1. Our commitment
Protecting the data our customers run their business on is core to OSLO. This page summarises how OSLO HQ — which owns and operates the OSLO product and the OSLO Labs brand — handles data under applicable data-protection laws, including the EU/UK GDPR, and complements our Privacy Policy and Terms of Service. It is written for administrators, data protection officers, and procurement teams evaluating OSLO.
2. Controller & processor roles
For data you and your users put into a workspace (“Customer Data”), you are the controller and OSLO HQ is the processor — we process that data only on your documented instructions. For our own website, waitlist, marketing, and account administration, OSLO HQ acts as the controller.
3. Scope of processing
- Subject matter: provision of the OSLO platform and support.
- Duration: for the term of your agreement, plus limited retention as described below.
- Nature & purpose: hosting, storing, and processing Customer Data to deliver the service.
- Data types: business contact details, CRM and finance records, project and people data you choose to store.
- Data subjects: your staff, customers, leads, vendors, and other contacts.
4. Security measures
We apply technical and organisational measures appropriate to the risk, including:
- Encryption of data in transit (TLS) and at rest.
- Role-based access control, granular permissions, and least-privilege administration.
- Audit logging of security-relevant actions.
- Secrets and integration tokens stored encrypted.
- Regular backups, monitoring, and access reviews.
5. Tenant isolation & access
Each workspace's data is logically isolated and scoped to that tenant. Our personnel access Customer Data only where necessary to provide support or maintain the service, under confidentiality obligations and least-privilege controls.
6. Sub-processors
We use a limited set of trusted sub-processors for cloud hosting, database and storage, email delivery, analytics, and payment processing. Each is bound by data-protection terms consistent with this page. We maintain a current list of sub-processors and will provide it, and notice of material changes, on request to the contact below.
7. International transfers
Where Customer Data is transferred outside its region of origin, we rely on appropriate safeguards such as the EU/UK Standard Contractual Clauses and equivalent mechanisms, together with supplementary measures where needed.
8. Data subject requests
Where OSLO HQ acts as processor, we will promptly forward any data subject request we receive to you and, on your instruction, assist you in responding — including through in-product tools to access, correct, export, and delete records. Where we are controller, individuals can exercise their rights as described in the Privacy Policy.
9. Breach notification
We maintain incident-response procedures and will notify affected customers without undue delay after becoming aware of a personal-data breach affecting their Customer Data, providing the information you need to meet your own notification obligations.
10. Retention & deletion
We retain Customer Data for as long as your account is active. On termination you may export your data for a limited period, after which we delete or anonymise it, subject to any retention required by law. You can also delete records within the product at any time.
11. Data Processing Agreement
A Data Processing Agreement (DPA) incorporating the terms summarised here, including the Standard Contractual Clauses where applicable, is available to customers on request. Contact us to execute a DPA for your workspace.
12. Data protection contact
For data-protection questions, sub-processor lists, or to request a DPA, email privacy@getoslo.ai.