Privacy Policy
Last updated 8 September 2026.
This policy explains what data Ollasync processes when you use our service, and your rights over it.
The short version
- Application data is processed in the United States (Detroit); live media and recordings on servers in Germany (Frankfurt). The managed service is not offered as EU-only hosting; self-hosting keeps all data on infrastructure you control. Details in the DPA.
- Encrypted messaging is end-to-end encrypted — we store only ciphertext and cannot read its content.
- We do not sell your data and we do not use it to train advertising or third-party models.
- You can request access to, or deletion of, your personal data at any time.
What we process
Account data
Your name, email address, organisation and authentication details (including 2FA and passkey metadata) so you can sign in and we can operate your workspace.
Content
Encryption differs by data type, as described on our security page. For end-to-end encrypted messaging, we store only opaque ciphertext and hold no keys. For meetings, media is encrypted in transit and relayed; for deal-room documents, content is encrypted in transit and access-controlled. We process this content only to deliver the service. When a participant turns on live captions, translation or AI meeting notes, the speech in that meeting is sent to our speech provider (transcription, translation, synthesis) and, for notes, its transcript to an AI provider; both are listed in the DPA, and everyone in the meeting is shown a notice when it starts.
Metadata
To route and secure the service we necessarily process routing and operational metadata — for example room identifiers, membership, connection times, and message size and timing. For encrypted messaging, this metadata does not reveal message content.
Logs
We keep security and audit logs (sign-ins, invites, NDA acceptance, document access) to protect accounts and support your own compliance needs.
Why we process it
To provide and secure the service, to authenticate you, to prevent abuse, and to meet legal obligations. Our lawful bases under the GDPR are the performance of our contract with you, our legitimate interest in operating a secure service, and, where applicable, your consent.
Sub-processors & data sharing
We use a small set of infrastructure providers to operate the hosted service. They are listed, with their roles and locations, in our Data Processing Agreement, available on request. We do not share your data with advertisers or data brokers.
Retention
We keep account and content data for as long as your workspace is active. Cloud recordings are deleted 90 days after they are made (earlier on request). A room you close is removed in full 90 days after closing — messages, documents and recordings. Per-room disappearing-message timers are supported. Encrypted backups are retained for 30 days (databases) and 90 days (recordings and configuration). You can delete your own account from the workspace settings; a workspace owner can delete the whole workspace and everything in it. On request or on account closure, we delete personal data within a reasonable period, subject to legal retention obligations.
Your rights
Under the GDPR you have the right to access, correct, delete, restrict or port your personal data, and to object to certain processing. Contact [email protected] and we will respond within the timeframes the law requires. You may also complain to your data-protection authority.
Cookies
Our marketing site uses no third-party advertising or tracking cookies. The application uses first-party cookies strictly necessary to keep you signed in.
Contact
Questions about this policy or your data: [email protected]. Security matters: [email protected].
Grievance officer (India)
For users in India, under the Digital Personal Data Protection Act, 2023, grievances about your personal data go to our Grievance Officer, Amit Tanwar, at [email protected]. We acknowledge every grievance and resolve it within the period the law requires.
This policy reflects how the product works today and will be updated as the service evolves. It is provided for transparency and should be reviewed alongside your contract and DPA.