Privacy notice
Last updated 4 October 2026. How Triad Global, LLC handles personal information in Triad Core, the business platform at core.triadglobal.org. The English text governs.
Who is responsible
Triad Core is provided to businesses (our customers). For the records a customer keeps in its workspace (its customers, suppliers, documents, employees and so on) the customer decides what is processed and why, and Triad Global processes that information on the customer's behalf and on its instructions, as its service provider (processor). Questions about those records go first to the customer that invited you.
For the accounts people use to sign in, for security logs and for billing contacts, Triad Global, LLC is responsible (controller).
What we process
- Account details: name, work email, password (stored only as a salted hash), language and layout choices, and, when you use Sign in with Google, your Google account email and name. Google never creates a Triad Core account; it signs in an account your organization already invited.
- Workspace records your organization enters: contacts, documents, lines, notes, files and photos, stock, finance and, when the HR module is used, employee records such as working hours and leave. We do not ask for sensitive categories of data; a customer that stores them is responsible for its own legal basis.
- Security and usage data: sign-in times, IP address, browser type, one log line per request, and an audit trail of changes in each workspace.
- Triad AI questions and answers, when your organization has Triad AI switched on.
- Connected mailboxes and calendars: when a person connects their Gmail or Microsoft 365 mailbox (or an administrator connects a shared one), the messages, attachments and addresses Triad Core reads to show them in the inbox and file them on records, the messages sent from Triad Core, and calendar events used to log meetings. The section "Google user data" below explains this for Google accounts.
- Team chat messages and the people they mention; electronic signatures (typed name, drawn signature, time, IP address and browser of the signer); customer portal visits (when a link was opened and how often).
- HR records, when the HR module is used: employment details, working time, leave, training and, where the customer enters them, salaries and national identity numbers. Identity numbers are encrypted in the database and shown only to people with the salary right.
Why we process it
- To provide, secure and support the service the customer ordered (contract).
- To keep the service safe: rate limits, fraud and abuse prevention, audit trail, backups (legitimate interest and legal obligations).
- To send service emails such as invitations, password resets, approvals and alerts. We do not send marketing email from Triad Core.
Google user data (Gmail and Google Calendar)
This part explains what Triad Core does with information it receives from Google when a person connects a Google account. Connecting is optional. It is done by the person who owns the mailbox, or, for a shared company mailbox such as sales@, by an administrator who signs in to it.
Triad Core's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What Triad Core asks Google for, and why:
- Your Google account email address and basic sign-in identity (openid, email): to know which mailbox was connected and to show it to you.
- Gmail, read only (gmail.readonly): to read your emails and attachments so they appear in the Triad Core inbox and can be filed on the customer, supplier, order or deal they belong to, and to search your mailbox when you look for an email to attach. Triad Core never changes, labels, moves or deletes anything in your mailbox.
- Gmail, send only (gmail.send): to send the emails you write in Triad Core from your own address, so they sit in your Sent folder. Nothing is sent until you press Send (or confirm a Triad AI draft).
- Google Calendar events on calendars you own, read only (calendar.events.owned.readonly): to read the events of your own calendar so meetings can be logged as activities on the customers they involve. Triad Core never changes your calendar.
How Google user data is used. Only to provide and improve the features you see in Triad Core: the inbox, filing emails on records, search, sending, logging meetings and, when your organization has it switched on, Triad AI answers about an email you ask about. It is never used for advertising, never sold, never shared with data brokers or advertising platforms, and never used to decide whether someone gets credit or a loan.
No AI training. Google user data is not used to develop, improve or train any general artificial intelligence or machine learning model, ours or anyone else's. When Triad AI is on and you ask about an email, that email is sent to Google Vertex AI only to produce your answer; Google Cloud terms do not allow Google to train its models on it, and nothing is changed or sent until you confirm.
Who can see it. A personal mailbox is visible in Triad Core only to its owner. A shared mailbox is visible only to the people its administrator lets in. An email the owner (or an automatic filing rule the owner set) files on a record becomes part of the organization's records and visible to the people who may open that record.
People at Triad Global do not read your emails or calendar. The only exceptions are the ones Google allows: when you ask us to look at specific messages (for example in a support request) and agree to it; when it is needed for security, such as investigating abuse or a security incident; to comply with the law; or when the data is aggregated and anonymized and used for internal operations.
Who it is shared with. Only with the sub-processors that run the service for us (Google Cloud for hosting and storage, and Google Vertex AI when Triad AI is on), when the law requires it, or as part of a merger or sale of the business, and then only after you were told and agreed. Nobody else.
How it is stored and protected. Your Google sign-in tokens are encrypted with a separate key, kept only on our servers and never sent to a browser. The emails Triad Core copies are stored in our database on Google Cloud in the United States, encrypted in transit and at rest, and kept apart from other customers' data at the database level. See /legal/security for the full list of measures.
How long it is kept. While the mailbox is connected, Triad Core keeps a copy of the emails of the period the mailbox settings name (14 days back by default, at most 90) and of new emails as they arrive, so the inbox works. Emails filed on a record are kept as part of the organization's records until the organization deletes them, and at the latest within 30 days after its agreement with Triad Global ends. Database backups roll off after 7 days.
Disconnecting and deleting. You can disconnect a mailbox at any time in Triad Core under Communication, Mailboxes, Disconnect. When you do, Triad Core asks Google to revoke its access, deletes your Google tokens at once, stops all reading and sending, and deletes the copies of emails that were not filed on a record. Emails already filed on records stay with the organization's records. You can also remove Triad Core's access at any time in your Google account at myaccount.google.com/permissions; Triad Core then can no longer read or send anything.
