Awesome People Leaders Privacy Policy
Effective: 09/08/2026
Last updated: 09/08/2026
Awesome People Leaders respects the privacy of the people who use our services. This Privacy Policy explains how DonnaKyle Inc, doing business as Awesome People Leaders ("APL," "we," "us," or "our"), collects, uses, stores, shares, and deletes personal information when we provide the AwesomeEQ and AwesomeWork services, including our Microsoft Outlook add-in, Google Workspace add-on, web applications, reports, and related support services (collectively, the "Services").
This policy applies to business customers that make the Services available to their workforce or other authorized users (each a "Client") and to the individuals who use the Services ("Authorized Users" or "you"). It does not govern Microsoft, Google, Teachable, or another third party's own handling of information under its privacy policy.
1. Our role and the Client's role
APL generally processes personal information on behalf of the Client that provides your access to the Services. The Client determines who may use the Services and may control account provisioning, entitlements, reporting, and retention instructions. In that context, the Client is generally the controller or business and APL is generally the processor or service provider, as those terms are defined by applicable privacy law.
APL is responsible for information it collects for its own business purposes, such as account security, service administration, support, and legal compliance. A Client instruction does not permit APL to use Google Workspace data in a way that conflicts with Google's policies or the commitments in Section 7 of this policy.
If you use the Services through your employer or another organization, that organization may have its own notices, policies, and rights concerning business communications and workplace data. Questions about the Client's practices should be directed to the Client.
2. Information we collect and process
The information we process depends on the Service and feature you use.
Account, organization, and course information
We may process:
-
your name, business email address, role, organization, and department;
-
account identifiers, authentication status, and service entitlements;
-
Teachable account, enrollment, course, and lesson information needed to authenticate you and determine which APL curriculum may be used to generate coaching; and
-
information a Client supplies to provision, administer, or support its account.
We do not receive your Microsoft or Google account password. Microsoft and Google control their own authentication and authorization processes. APL's current product sign-in uses Teachable to confirm identity and course access.
Microsoft Outlook content
When you use the Outlook add-in to analyze an open message or draft, the add-in may read and send to APL:
-
the subject and message body;
-
sender and recipient names and email addresses;
-
your signed-in mailbox address;
-
whether the item is received mail, a new draft, or a drafted reply or forward;
-
shared-mailbox context and an identifier for the Outlook item; and
-
for a drafted reply or forward, the draft and quoted thread that Microsoft makes available as one body.
The add-in holds the active item in memory while its task pane is open and sends the content over HTTPS to APL when analysis begins. It does not store raw message content in browser local storage or Microsoft roaming settings. The current Office add-in integration is limited to the item the user has opened or is drafting; it does not browse the user's mailbox.
Google Workspace and Gmail content
When you use the Gmail add-on to analyze the currently open message, APL may receive or access:
-
your Google-verified email address;
-
a short-lived authorization token and add-on token supplied by Google;
-
the current Gmail message identifier, sender, labels, subject, and message body; and
-
classifications, attribution, scores, or other information derived from that message.
APL uses the short-lived tokens to request only the current message from the Gmail API. The Gmail add-on does not request general access to browse your mailbox. APL does not create a permanent copy of the raw Gmail message body or subject as part of the normal analysis flow. We may retain the limited request and derived records described in Sections 3, 5, and 9.
Generated insights, feedback, and support information
We process the coaching insight generated for you and information about how the result was delivered. If you rate an insight or interact with a lesson or product control, we may record the request identifier and that interaction.
Issue reporting is optional. If you choose Send report, we receive the generated result, the request identifier, the experience displayed, your optional note, and a record that you chose to submit it. Do not include information in a support note that APL does not need to investigate the issue.
Service, device, and usage information
We may collect service logs and technical information such as IP address, browser or host type, operating system, timestamps, request status, performance data, feature interactions, and security events. Product reporting may include request counts, whether an insight was generated, lesson and button interactions, and structured capability or risk classifications. These records can be associated with an Authorized User or Client account.
Website and browser storage
Our public websites and web applications may use cookies or similar storage needed for security, authentication, preferences, and service operation. The Outlook add-in stores its APL session token in environment-specific browser local storage on the device and stores a non-sensitive first-run preference in Microsoft roaming settings. Blocking required storage can prevent the Services from working.
3. How we use information
We use personal information only as reasonably necessary to:
-
authenticate Authorized Users and verify course and product entitlements;
-
retrieve the message an Authorized User has chosen to analyze;
-
generate and display request-specific leadership coaching and related course recommendations;
-
attribute a request to the correct user, mailbox context, Client, and product surface;
-
operate product features, record requested feedback, and investigate reports users choose to submit;
-
provide Client administration, aggregate usage reporting, and permitted personal views;
-
maintain, secure, troubleshoot, and measure the reliability of the Services;
-
enforce our agreements and protect the rights, safety, and integrity of APL, our Clients, Authorized Users, and others; and
-
comply with applicable law and valid legal process.
