FeaturesGovernanceAsk OSLOAboutFAQ
Log inGet Early Access

Legal · Privacy

Privacy Policy

This policy explains what personal data OSLO HQ collects when you use the OSLO platform and getoslo.ai, why we collect it, and the choices and rights you have over it.

Last updated 12 July 2026

On this page

  • 1. Overview
  • 2. Data we collect
  • 3. How we use data
  • 4. Legal bases
  • 5. Sharing & processors
  • 6. Retention
  • 7. Security
  • 8. Your rights
  • 9. International transfers
  • 10. Cookies & analytics
  • 11. Children
  • 12. Changes
  • 13. Contact us

1. Overview

OSLO (“OSLO”, the “platform”) is owned and operated by OSLO HQ(“we”, “us”, “our”), which owns the OSLO product and the OSLO Labs brand. This Privacy Policy applies to the getoslo.ai website, the OSLO application, and related services. It describes how we handle personal data both as a controller (for our own website visitors and account holders) and as a processor (for data our customers put into the platform).

Where we process data on a customer's behalf, that customer is the controller and their own agreement and instructions govern that data. See our Data Protection page for the processing terms.

2. Data we collect

  • Account & profile data — name, work email, phone, company, role, and authentication identifiers when you sign up or are invited to a workspace.
  • Customer content — the records you create in OSLO (leads, contacts, deals, invoices, projects, employees, documents, messages). We process this on your instructions.
  • Usage & device data — log data, IP address, browser and device type, pages viewed, and feature interactions, used to operate and secure the service.
  • Payment data — billing details are handled by our payment processors; we do not store full card numbers.
  • Communications — messages you send to support, waitlist sign-ups, and survey responses.

3. How we use data

  • Provide, maintain, and secure the platform and your account.
  • Authenticate users and enforce roles, approvals, and access controls.
  • Process transactions and send service, security, and billing notices.
  • Improve features, diagnose problems, and prevent fraud and abuse.
  • Respond to support requests and, where permitted, send product updates.

Where OSLO or other automated features act on your data, they operate within the roles, approvals, and guardrails configured by your workspace administrators. We do not use customer content to train third-party foundation models without a lawful basis and your configuration.

4. Legal bases (EEA/UK)

Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to deliver the service); legitimate interests (to secure, improve, and support the platform); consent (for optional marketing and certain cookies); and legal obligation (for tax, accounting, and compliance). You may withdraw consent at any time.

5. Sharing & sub-processors

We do not sell personal data. We share it only with vetted service providers that help us run the platform — cloud hosting, database and storage, email delivery, analytics, and payment processing — under contracts that require appropriate safeguards. We may also disclose data where required by law or to protect our rights and users.

6. Retention

We keep personal data for as long as your account is active and as needed to provide the service, then for the period required to meet legal, tax, and accounting obligations or to resolve disputes. Customer content is deleted or returned in line with your agreement after termination.

7. Security

We use encryption in transit and at rest, role-based access control, tenant isolation, audit logging, and least-privilege access to protect data. No method of transmission or storage is perfectly secure, but we work to protect your information and to notify you of material incidents as required by law.

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, and to object to certain processing. Account holders can manage much of their data in-product. To exercise other rights, contact us using the details below. Where we act as a processor, we will route your request to the relevant customer.

9. International transfers

We may process data in countries other than your own. Where we transfer personal data across borders, we use appropriate safeguards such as Standard Contractual Clauses and equivalent mechanisms.

10. Cookies & analytics

We use strictly necessary cookies to run the site and product, and — with your consent where required — analytics cookies to understand usage. You can control cookies through your browser settings.

11. Children

OSLO is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16.

12. Changes to this policy

We may update this policy from time to time. We will post the revised version here and update the “Last updated” date; material changes will be notified where required.

13. Contact us

Questions about this policy or your data? Email privacy@getoslo.ai, or write to OSLO HQ, Privacy Team. If you are in the EEA/UK and are unsatisfied with our response, you may lodge a complaint with your local data protection authority.

Active by default. Accountable by design.

A product of OSLO Labs.

Product

  • Sales & CRM
  • Finance
  • Projects & Field
  • Reporting
  • Ask OSLO
  • Governance

Legal

  • Privacy Policy
  • Terms of Service
  • Data Protection

© 2026 OSLO HQ. OSLO & the OSLO Labs brand are owned by OSLO HQ.

PrivacyTermsData Protection