1. Who we are
Celeritic is a partner intelligence platform for alliance and partnership teams, operated by CelerityHat To confirm: full legal name of the contracting entity, for example with its corporate suffix ("CelerityHat", "we", "us"), To confirm: registered business address.
This policy explains what information Celeritic handles, why, who can see it, how long we keep it, and the choices you have. It covers celeritic.com, the Celeritic application and the Celeritic browser extension.
For the information your organisation puts into Celeritic (for example its deals, documents and partner data), your organisation decides what goes in and who may see it, and we process it to provide the service on its behalf. For the information we need to run your account (for example your sign-in details and our security logs), we decide how it is used. Questions about either go to help-celeritic@celerityhat.com.
2. What we collect
We collect the categories of information below. Each list gives examples and is not exhaustive: the categories are what matter, and the examples show what they include today.
- Account and profile information, including your email address, display name, profile photo (from Google sign-in, or one you add), organisation name, job title, your role in the organisation (owner, admin or member) and the partner and feature access you have been given.
- Sign-in and security information, including a record of sign-ins with the IP address, browser user agent, time and outcome; session tokens; email verification status. Passwords are held by our self-hosted identity service as salted hashes, never in the application database.
- Organisation administration, including join requests and approvals, invitations (with the email address of the person invited), access requests and their notes, and the history of support access your organisation has granted to CelerityHat.
- Business records you sync or enter, including CRM opportunities (deal name, stage, amount, close date, customer name and country, owner name and other CRM fields), named customer contacts on a deal (name, email, phone, title), email history attached to a deal in your CRM (subject, body, sender and recipients), deal registrations and their drafts, partner programme tiers and requirements, partnership health figures and revenue metrics.
- Documents and content, including files you upload (such as offer decks, case studies and proof-of-value documents), the text we extract from them, and the claims, offers and summaries we derive from that text.
- Credentials for systems you connect, including OAuth tokens and API keys for your CRM and partner portals. These are encrypted before they are stored.
- Assistant conversations, including everything you type to CeleriticAI, its replies, and the records it looked up to answer.
- Activity and usage information, including an activity feed of changes in your organisation, notifications, searches that found nothing, issue reports you send us, and technical logs of requests to our servers (IP address, requested address, time, status and a request identifier).
- Information from the browser extension, including tier, competency and requirement values it reads from partner portals when you start a sync, and the result of a registration form it fills for you.
Celeritic is growing quickly, and new features may process additional categories of information. When that happens we update this policy before or when the feature launches, and changes that matter are announced as described in "Changes to this policy". A new feature never changes the commitments in this policy about selling data, training AI models, human access, retention or deletion without that notice.
3. Where it comes from
- From you: when you create an account, complete your profile, upload a document, type into the assistant, or enter partner or deal details by hand.
- From your organisation's owners and admins: when they invite you, approve you, give you access to partners or features, or connect systems on the organisation's behalf.
- From systems your organisation connects: Salesforce, HubSpot, Microsoft Partner Center, AWS Partner Central, Google Cloud, Databricks, Snowflake and others you choose to connect. We read from them, and where you ask us to, we write back to them (for example updating an opportunity stage, or creating an account record in Salesforce for a new customer).
- From Google, if you sign in with Google: your Google account email, name and profile photo.
- From the Celeritic browser extension: only from the partner portal pages it is permitted to read, and only when you start a sync or a registration from Celeritic.
- From your browser and our servers: technical information generated when you use the service, such as your IP address and the pages you request.
4. Why we use it
- To provide Celeritic: show your pipeline, partner status, documents and analytics; run the assistant; generate insights, summaries and registration drafts; sync with and write back to the systems you connect.
- To run your account and organisation: sign-in, email verification, approvals, invitations and access control.
- To keep the service secure and working: detect misuse, investigate errors, and keep audit records of sign-ins and of support access.
- To support you: answer your questions and issue reports, and, only under a support grant your organisation controls, look at your organisation's data to help.
- To communicate with you about the service: invitations, approvals, access requests and important changes. We do not send marketing email from Celeritic.
- To meet legal obligations and enforce our Terms of Service.
We do not sell your information, we do not share it for advertising, and we do not use it, or let anyone else use it, to train AI models.
