Privacy Statement
O27

Contrôle documentaire

Référence
PUB-04-EN
Version
1.0
Statut
approuvé
Dernière mise à jour
2026-08-18
Commit
6cb018d (signature vérifiée)

Table of Contents

French version: Déclaration de confidentialité. The French version prevails in case of divergence.

Purpose

This statement describes the personal data O27 processes, why it processes it, with whom it is shared, how long it is kept, and the rights you have.

It covers O27's websites, the platform it operates and the products that platform carries, in particular Paraphe (shared inbox) and Havre (platform for Belgian out-of-school care operators).

Controller

Item Value
Operator POSTULA CONCEPTIONS SRL
Company number BE 0775.772.346
Registered office Rue des Cyclistes Frontières 16, 4042 Herstal, Belgium
Trading name O27
Data protection contact contact@o27.io

O27 SRL is due to be incorporated in October 2026. The transfer of processing to that entity will be notified in advance.

No data protection officer is appointed to date. The question is reviewed at each annual review of this statement.

Two distinct roles

O27 acts sometimes as controller, sometimes as processor. The distinction determines your rights and whom to address them to.

Role Data concerned
Controller Website visitors, prospects and contacts, user accounts, access logs
Processor Content entrusted by a customer organisation: messages, attachments, contacts, case records

For data processed as a processor, the controller is the customer organisation: your employer, your care operator, or the entity that opened your access. O27 processes that data only on their instructions and forwards any request to them.

Processing as a controller

Processing Data Legal basis Retention
Website visits IP address, user agent, timestamp, requested resource Legitimate interest (security) As set by the logging policy
User accounts Name, work address, role, authentication factors Performance of the contract with the organisation Life of the account, then erasure
Access and security logs Account identifier, timestamp, action, IP address Legitimate interest (security), legal obligation As set by the logging policy
Enquiries and correspondence Name, address, content of the exchange Pre-contractual steps, legitimate interest Duration of the relationship, then limited archiving
Error monitoring Technical trace, account identifier, timestamp Legitimate interest (reliability) As set by the logging policy

No decision producing legal effects is taken on the sole basis of automated processing.

Processing as a processor

Where a customer organisation uses the platform, O27 processes on its behalf:

  • the content of messages synchronised from the connected mailbox: headers, bodies, attachments, threads;
  • the contact details contained in those messages: senders, recipients, signatures;
  • the case records entered in the product concerned, including, for Havre, data relating to minors and their legal guardians.

This data is used only to provide the service. It is not used to train models, and is neither sold, transferred, nor used for advertising or profiling.

Connecting a Google or Microsoft account

Paraphe connects to the mailbox you designate using OAuth 2.0. You authenticate with your provider; O27 neither receives nor stores your password.

Permissions requested

Provider Scope What it allows Why it is requested
Google openid Identifier of the authorising account Bind the connected mailbox to the account that consented
Google email Address of the authorising account Verify that the connected mailbox is the expected one
Google https://mail.google.com/ IMAP and SMTP access to the mailbox, over XOAUTH2 Synchronise messages into the shared inbox and send replies from your address
Microsoft openid, email, profile Identifier, address and principal name Bind and verify the connected mailbox
Microsoft offline_access Refresh token Keep synchronising without prompting for authentication on every cycle
Microsoft https://outlook.office.com/IMAP.AccessAsUser.All IMAP access to the mailbox Synchronise messages into the shared inbox
Microsoft https://outlook.office.com/SMTP.Send SMTP send Send replies from your address

Google offers no narrower scope for IMAP and SMTP access: https://mail.google.com/ is the only one that enables those protocols, and it is a restricted scope. We use it for that purpose alone.

What we do with the data so obtained

Synchronised messages are stored in the customer organisation's space, isolated from the others, to power the features visible on screen: shared inbox, search, threads, assistance in drafting replies.

The content of a message may be submitted to a language model when the user triggers a feature that depends on one. Model providers are qualified beforehand on three points: actual location of processing, commitment not to reuse data for training, retention period for requests on the provider's side. They are listed in the sub-processor register.

OAuth tokens are encrypted under an envelope specific to each customer organisation and are exposed by no interface.

Google Limited Use disclosure

O27's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Withdrawing your authorisation

You may at any time:

  1. disconnect the mailbox from within Paraphe, which deletes the stored tokens and stops synchronisation;
  2. revoke access directly at your provider, at myaccount.google.com/permissions for Google, at myapps.microsoft.com or account.live.com/consent/Manage for Microsoft.

Revocation stops synchronisation. Erasure of messages already synchronised is a matter for the customer organisation, as controller, under the terms of its contract.

Recipients

Data is disclosed only to the providers necessary to operate the service, bound by a processing agreement under Article 28 GDPR.

Provider Role Location
Hetzner Compute, storage, network, object storage Germany
OVH Storage of backup archives, encrypted European Union
Model providers Inference on content, at the user's request See the register

The sub-processor register is kept up to date and provided to customers on request. Any addition or replacement is notified to them before it goes into service.

Your own mail provider is not an O27 sub-processor: the mailbox stays with them, under their contract with you.

Data may also be disclosed to an authority where a legal obligation requires it.

Transfers outside the European Union

Hosting, storage and backups are located in the European Union. No transfer to a third country is in place as at the date of this statement. Should a model provider located outside the Union be retained, the customers concerned would be informed in advance, together with the applicable transfer mechanism.

Retention and erasure

Data Retention
Synchronised messages and attachments While the mailbox is connected, then as set by the customer contract
OAuth tokens Until the mailbox is disconnected or access revoked at the provider
User accounts Life of the account, then erasure
Access and security logs As set by the logging policy
Backup archives Encrypted, purged at the end of their retention cycle

At the end of the contractual relationship, the customer organisation's space is purged, backups included once their cycle expires.

Security

Encryption in transit and at rest, named accounts, multi-factor authentication, separate spaces per customer organisation, access logging, backups whose restoration is exercised.

The full description is provided to customers and prospects on request, at the contact address above. Vulnerabilities are reported to that same address.

Cookies

O27's public websites are static and set no cookies.

The application sets only the cookies necessary for it to work: authenticated session and cross-site request forgery protection. No advertising cookies, no third-party analytics trackers.

Your rights

Under the conditions of Articles 15 to 22 GDPR you have the right of access, rectification, erasure, restriction, objection and portability, and the right to withdraw consent at any time without affecting the lawfulness of processing carried out beforehand.

  • For processing where O27 is the controller, address your request to the contact above. It is answered within one month, extendable by two months where the request is complex.
  • For data processed as a processor, address the customer organisation. A request received by O27 is forwarded to them without delay.

You may lodge a complaint with the Belgian Data Protection Authority, Rue de la Presse 35, 1000 Brussels, dataprotectionauthority.be.

Changes to this statement

Any substantial change is communicated to customer organisations before it takes effect. The date of last update and the corresponding commit appear in the document control block of this page.