1. Summary
Warp Speed Solutions Inc., a Flexio Holding Inc company ("Routina", "we", "us", or "our") processes customer information as a "service provider" under California law or "processor" under the GDPR when operating the Routina platform on behalf of customers. We also act as a controller for a narrower set of information we determine the purposes of — account registration and administration, billing records, support correspondence, security logs, and information collected from visitors to our website.
Where this policy applies. This policy covers every environment we operate: the marketing website at getroutina.com and its subdomains, the standard platform at app.routina.tech, the partner environment at partners.routina.tech, and any other domain, subdomain, dedicated environment, or regional deployment we may add. Environments run on separate infrastructure and separate databases, so data does not move between them — but the way we handle your information is the same in each, and this single policy governs all of them.
Two commitments are worth stating up front, because they are the questions we are asked most: we do not sell or share personal information, and we do not use customer data to train machine learning models. Section 7 explains how that works when AI features are involved, including the limits of what we can promise about third-party model providers.
2. Information We Collect & Why
a. Information from Website Visitors
We gather standard server and usage information including browser type, language preference, referring site, pages visited, and the date and time of each request. This includes Internet Protocol (IP) addresses, and contact information when visitors voluntarily provide it — for example, the name, email address, and message you submit through our contact form.
When you submit that form, your IP address and a bot-detection token are processed by Cloudflare Turnstile to confirm the submission is not automated. See Section 9.
b. Why We Collect This Information
To operate and secure the website, to understand aggregate usage patterns, to prevent abuse and automated submissions, and to respond to the enquiries people send us.
c. Information from Account Users
Account creation requires a name and email address, along with a password or an authentication credential from a single sign-on provider where your organization uses one. Users may optionally provide additional profile information. For paid plans we also process billing contact details; card details are collected and stored by our payment processor, Stripe, and are not stored on Routina systems.
We record security and audit information about account activity, including sign-in events, IP addresses, and a log of actions taken in the platform — including actions taken by automated agents you configure.
"User Personal Information" encompasses any data that could identify an individual — usernames, email addresses, real names, photographs — as well as online identifiers like IP addresses and cookie data.
3. Processing Purposes
Routina uses collected data to:
- Create and maintain accounts
- Provide requested services
- Authenticate users and enforce team permissions
- Bill for the service and meter usage
- Surface in-product suggestions and configuration recommendations, based on how you have set up and used the platform
- Analyze service interaction patterns in aggregate
- Maintain security and audit logs, and investigate abuse
- Respond to support requests and send service communications
- Support legal documentation and compliance obligations
Routina does not use personal information to make automated decisions that produce legal or similarly significant effects on an individual. Where our platform is used to automate a decision, that automation is configured and controlled by our customer, not by Routina — see Section 6.
4. Legal Basis for Processing Information
Contractual Necessity: Name, email, authentication, and billing data are processed because they are required to provide the service you have signed up for.
Consent: Optional profile information and any non-essential cookies or marketing communications are processed on the basis of consent, which you may withdraw at any time.
Legitimate Interests: Remaining processing — security, fraud prevention, abuse detection, service reliability, aggregate usage analysis, and business correspondence — relies on our legitimate business interests, balanced against your rights.
Legal Obligation: Retention of financial and tax records, and responses to lawful requests.
5. Information About Children
Routina is a business product and is not directed to children. We do not offer accounts to anyone under 18, and we do not knowingly collect personal information from, or direct any of our content to, anyone under 18. If we learn that we have collected personal information from a person under 18, we will delete it promptly. If you believe we hold such information, contact privacy@getroutina.com.
6. Data Submitted Through Services
Data submitted via the Routina platform is processed only to provide the service. It is never sold, rented, or used for any purpose of our own beyond operating and securing the platform for the customer who submitted it. We act as a data processor for this data, and customers retain ownership and control of their operational data at all times.
Because customers configure which systems to connect and what their automations may do, the customer — not Routina — determines what personal data enters the platform and what is done with it. If you are an individual whose data has been processed through a Routina customer's account, contact that organization to exercise your rights; see Section 17.
7. AI Processing and Model Providers
a. What We Commit To
Routina does not use customer data, prompts, or AI-generated output to train, fine-tune, or otherwise develop machine learning models — not our own, and not anyone else's. We do not sell or share this data, and we do not repurpose it for our own commercial ends. This applies to all data in the platform, not only to data obtained through any particular integration.
b. How AI Processing Works
When you use an AI feature — a chat assistant, an automated classification, or an autonomous agent — the inputs to that feature, which may include personal data you have configured the feature to access, are sent to a model provider for inference. Model providers we engage on your behalf are listed at getroutina.com/subprocessors, are bound by written data protection terms, and are contracted for zero-retention or no-training handling where the provider offers it. Our subprocessor page identifies which providers those are.
c. Where Our Commitment Ends
Model providers set their own retention, abuse-monitoring, and model-improvement policies, and those policies can change. We select providers carefully and contract for the strongest terms available to us, but we cannot audit or guarantee a third party's internal handling of data, and we are not responsible for their use of it.
