Privacy policy

How [Legal entity name] handles personal data in and around OVIOO.

Updated 15 August 2026

Draft pending legal review. Placeholders in brackets must be completed before publication.

1. Who we are

[Legal entity name], [Registered address] ("we") provides OVIOO. For the personal data inside your mailboxes, your organisation is the controller and we act as processor on its instructions — see the Data Processing Agreement.

For account, billing and website data described below, we are the controller.

2. What we process

  • Account data: name, work email, organisation, role, authentication metadata.
  • Mailbox content: messages, headers, attachments and derived data (references, TODOs, tags) — processed on your organisation’s instruction to provide the service.
  • Connection data: provider, mailbox address, encrypted credentials or OAuth tokens, sync state and errors.
  • Usage data: feature and AI usage counters, device sessions, diagnostic logs.
  • Billing data: plan, subscription state, invoices. Card details are handled by our payment processor; we do not store card numbers.

4. AI processing

Where your organisation enables it, message content is sent to our AI subprocessors to produce suggestions — TODOs, reference matches, tags, summaries and drafts. Content is sent only within the permission boundary of the requesting user.

We do not use your content to train models offered to other customers, and we require the same of our AI subprocessors under contract. AI features can be switched off entirely by the organisation owner, and email continues to work when they are.

5. Sharing

We share personal data only with the subprocessors listed on the subprocessors page, under written agreements, and with authorities where legally required. We do not sell personal data and we do not use it for advertising.

6. International transfers

Data is hosted in the European Union by default. Where a subprocessor processes data outside the EEA, we rely on Standard Contractual Clauses and supplementary measures as appropriate.

7. Retention

Mailbox content and derived data are retained while the mailbox is connected and, after removal or the end of a subscription, for a 30-day recovery window before permanent deletion. Billing records are kept as long as tax law requires. Diagnostic logs are kept for 90 days.

8. Your rights

You may request access, correction, deletion, restriction, portability, or object to processing. If your data is inside a customer’s workspace, we will refer you to that organisation as controller and support them in responding.

Contact privacy@ovioo.app. You also have the right to complain to your supervisory authority.

9. Security

Encryption in transit and at rest, per-organisation isolation, encrypted credential storage, least-privilege support access and audit logging. See the security page for detail.

10. Changes

We will post material changes here and notify organisation owners by email at least 30 days before they take effect.

See it on your own mailbox

Fourteen-day trial for the whole organisation, no card.