5. Who can see it inside your organisation
- Owners and admins manage the organisation: they approve and invite members, connect systems, and decide which partners and features each member can reach. They can see the organisation's data, including member names and email addresses.
- Members see only the partners and features they have been given access to. Deals, documents, activity and search results outside that access are not shown to them.
- Your assistant conversations are yours: other members, owners and admins cannot list or read them.
- Documents are visible to the whole organisation or limited to admins, and members see only the documents for the partners they have been given access to, through the folders, partner tags and grants your organisation sets.
CelerityHat staff
CelerityHat staff cannot open your organisation's data in Celeritic unless your organisation has granted support access. A grant is created by an owner or admin, lasts a fixed time (24 hours, 72 hours or 7 days), can be revoked at any moment with immediate effect, and is logged: your owners and admins can see when it was granted, by whom, why, when it was last used and when it ended. There is no way for staff to create or extend a grant themselves. Without a grant, staff can still see the list of organisations with their names, member counts and whether a grant is active, and review new organisations before they go live, but not the organisation's data.
Separately, a small number of CelerityHat engineers can reach the underlying systems to operate them (for example to restore a backup or investigate an outage). They do not use that access to read customer content except to keep the service running, for security, or where the law requires it.
6. Sub-processors
We use a small number of service providers to run Celeritic. They process information only on our instructions and only to provide their service to us.
- Google Cloud: hosting of the application, its database and identity service (Compute Engine, in the United States); document storage and database backups (Cloud Storage); text embeddings for document search (Vertex AI); secret storage (Secret Manager); logs and monitoring (Cloud Logging and Cloud Monitoring); secure administrative access (Identity-Aware Proxy).
- Google Workspace: sending the emails Celeritic sends, such as invitations, approvals and verification emails, and receiving the messages you send to our help address.
- Anthropic: the large language model behind the assistant and our AI features (see "AI processing").
Our pages also load fonts from Google Fonts, which means your browser contacts Google and shares your IP address with it when a page loads.
The systems your organisation connects (such as Salesforce, HubSpot, Microsoft, AWS, Google Cloud, Databricks and Snowflake) are not our sub-processors. Your organisation uses them under its own agreements, and we exchange data with them only because you asked us to.
We will update this list before we add a new sub-processor.
7. AI processing
Several features use a large language model, provided by Anthropic, a sub-processor. To provide those features, customer content is sent to the model provider, including:
- your assistant conversations, together with the records the assistant looks up to answer, for example deal details and deal owner names, named customer contacts on a deal and registration (name, email, phone, title and address), partner status, your organisation's "about us" text, short excerpts of deal emails with their senders and recipients, and whole documents it is asked to read;
- uploaded documents, when we extract their text, claims, offers and summaries;
- deal and partner records, when we generate insights, summaries and registration checks.
Document search also sends document text, and the question you ask, to Google Vertex AI to compute embeddings.
We do not sell this content and we do not use it, or allow the provider to use it, to train models. The provider may retain inputs and outputs for a limited period under its commercial terms, To confirm: the retention period and the no-training terms that apply to our Anthropic account. Zero data retention is not in place yet; we are working towards it, and this section will say so when it is.
An admin can turn off AI use for any document, which keeps it out of the assistant's answers and the assistant's document search. The document is still processed when it is uploaded, to extract its text, claims and summaries and to index it for search. To confirm: product decision on whether the AI opt-out should also stop ingestion and summaries AI output can be wrong; see the Terms of Service.
8. Google user data
Celeritic's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Today we receive information from Google only when you sign in with Google: your email address, name and profile photo, used to create and identify your account.
If you connect your Google Calendar (a feature we are preparing), these commitments apply:
- Calendar access is read-only. Celeritic never creates, changes or deletes anything in your calendar.
- We use calendar information only to provide meeting features in Celeritic, such as meeting counts per partner, upcoming partner meetings and meeting preparation.
- We do not use it for advertising, we do not sell it, and we do not use it to train generalised AI models.
- People do not read it, except with your consent, for security purposes such as investigating abuse, or to comply with the law.