This matters most if you supply your own model provider API key. In that case, requests run under your account with that provider, and their agreement with you — not ours — governs what happens to the data. That provider is not a Routina subprocessor for those requests. We pass the data to them at your instruction. You should review your provider's terms and confirm they meet your compliance obligations before enabling this.
d. Accuracy
AI output can be inaccurate, incomplete, or fabricated. It should not be relied on as the sole basis for decisions about a person, and it is not a substitute for professional judgment. See Section 6 of our Terms of Service.
8. Information Sharing
Routina does not sell or share personal information, as those terms are defined under the CCPA and comparable state privacy laws. We do not share personal information for cross-context behavioral advertising, and we have not done so in the preceding twelve months. We may share:
- Aggregated or de-identified data that cannot reasonably be used to identify any individual, for analytics and product improvement
- Information with service providers and subprocessors — hosting, payment processing, communications, model inference, security — under written data protection agreements limiting their use of it. Our current list is at getroutina.com/subprocessors
- Data with law enforcement or regulatory bodies pursuant to valid legal process (see Section 16)
- Information in connection with a merger, acquisition, or sale of assets, subject to notice and the continued application of this policy
9. Cookies and Tracking
a. What We Use Today
Our website and platform use cookies and similar technologies that are strictly necessary to operate: keeping you signed in, maintaining your session and team context, remembering interface preferences, protecting forms against automated abuse, and load balancing. These do not require consent and cannot be disabled without breaking the service.
The third-party technologies currently in use on our public website are:
- Cloudflare Turnstile — bot detection on our contact and sign-up forms. Processes your IP address and browser signals to distinguish humans from automated submissions. Strictly necessary for abuse prevention.
- Webflow — hosting and delivery of the marketing website, including its content delivery network.
- Amazon Web Services and Cloudflare — hosting, content delivery, and network security for the website and platform.
- Google Fonts and jQuery CDN — delivery of typefaces and scripts. These requests disclose your IP address to the host serving the file.
You can configure your browser to refuse cookies, but parts of the service will not function.
b. Analytics and Marketing
We reserve the right to use analytics and marketing technologies — including product analytics, advertising measurement, and remarketing — on our public marketing website. Where we do, and where consent is legally required, we will present a consent mechanism and will not set non-essential cookies before you give it. We will update the list in Section 9(a) and note the change under Section 21 before or when any such technology goes live. We do not run advertising or marketing trackers inside the authenticated platform.
c. Global Privacy Control
We honour the Global Privacy Control (GPC) signal and other recognized opt-out preference signals where applicable law requires. Because we do not sell or share personal information, a GPC signal does not change how we handle your data — but we will continue to honour it if that ever changes. We do not otherwise respond to browser "Do Not Track" signals, as there is no common standard for them.
10. Links to Third-Party Websites
Our platform and website may contain links to third-party websites. Routina is not responsible for the privacy practices of those websites and encourages users to review their privacy policies independently before providing any personal information.
11. Correcting, Updating, or Deleting Information
Users may update personal information through account settings at any time. To request access to, correction of, or deletion of your personal information, contact privacy@getroutina.com. We will respond to all verified requests within the timeframes required by applicable law, and we may ask for information sufficient to verify your identity before acting on a request. We will not discriminate against you for exercising these rights.
12. Data Retention
We retain personal information for as long as needed for the purpose it was collected, and then delete or anonymize it. The criteria we apply are the nature and sensitivity of the data, the purpose it serves, whether an ongoing account or contract depends on it, and any legal or regulatory retention obligation. In general:
- Account and profile data — for the life of the account.
- Customer operational data in the platform — for the life of the account, then handled under Section 15.3 of the Terms of Service and Section 13 of the DPA: available for export or deletion for 90 days after termination, then deleted or anonymized.
- Billing and tax records — as long as required by applicable financial and tax law, typically seven years.
- Security and audit logs — retained for a limited period appropriate to their purpose, and longer where an active security investigation or legal obligation requires it.
- Support and contact correspondence — retained while needed to handle the enquiry and maintain a record of the relationship.
- Backups — purged on our backup rotation schedule, not exceeding 90 days from a deletion request.
13. Security Measures
We maintain an information security program aligned to the NIST Cybersecurity Framework at approximately Tier 2 (Risk Informed), which we continue to develop as the company grows. The program includes encryption of personal data in transit (TLS 1.2 or higher) and at rest (AES-256), role-based access control and least-privilege administration, multi-factor authentication on internal systems, audit logging of access and configuration changes, network segmentation and monitoring, vendor security review, backup and recovery procedures, and periodic review of the above.
No method of transmission or electronic storage is completely secure, and we cannot guarantee absolute security.
