Skip to main content
Last updated: October 8, 2026. DispoIQ provides business software for managing deals, buyers, contacts, and communications. Its application includes authentication, permission checks, and customer-scoped access controls. Security also depends on how your team manages accounts, uploads information, and shares deals. This overview explains those safeguards and practical steps you can take. Security terms in an agreement that applies to your workspace remain separate from this overview. For questions about personal-information handling, contact support@dispoiq.app.

1. Account access and permissions

DispoIQ uses an authentication provider for user sign-in. The application checks the user’s organization, membership status, and permissions when authorizing workspace access. A disabled or pending member cannot pass the application’s membership check. Actions requiring an administrator or owner are subject to additional permission checks. Use an individual account for each team member and keep sign-in credentials private. Give each person only the access needed for their work, review access when responsibilities change, and disable access when someone leaves your team. Protect the email account used to sign in as carefully as your DispoIQ account.

2. Workspace records and deal sharing

Application access controls scope customer records to the relevant workspace. Internal platform access is subject to a separate staff-access boundary; being an owner of a customer workspace does not itself give access to the internal console. Sharing a deal makes the information you publish available to its intended audience. Personalized deal links can grant access to the deal and associate activity with the buyer linked to that URL. Someone can forward a link, so treat personalized links as private and share them only with intended recipients. Deal photos and documents may be accessible through their resource URLs. A personalized deal link does not establish that every linked file requires the same access check. Review files before uploading them and avoid publishing confidential contracts, identity documents, account credentials, or unnecessary personal information.

3. Payments and integration credentials

Payment entry uses the payment provider’s hosted payment flows. DispoIQ receives transaction information and payment-method summaries for billing. Keep full payment-card details out of ordinary support correspondence and workspace content. Keep payment, authentication, and communications-provider credentials out of contact notes, uploaded documents, message templates, and ordinary support correspondence. Provide integration information only through the applicable setup process, and contact support if you believe a credential has been exposed.

4. Data protection and diagnostics

Where error reporting is enabled, the application’s configured controls reduce exposure of request data through URL masking, request-body removal and filtering of request headers. Error descriptions, issue reports and other diagnostic information can still contain information supplied by users or the application. Include only the information needed to explain a problem.

5. Availability, recovery, and retention

Keep your own copies of business-critical records and documents. Subscription access, exports and record deletion are separate processes. Canceling a subscription or disabling a team member does not itself establish that all related information has been erased. Retention is not a guarantee of restoration or backup recovery. Under the account-closure policy, customers have 90 days from the end of paid subscription access to request an export of information they are entitled to receive. DispoIQ may delete eligible workspace records after 180 days from that same end of paid access; this is not a promise that every copy is erased on day 180. The request window does not extend ordinary paid application access or expand source-data rights. A request received within the 90-day request window is not canceled merely because that window expires. DispoIQ will preserve the information it is authorized to provide and needs to fulfill that request until the request is fulfilled or otherwise lawfully resolved, except to the extent an earlier deletion obligation requires a different result. Routine deletion after 180 days will not by itself defeat such a timely request. These windows do not postpone individual privacy requests, override earlier applicable legal, source-license or separately agreed processing duties, or forfeit unused wallet funds purchased with money. Transaction records, suppression evidence, legal holds, provider copies and backup handling require their own lawful treatment. This overview sets no backup schedule or recovery-time guarantee.

6. Reporting a security concern

Contact support@dispoiq.app if you suspect unauthorized access, an exposed credential, inappropriate data access, or another security issue. This address is routed to DispoIQ’s support inbox. In your initial message, describe what happened, when you noticed it, and the affected feature. Avoid sending passwords, API keys, complete buyer lists, identity documents, or other unnecessary sensitive information. Ask for an appropriate way to provide additional evidence if it is needed. Support will record and triage security reports and escalate suspected incidents for authorized technical assessment. DispoIQ will assess the affected information and systems, take appropriate containment and corrective steps, and coordinate necessary cooperation with affected customers and relevant service providers. We will notify affected customers, individuals or authorities when applicable law or a separately agreed processing commitment requires it, using the required timing, content and procedure. An ongoing investigation does not permit delaying a required notice beyond its applicable deadline. A report is not itself confirmation that an incident has occurred. This reporting procedure sets no guaranteed acknowledgment or resolution time. No online service can guarantee absolute security. If you believe your account is compromised, protect your sign-in email, review your account access, and contact support promptly.