Privacy Policy for ExSign for Google Workspace

Last Updated: 7 September 2026

Hosting Controller Inc. ("we," "our," "us") is committed to protecting the privacy and personal data of users of ExSign for Google Workspace ("ExSign," "Service"). This Privacy Policy explains how we collect, use, store, and protect personal data in compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679, Google Workspace API User Data Policy requirements, and other applicable data protection laws.

Please read this Privacy Policy before using our Services or providing us with any information or data. If you do not agree to the terms of this Privacy Policy, please discontinue use of our Services and immediately leave our website. Please note that if you do not consent to this Privacy Policy or withdraw your consent, you may not be able to access our Services, as the processing of Personal Information related to you as described in this Privacy Policy is necessary for the performance of our contract with you and for our legitimate business purposes.

Data Controller and Data Processor Roles

Customers (you) act as the Data Controller, determining the purposes and means of processing personal data within ExSign.

Hosting Controller Inc. acts as the Data Processor, processing data on your behalf in accordance with your instructions and the Data Processing Agreement (DPA). We process data only as instructed and maintain appropriate technical and organizational measures to ensure data security.

A copy of our Data Processing Agreement is available upon request. The DPA incorporates Standard Contractual Clauses (SCCs) and all necessary GDPR compliance requirements. To request a copy, contact our Data Protection Officer at dpo@hostingcontroller.com.

Data Protection Officer

Hosting Controller Inc. has appointed a Data Protection Officer (DPO) to oversee compliance with this Privacy Policy and applicable data protection law. You may contact our DPO directly with any questions, concerns, requests, or data subject rights related to the processing of personal data:

DPO Name: [Insert DPO Name]
Email: [Insert DPO Email, e.g., dpo@hostingcontroller.com]
Postal Address: [Insert Registered Business Address]

What Information Do We Collect?

ExSign for Google Workspace connects to your organization's Gmail accounts (via the Gmail API and/or Google Workspace Admin SDK, as authorized by your Google Workspace administrator) to apply rule-based email signatures on a server-side basis.

Data Collection Categories

Non-Sensitive Scopes

  • Primary Google Account email address
  • Personal info
  • Association through personal info on Google

Sensitive Scopes

  • Info about users on your domain
  • Domains related to your customers
  • Groups on your domain
  • Group subscriptions on your domain
  • Organization units on your domain

What We DO NOT Collect or Access

We are transparent about what we explicitly do NOT access or store:

  • We DO NOT store or handle email account passwords
  • We DO NOT process or store email attachments
  • We DO NOT track who users email or when they email
  • We DO NOT track your browsing activity outside of our service

Scope Authorization

We access data only through the OAuth scopes and permissions explicitly authorized by your Google Workspace administrator during installation and configuration of ExSign, consistent with Google's API User Data Policy, including its Limited Use requirements.

Your administrator can view and manage these permissions at any time through the Google Workspace Admin Console.

Purpose and Legal Basis of Processing

Processing Purposes

We process Personal Information solely for the following purposes:

  • Primary Service Delivery: To generate and apply email signatures and disclaimers to outgoing Gmail messages as configured
  • Dynamic Fields: To read directory attributes (where authorized) to populate dynamic signature fields (name, title, department, etc.)
  • Service Maintenance: To provide, maintain, and improve ExSign services
  • Security and Compliance: To ensure system security, fraud prevention, and compliance with legal obligations
  • Customer Support: To provide customer support and resolve technical issues
  • Service Improvement: To analyze aggregated, non-identifying data to improve service reliability
  • Billing and Accounting: To process billing and maintain financial records

Legal Basis for Processing (Article 6 GDPR)

1. Performance of Contract (Article 6(1)(b) GDPR)

Applicable to: Core service delivery, signature application, dynamic field population

Description: Processing is necessary to perform our contract with you to provide the ExSign service. Without this data, we cannot apply signatures to your emails as configured.

Data involved:

  • Email addresses
  • User profile data (name, title, department, location)
  • Organization unit information
  • OAuth tokens for Gmail API access

2. Legitimate Interests (Article 6(1)(f) GDPR)

Applicable to: Security, fraud prevention, service improvement, analytics

We process personal data based on legitimate business interests, which we have carefully balanced against your privacy rights.