For healthcare customers, Routina is built to support HIPAA compliance requirements, including safeguards for Protected Health Information (PHI). Business Associate Agreements (BAAs) are available on request — contact legal@getroutina.com. Do not transmit PHI to the service before a BAA is signed.
Where we produce aggregate or statistical information from data that includes PHI, we do so only after de-identifying it in accordance with 45 C.F.R. § 164.514(b), and we do not attempt to re-identify it.
14. Incident Management and Data Breach Notification
We maintain an incident response plan and review it periodically. If we determine that a security incident has resulted in a breach of personal data, we will notify affected customers and, where applicable, affected individuals and regulators, without undue delay and within the timeframes required by applicable law — including any obligations under the GDPR, HIPAA, and state breach notification statutes.
Our notice will describe what we know at the time: the nature of the incident, the categories of data and people affected, the likely consequences, and the steps taken or planned in response. Investigations take time, and initial information is often incomplete; we will provide further detail as it becomes available rather than delaying the initial notice. Contractual notification commitments to business customers are set out in Section 10 of the DPA and control where they are more specific.
15. Global Privacy Practices
Routina is headquartered in Puerto Rico, United States. Data may be stored and processed in the United States, though subprocessors may operate in other jurisdictions; the current list and their locations are at getroutina.com/subprocessors. We apply consistent privacy standards globally regardless of the user's location, and we implement appropriate safeguards for international data transfers.
16. Compelled Disclosure
We may disclose personal information to government authorities or law enforcement when required by valid legal process or when reasonably necessary to protect our rights, property, or the safety of our users. We review requests for validity and scope, disclose only what the request requires, and will attempt to notify affected users of any such disclosure when legally permitted to do so.
17. CCPA and GDPR Applicability
When processing customer data on behalf of our business customers, Routina functions as a "service provider" under the California Consumer Privacy Act (CCPA) and a "data processor" under the General Data Protection Regulation (GDPR). In these cases, data subjects should contact the customer organization — not Routina directly — to exercise their data rights. If you contact us instead, we will forward your request to the relevant customer and let you know we have done so.
Individuals who interact with Routina directly — as account holders, billing contacts, website visitors, or enquirers — may contact privacy@getroutina.com to exercise their rights.
18. Notice to California Residents
California residents have the following rights under the CCPA:
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of recipients
- Right to Correct: Request correction of inaccurate personal information
- Right to Delete: Request deletion of your personal information, subject to certain exceptions
- Right to Opt Out of Sale or Sharing: Routina does not sell or share personal information as those terms are defined under the CCPA, so there is nothing to opt out of; we honour the Global Privacy Control regardless (see Section 9c)
- Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information for any purpose beyond providing the service
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights
To submit a request, email privacy@getroutina.com. We may require sufficient verification information to confirm your identity before fulfilling requests, and an authorized agent may submit a request on your behalf with proof of authorization.
19. Notice to European Users
Legal Bases for Processing
Contractual Necessity: Essential account data, billing information, and support-related communications.
Legitimate Interest: Security, fraud prevention, service reliability, aggregate usage analysis, and business operations.
Consent: Optional profile data, marketing communications, and any non-essential cookie or tracking technologies.
Your Rights Regarding Personal Data
EEA, UK, and Swiss residents may exercise the following rights by contacting privacy@getroutina.com:
- Access: Request information about personal data we process about you
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your personal data
- Withdrawal of Consent: Revoke consent for consent-based processing at any time
- Portability: Obtain a copy of your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests
- Restriction: Request that we limit further processing of your data
- Complaint: Lodge a complaint with your local supervisory authority
Transfer of Personal Data
Personal data may be transferred to the United States. Where required, we implement appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission, and the UK International Data Transfer Addendum for transfers from the United Kingdom, to ensure adequate protection of your personal data. Business customers may request execution of SCCs by contacting privacy@getroutina.com.
20. Google Workspace APIs Use
Data obtained through Google Workspace APIs is not used to develop, improve, or train generalized artificial intelligence (AI) or machine learning (ML) models, and is not transferred to any third party for that purpose. Use of Google Workspace API data is strictly limited to providing and improving Routina's user-facing functionality in accordance with Google's API Services User Data Policy, including its Limited Use requirements. This restates, for Google's data specifically, the broader commitment made in Section 7.
21. Policy Changes
We may update this Privacy Policy from time to time, and will revise the version and date at the top of this page when we do. Material changes will be communicated via email to registered account holders or through a prominent notice on our platform, and will take effect no sooner than 30 days after that notice unless a shorter period is required by law. Continued use of Routina following notice of changes constitutes acceptance of the revised policy.
22. Contact Information
For privacy inquiries, requests, or questions about this policy, please contact us at:
Warp Speed Solutions Inc., a Flexio Holding Inc company (Routina)
Privacy inquiries and data subject requests: privacy@getroutina.com
Legal notices and BAA requests: legal@getroutina.com
Built in Puerto Rico, United States