Privacy Policy
Last updated: 2024-05-01
This SERVICEME RAG plugin for Dify is maintained by Medalsoft and is governed by the principles set out in the Medalsoft Global Privacy Policy (https://www.medalsoft.com/en-us/privacy-policy.html). The sections below describe how the plugin handles information when you deploy it inside your own Dify environment.
Information We Collect
Credentials You Provide
- Base URL, client ID, client secret, and account identifier required to authenticate against your SERVICEME environment.
- Optional configuration parameters (for example, workspace IDs or ranking weights) supplied by you within Dify.
Operational Metadata
- Time-stamped audit logs describing authentication attempts, query payload size, and response status codes.
- Minimal diagnostic data generated when errors occur (stack traces or error identifiers).
The plugin does not collect or store user-generated content beyond what is necessary to fulfill each API request, and it does not persist RAG query content after a response is returned.
How We Use Information
- Authenticate against SERVICEME on your behalf and refresh access tokens securely.
- Execute RAG searches and deliver results to Dify workflows as requested.
- Monitor runtime health, investigate faults, and improve reliability.
- Comply with applicable legal requirements and protect SERVICEME systems from misuse.
Sharing and Disclosure
- We do not sell, rent, or trade any information processed by the plugin.
- Operational metadata may be shared with trusted Medalsoft infrastructure or support providers who help us maintain the service and are bound by contractual confidentiality obligations.
- We may disclose information if required to satisfy legal obligations or to protect the rights, property, or safety of Medalsoft, our users, or the public.
Data Security
- Credentials are stored only within your Dify deployment; they are transmitted to SERVICEME over encrypted channels (TLS 1.2+).
- Access tokens are cached in memory with least-privilege scope and automatically rotated when expired.
- Diagnostic artifacts are restricted to authorized administrators and purged according to internal retention schedules.
Data Retention
- Authentication tokens are kept only for the duration necessary to complete API calls and automatically refreshed or discarded thereafter.
- Audit logs and diagnostic metadata are retained for a period consistent with Medalsoft’s corporate policy and applicable regulations, after which they are securely deleted or anonymized.
Your Choices and Rights
- You control which SERVICEME credentials are provided to the plugin and may revoke them at any time from within your SERVICEME console.
- You can delete cached credentials or reinstall the plugin to remove all locally stored data.
- If you require access, correction, or deletion of diagnostic records maintained by Medalsoft, contact us using the details below.
International Data Transfers
Information processed by the plugin may be stored or accessed in jurisdictions where Medalsoft or its service providers operate. We apply safeguards consistent with the Medalsoft Global Privacy Policy to protect information during cross-border transfers.
Contact
For privacy-related questions or requests, please reach out to privacy@medalsoft.com or contact your Medalsoft account representative.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the repository or release notes. Continued use of the plugin after an update constitutes acceptance of the revised policy.