Чернетка на перевірці — заповнювачі ще фіналізуються.
Rolyio Privacy Policy
Last updated: [DATE]
TODO before publication (placeholders to resolve with legal counsel):
[COMPANY LEGAL NAME / OPERATOR] — legal entity or sole operator name
[REGISTERED ADDRESS] — registered business address
[JURISDICTION] — governing jurisdiction / place of establishment
[DATE] — effective date
support@rolyio.com — confirm official contact address
- Confirm hosting provider and region once finalized (Hetzner, Germany/EU is planned, not yet contractual)
- Confirm Paddle as merchant of record once billing launches
- Legal review: GDPR controller/processor analysis, DPA availability, lawful bases, data subject rights process, supervisory authority references
1. Who We Are
Rolyio (“Rolyio”, “we”, “us”) is a software-as-a-service product available at rolyio.com that lets teams share contacts across Google Workspace and Microsoft 365 accounts, including cross-ecosystem sharing (for example, a contact owned in Google shared to recipients in Outlook, and vice versa).
Rolyio is operated by [COMPANY LEGAL NAME / OPERATOR], [REGISTERED ADDRESS], [JURISDICTION].
Contact: support@rolyio.com
2. Summary (Read This First)
- We do not store a copy of your address book. Your contacts live in your provider (Google or Microsoft). Rolyio reads and writes contacts through the Google People API and Microsoft Graph API on your behalf, but does not maintain its own copy of your contact list, with the narrow exceptions described in Section 5 (Trash snapshots and audit log payloads).
- No passwords. Sign-in is exclusively via Google or Microsoft OAuth. We never see or store your password.
- You stay in control. You can revoke Rolyio’s access at any time from your Google or Microsoft security settings, or disconnect your account inside the app.
- Google user data is handled under Google’s Limited Use requirements (see Section 7).
3. Roles Under Data Protection Law (GDPR)
Where the EU/UK General Data Protection Regulation or similar laws apply:
- For the contact data processed through the Service (your team’s contacts, shared contacts, and related sync data): the customer (your organization or you as the account holder) is the data controller, and Rolyio acts as a data processor, processing contact data only on the customer’s instructions as expressed through the Service’s features (sharing rules, labels, sync).
- For Rolyio user account data (your email, name, domain, subscription and usage records): Rolyio acts as the data controller.
A data processing addendum (DPA) reflecting these roles is available on request at support@rolyio.com.
When you sign in with Google or Microsoft OAuth, we store:
- Your email address, display name, and email domain
- OAuth access and refresh tokens, encrypted at rest with AES-256-GCM
We do not store passwords, because we never receive them.
4.2 Sharing configuration
- Labels you create and share rules you configure (who shares what with whom)
4.3 Sync metadata (not contact content)
- Links: mappings between copies of a contact across accounts. These are identifiers only — they record that “contact X in account A corresponds to contact Y in account B” and do not contain the contact’s content.
- Sync state: provider sync cursors and related bookkeeping needed to keep contacts in sync.
4.4 Audit log
- A log of actions taken in the Service (who did what, and when). Entries are primarily metadata, but action payloads may include contact names (for example, “shared contact Jane Doe with team Sales”).
4.5 Trash (temporary deletion snapshots)
- When a shared contact is deleted, Rolyio temporarily retains a snapshot of the full contact content in a Trash area so that accidental deletions can be recovered. Trash entries are automatically and permanently purged after 30 days.
Through the Google People API and Microsoft Graph API, Rolyio reads and writes contact and directory data in order to perform sharing and synchronization. Except for the Trash snapshots and audit log payloads described above, this data is processed in transit and is not stored in Rolyio’s database.
5. OAuth Scopes We Request and Why
Google
| Scope | Purpose |
|---|
| Contacts (read/write) | Read and write contacts to perform sharing and synchronization |
directory.readonly | Read the Workspace directory to identify teammates for sharing |
admin.directory.user.readonly | Used solely to verify whether the signed-in user is a Workspace administrator |
Microsoft
| Scope | Purpose |
|---|
Contacts.ReadWrite (delegated) | Read and write contacts to perform sharing and synchronization |
Directory.Read.All (delegated) | Read the tenant directory to identify teammates for sharing |
Microsoft 365 organizations may optionally grant tenant-wide admin consent; this is not required for individual use.