Service Security and Fraud Prevention:

  • We need to detect unauthorized access and prevent API abuse
  • Data is minimized (no personal content, only technical identifiers)
  • Processing is limited to what's necessary for security
  • Retention: 90 days

Service Reliability and Optimization:

  • We analyze aggregated, non-identifying data to improve performance
  • Individual users are not profiled
  • Results directly improve service quality for all customers

3. Legal Obligation (Article 6(1)(c) GDPR)

Applicable to: Billing records, compliance records, data subject requests

Specific Legal Obligations:

  • Tax laws (require retention of billing/transaction records for 7 years)
  • Data protection law compliance
  • Google Workspace API terms (require audit trail of data access)
  • Telecommunications regulations (where applicable)

No Advertising, No Data Sales

We explicitly commit that:

  • We DO NOT use data obtained through Google Workspace APIs to serve advertisements
  • We DO NOT sell, rent, or trade personal data with third parties
  • We DO NOT transfer data to third parties for purposes unrelated to the ExSign service
  • We comply fully with Google's API Services User Data Policy, including Limited Use requirements

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected.

Retention Schedule by Category

Data CategoryDurationReason
Account and Service DataDuration of service + 90 daysService recovery window
OAuth Tokens and API CredentialsWhile service is active; deleted immediately upon terminationSecurity requirement
Security and Access Logs90 daysSecurity monitoring
Error and Technical Logs90 daysTroubleshooting and improvement
Billing and Transaction Records7 yearsTax law requirement
System BackupsUntil deleted; permanently deleted within 90 days of terminationDisaster recovery

Deletion Procedures

Upon Account Termination:

  • Day 1: Soft delete — data marked for deletion, inaccessible to users
  • Within 90 days: Permanent delete — all data permanently removed from live systems
  • Backup deletion: All backup copies deleted within 90 days

Data Sharing and Subprocessors

We do not share personal data with third parties except as necessary to provide the ExSign service or as required by law.

Subprocessors (Data Processors)

We use the following subprocessors to securely process and host data. All subprocessors are bound by Data Processing Agreements incorporating GDPR requirements and Standard Contractual Clauses.

SubprocessorPurposeLocationSafeguards
Google Cloud PlatformCloud hosting, data processing, infrastructureNorth America (USA)Google's Data Processing Amendment
Microsoft AzureBackup and disaster recovery (if applicable)North America (USA)Microsoft Data Protection Agreement

No Data Sales or Sharing

We explicitly do NOT:

  • Sell personal data to third parties
  • Rent personal data to third parties
  • Trade personal data with third parties
  • Share data for marketing purposes
  • Share data for advertising purposes

International Data Transfers

Where Data is Stored

Your data may be transmitted between the service components of ExSign as necessary for the provision of the Services. Such transfers are strictly limited to internal communication between ExSign service components and are never transferred, disclosed, or made accessible outside of the ExSign service infrastructure.

Legal Mechanisms for Transfers

Where Customer Data is transferred outside the EEA/UK, Hosting Controller relies on one or more of the following legal mechanisms to ensure an adequate level of protection, as required by GDPR Chapter V (Articles 44-50):

Standard Contractual Clauses (SCCs)

  • European Commission-approved contractual terms (2021/914)
  • Incorporated into our Data Processing Agreement with customers
  • Remain valid and enforceable

UK International Data Transfer Addendum

  • Supplementary terms required for transfers subject to UK GDPR
  • Issued by the UK Information Commissioner's Office (ICO)
  • Included in our DPA for UK-based customers

Adequacy Decisions (Article 45 GDPR)

  • European Commission decisions that certain countries provide adequate protection
  • Example: EU-U.S. Data Privacy Framework certification

Your Rights Regarding Transfers

You have the right to:

  • Request details about transfer safeguards
  • Request a copy of applicable SCCs or other mechanisms
  • Lodge a complaint if you believe transfers are inadequate

Security of Personal Information

We implement comprehensive technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction.

