Privacy Policy
Last updated 1 August 2026.
This policy explains what data Ollasync processes when you use our hosted service, and your rights over it. If you self-host Ollasync, you are the operator and controller of your deployment — this policy covers our managed service.
The short version
- We host our managed service in the EU (Frankfurt).
- Encrypted messaging is end-to-end encrypted — we store only ciphertext and cannot read its content.
- We do not sell your data and we do not use it to train advertising or third-party models.
- You can request access to, or deletion of, your personal data at any time.
What we process
Account data
Your name, email address, organisation and authentication details (including 2FA and passkey metadata) so you can sign in and we can operate your workspace.
Content
Encryption differs by data type, as described on our security page. For end-to-end encrypted messaging, we store only opaque ciphertext and hold no keys. For meetings, media is encrypted in transit and relayed; for deal-room documents, content is encrypted in transit and access-controlled. We process this content only to deliver the service.
Metadata
To route and secure the service we necessarily process routing and operational metadata — for example room identifiers, membership, connection times, and message size and timing. For encrypted messaging, this metadata does not reveal message content.
Logs
We keep security and audit logs (sign-ins, invites, NDA acceptance, document access) to protect accounts and support your own compliance needs.
Why we process it
To provide and secure the service, to authenticate you, to prevent abuse, and to meet legal obligations. Our lawful bases under the GDPR are the performance of our contract with you, our legitimate interest in operating a secure service, and, where applicable, your consent.
Sub-processors & data sharing
We use a small set of infrastructure providers to operate the hosted service. They are listed, with their roles and locations, in our Data Processing Agreement, available on request. We do not share your data with advertisers or data brokers.
Retention
We keep account and content data for as long as your workspace is active. Rooms can be closed and purged, and per-room disappearing-message TTLs are supported. On request or on account closure, we delete personal data within a reasonable period, subject to legal retention obligations.
Your rights
Under the GDPR you have the right to access, correct, delete, restrict or port your personal data, and to object to certain processing. Contact [email protected] and we will respond within the timeframes the law requires. You may also complain to your data-protection authority.
Cookies
Our marketing site uses no third-party advertising or tracking cookies. The application uses first-party cookies strictly necessary to keep you signed in.
Contact
Questions about this policy or your data: [email protected]. Security matters: [email protected].
This policy reflects how the product works today and will be updated as the service evolves. It is provided for transparency and should be reviewed alongside your contract and DPA.