We use the information described above only to:
- Provide, operate, and maintain the contact sharing and synchronization features you configure
- Authenticate you and keep your session working (OAuth tokens)
- Show you what happened in your account (audit log)
- Let you recover accidentally deleted contacts (Trash, 30-day TTL)
- Send transactional email such as sharing invitations (via AWS SES)
- Handle billing for paid subscriptions (via Paddle, as merchant of record, once billing is live)
- Respond to support requests
We do not sell personal data, use it for advertising, or use it to train machine learning or AI models.
7. Google API Services User Data Policy — Limited Use Disclosure
Rolyio’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide or improve the user-facing contact sharing and synchronization features that are prominent in Rolyio’s interface. We do not use it for any other purpose.
- We do not transfer Google user data to third parties, except: (a) as necessary to provide or improve those user-facing features (e.g., our hosting infrastructure acting as a processor), (b) as required for security purposes (such as investigating abuse), (c) to comply with applicable law, or (d) as part of a merger, acquisition, or sale of assets after obtaining explicit prior consent from the user.
- We do not sell Google user data.
- We do not use or transfer Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
- We do not use Google user data to train, develop, or improve machine learning or artificial intelligence models, whether generalized or otherwise, and we do not allow third parties to do so.
- Humans do not read Google user data unless: (a) we have your affirmative agreement to view specific data (e.g., for a support request you initiate), (b) it is necessary for security purposes such as investigating abuse, (c) it is necessary to comply with applicable law, or (d) the data has been aggregated and anonymized for internal operations.
We apply the same standards to Microsoft user data accessed via Microsoft Graph.
8. Sharing and Disclosure
We share personal data only with:
- Subprocessors engaged to run the Service, listed in our Subprocessor List (currently: AWS SES for transactional email; Hetzner (Germany/EU) for hosting, planned; Paddle as merchant of record for billing, planned).
- Google and Microsoft, which are not our subprocessors: you have your own direct relationship and agreements with your provider, and your contacts remain hosted by them.
- Authorities, where required by applicable law.
- A successor entity in a merger, acquisition, or asset sale, subject to Section 7 for Google user data.
We do not sell personal data and do not share it with advertisers or data brokers.
9. Data Retention and Deletion
Full details are in our Data Deletion and Retention Policy. In summary:
- Disconnect account: OAuth tokens are deleted immediately.
- Delete account or organization (in-app): users, labels, share rules, links, and sync state are deleted in a cascade.
- Audit log: retained up to 30 days after deletion.
- Backups: retained up to 90 days, then expire.
- Trash: automatically purged after 30 days.
10. Security
- OAuth tokens are encrypted at rest using AES-256-GCM.
- Authentication is delegated entirely to Google and Microsoft OAuth; Rolyio holds no passwords.
- Access to contact data is limited to what is needed to perform the sharing and sync you configure.
No system is perfectly secure, and we do not claim any specific security certification. We will notify affected customers of a personal data breach as required by applicable law.
11. International Transfers
Hosting is planned in Germany (EU) with Hetzner. Some subprocessors (such as AWS SES) may process data in other regions; see the Subprocessor List. Where personal data subject to the GDPR is transferred outside the EEA, we will rely on appropriate safeguards such as adequacy decisions or standard contractual clauses.
12. Your Rights
Depending on your location, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to certain processing.
- For contact data processed on behalf of your organization, please direct requests to your organization (the controller); we will assist them as processor.
- For your Rolyio account data, contact us at support@rolyio.com, or use the in-app disconnect/delete functions described in Section 9.
You can revoke Rolyio’s API access at any time via your Google security settings or Microsoft My Apps. You may also have the right to lodge a complaint with a data protection supervisory authority.
13. Children
Rolyio is a business tool and is not directed to children. We do not knowingly collect personal data from children.
14. Changes to This Policy
We may update this policy from time to time. We will post the updated version at rolyio.com with a revised “Last updated” date and, for material changes, notify account holders by email or in-app notice.
[COMPANY LEGAL NAME / OPERATOR]
[REGISTERED ADDRESS], [JURISDICTION]
Email: support@rolyio.com