To ask us to delete Google user data we hold about you, including filed copies, email office@triadglobal.org with the subject "Delete my Google data" from the address you connected. We confirm and finish within 30 days. For emails filed on your organization's records we tell your organization, which decides about its own records.
Connected Microsoft 365 mailboxes
Microsoft 365 mailboxes work the same way: connecting is optional, a personal mailbox is visible only to its owner, Triad Core asks Microsoft only for the access it needs to read, file and send email and read calendar events, mail is not used for advertising, not sold and not used to train AI models, and disconnecting deletes the tokens and the copies of emails that were not filed. You can also remove access in your Microsoft account.
Triad AI
When a workspace has Triad AI on, a question and the records it needs (for example an order, or an email the person asked about) are sent to Google Vertex AI to produce the answer. Google processes them under Google Cloud terms, which do not allow using customer data to train Google models. Triad AI proposes actions; nothing is created, changed or sent until a person confirms. Administrators can switch Triad AI off for the workspace.
Customer portal links
A customer's staff member may make a private portal link for a contact at one of its customers. The link shows only that customer's own orders, shipments, invoices and certificates of the last year, needs no account, expires, and can be revoked. We record when it was opened. Anyone holding the link can open it, so it should be sent only to the right person.
Who helps us (sub-processors)
- Google Cloud (Google LLC): hosting, database, file storage, backups and logs, in the United States (us-east4, Northern Virginia).
- Google Vertex AI (Gemini models), only when Triad AI is on for a workspace. Requests are processed under Google Cloud terms, which do not allow Google to train its models on customer prompts or data.
- Google Identity, only when you choose Sign in with Google.
- An email delivery provider for service emails, when email sending is switched on.
- Google (Gmail API, Google Calendar API) and Microsoft (Microsoft Graph), only for mailboxes and calendars a person chooses to connect.
The current list, with locations and purposes, is at /legal/subprocessors. We tell customers before adding a new sub-processor that handles workspace records. We do not sell or rent personal information and do not share it for advertising.
Where it is stored and international transfers
Triad Core data is stored in the United States. If you or your organization are outside the United States (for example in Korea, Israel or the European Union), your information is transferred to and processed in the United States. Customers that are subject to such rules (for example Korea's Personal Information Protection Act or Israel's Protection of Privacy Law) disclose this transfer to their own people and, where required, rely on the data processing terms in their agreement with Triad Global.
People in Korea
For customers in the Republic of Korea, the records they keep in Triad Core are entrusted to Triad Global for processing and transferred overseas as follows (Personal Information Protection Act, Articles 26 and 28-8). Recipient: Triad Global, LLC (office@triadglobal.org), and its sub-processor Google LLC. Country: United States (Northern Virginia). Items: the personal information the customer enters (names, business contact details, transaction records, and HR records where used). When and how: continuously over encrypted connections while the service is used. Purpose: hosting and operating Triad Core for the customer. Retention: for the term of the customer's agreement and 30 days after, backups 7 days. The customer, as the personal information controller, discloses this entrustment and transfer in its own privacy policy, and a data subject may refuse the transfer by asking the customer, which may mean the customer cannot keep that person's records in Triad Core.
People in Israel and the European Union
For customers in Israel, Triad Global acts as the customer's holder (processor) under the Protection of Privacy Law as amended in 2025, under the data processing addendum, which covers security, confidentiality, breach notice and return or deletion. For personal data of people in the European Economic Area, the United Kingdom or Switzerland, transfers to the United States rely on the Standard Contractual Clauses incorporated in the data processing addendum.
California and other US states
For workspace records, Triad Global is a service provider and processor: it does not sell or share personal information, uses it only to provide the service under the customer's agreement, and does not combine it with information from other sources except as the law allows.
How long we keep it
Workspace records are kept for as long as the customer's agreement runs. Copies of emails from connected mailboxes follow the section "Google user data" above. Items moved to the recycle bin stay restorable until removed by the customer. After an agreement ends we delete or return workspace records within 30 days, unless the law requires us to keep them. Database backups roll off after 7 days. Security logs are kept for up to 30 days, the workspace audit trail for as long as the workspace exists.
Security
Encryption in transit (HTTPS with HSTS) and at rest; each customer's records separated at the database level (row-level security); role-based access with hidden fields for prices, costs and salaries; rate-limited sign-in; an append-only audit trail; daily backups with point-in-time recovery; secrets kept in a managed secret store. No system is perfectly secure; we will tell affected customers without undue delay, and within 72 hours of confirming a security incident that affects their records.
Cookies
Triad Core uses only cookies that are needed to run it: a session cookie that keeps you signed in, and small preference entries (language, theme, sidebar) kept in your browser. There are no advertising or analytics cookies in Triad Core.
Your choices and rights
You can see and change your name, password, two-step sign-in and language from the account menu (Account and security). Depending on where you live you may have the right to access, correct, delete or receive a copy of your personal information, or to object to its use. For workspace records, ask the organization that invited you; we help it answer. For account data, or if you cannot reach your organization, email office@triadglobal.org with the subject "Privacy request". We answer within 30 days. You may also complain to your local data protection authority.
Children
Triad Core is a business tool and is not meant for children.
Changes
We update this notice when our practices change and show the date above. Material changes are announced to customer administrators in advance.