We may use information that has been aggregated or de-identified so it cannot reasonably identify an individual to understand service performance and improve the Services. We do not attempt to re-identify that information. Google Workspace data, including data derived from it, remains subject to the additional restrictions in Section 7 even when aggregated or de-identified.
We do not sell personal information. We do not use message content or Workspace-derived data for targeted advertising, credit eligibility, lending, or data-broker activities. We do not use or transfer Microsoft API data, including aggregated, anonymized, or derived data, for advertising or marketing.
4. AI-assisted processing
The Services use artificial intelligence to generate coaching. For each analysis request, APL sends the selected email content and relevant APL course material to OpenAI through its business API. The model returns a request-specific response, which APL presents as coaching, classifications, and related course suggestions.
AI output is generated from patterns and may be incomplete or inaccurate. It should be reviewed by the user and is not a substitute for legal, human-resources, medical, financial, or other professional advice. APL does not use, and does not authorize its service providers to use, Microsoft 365 or Google Workspace content to train or improve generalized or foundation AI models. APL does not make decisions producing legal or similarly significant effects about individuals based solely on the generated coaching.
5. How we share information
We disclose personal information only as described below:
-
The Client. We may make account administration, permitted usage reporting, aggregate analytics, or user-specific information available to the Client that provides your access. The exact views depend on the Client's configuration and applicable privacy safeguards.
-
Service providers. We use providers that perform services for us under contract, including Microsoft Azure for cloud hosting and service telemetry, OpenAI for request-specific AI processing, Teachable for authentication and course entitlements, and identity, communications, security, and support providers used for relevant features. They may process information only to perform services for APL and subject to appropriate confidentiality and data protection obligations.
-
At your direction or with your consent. We disclose information when you intentionally use a feature that requires the disclosure or direct us to do so.
-
Security and legal compliance. We may disclose information when reasonably necessary to investigate fraud, abuse, or a security incident; protect rights or safety; comply with law; or respond to valid legal process.
-
Business transaction. Information may transfer as part of a merger, financing, acquisition, reorganization, or sale of assets, subject to applicable law and the continuing commitments in this policy. Google Workspace data transfers are also subject to Google's Limited Use restrictions and, where required, prior user consent.
We do not allow service providers to use personal information for their own advertising or to sell it. We require contractors, agents, and successors that process Google Workspace data to follow the Google-specific commitments in Section 7.
6. Client reporting and derived analytics
The Services create operational and product-use records from analysis requests. Depending on the Client's configuration, reporting can include counts of requests and insights, feature interactions, course or lesson activity, and aggregate leadership capability or risk themes.
Some structured request records carry identity at rest so APL can enforce organization boundaries, calculate privacy thresholds, deduplicate repeated analysis of the same item, and provide a user with their own view. Organization and department reporting uses aggregate views and privacy floors. APL personnel with an authorized operational role may have access to identity-linked records for support, security, data-quality, and Client administration purposes.
We do not provide Clients with raw email message bodies through analytics dashboards or scheduled reports.
7. Google Workspace data commitments
This section applies to information APL receives from Google Workspace APIs and to information derived from that data. If another part of this policy is broader, this section controls for Google Workspace data.
APL uses Google Workspace data only to provide or improve the user-facing feature that the user has requested: analyzing the currently open Gmail message and presenting leadership coaching and related course recommendations. We transfer that data only as necessary to provide that feature, with the user's consent; for security purposes; to comply with applicable law; or as part of a business transaction with any consent required by Google policy.
APL personnel do not read raw Gmail content unless:
-
the user gives affirmative, documented consent for APL personnel to review specific data for support;
-
access is necessary to investigate abuse or a security incident;
-
access is necessary to comply with applicable law; or
-
the data has been aggregated and de-identified and is used for internal operations in a manner permitted by Google's policies.
APL does not use or transfer Google Workspace data to advertise to users, sell data, determine creditworthiness or lending eligibility, operate as a data broker, or create, train, or improve a generalized or foundation AI model. APL does not scrape Gmail or create a database or permanent copy of Gmail messages.
APL's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The Google Workspace add-on's access can be removed by a user or Workspace administrator through Google's account or Marketplace administration controls. Revoking access prevents new access; it does not by itself delete records APL was permitted to retain before revocation. To request deletion of retained APL records, follow Section 10.
8. Human access and confidentiality
APL limits access to personal information to personnel and contractors who need it for their role. Access is subject to authentication, authorization, confidentiality obligations, and logging or monitoring appropriate to the system.
