Privacy Policy

Our privacy policy and how we use your data

Privacy Policy

Last Updated: September 25, 2026

Queli d.o.o. ("Queli," "we," "our," or "us") respects your privacy. This Privacy Policy explains how we process personal data when you visit our websites or use Queli business software, mobile applications, and integrations, including the Queli CRM connection for ChatGPT (together, the "Service").

1. Who We Are and How to Contact Us

Company and controller: Queli d.o.o.

Address: Bukovačka cesta 250A, 10000 Zagreb, Croatia

Email: office@queli.ai

You may contact us with privacy questions or to exercise your data protection rights.

2. The Data We Process and Our Role

Queli acts in two main capacities:

  • Processor: When an organization uses Queli to process its CRM records, files, communications, or other business data, that organization is normally the controller and Queli processes the data under its instructions and our agreement.
  • Controller: Queli is the controller for account, website, security, support, and business-administration data that we need to operate the Service.
CategoryWhat it includesSource
Account DataName, business email address, password hash, organization membership, role, and account settingsYou and your organization
Customer ContentCRM records, project and contract data, files, messages, survey content, transcripts, and other information entered or connected by an authorized userYou, your organization, and services your organization connects
Integration and Authorization DataConnection identifiers, OAuth grants and tokens, approved scopes, and the data requested from or returned to a connected service. Queli does not receive your ChatGPT password.You, Queli, and the connected service
Usage and Security DataIP address, browser and device information, timestamps, request and error logs, and security eventsGenerated when you use the Service

Account information is required to create and secure an account. Customer Content and integrations are optional, but features that depend on them will not work unless an authorized user supplies or connects the required data.

3. How and Why We Use Data

PurposeData categoriesLegal basis
Provide, authenticate, maintain, and support the ServiceAccount, Customer Content, Integration, UsagePerformance of our contract and customer instructions
Run integrations that an authorized user connects or invokesAccount, Customer Content, IntegrationPerformance of our contract and customer instructions
Secure the Service, prevent abuse, and diagnose faultsAccount, Integration, UsageLegitimate interests in operating a reliable and secure service
Meet legal obligations and establish or defend legal claimsRelevant account, contract, transaction, and security dataLegal obligation or legitimate interests

When we act as a processor, the customer determines the legal basis for processing Customer Content. Equivalent local legal grounds may apply outside the EEA and UK.

4. Cookies and Similar Technologies

We use cookies and similar technologies to operate and secure the Service. See our Cookie Policy for details. You can disable cookies in your browser, but essential account features may stop working.

5. How We Share Data

We disclose personal data only:

  • To service providers that help us host, secure, support, and operate the Service under contractual obligations.
  • To connected services when an authorized user chooses to connect or invoke them.
  • When required by law or when reasonably necessary to protect rights, property, users, or the Service.

We do not sell or rent personal data.

Queli CRM for ChatGPT

Installing the plugin alone does not give ChatGPT access to Queli data. Before using it, a user must sign in to Queli and approve the requested access. Existing grants remain read-only unless the user returns to Queli and approves additional scopes.

Depending on the plugin version and requested function, the connection may ask the user to approve one or more of these seven scopes:

  • queli.crm.read reads the CRM objects, fields, relationships, and records the user may see.
  • queli.crm.files.read lists and downloads files from permitted CRM record file fields.
  • queli.crm.files.write attaches files to CRM records and permanently deletes permitted CRM record files.
  • queli.email.read searches and reads permitted email metadata, message bodies, and attachments.
  • queli.crm.write creates and edits CRM records and relationships.
  • queli.crm.delete permanently deletes permitted CRM records.
  • queli.workflows.execute previews and runs listed Queli actions and workflows the user may execute.

This plugin version cannot send email. Its email access is limited to the permitted search and read functions described above. Queli may process and send email through separately enabled application features or customer-configured mailbox workflows. Those functions are not available to ChatGPT through this plugin version.

A scope does not give a user access they lack in Queli. For every request, Queli checks the user's active workspace membership and the relevant role, object, field, record, mailbox, action, and workflow permissions. Queli returns only the data needed for the requested function and allowed by those checks.

