IRM365
Privacy Policy

Privacy Policy

How Voxa Global - F.Z.C, operating IRM365 under the VoxaSoft brand, collects, uses, protects, and retains information.

Last updated: August 21, 2026

1. Introduction and Our Role

Voxa Global - F.Z.C (“we”, “us”, or “our”) operates IRM365 under the VoxaSoft brand. Voxa Global - F.Z.C is licensed and registered under number 53941 at B.C. 1302601, Ajman Free Zone C1 Building, Ajman Free Zone, Ajman, United Arab Emirates. This Privacy Policy explains how we collect, use, store, share, and protect information when you use our website, applications, and related services (collectively, the “Service”).

If you use IRM365 on behalf of an organization, that customer organization ordinarily determines why and how personal data in its tenant is used and acts as the data controller. Voxa Global - F.Z.C processes that tenant data on the customer’s documented instructions to provide IRM365 and ordinarily acts as the data processor. The customer is responsible for its privacy notices, lawful basis, instructions, user access, and responses to requests concerning tenant data.

Voxa Global - F.Z.C acts as a controller for personal data it processes for its own purposes, including website operations, demo and trial requests, account administration, billing, security, support, and legal compliance.

2. Information We Collect

Account and contact information

We may collect names, email addresses, phone numbers, job titles, company names, branch or team details, language/timezone preferences, login credentials, support messages, and demo or trial requests.

Billing and subscription information

We may collect billing contact details, plan and seat information, invoices, payment status, renewal dates, and records needed to administer subscriptions. Card details are processed by our payment provider, such as Stripe, where applicable; we do not store full card numbers ourselves.

Customer and tenant data

IRM365 stores the business data your organization enters or imports into the platform. This may include leads, lead preferences, assignments, duplicate records, customers, companies, brokers, employees, system users, campaigns, opportunities, activities, notes, calls, tasks, sales offers, MOUs, lease contracts, invoices, receipts, payments, payables, installments, PDCs, RCDs, cash flows, commissions, projects, properties, units, ownership history, document templates, attachments, approvals, roles, permissions, audit logs, reports, and related operational records.

Integration data

When your tenant connects integrations, we may process data from or send data to configured services such as property portals, Meta Lead Ads, TikTok, Google services, Microsoft services, Zoho Mail, email, calendar, messaging, payment, or other third-party systems required for the integration to work.

Usage, device, and security data

We may collect logs and metadata such as IP address, browser, device, pages or features used, timestamps, referring URLs, authentication events, user agent, and error or diagnostic data. Audit logs may record who changed a business record, when, what changed, and from where.

3. How We Use Information

  • Provide, maintain, secure, and improve IRM365.
  • Create and administer accounts, tenants, users, roles, permissions, and subscriptions.
  • Import, process, display, export, and report on tenant data as requested by your organization.
  • Enable integrations, lead capture, activities, document generation, billing, and support workflows.
  • Send transactional communications, security notices, invoices, service updates, and support responses.
  • Analyze usage patterns, troubleshoot issues, prevent abuse, and maintain platform reliability.
  • Comply with legal, accounting, tax, regulatory, and contractual obligations.

4. AI-Assisted Features

IRM365 may include AI-assisted features such as lead summaries, draft messages, and suggested next actions. When these features are used, relevant tenant data may be processed to generate the requested output. AI outputs are provided to assist users and should be reviewed before being sent, relied on, or used in customer communications.

5. Security and Access Controls

We use commercially reasonable administrative, technical, and organizational measures designed to protect information, including tenant isolation, role-based permissions, encrypted connections, access controls, backups, and audit logging where applicable. Your organization is responsible for assigning appropriate roles, limiting permissions, and protecting user credentials.

No electronic transmission or storage system is completely secure. We cannot guarantee absolute security, but we work to maintain appropriate safeguards for the nature of the Service and the data processed.