APL personnel do not routinely review raw message content. Human review may occur when you explicitly submit information for support, when necessary to protect security or prevent abuse, or when required by law. The narrower Google Workspace rules in Section 7 always apply to Google data.
9. Retention and deletion
APL retains each category of information only for as long as needed for the purpose described in this policy, to provide the Services under the Client agreement, and to meet security or legal obligations. We do not retain information indefinitely merely because it may be useful later.
The production retention schedule will be published here before launch:
Proposed public retention statement by Category
Raw Outlook and Gmail message content used for normal analysis: Processed transiently for the request and not intentionally stored in product or reporting databases after processing.
Generated coaching prose: Up to 90 days for legacy product flows.
Request identifiers, sender/mailbox fields, interaction telemetry, and structured classifications: 90 Days
Analytics copies and scheduled reports: 90 Days
User-submitted issue reports: Deleted 30 days after the report was last modified, subject to any short backup or legal hold.
Account and entitlement records: For the Client relationship and one year afterward, unless law or the Client agreement requires otherwise.
Application and security telemetry: 90 Days
Backups: Removed or rendered inaccessible on the ordinary backup cycle within 90 Days, unless subject to a legal hold.
When an account is closed or a valid deletion request is approved, APL deletes or de-identifies the covered information from active systems and instructs relevant service providers to do the same, subject to contractual, security, backup, and legal exceptions. Information retained for a legal exception is isolated from ordinary use and deleted when the exception ends.
When APL receives notice that a user has uninstalled or disconnected the Microsoft add-in, abandoned or closed the associated account, or ended the applicable subscription, APL deletes the Microsoft API data associated with that account unless the Client directs an authorized transfer, Microsoft permits continued retention, or applicable law requires retention.
10. Your choices and privacy rights
Depending on where you live and the context in which APL processes your information, you may have the right to request access, correction, deletion, restriction, portability, or an objection to certain processing. You may also have the right to appeal our response and to lodge a complaint with a privacy regulator. APL will not discriminate against you for exercising an applicable privacy right.
If the Client controls the information, send your request to the Client. You may also contact APL at trust@awesomepeopleleaders.com; we will respond directly when APL is responsible or route the request to the appropriate Client when required. We may request information needed to verify your identity and authority. An authorized agent may submit a request where applicable law permits it.
To stop new processing through an add-in, sign out and remove the add-in, or ask your Workspace or Microsoft 365 administrator to remove access. Removing an add-in or revoking platform access does not automatically delete records already held by APL; use the request process above for deletion.
Users in the European Economic Area or United Kingdom may also contact the data protection authority where they live or work. A list of European Economic Area authorities is available from the European Data Protection Board.
APL does not sell personal information or share it for cross-context behavioral advertising. If our practices change in a way that creates a legal right to opt out, we will provide the required notice and control before that change takes effect.
Legal bases for EEA and UK processing
Where European Economic Area or United Kingdom law requires a legal basis, APL processes personal information as necessary to perform its agreement with a Client or provide a feature an Authorized User requests; to comply with legal obligations; with consent where consent is required; and for legitimate interests such as securing, supporting, and improving the reliability of the Services, provided those interests are not overridden by the individual's rights. The Client determines the legal basis for processing it controls.
11. Security
APL uses administrative, technical, and organizational safeguards designed to protect personal information. These include encrypted HTTPS transmission, access controls, environment-separated credentials, restricted production logging, cloud identity controls, and service monitoring. No method of transmission or storage is completely secure, but APL maintains safeguards appropriate to the nature of the information and the risks of processing it.
If you believe information has been exposed or misused, contact trust@awesomepeopleleaders.com.
12. International transfers
APL and its service providers may process information in the United States and other countries that may have different data protection laws from your location. Where required, APL uses an approved transfer mechanism and contractual safeguards for cross-border transfers.
13. Children
The Services are business tools intended for adults and are not directed to children under 18. APL does not knowingly collect personal information from children through the Services. If you believe a child has provided personal information to APL, contact trust@awesomepeopleleaders.com.
14. Changes to this policy
We may update this policy as our Services or legal obligations change. We will post the updated policy with a revised "Last updated" date. If a change materially expands how we use or share personal information, we will provide additional notice or obtain consent where required before the change takes effect.
APL will not use Google Workspace data for a materially different purpose without updating its disclosures and obtaining any consent required by Google policy. APL will also provide updated notice and obtain any required additional consent before materially expanding its purpose for or permissions to Microsoft data.
15. Contact us
Questions, privacy requests, and complaints may be sent to: DonnaKyle Inc
Doing business as Awesome People Leaders at 220 Waterway Blvd, Indianapolis, IN 46202
Email: trust@awesomepeopleleaders.com
Support: https://www.awesomepeopleleaders.com/contact