CRM changes, permanent deletion, file attachment or deletion, and workflow execution use a two-step process. Queli first creates an expiring preview without performing the operation. The operation requires a separate apply or confirm request that refers to that preview. Permanent record and file deletion cannot be undone.

Once Queli returns information to ChatGPT, OpenAI processes that information under the user's or organization's ChatGPT terms, settings, and data controls. Review the OpenAI Privacy Policy for details. Files supplied through ChatGPT for attachment are transferred to Queli and stored with the selected CRM record.

You can disconnect the plugin in ChatGPT or contact office@queli.ai to request revocation of its Queli access. Revocation stops future access. It does not remove information that was already sent to OpenAI, which handles that information under its own terms, settings, and retention rules.

6. International Transfers

We and our service providers may process personal data in the EEA and in other countries. Where a transfer requires safeguards under applicable law, we use an approved mechanism such as the European Commission's Standard Contractual Clauses, the UK Addendum, or an adequacy decision. A connected service may process data in the locations described in its own privacy documentation.

7. Retention and Deletion

  • Customer Content: Retained according to the customer's configuration, instructions, and contract, then deleted or de-identified subject to backup cycles and legal obligations.
  • Account and contract records: Retained while the account or commercial relationship is active and afterwards when required for tax, bookkeeping, dispute, or other legal purposes.
  • Integration authorization: Access tokens are retained only while needed to operate the connection and cease to be usable when they expire or are revoked. Connection and consent records may be retained for security and audit purposes.
  • Usage and security logs: Retained for a limited period appropriate to security, abuse prevention, reliability, and legal requirements.

Customers and authorized users can use available product controls or contact office@queli.ai to request deletion. Some requests must be handled by the customer organization that controls the data.

When a plugin version offers previewed operations, remote-write previews are usable for five minutes by default and may be configured for a shorter period or for up to 15 minutes. Expiry prevents a later apply or confirm request. It does not mean every stored copy is physically deleted at that moment. Expired, unapplied previews are removed through bounded cleanup.

Email-send preview content created through the Queli application, outside this ChatGPT plugin version, becomes eligible for scheduled deletion seven days after the preview was applied. Cleanup runs in bounded batches, so deletion may happen later. The seven-day rule does not set a retention period for operation receipts, consent records, audit or security logs, connected mailbox providers, or email recipients. Queli retains those records according to operational need, customer instructions, contracts, and legal obligations. Other recipients apply their own retention rules.

8. Security

We use technical and organizational safeguards appropriate to the nature of the Service, including access controls, encrypted network connections, logging, monitoring, and recovery procedures. No internet service can guarantee absolute security. We investigate suspected personal-data breaches and notify customers and authorities when required by contract or law.

9. AI and Automated Processing

Queli features may use AI to search, classify, summarize, transcribe, or generate information at a user's request or as part of a workflow configured by a customer. These features process only the information and Customer Content needed for the requested function, subject to the user's permissions and the customer's instructions.

Unless separately agreed in writing, Queli does not use Customer Content to train or fine-tune machine-learning models for the benefit of third parties. Connected AI services process information under their own terms and data controls. The Queli CRM connection for ChatGPT performs only the functions the user has separately authorized and requested. Changes to CRM data, files, or workflow state require the two-step preview and apply or confirm process described above.

10. Your Rights

Depending on applicable law, you may have rights of access, rectification, deletion, restriction, portability, and objection. You may withdraw consent where processing relies on consent.

Submit a request to office@queli.ai. We may need to verify your identity or direct the request to the customer organization that controls the relevant Customer Content. You may also lodge a complaint with the Croatian Personal Data Protection Agency (AZOP) or your local supervisory authority.

11. Children

The Service is intended for business users and is not directed at children under 16. If you believe a child has provided personal data to us, contact us so we can investigate and take appropriate action.

12. Changes to This Policy

We may update this Policy as the Service or legal requirements change. We will publish the current version and its update date on this page and provide other notice when required by law or our agreement with a customer.

13. Additional Information

Contact

Email: office@queli.ai

Post: Queli d.o.o., Bukovačka cesta 250A, 10000 Zagreb, Croatia