Google API User Data Use
Actovian is operated by Miloš Topić, an individual service provider based in the Republic of Serbia. Contact: office@actovian.com. This English version is the controlling version.
This disclosure supplements the Actovian Privacy Policy for customers who choose to connect Google Workspace. Google connection is optional and controlled by a workspace owner.
1. Data Actovian accesses
- Basic identity: the email address of the connected Google account so the owner can verify the connection.
- Gmail read-only data: messages, message metadata and incremental history needed to synchronize customer-authorised business context.
- Gmail compose data: draft content and draft identifiers required to create a human-approved draft. Actovian does not enable automatic sending.
- Calendar event data: events, attendees, dates, descriptions and incremental synchronization state needed to read or create an approved event.
2. How the data is used
Google data is used only to provide visible customer-requested features: synchronizing business context, preparing AI-assisted internal work, creating a Gmail draft after exact human approval, creating an approved Calendar event, showing provider evidence and maintaining integration reliability.
3. Sharing and prohibited uses
Google user data is shared only with infrastructure and AI subprocessors when necessary to provide the requested Actovian feature, under contractual and security controls. It is not sold, used for advertising, used to determine creditworthiness, or used to train general-purpose AI models by Actovian. Human access is limited to security, support or legal needs and only when necessary and appropriately authorised.
Actovian's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
4. Storage and protection
OAuth access and refresh tokens are encrypted before database storage and are never exposed to browser code. Synchronized payloads and cursors are encrypted where designed, tenant-scoped and accessible only to authorised workspace members and protected workers. Provider actions require an unchanged payload hash, an appropriate approval and stored provider evidence.
5. Retention, revocation and deletion
A workspace owner may disconnect Google from the Integrations page. Actovian then attempts provider revocation and removes stored local credentials and synchronization state. Synchronized Gmail and Calendar resource data is retained for no more than 90 days on a rolling basis unless the customer deletes the workspace or requests earlier deletion, subject to narrowly required security and legal records. Users may also revoke access from their Google Account permissions page.
6. Questions
Questions, access requests and deletion requests may be sent to office@actovian.com.