Privacy Policy

Effective: September 9, 2026
Last updated: September 9, 2026

This policy explains what personal data My Portal App, LLC handles, why we handle it, and what rights you have. Please read it before using this website or authorizing an integration.

1. WHO WE ARE

The entity. My Portal App, LLC is a [[STATE]] limited liability company with a mailing address at 1321 Upland Dr. STE 6351, Houston, TX 77043. References in this policy to “My Portal App”, “we”, “us” and “our” mean My Portal App, LLC.

Contact. Privacy enquiries and rights requests should be sent to privacy@myportalapp.com, or by mail to the address above.

Scope. This policy covers two things: this website, and the integration service described in Section 2. It does not cover any business application platform on which you hold an account. If you use a portal or platform provided to you by another company, that company’s own privacy policy governs the data inside it.

2. WHAT MY PORTAL APP DOES

The integration service. My Portal App operates an integration service at integrations.myportalapp.com. Its function is narrow. When a user of a connected business application chooses to link a third-party account, such as Google or Microsoft, our service is the endpoint that receives the authorization from that provider and passes it to the business application platform the user is actually using.

What that means in practice. We are a conduit for the authorization step. We do not decide what data is requested, and we do not decide what it is used for. Those decisions are made by the organization operating the business application and by the user who grants the authorization.

Roles. For data handled by the integration service, we act as a processor. The organization whose application you are using is the controller. For this website, we act as a controller.

The platform. The business application platform that receives authorizations from our integration service is operated by SuiteDash, Inc., a Delaware corporation, which acts as a sub-processor for integration data. My Portal App, LLC and SuiteDash, Inc. are affiliated companies.

3. DATA HANDLED BY THE INTEGRATION SERVICE

What we receive. When you authorize a connection, we receive the authorization code or token issued by the third-party provider, the identifier of the account you authorized, the scopes you granted, and technical data associated with the request such as IP address and timestamp.

What we do with it. We validate the response, associate it with the correct destination platform account, and transmit it onward to that platform. We hold the authorization only as long as needed to complete that handoff.

What we do not do. We do not read, index, analyze or profile the content of your third-party account. We do not use integration data to build advertising or marketing profiles. We do not sell it or share it. We do not use it to train machine learning or artificial intelligence models.

4. DATA FROM THE ACCOUNTS YOU CONNECT

Access is limited to the scopes you grant. The permissions shown at the consent screen are the only permissions used. You can review and revoke them at any time in your Google or Microsoft account settings, and revocation takes effect immediately.

Content data. Where a connection permits access to content such as messages, calendar events, contacts or files, that content is retrieved for and delivered to the business application platform you are using, at your direction, to provide the feature you enabled. It is not retained on our integration service beyond the transmission.

5. WEBSITE VISITOR DATA

What we collect. When you visit this website we collect technical data, including IP address, browser type and version, operating system, referring page and pages viewed. If you submit a form, we collect the information you provide, which typically includes your name, email address and company name.

Cookies. We use cookies to maintain session state and to understand how the site is used. You can control cookies through your browser settings. Blocking them may prevent parts of the site from working.

Children. This website is not directed at children and we do not knowingly collect personal data from anyone under 16.

6. WHY WE HANDLE YOUR DATA, AND ON WHAT BASIS

Integration data. Processed on the documented instructions of the controlling organization, on the basis of the contract between that organization and its platform provider, and in reliance on the consent you gave at the provider’s consent screen.

Website form submissions. Processed on the basis of our legitimate interest in responding to enquiries, or on the basis of steps taken at your request before entering a contract.

Website technical data. Processed on the basis of our legitimate interest in operating and securing the site.

Legal obligations. Where we are required to retain or disclose data by law.

7. WHO WE SHARE DATA WITH

Service providers. We use a small number of vendors for hosting, infrastructure and security. A current list of sub-processors is maintained at myportalapp.com/sub-processors. Each is bound by written terms imposing obligations substantially equivalent to those in this policy.

Affiliated companies. Integration data is transmitted to SuiteDash, Inc. as described in Section 2, under written intercompany terms.

We do not sell. We do not sell personal data and we do not share it for cross-context behavioral advertising, as those terms are defined under United States state privacy laws.

Legal process. We may disclose personal data where required by law. We do not disclose data to law enforcement in the absence of a court order or other legally valid demand, and unless we are legally prohibited from doing so, we will notify the affected party.

Change of control. If My Portal App, LLC is acquired or merged, personal data may transfer as part of that transaction. We will provide notice before any data becomes subject to a different privacy policy.

8. HOW LONG WE KEEP DATA

Integration authorizations in transit. Deleted on completion of the handoff, and in any event within [[N]] hours.

Integration request logs. [[N]] days.

Website form submissions. [[N]] months from last contact.

Website server and security logs. [[N]] days.

Where a longer period is required by law, or is necessary to establish, exercise or defend a legal claim, we retain the data for that period and no longer.

9. GOOGLE USER DATA

Limited Use. My Portal App’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

What this means. Data obtained through Google APIs is used only to provide or improve the user-facing features you authorized. It is not transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition. It is not used for advertising. It is not read by any human except with your affirmative consent, for security purposes, to comply with applicable law, or where the data is aggregated and anonymized. It is not used to develop, improve or train generalized artificial intelligence or machine learning models.