Technical Security Measures

Encryption in Transit

  • TLS 1.2 or higher for all data transmitted over networks
  • All API connections use HTTPS with strong cipher suites
  • End-to-end encryption for sensitive authentication data

Encryption at Rest

  • AES-256 encryption for data stored in databases
  • Encrypted backup storage
  • Encrypted log storage

Access Control

  • Role-Based Access Control (RBAC) to limit data access
  • Multi-Factor Authentication (MFA) required for administrative access
  • Principle of least privilege: users access only necessary data

API Security

  • OAuth 2.0 for secure authentication with Google Workspace
  • Secure storage and rotation of API credentials
  • Immediate revocation of tokens upon account termination

Organizational Measures

  • Annual privacy and data protection training for all staff
  • Confidentiality agreements for all employees
  • All administrative access logged and monitored
  • Annual third-party security audits
  • Penetration testing by qualified security firms
  • Regular backup testing and recovery drills
  • Firewall protection and network segmentation

Your Data Subject Rights

You have the following rights under GDPR. Below is an explanation of each right and how to exercise it.

How to Submit a Request

  • Email: dpo@hostingcontroller.com
  • Subject: Data Subject Rights Request - [Type of Request]
  • Include: Your full name, email address, type of request, and identity verification (last 4 of ID)

Response Timeline

PhaseTimelineWhat We Do
AcknowledgmentWithin 5 business daysConfirm receipt and provide reference number
Substantive ResponseWithin 30 calendar daysProvide complete information or take action
Extension (if needed)Up to 90 days totalFor complex or voluminous requests

Cost: FREE (we charge no fee for data subject requests)

Right 1: Right of Access (Article 15 GDPR)

What this means: You can obtain a copy of all personal data we hold about you.

What you'll receive:

  • Complete copy of all personal data we hold
  • The purposes of processing
  • The categories of data
  • Retention period

Response format: CSV, JSON, or PDF (your choice)
Cost: Free

Right 2: Right to Rectification (Article 16 GDPR)

What this means: You can correct inaccurate or incomplete personal data.

Examples:

  • Email address is misspelled
  • Department/title information is out of date
  • Organization name is incorrect

Our response: Within 30 calendar days, we'll update your data and confirm the change
Cost: Free

Right 3: Right to Erasure (Article 17 GDPR)

What this means: You can request deletion of your personal data under specific circumstances.

When you have this right:

  • The data is no longer necessary for its purpose
  • You withdraw consent with no other legal basis
  • The data was unlawfully processed

When we CANNOT erase (exceptions):

  • The data is necessary to fulfill our contract (you'd need to terminate service)
  • Tax laws require keeping records for 7 years
  • Legal claims require the data

Deletion timeline: Immediate soft delete, permanent delete within 90 days

Right 4: Right to Restrict Processing (Article 18 GDPR)

What this means: You can ask us to limit how we use your data (stored but not processed).

When you can use this:

  • You contest accuracy of data (while we investigate)
  • You object to processing (pending investigation)

Response timeline: Within 30 calendar days

Right 5: Right to Data Portability (Article 20 GDPR)

What this means: You can receive your data in a machine-readable format.

What data you can request:

  • Account information (name, email, organization)
  • Your configuration and preferences
  • Service usage data

Response format: CSV, JSON, or XML (your choice)
Cost: Free

Right 6: Right to Object (Article 21 GDPR)

What this means: You can object to processing based on legitimate interests or direct marketing.

Object to Legitimate Interest Processing:
Email: dpo@hostingcontroller.com | Subject: Data Subject Rights Request - Right to Object

Object to Direct Marketing:
Email: privacy@hostingcontroller.com or click "Unsubscribe" in any marketing email

Response timeline: Within 30 calendar days (or within 10 business days for marketing)

Right 7: Right to Lodge a Complaint (Article 77 GDPR)

What this means: You can lodge a complaint with a data protection authority.

Before complaining to an authority: We recommend contacting our DPO first to resolve the issue (give us 30 days).