- Within your organisation, the details of a meeting with a partner can be seen by you, by your organisation's owners and admins, by colleagues who are on that meeting, and by CelerityHat support only under an active support grant. We tell you this on the consent screen before you connect. To confirm: Limited Use lets people read Google user data only with the user's affirmative agreement, or for security, legal compliance or aggregated internal operations. This design shows partner meeting details to the organisation's owners and admins, and to CelerityHat support under a grant the organisation (not the calendar owner) creates. The owner must decide whether stating this plainly here and on the consent screen satisfies Limited Use, or whether each viewer path needs the calendar owner's own agreement (#281)
- We keep a limited window of events and delete your calendar data when you disconnect your calendar, when you leave your organisation, or when your account is deleted.
9. Retention and deletion
We keep information for as long as your account or your organisation uses Celeritic, unless you delete it sooner or a shorter period is stated below.
- Deleting a deal removes it together with its email history, activity and registrations, and stops it being synced again.
- Deleting a document removes it from Celeritic straight away and permanently deletes it 30 days later. A copy of the file can remain in our storage history for up to a further 90 days, so a mistaken deletion can be recovered, after which it is gone.
- You can delete any of your assistant conversations at any time.
- Disconnecting a CRM or partner system deletes the stored credentials immediately. Records already synced from it stay in Celeritic until your organisation deletes them or asks us to.
- Support access ends when its grant expires or is revoked. The record that it happened is kept, so your organisation has a history of every grant.
- Sign-in records, activity, notifications and technical logs are kept for security and audit. To confirm: retention periods for sign-in records, activity and server logs; none is enforced automatically today
- Database backups are kept for up to 180 days, so information deleted from Celeritic can remain in a backup until that backup expires. Backups are used only to restore the service. To confirm: that the backup buckets delete old versions too, so 180 days is the real maximum
Deleting your account or organisation
To delete your account, or for an owner to delete your organisation and all of its data, email help-celeritic@celerityhat.com. We confirm the request comes from you (or from an owner of the organisation), carry it out within To confirm: response time for privacy requests, for example 30 days, and tell you when it is done. Removing a member from an organisation detaches them from it straight away.
10. Security
- Traffic to Celeritic is encrypted in transit with TLS.
- Credentials for the systems you connect are encrypted before they are stored, and are never sent back to the browser.
- Every request is checked against your organisation and your access, so one organisation cannot reach another's data, and members reach only what they have been given.
- Session tokens are kept in cookies that page scripts cannot read.
- Administrative access to our servers goes through Google Identity-Aware Proxy, and access to production secrets is restricted to the deployment system and a small number of operators.
- Sign-ins and support access are logged.
No system is perfectly secure. We do not currently hold a third-party security certification. To confirm: breach notification commitment; suggested wording: If we learn of a breach affecting your information, we will tell you and your organisation without undue delay.
11. International transfers
Celeritic is hosted in the United States (Google Cloud, us-central1), and our AI provider processes data in the United States. If you use Celeritic from another country, your information is transferred to and processed in the United States. To confirm: the storage location of our Cloud Storage buckets and the region where Anthropic processes our data; and the transfer mechanism offered to customers in the EU, UK and elsewhere, for example Standard Contractual Clauses in a data processing agreement
12. Your rights and choices
Depending on where you live, you may have the right to:
- access the information we hold about you and get a copy of it;
- correct information that is wrong (you can edit most of your profile in Settings);
- delete your information;
- receive your information in a portable format;
- object to, or ask us to restrict, how we use it;
- withdraw consent where we rely on it, for example by disconnecting a connected system.
To exercise any of these, email help-celeritic@celerityhat.com. We will verify the request and respond within To confirm: response time for privacy requests, for example 30 days. Where your organisation controls the information (for example a deal record), we will work with your organisation's owners to handle it. You will not be treated differently for exercising a right. You may also complain to your local data protection authority.
California residents: we do not sell or share personal information for cross-context behavioural advertising.
13. Children
Celeritic is a business tool for use with a work email address. It is not directed to children and we do not knowingly collect information from anyone under To confirm: minimum age; suggested 16, or 18 to match a service for work accounts only. If you believe a child has given us information, contact us and we will delete it.
15. Changes to this policy
Every version of this policy carries a version number and the date it was last updated, shown at the top. When we make a material change, we tell you in the app or by email before it takes effect. We update this policy before or when a new feature processes information in a way it does not already describe.
16. Contact
Questions, requests and complaints about privacy: help-celeritic@celerityhat.com. To confirm: that help-celeritic@celerityhat.com is the address for privacy and legal requests, or name a dedicated one