1. Overview
OSLO (“OSLO”, the “platform”) is owned and operated by OSLO HQ(“we”, “us”, “our”), which owns the OSLO product and the OSLO Labs brand. This Privacy Policy applies to the getoslo.ai website, the OSLO application, and related services. It describes how we handle personal data both as a controller (for our own website visitors and account holders) and as a processor (for data our customers put into the platform).
Where we process data on a customer's behalf, that customer is the controller and their own agreement and instructions govern that data. See our Data Protection page for the processing terms.
2. Data we collect
- Account & profile data - name, work email, phone, company, role, and authentication identifiers when you sign up or are invited to a workspace.
- Customer content - the records you create in OSLO (leads, contacts, deals, invoices, projects, employees, documents, messages). We process this on your instructions.
- Data from connected integrations - when a customer connects a service such as Meta Lead Ads, we receive the data that service sends for that customer, such as lead form submissions. See section 6.
- Usage & device data - log data, IP address, browser and device type, pages viewed, and feature interactions, used to operate and secure the service.
- Payment data - billing details are handled by our payment processors; we do not store full card numbers.
- Communications - messages you send to support, waitlist sign-ups, and survey responses.
3. How we use data
- Provide, maintain, and secure the platform and your account.
- Authenticate users and enforce roles, approvals, and access controls.
- Process transactions and send service, security, and billing notices.
- Improve features, diagnose problems, and prevent fraud and abuse.
- Respond to support requests and, where permitted, send product updates.
Where OSLO or other automated features act on your data, they operate within the roles, approvals, and guardrails configured by your workspace administrators. We do not use customer content to train third-party foundation models without a lawful basis and your configuration.
4. Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to deliver the service); legitimate interests (to secure, improve, and support the platform); consent (for optional marketing and certain cookies); and legal obligation (for tax, accounting, and compliance). You may withdraw consent at any time.
6. Meta Lead Ads
OSLO can connect to a customer's Facebook Page so that people who fill in that customer's lead ad forms on Facebook or Instagram appear as leads in the customer's OSLO CRM. In this case the customer (the advertiser) is the controller of the lead data and OSLO processes it on their behalf, as an advertiser-authorised CRM platform.
How a connection is made.A workspace owner or admin clicks “Continue with Facebook” in Settings → Integrations, logs in with Facebook, and grants permission. They then choose which Pages to connect and which lead forms to import. OSLO only retrieves leads from the Pages and forms they choose.
What we receive from Meta.
- The answers a person enters in the advertiser's lead form, such as name, email, phone number, city, and any custom questions the advertiser asked.
- The time the form was submitted.
- The form, ad, ad set and campaign the lead came from.
- The names and IDs of the Pages and lead forms the admin manages, so they can choose what to connect.
- An access token for each connected Page, so we can retrieve new leads. Tokens are encrypted and are never shown to users.
How it is used.Each lead is saved in that advertiser's workspace, assigned to one of their team members, and used so their team can contact the person about the product or service they asked about. Only members of that workspace can see it, according to the roles the advertiser sets. Other OSLO customers can never see it.
What we never do with it.We do not sell lead data. We do not use it for our own marketing or advertising, combine it across customers, use it to build profiles, or use it to train AI models. If the advertiser uses OSLO's AI features on their own leads, the data is processed only to answer that advertiser's request, through the service providers described in section 5.
Retention and deletion.The advertiser can click Disconnect in Settings → Integrations at any time. This immediately stops OSLO retrieving leads and deletes the stored access tokens. Leads already imported are kept as the advertiser's business records until the advertiser deletes them or their account ends, after which they are deleted as described in section 7. You can also remove OSLO from your Facebook account under Settings → Apps and Websites.
If you filled in a lead form. Your details are held for the business whose ad you responded to, so please contact that business first. You can also email privacy@getoslo.ai to ask us to delete your data. We will pass your request to that business and help them carry it out.
7. Retention
We keep personal data for as long as your account is active and as needed to provide the service, then for the period required to meet legal, tax, and accounting obligations or to resolve disputes. Customer content is deleted or returned in line with your agreement after termination.
8. Security
We use encryption in transit and at rest, role-based access control, tenant isolation, audit logging, and least-privilege access to protect data. No method of transmission or storage is perfectly secure, but we work to protect your information and to notify you of material incidents as required by law.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, and to object to certain processing. Account holders can manage much of their data in-product. To exercise other rights, contact us using the details below. Where we act as a processor, we will route your request to the relevant customer.
10. International transfers
We may process data in countries other than your own. Where we transfer personal data across borders, we use appropriate safeguards such as Standard Contractual Clauses and equivalent mechanisms.
12. Children
OSLO is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16.
13. Changes to this policy
We may update this policy from time to time. We will post the revised version here and update the “Last updated” date; material changes will be notified where required.
14. Contact us
Questions about this policy or your data? Email privacy@getoslo.ai, or write to OSLO HQ, Privacy Team. If you are in the EEA/UK and are unsatisfied with our response, you may lodge a complaint with your local data protection authority.