sign-in links and invitations; sees the email address and the one-time link.
- Google, Microsoft: Sign-in identity (name, email, picture) when you choose to sign in with them.
- Vercel AI Gateway, routing to Anthropic: Receives the agent's prompts: record fields and the public evidence it gathered, and the photograph of a business card when a rep scans one. Zero data retention on the gateway and at the model provider.
- Context.dev: Receives company domain names, and person lookups when that capability is on for your workspace, to enrich records.
- Sentry (EU): Error reports with personal data removed in code.
- UptimeRobot: Checks the public addresses of the service; receives no records.
No provider receives correspondence, because none is connected. Each provider is bound by a data processing agreement on its terms.
Where it lives
Everything at rest is in Frankfurt, Germany (European Union). The research agent runs in the United States and processes records in memory only. [Legal to confirm: the lawful basis for the cross-border transfer of personal data from the UAE and India to Frankfurt under the UAE Personal Data Protection Law and India's Digital Personal Data Protection Act, and the wording to record it here.] Hosting in the UAE is available when a customer's obligations require it.
How long it is kept
- Records live until your people delete them. Deleting a contact also blocks the address so a form or import cannot recreate it; the reason for the block is kept, not the person.
- Agent audit and attribution rows are kept for twelve months.
- Agent evidence is append-only: a rejected fact stays recorded as rejected.
- Backups are kept daily by the database provider.
- When your agreement ends we hand over a full export on request and delete the workspace within thirty days.
Your rights and how to use them
A person whose data is in a workspace asks the company that runs that workspace first; its admins can find, correct, export or delete a record. Anyone can write to akshay@triwaytechnologies.com about their own sign-in account, or if a workspace does not respond. [Legal to confirm: statutory response times and the complaint route under UAE PDPL and India DPDP.]
What the service does not do
- No automated outbound: the agent cannot send email or messages.
- No reading of message bodies for analytics.
- No selling of data and no use of your data to train models.
- No client data sent to the model beyond what the agent needs for the record in hand, and none retained by the provider.