Privacy Statement
O27
Contrôle documentaire
- Référence
- PUB-04-EN
- Version
- 1.0
- Statut
- approuvé
- Dernière mise à jour
- 2026-08-18
- Commit
6cb018d(signature vérifiée)
Table of Contents
French version: Déclaration de confidentialité. The French version prevails in case of divergence.
Purpose
This statement describes the personal data O27 processes, why it processes it, with whom it is shared, how long it is kept, and the rights you have.
It covers O27's websites, the platform it operates and the products that platform carries, in particular Paraphe (shared inbox) and Havre (platform for Belgian out-of-school care operators).
Controller
| Item | Value |
|---|---|
| Operator | POSTULA CONCEPTIONS SRL |
| Company number | BE 0775.772.346 |
| Registered office | Rue des Cyclistes Frontières 16, 4042 Herstal, Belgium |
| Trading name | O27 |
| Data protection contact | contact@o27.io |
O27 SRL is due to be incorporated in October 2026. The transfer of processing to that entity will be notified in advance.
No data protection officer is appointed to date. The question is reviewed at each annual review of this statement.
Two distinct roles
O27 acts sometimes as controller, sometimes as processor. The distinction determines your rights and whom to address them to.
| Role | Data concerned |
|---|---|
| Controller | Website visitors, prospects and contacts, user accounts, access logs |
| Processor | Content entrusted by a customer organisation: messages, attachments, contacts, case records |
For data processed as a processor, the controller is the customer organisation: your employer, your care operator, or the entity that opened your access. O27 processes that data only on their instructions and forwards any request to them.
Processing as a controller
| Processing | Data | Legal basis | Retention |
|---|---|---|---|
| Website visits | IP address, user agent, timestamp, requested resource | Legitimate interest (security) | As set by the logging policy |
| User accounts | Name, work address, role, authentication factors | Performance of the contract with the organisation | Life of the account, then erasure |
| Access and security logs | Account identifier, timestamp, action, IP address | Legitimate interest (security), legal obligation | As set by the logging policy |
| Enquiries and correspondence | Name, address, content of the exchange | Pre-contractual steps, legitimate interest | Duration of the relationship, then limited archiving |
| Error monitoring | Technical trace, account identifier, timestamp | Legitimate interest (reliability) | As set by the logging policy |
No decision producing legal effects is taken on the sole basis of automated processing.
Processing as a processor
Where a customer organisation uses the platform, O27 processes on its behalf:
- the content of messages synchronised from the connected mailbox: headers, bodies, attachments, threads;
- the contact details contained in those messages: senders, recipients, signatures;
- the case records entered in the product concerned, including, for Havre, data relating to minors and their legal guardians.
This data is used only to provide the service. It is not used to train models, and is neither sold, transferred, nor used for advertising or profiling.
Connecting a Google or Microsoft account
Paraphe connects to the mailbox you designate using OAuth 2.0. You authenticate with your provider; O27 neither receives nor stores your password.
Permissions requested
| Provider | Scope | What it allows | Why it is requested |
|---|---|---|---|
openid |
Identifier of the authorising account | Bind the connected mailbox to the account that consented | |
email |
Address of the authorising account | Verify that the connected mailbox is the expected one | |
https://mail.google.com/ |
IMAP and SMTP access to the mailbox, over XOAUTH2 | Synchronise messages into the shared inbox and send replies from your address | |
| Microsoft | openid, email, profile |
Identifier, address and principal name | Bind and verify the connected mailbox |
| Microsoft | offline_access |
Refresh token | Keep synchronising without prompting for authentication on every cycle |
| Microsoft | https://outlook.office.com/IMAP.AccessAsUser.All |
IMAP access to the mailbox | Synchronise messages into the shared inbox |
| Microsoft | https://outlook.office.com/SMTP.Send |
SMTP send | Send replies from your address |
Google offers no narrower scope for IMAP and SMTP access:
https://mail.google.com/ is the only one that enables those protocols, and it
is a restricted scope. We use it for that purpose alone.
What we do with the data so obtained
Synchronised messages are stored in the customer organisation's space, isolated from the others, to power the features visible on screen: shared inbox, search, threads, assistance in drafting replies.
The content of a message may be submitted to a language model when the user triggers a feature that depends on one. Model providers are qualified beforehand on three points: actual location of processing, commitment not to reuse data for training, retention period for requests on the provider's side. They are listed in the sub-processor register.
OAuth tokens are encrypted under an envelope specific to each customer organisation and are exposed by no interface.
Google Limited Use disclosure
O27's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Withdrawing your authorisation
You may at any time:
- disconnect the mailbox from within Paraphe, which deletes the stored tokens and stops synchronisation;
- revoke access directly at your provider, at myaccount.google.com/permissions for Google, at myapps.microsoft.com or account.live.com/consent/Manage for Microsoft.
Revocation stops synchronisation. Erasure of messages already synchronised is a matter for the customer organisation, as controller, under the terms of its contract.
Recipients
Data is disclosed only to the providers necessary to operate the service, bound by a processing agreement under Article 28 GDPR.
| Provider | Role | Location |
|---|---|---|
| Hetzner | Compute, storage, network, object storage | Germany |
| OVH | Storage of backup archives, encrypted | European Union |
| Model providers | Inference on content, at the user's request | See the register |
The sub-processor register is kept up to date and provided to customers on request. Any addition or replacement is notified to them before it goes into service.
Your own mail provider is not an O27 sub-processor: the mailbox stays with them, under their contract with you.
Data may also be disclosed to an authority where a legal obligation requires it.
Transfers outside the European Union
Hosting, storage and backups are located in the European Union. No transfer to a third country is in place as at the date of this statement. Should a model provider located outside the Union be retained, the customers concerned would be informed in advance, together with the applicable transfer mechanism.
Retention and erasure
| Data | Retention |
|---|---|
| Synchronised messages and attachments | While the mailbox is connected, then as set by the customer contract |
| OAuth tokens | Until the mailbox is disconnected or access revoked at the provider |
| User accounts | Life of the account, then erasure |
| Access and security logs | As set by the logging policy |
| Backup archives | Encrypted, purged at the end of their retention cycle |
At the end of the contractual relationship, the customer organisation's space is purged, backups included once their cycle expires.
Security
Encryption in transit and at rest, named accounts, multi-factor authentication, separate spaces per customer organisation, access logging, backups whose restoration is exercised.
The full description is provided to customers and prospects on request, at the contact address above. Vulnerabilities are reported to that same address.
Cookies
O27's public websites are static and set no cookies.
The application sets only the cookies necessary for it to work: authenticated session and cross-site request forgery protection. No advertising cookies, no third-party analytics trackers.
Your rights
Under the conditions of Articles 15 to 22 GDPR you have the right of access, rectification, erasure, restriction, objection and portability, and the right to withdraw consent at any time without affecting the lawfulness of processing carried out beforehand.
- For processing where O27 is the controller, address your request to the contact above. It is answered within one month, extendable by two months where the request is complex.
- For data processed as a processor, address the customer organisation. A request received by O27 is forwarded to them without delay.
You may lodge a complaint with the Belgian Data Protection Authority, Rue de la Presse 35, 1000 Brussels, dataprotectionauthority.be.
Changes to this statement
Any substantial change is communicated to customer organisations before it takes effect. The date of last update and the corresponding commit appear in the document control block of this page.