PaperIQ
Privacy Policy
Last updated: 2026-09-14
This policy explains what MZE IQ LLC, d/b/a PaperIQ (“PaperIQ”, “we”) collects when you use the PaperIQ application, why we collect it, how long we keep it, and who we share it with. PaperIQ is business software sold to organisations; most personal data we hold is supplied to us by a customer organisation about its own users and its own business contacts.
Who we are
PaperIQ is a proposal, quoting and contract application operated by MZE IQ LLC, d/b/a PaperIQ. Contact us at info@paperiq.org or by post at our registered address, available on request.
Two roles matter throughout this policy. For data about our own account holders we are the controller. For the documents, pricing, CRM records and recipient contact details a customer organisation puts into PaperIQ, that organisation is the controller and we act as its processor, on its instructions.
What we collect and why
- Account data — name, work email address, a hashed password, organisation, role and permissions. Used to authenticate you, to apply your organisation’s access rules, and to send service email (verification, password reset, notifications).
- Customer content — proposals, quotes, contracts, pricing, templates, uploaded files and the recipient names, email addresses and phone numbers your organisation enters in order to send a document. Used to provide the service to your organisation.
- Connected-system data — when your organisation connects Salesforce or a cloud-storage provider, we read the records and files it authorises so they can be merged into documents. The connection is made by your organisation and can be revoked by it at any time.
- Delivery and audit records — when a document is sent, we record who sent it, when, the destination email address or mobile number, the message text and the delivery result. This is the audit trail a contract workflow requires, and it is what lets your organisation prove what was sent.
- Service and security logs — request logs, IP address, browser user agent and error reports, used to operate the service, to investigate faults and to detect abuse.
- Billing data — plan, seats and invoices. Card details are entered directly with our payment processor; we do not receive or store card numbers.
We do not sell personal data, and we do not use customer content to train machine-learning models.
SMS and text messaging
PaperIQ sends text messages containing a link to a business document — a proposal, quote or contract — to people who have asked us to. A mobile number is never sent a document until the person holding it has replied YES to an opt-in invitation from their own handset. Messages are sent and received through our messaging provider, Telnyx.
Text message terms at a glance. Message frequency may vary. Standard Message and Data Rates may apply. Reply STOP to opt out. Reply HELP for help.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
PaperIQ is the sender. Every message is sent by MZE IQ LLC, d/b/a PaperIQ from a single PaperIQ number, under one registered brand and one carrier-approved campaign. An authenticated user of a customer organisation, holding the document-send permission, asks us to text a document to a number; we then text that number an invitation naming the person and the company asking, and we send the document only if the recipient replies YES. Nothing a customer organisation types into PaperIQ is treated as the recipient’s consent.
The consent record is the recipient’s own reply. We store the reply verbatim, with the mobile number it came from and the time it arrived. Consent is held per organisation: replying YES to an invitation from one company does not let a different PaperIQ customer text you.
Messages are conversational, transactional business messages sent to a counterparty in an active sales or contracting conversation — the recipient is expecting the document. They are not marketing or promotional messages, and PaperIQ does not send bulk or campaign messaging.
Opting out. Reply STOP to any message to stop receiving them; Reply HELP for help. STOP and HELP are honoured by Telnyx and the mobile carriers at the network level, and PaperIQ also records the opt-out on its own suppression list. That list is global: it covers every organisation using PaperIQ, not only the one that contacted you. After an opt-out, no PaperIQ customer can text the number and no one inside PaperIQ can re-subscribe it — only the recipient can, by texting START. Message and data rates may apply. Message frequency varies.
What we store about a text: the recipient’s mobile number, the message text, the sending user, the timestamp and the delivery result. We also store the consent record for that number — when the invitation was sent, and the recipient’s reply verbatim with the time it arrived — and, for an opt-out, the number and the message that opted it out. Full terms are in the SMS messaging terms.
Who we share data with
We share data with service providers who process it on our behalf, under contract, for the purposes described above and no other:
- Supabase — managed PostgreSQL database hosting.
- Google Cloud Platform and Firebase — application hosting and file storage.
- Telnyx — SMS delivery.
- Resend — transactional email delivery.
- Stripe — subscription billing and payment processing.
- Anthropic — the model provider behind PaperIQ’s optional AI drafting features.
We also transmit data to systems your own organisation connects and controls — for example Salesforce, Google Drive, Dropbox or Box. Those transfers happen at your organisation’s direction, and the receiving system’s own privacy terms govern what it does with the data.
We may disclose data where legally required, and to a successor in a merger or acquisition, in which case this policy continues to apply until it is superseded with notice.
How long we keep it
- Account and customer content — for as long as the customer organisation’s account is active, and then deleted or returned on request.
- Send and signature audit records, including SMS records — retained with the document they belong to, because they are the evidence that a document was delivered and executed.
- Service and security logs — retained on a rolling short-term basis for operations.
- Billing records — retained for as long as tax and accounting rules require, regardless of account status.
To request deletion of data your organisation holds in PaperIQ, contact info@paperiq.org. Where we act as a processor we will refer a recipient’s request to the customer organisation that controls the data, and support that organisation in answering it.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to delete it, to obtain a copy in a portable format, to object to or restrict certain processing, and to withdraw consent. We do not sell personal data and do not share it for cross-context behavioural advertising, so there is nothing to opt out of in that respect. Exercise any of these rights by writing to info@paperiq.org; we will not treat you differently for doing so.
Security, children and changes
Access to customer data is scoped to the organisation it belongs to, passwords are stored hashed, and traffic is encrypted in transit. No system is perfectly secure, so we also keep audit records of sensitive actions.
PaperIQ is business software and is not directed at children. We do not knowingly collect personal data from anyone under 16.
If we change this policy we will update the “Last updated” date above and, for material changes, notify account holders by email.
Contact
MZE IQ LLC, d/b/a PaperIQ
our registered address, available on request
info@paperiq.org