Revoking access. You can withdraw access at any time at myaccount.google.com/permissions.

10. MICROSOFT USER DATA

Scope of use. Data obtained through Microsoft identity and Microsoft Graph APIs is used only to provide the features you authorized. It is not used for advertising, is not sold or shared, and is not used to train generalized artificial intelligence or machine learning models.

Revoking access. You can withdraw access at any time at myapps.microsoft.com.

11. SECURITY

Measures. We maintain technical and organizational measures appropriate to the risk, including encryption in transit, encryption at rest where applicable, access controls, logging of access to systems holding personal data, and periodic review of those controls.

Access to accounts. We access an account only to resolve a problem or correct a defect. We do not open uploaded files unless asked to. Access is logged.

Incidents. Where we become aware of a personal data breach affecting data we handle, we notify the relevant controller without undue delay, and any supervisory authority or individual where we are required to do so.

12. INTERNATIONAL TRANSFERS AND THE DATA PRIVACY FRAMEWORK

Where data is processed. We process personal data in the United States. Personal data originating in the European Union, the United Kingdom and Switzerland is transferred to, and retained in, the United States.

Participation. My Portal App, LLC complies with the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework, as administered by the U.S. Department of Commerce. We have certified that we adhere to the Data Privacy Framework Principles with regard to the processing of personal data received in reliance on the applicable framework. Where there is any conflict between this policy and the Principles, the Principles govern. To learn more, and to view our certification, visit dataprivacyframework.gov.

Liability for onward transfers. We remain responsible and liable under the Principles if a third party we engage to process personal data on our behalf does so in a manner inconsistent with the Principles, unless we prove we are not responsible for the event giving rise to the damage.

Independent recourse. In compliance with the Principles, we commit to resolving complaints about our collection or use of your personal data. Individuals with enquiries or complaints should first contact us at privacy@myportalapp.com. We further commit to refer unresolved complaints to [[INDEPENDENT RECOURSE MECHANISM, EXACTLY AS FILED]], an alternative dispute resolution provider located in the United States. This service is provided at no cost to you. If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed it to your satisfaction, please visit [[IRM URL]] for more information and to file a complaint.

Regulatory oversight. Our commitments under the Data Privacy Framework are subject to the investigatory and enforcement powers of the United States Federal Trade Commission.

Binding arbitration. Under certain conditions, more fully described in Annex I of the Principles, you may invoke binding arbitration when other dispute resolution procedures have been exhausted.

Disclosure requirements. We may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.

13. YOUR RIGHTS UNDER EUROPEAN, UNITED KINGDOM AND SWISS LAW

The rights. Subject to conditions and exceptions in applicable law, you have the right to access your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to data portability, and not to be subject to decisions based solely on automated processing.

How to exercise them. Write to privacy@myportalapp.com. We may ask for information to verify your identity before we respond, which is a security measure to ensure data is not disclosed to someone with no right to receive it. We respond within one month, and will tell you if a complex or repeated request requires longer.

Requests about integration data. Because we act as a processor for integration data, we refer a request concerning that data to the controlling organization and assist them in responding.

Complaints. You have the right to complain to your supervisory authority. A list of EEA authorities is at edpb.europa.eu. In the United Kingdom the authority is the Information Commissioner’s Office. In Switzerland it is the Federal Data Protection and Information Commissioner.

14. YOUR RIGHTS UNDER UNITED STATES STATE LAW

Who this applies to. Residents of California, Virginia, Colorado, Connecticut, Utah, Texas and other states with comprehensive privacy laws have the rights described below, subject to the conditions and exceptions of the applicable law.

The rights. To know what personal data we have collected and how it is used and disclosed. To obtain a copy of that data. To correct inaccurate data. To request deletion. To opt out of sale, of sharing for cross-context behavioral advertising, and of profiling with legal or similarly significant effects. To be free from discrimination for exercising these rights.

Sale and sharing. We do not sell personal data and we do not share it for cross-context behavioral advertising. We do not process personal data for profiling in furtherance of decisions producing legal or similarly significant effects.

Sensitive personal information. We do not seek to collect sensitive personal information, and we do not use or disclose it for purposes other than those permitted without a right to limit. Where a user of a connected application chooses to transmit such information through an authorized integration, we handle it as a processor on the instructions of the controlling organization and for no independent purpose of our own.

Making a request. Send your request to privacy@myportalapp.com. We verify your identity before responding and reply within the period required by the applicable law, generally 45 days, with one permitted extension where necessary. An authorized agent may submit a request on your behalf with proof of authorization. If we decline a request, you may appeal by replying to our response, and we will inform you of the outcome and of your right to contact your state attorney general.

15. CHANGES TO THIS POLICY

How we notify you. We may update this policy. Material changes will be notified by posting a prominent notice on this website, and where we hold your contact details and the change materially affects you, by email. The date at the top of this policy shows when it was last revised.

16. HOW TO CONTACT US

Privacy enquiries and rights requests. privacy@myportalapp.com

By mail. My Portal App, LLC, 1321 Upland Dr. STE 6351, Houston, TX 77043, USA