Trust center
Privacy policy
This policy explains what information Critical Path, a product by QuadrantWorks, processes, why we use it, and the controls available to you.
Last updated September 23, 2026
Information we process
We process account details such as your name and email address, workspace content you choose to add, product activity needed to operate the service, and support communications you send to us.
If you connect Google or Microsoft, we receive the account identity and authorization tokens needed to provide the calendar and email features you approve. We do not request permission to read your inbox.
If you enable WhatsApp control, Meta processes the messages you send. Critical Path uses each inbound message to answer the request but does not retain its body in the workspace database; we retain the linked phone number, consent and revocation times, delivery identifiers, rate-limit evidence, and task changes you confirm. If you enable native push reminders, we process an Apple device token and delivery status. Device tokens are used only to route notifications to your device.
Website inquiries and CRM
Our optional Talk to our team form is hosted by HubSpot. If you submit it, HubSpot receives your name, email address, any phone number and message you provide, and your consent choices. We use the submission to create or update a CRM contact and respond to your inquiry. This form does not automatically make a new contact a marketing contact; the product-updates checkbox is optional.
The form uses Google reCAPTCHA v3 to assess suspicious submissions. Google may process technical data associated with your visit for that verification. The form links to this policy before submission.
Help Center chat
Our hosted Help Center offers a HubSpot chat widget. If you start a chat, HubSpot processes your messages, the contact details you choose to provide, and any support ticket created from the conversation. The widget may suggest published help articles before routing your question to a person. Chat cookies are used only after you accept the widget's cookie notice.
Do not send passwords, tokens, payment-card details, or unredacted workspace content in support chat. You can also contact us by email without using the chat widget.
AI and meeting intelligence
External AI processing is off by default. If both you and the deployment administrator enable it, asking Quadrant AI a question sends the question and a bounded set of relevant workspace facts to our AI processing provider to produce an answer or proposed action. Provider-side response storage is disabled where supported. A metadata-only egress record captures the processor, purpose, data categories, item count, outcome, and time—never the task, transcript, or prompt content. Critical Path requires confirmation before an AI-proposed task change is applied.
Meeting intelligence is optional. When an organizer adds QuadrantWorks to a meeting, the bot joins visibly. We process the meeting link, title, participant-provided speech converted into transcript text, speaker labels, timestamps, meeting notes, and suggested actions. We do not enable silent capture, and suggested actions do not become tasks until a workspace user approves them. The organizer is responsible for giving notice and obtaining any consent required by law, contract, or workplace policy.
Apple purchases
If you purchase or restore a Focus or Pro subscription through Apple, we process Apple transaction identifiers, the subscription product, purchase and expiry dates, introductory-offer eligibility, and renewal, refund or revocation status linked to your Critical Path account. We use these records to verify purchases, provide the correct access, restore subscriptions and prevent duplicate or unauthorized use.
Apple handles payment. We do not receive your Apple payment-card details. These purchase records are not used for advertising or tracking. Any retention requirements must be addressed as part of an account-deletion request; this policy does not promise that disabling an account immediately erases purchase records.
How we use information
We use information to provide and secure Critical Path, synchronize the calendar actions you request, answer workspace questions, create meeting notes and suggested actions, send workflow messages on your behalf, troubleshoot issues, and improve product reliability.
We do not sell personal information or use connected-account data for advertising.
Google user data
Critical Path uses Google data only to deliver user-facing features you initiate: checking availability, creating or updating calendar events, and sending email on your behalf. Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
Sharing and service providers
We share information only with infrastructure and delivery providers that help operate the service, when you direct us to integrate with another service, or when required by law. Providers are limited to the information necessary to perform their work and must protect it.
Security and retention
We use access controls, encrypted transport, and encrypted storage for integration credentials. OAuth authorization links are time-limited and single use. We keep information only while needed to provide the service, meet legitimate operational needs, or comply with legal obligations.
Your choices
You can disconnect a provider from Critical Path or revoke access in your Google or Microsoft account at any time. Settings → Data & privacy provides a workspace snapshot export and an authenticated account-deletion request. An accepted deletion request disables access immediately. Final erasure or pseudonymization is operator-reviewed, and support confirms the applicable timeline and completion status; Critical Path does not currently publish a guaranteed erasure deadline. Shared workspace owners must first arrange ownership transfer. You may also contact us about access or correction. We may need to verify your identity before completing a request.
See Help & support for export steps, current deletion limitations and contact details. Deleting your account does not cancel an Apple subscription or remove events and messages already sent to external services.
Changes to this policy
We may update this policy as the service evolves. We will revise the date above and provide additional notice when a change materially affects your rights or how we use information.