6. Third-Party Sharing and Subprocessors

We do not sell personal information. We may share information only as needed for the following purposes:

  • Service providers: hosting, infrastructure, email delivery, analytics, monitoring, support, payment processing, backups, and similar vendors.
  • Support providers: when you contact us through live chat, we use third-party support tools such as Crisp to process your message, contact details, company context, and technical metadata so we can respond and troubleshoot issues.
  • Configured integrations: property portals, advertising platforms, Google services, messaging providers, payment processors, or other systems your organization connects to IRM365.
  • AI or automation providers: where AI-assisted or automation features are enabled and processing is necessary to provide the requested feature.
  • Legal and compliance: when required by law, court order, subpoena, regulator, or to protect rights, safety, security, or prevent abuse.
  • Business transfers: in connection with a merger, acquisition, financing, restructuring, or sale of assets, subject to appropriate protections.

7. Google, Microsoft & Zoho Email Connections

IRM365 offers an optional personal email integration that lets an agent send CRM follow-up emails from their own Gmail, Microsoft Outlook / Microsoft 365, or Zoho Mail account. This feature is user-initiated and opt-in, and each connection belongs to the user who authorized it.

What we access

When you connect a mailbox, we request the permissions needed to identify the connected account and send email on your behalf. For Google, this includes the gmail.send scope. For Microsoft, this includes Mail.Send plus basic account identity permissions. For Zoho Mail, this includes ZohoMail.accounts.READ and ZohoMail.messages.CREATE. We do not request mailbox permissions to read, search, or delete your existing messages.

How we use it

We use these permissions only to send the specific emails you compose and send from within IRM365, so replies arrive in your own inbox. We do not send email automatically without your action.

What we store

We store the OAuth tokens needed to keep the connection active (held securely), the connected account identifier and email address, and the metadata of messages sent through IRM365. You can disconnect a mailbox at any time from Settings → Mail Accounts, or revoke access through your Google, Microsoft, or Zoho account security settings.

IRM365’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google OAuth permissions only to provide the user-facing email-sending features you request. We do not sell Google user data, use it for advertising, or allow humans to read email content except where required for support, security, legal compliance, or with your explicit permission.

8. Cookies and Website Tracking

We use essential cookies to keep sessions active, remember preferences, and provide core functionality. With your consent, we also use analytics and performance technologies to understand how visitors use our site and to improve it.

These optional technologies include website analytics (such as Google Analytics, delivered through Google Tag Manager) and session-replay and heatmap analytics (such as Microsoft Clarity), which record anonymized interactions like clicks, scrolling, and navigation to show how pages are used. Sensitive input fields are masked and we do not use these tools to capture the content you type into forms.

Non-essential cookies load only after you accept them in our cookie banner. You can change your choice at any time by clearing this site’s data in your browser, and you can manage cookies through your browser settings.

9. Data Retention and Deletion

We retain customer tenant data while the subscription is active and as needed to provide the Service. Unless a written agreement states otherwise, tenant data is retained for up to 60 days after termination to allow export or account reactivation and is then deleted or anonymized from active systems. Residual copies in backups are retained for no more than a further 90 days and are not restored for routine access.

We may retain billing, tax, accounting, security, fraud-prevention, audit, and legal records for longer where required by law or reasonably necessary to establish, exercise, or defend legal claims. A valid legal hold may delay deletion. Aggregated or irreversibly anonymized information may be retained because it no longer identifies an individual or customer.

10. Your Rights and Choices

Depending on your location and role, you may have rights to access, correct, delete, export, restrict, or object to processing of personal information. For tenant data, please contact the customer organization that controls the relevant tenant first. We assist customers with valid data-subject requests as required by our contractual and legal obligations. For information Voxa Global - F.Z.C controls directly, contact us at [email protected].

11. International Processing

Information may be processed in countries other than where you are located. Where required, we use appropriate safeguards for cross-border processing, such as contractual protections with service providers.

12. Children’s Privacy

IRM365 is a business service and is not intended for individuals under 18. We do not knowingly collect personal information from children.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version on our website and update the “Last updated” date. Material changes may be communicated through the website, application, or other reasonable means.

14. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

  • Email: [email protected]
  • Legal entity: Voxa Global - F.Z.C
  • Brand: VoxaSoft
  • Licence and registration number: 53941
  • Registered office: B.C. 1302601, Ajman Free Zone C1 Building, Ajman Free Zone, Ajman, United Arab Emirates
  • Website: irm365.com