Our Lead Supervisory Authority:

Authority: [INSERT AUTHORITY NAME]
Email: [INSERT EMAIL]
Phone: [INSERT PHONE]
Website: [INSERT WEBSITE]

Your Local Authority: You also have the right to complain to your local supervisory authority.
Cost: FREE (filing a complaint is always free)

Data Breach Notification

Hosting Controller Inc. is committed to protecting your data. In the unlikely event of a confirmed personal data breach, we follow strict procedures to notify all relevant parties.

Our Commitment

In case of a data breach, we will:

  • Notify supervisory authorities within 72 hours (GDPR requirement)
  • Notify affected individuals without undue delay
  • Investigate the breach thoroughly
  • Implement corrective measures
  • Provide transparent communication

Breach Notification Timeline

  • Immediate (24 hours): Activate incident response team, contain the breach
  • 72 hours: Notify supervisory authority
  • Without undue delay: Notify affected individuals (if high risk)
  • Ongoing: Investigation and remediation

Report a Breach

If you become aware of a potential data breach, please contact us immediately:

Email: security@hostingcontroller.com
Phone: +1 (647) 799-1000
Subject: Data Breach Report

Cookies and Tracking Technologies

Our Cookie Policy

By default, we only use cookies that are strictly necessary for the proper functioning of our services. Necessary cookies do not require consent under GDPR.

Cookie Categories

Essential Cookies (No Consent Required)

  • Session tokens (keep you logged in)
  • CSRF protection (prevent cross-site attacks)
  • Security credentials

Functional Cookies (Consent Required)

  • Language preference
  • Interface theme (light/dark mode)
  • Display settings

Your Cookie Rights

You have the right to:

  • Refuse non-essential cookies
  • Withdraw consent for functional cookies
  • Delete cookies from your device
  • Control cookies through browser settings

Important Statement

We DO NOT use:

  • Third-party cookies for tracking or advertising
  • Web beacons or pixel tags
  • Cross-site tracking
  • Fingerprinting
  • Behavioral tracking for marketing

Supervisory Authority for Complaints

Hosting Controller Inc. operates under the supervision of the following data protection authority:

Authority: [INSERT ACTUAL AUTHORITY NAME]
Country: [INSERT COUNTRY]
Email: [INSERT EMAIL]
Phone: [INSERT PHONE]
Website: [INSERT WEBSITE]
Address: [INSERT ADDRESS]

How to File a Complaint

Before filing: We recommend contacting our DPO first to resolve the issue (give us 30 days).

If unsatisfied, you can file a formal complaint with the supervisory authority with:

  • Your name and contact information
  • Description of the alleged violation
  • How your rights were affected
  • Dates and timeline of events
  • Evidence or documentation

Cost: FREE — Filing a complaint is always free

Other Supervisory Authorities

You have the right to lodge a complaint with any supervisory authority in the country where you reside, work, or where the alleged violation occurred.

If you are in the EU: Find your Member State's data protection authority via the European Data Protection Board at https://edpb.europa.eu.

If you are in the UK:

Information Commissioner's Office (ICO)
Water Lane, Walsall, WS2 9NF, United Kingdom
Email: icocasework@ico.org.uk
Phone: +44 (0)303 123 1113
Website: https://ico.org.uk

Our Privacy Commitment

At Hosting Controller Inc., we believe privacy is a fundamental right. We are committed to:

  • Transparency in how we process data
  • Respecting your rights under GDPR and other applicable laws
  • Protecting your data with strong security measures
  • Limiting data collection to what's necessary
  • Being honest about how your data is used
  • Responding promptly to your requests
  • Cooperating with supervisory authorities
  • Continuously improving our privacy practices

If you have concerns or questions about our privacy practices, please contact our Data Protection Officer. We value your trust and are committed to maintaining it.

We may update this Privacy Policy to reflect service improvements, legal requirements, or other factors. Updates will be posted on our website with a revised "Last Updated" date.

Contact Information

Data Protection Officer
Email: dpo@hostingcontroller.com
Phone: [INSERT PHONE]
Address: [INSERT ADDRESS]
Response Time: Within 30 business days

General Privacy Inquiries
Email: sales@hostingcontroller.com
Phone: +1 (647) 799-1000
Website: https://hostingcontroller.com

Security Issues
Email: security@hostingcontroller.com
Phone: +1 (647) 799-1000
Available 24/7 for security incidents