This Privacy Policy explains how Digital Workspace (“Digital Workspace”, “we”, “us”) collects, uses, shares and protects personal information when you visit digitalworkspace.app or use the Digital Workspace application (the “Service”). It should be read together with our Terms of Service.
1. Who is responsible for your data
Digital Workspace is a business platform used by organizations (“Customers”) and the people they invite (“Users”). We act in two roles:
- On behalf of Customers for the content stored in a workspace, such as CRM records, documents, files, messages, HR records and knowledge articles. The Customer decides what is stored and who can see it, and we process this data only to provide the Service to them. If you are a User, your organization’s administrator is your first point of contact.
- As the responsible party for account and sign-up data, website enquiries, billing, security logs and communications with us.
2. Information we collect
Information you provide
- Account and organization details: name, work email, phone number, company name, password (stored only as a one-way hash), job title, department, profile photo and other profile fields you choose to complete.
- Workspace content: everything you and your colleagues create or upload, including accounts, contacts, leads, opportunities, campaigns, tickets, projects, documents and files, chat messages, knowledge articles, HR and training records, reports and dashboards.
- Enquiries: details you send through our “Contact sales” and sign-up forms.
Information from connected services
- Google (Gmail) and Microsoft (Outlook): when you choose Continue with Gmail or Continue with Outlook, we receive your email address and name, plus authorization to read and send email for that account. We store access and refresh tokens and copies of the messages synced into your in-app inbox (the newest messages, in pages of 50). See section 4.
Information from people outside your organization
- Web forms: names, email addresses, phone numbers, company names and request details submitted through public lead or incident forms that a Customer publishes.
- E-signatures: signer name, email address, typed signature, consent, time of signing, IP address and browser details, recorded as an audit trail.
Information collected automatically
- Technical and usage data: IP address, browser and device type, pages visited, sign-in times and security events, collected through server logs.
- Cookies: see section 9.
3. How we use information
- To provide, operate and maintain the Service, including sign-in, workspaces, modules, notifications and support.
- To send service emails, such as invitations, password resets, e-signature requests, approvals and security notices. Where you have connected a mailbox, emails you write or launch (including replies and CRM campaign emails) are sent from your own address at your request.
- To secure the Service, prevent abuse and fraud, and investigate incidents.
- To respond to enquiries and manage our customer relationships, including subscriptions and billing.
- To understand and improve the Service using aggregated, de-identified information.
- To comply with legal obligations and enforce our Terms.
4. Data from Google and Microsoft accounts
Connecting a mailbox is optional. When you choose Continue with Gmail or Continue with Outlook in the Email module, you authorize Digital Workspace to access that one mailbox. We request only these permissions:
| Permission | What we access | Why |
|---|---|---|
Basic profile (openid, email, profile) | Your name and email address | To identify the connected mailbox and show which address you send from |
Read email (Gmail gmail.readonly, Outlook Mail.Read) | Messages in your Inbox: sender, recipients, subject, date and body | To show your inbox inside Digital Workspace, so you can read messages and link them to CRM records and service desk incidents |
Send email (Gmail gmail.send, Outlook Mail.Send) | Permission to send from your address; no access to other mail | To send emails you write or launch in the Service, such as replies, CRM campaign emails and e-signature requests, from your own address |
We never modify, label, move or delete messages in your mailbox, and we never send email from it except when you click Send or launch a campaign you own or are allowed to edit.
How Google and Microsoft data is stored
- Messages are synced into your workspace (the newest messages, in pages of 50) and stored encrypted in transit and at rest on our infrastructure in the European Union.
- Access and refresh tokens are stored on our servers and used only to sync your inbox and send the emails you ask us to send.
- Synced messages are visible only to you, the person who connected the mailbox. They are not shared with your colleagues unless you link or forward a message yourself.
Limited Use of Google user data
Digital Workspace’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide and improve the user-facing email features described above, which are visible and prominent in the Email module.
- We do not transfer Google user data to others, except as necessary to provide or improve those features, to comply with applicable law, for security purposes (such as investigating abuse), or as part of a merger, acquisition or sale of assets with notice to you.
- We do not use or transfer Google user data for serving advertisements, including retargeting, personalized or interest-based advertising.
- We do not sell Google user data, and we do not use it to determine creditworthiness or for lending purposes.
- We do not use Google user data to develop, improve or train generalized or non-personalized artificial-intelligence or machine-learning models.
- No person at Digital Workspace reads Google user data unless you give us affirmative permission for specific messages (for example for support), it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and anonymized for internal operations.
Data received through Microsoft Graph is handled under the same restrictions.
Disconnecting and deleting your mailbox data
- Click Disconnect in the Email module at any time. Digital Workspace stops syncing and can no longer send from your mailbox.
- You can also revoke access directly in your Google Account or Microsoft account settings.
- To have your synced messages and stored tokens deleted, email info@digitalworkspace.app from the connected address or ask your workspace administrator. We delete them within 30 days.
- Mailbox data is also deleted when your user account or your organization’s workspace is deleted.
6. Where data is stored
Workspace data is stored primarily in the European Union (Frankfurt, Germany). Some providers may process limited data in other countries, including the United States. Where we transfer personal information internationally, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
7. How long we keep data
- Workspace content is kept for as long as the Customer’s account is active, or until the Customer or an authorized User deletes it.
- When a subscription ends, we delete or anonymize workspace data within 90 days unless the Customer asks for an export first or the law requires us to keep it. Backups are overwritten on a rolling basis.
- Mailbox data is removed when the connected account’s data is deleted at your request or the workspace is closed.
- E-signature audit trails are kept with the signed document for as long as the document exists, because they evidence the signature.
- Security logs are kept for a limited period, typically up to 12 months.
8. Security
- All traffic is encrypted in transit with HTTPS (TLS), and data is stored on encrypted infrastructure.
- Passwords are stored only as salted one-way hashes. Strong passwords are required, and temporary passwords must be changed at first sign-in.
- Access inside a workspace is limited by roles, module permissions and confidential-document controls.
- Changing or resetting a password signs out other sessions.
10. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete or export your personal information, and to object to or restrict certain processing. These rights include those under the EU and UK GDPR, the California Consumer Privacy Act, and the Law of the Republic of Uzbekistan “On Personal Data”. You can also withdraw consent where processing is based on consent.
- You can update most profile information yourself in Profile.
- For workspace content, contact your organization’s administrator. We will help them respond.
- For other requests, email info@digitalworkspace.app. We may need to verify your identity, and we respond within the time the law requires.
You may also complain to your local data protection authority.
11. Children
The Service is intended for businesses and is not directed to children under 16. We do not knowingly collect personal information from children.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the new version on this page and change the “Last updated” date. For material changes, we will notify Customers by email or in the Service.
13. Contact us
Questions or requests about privacy: info@digitalworkspace.app.