OseyroDE
Back to home

Privacy

Privacy policy

This policy explains in plain language which data Oseyro processes and how you can exercise your rights.Last updated: September 2026

1. Controller

The controller under the General Data Protection Regulation is:

Xsigns GmbH & Co. KG · Clärenore-Stinnes-Straße 15 · 27283 Verden (Aller) · Germany

Email: info@xsigns.de · Phone: +49 4231 9033900

2. Visiting this website

When you visit oseyro.com, our hosting system processes technically necessary log data. This may include your IP address, time, requested address, transferred volume, referrer, browser and operating system. We use it to provide a secure and stable website under Art. 6(1)(f) GDPR.

The public website currently uses no analytics or advertising services and sets no marketing cookies. Technically necessary delivery and security functions remain unaffected.

3. Contacting us

If you contact us by email, we process your contact details and message to respond. Depending on your request, the legal basis is Art. 6(1)(b) or (f) GDPR.

4. Using Oseyro

When you use an Oseyro environment, we process account, organization, communication and usage data needed for sign-in, customer service, tasks, calendars, collaboration, security and auditability. The customer operating the environment determines which content is processed. Xsigns generally processes this data on that customer’s documented instructions.

Role-based permissions limit access. Private areas, personal mailboxes and private calendar details are only shown in full to authorized users.

5. Google user data

Connecting Google is optional and is performed individually by each user for their own Google Account. Oseyro only accesses the data shown on the consent screen and required for the feature the user enables.

  • Calendar: calendar lists and selected event title, description, location, attendees, time and status; creation or updates of business events in the expressly selected target calendar.
  • Google Meet: creation of a meeting space only when expressly requested by the user.
  • Google mailbox: when enabled, retrieval and delivery of required email data and related attachments through Google.
  • Account information: technical Google identifier and email address used to bind the connection to the correct user.

6. Use and protection of Google data

Google user data is used solely to provide the calendar, meeting and mailbox features enabled by the user. It is not sold, used for advertising or used to train general-purpose AI models.

OAuth access tokens are purpose-bound, encrypted and stored separately from application content. Data is shared only with contracted infrastructure providers or subprocessors where necessary to provide the selected function and covered by appropriate data protection safeguards. Human access occurs only with authorization, for security, troubleshooting or legal obligations.

Our use of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.

7. Retention and deletion

We retain personal data only while needed for its purpose, the contract, security or legal obligations. The operator of an Oseyro environment may define customer-specific retention periods.

Disconnecting Google ends new access and deletes the associated tokens. Deleting a private personal mailbox removes all mailbox-only private messages, raw data, metadata, drafts, attachments and outgoing messages. Content previously and intentionally transferred into a public ticket area and necessary minimal audit records may remain under applicable retention rules. See “Delete data” for details.

8. Recipients and transfers

We use carefully selected providers for hosting, communications, security and integrations enabled by customers. Required data-processing agreements are in place. Transfers outside the European Economic Area occur only with an appropriate legal basis and safeguards.

9. Your rights

Subject to legal conditions, you may request access, correction, deletion, restriction, portability or object to processing, and withdraw consent for the future. Contact info@xsigns.de.

You may also lodge a complaint with a data protection authority. The competent authority is in particular the State Commissioner for Data Protection of Lower Saxony, Prinzenstraße 5, 30159 Hanover, Germany.

© 2026 Xsigns GmbH & Co. KGinfo@xsigns.de