Privacy Policy for ExSign for Google Workspace
Last Updated: 12 August 2026
Hosting Controller Inc. ("we," "our," "us") is committed to protecting the privacy and personal data of users of ExSign for Google Workspace ("ExSign"). This Privacy Policy explains how we collect, use, store, and protect personal data in compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679, Google Workspace API User Data Policy requirements, and other applicable data protection laws.
Please read this Privacy Policy before using our Services or providing us with any information or data. If you do not agree to the terms of this Privacy Policy, please discontinue use of our Services and immediately leave our website. Please note that if you do not consent to this Privacy Policy or withdraw your consent, you may not be able to access our Services, as the processing of Personal Information related to you as described in this Privacy Policy is necessary for the performance of our contract with you and for our legitimate business purposes.
Data Controller and Data Processor Roles
Customers (you) act as the Data Controller, determining the purposes and means of processing personal data within ExSign.
Hosting Controller Inc. acts as the Data Processor, processing data on your behalf in accordance with your instructions and the Data Processing Agreement (DPA).
Data Protection Officer. Hosting Controller Inc. has appointed a Data Protection Officer (DPO) to oversee compliance with this Privacy Policy and applicable data protection law. You may contact our DPO directly with any questions, concerns, or requests relating to the processing of personal data:
DPO Name: [Insert DPO Name]
Email: [Insert DPO Email, e.g., dpo@hostingcontroller.com]
Postal Address: [Insert Registered Business Address]
What Information Do We Collect?
ExSign for Google Workspace connects to your organization's Gmail accounts (via the Gmail API and/or Google Workspace Admin SDK, as authorized by your Google Workspace administrator) to apply rule-based email signatures on a server-side basis. In doing so, we may collect and store personal data about you (referred to throughout this privacy policy as Personal Information). The Personal Information we collect includes the following categories:
Non-Sensitive Scopes
- Primary Google Account email address
- Personal info
- Association through personal info on Google
Sensitive Scopes
- Info about users on your domain
- Domains related to your customers
- Groups on your domain
- Group subscriptions on your domain
- Organization units on your domain
We access this data only through the OAuth scopes and permissions explicitly authorized by your Google Workspace administrator during installation and configuration of ExSign, consistent with Google's API User Data Policy, including its Limited Use requirements.
Purpose and Legal Basis of Processing
We process Personal Information solely for the following purposes:
- To generate and apply email signatures and disclaimers to outgoing Gmail messages in line with your configuration.
- To read directory attributes (where authorized) to populate dynamic signature fields.
- To provide, maintain, and improve ExSign services.
- To ensure system security, fraud prevention, and compliance with legal obligations.
- To provide customer support and resolve technical issues.
The legal basis for processing includes:
- Performance of Contract (Art. 6(1)(b) GDPR): delivering the ExSign service.
- Legitimate Interests (Art. 6(1)(f) GDPR): ensuring service reliability, fraud prevention, and security.
- Legal Obligations (Art. 6(1)(c) GDPR): compliance with applicable regulations.
We do not use data obtained through Google Workspace APIs to serve advertisements, and we do not sell such data or transfer it to third parties for purposes unrelated to providing and improving the ExSign signature service, consistent with Google's API Services User Data Policy.
Data Retention
- Customer data is retained for 90 days after service termination, after which it is securely deleted.
- If a customer deletes their tenant or disconnects their Google Workspace domain from ExSign, an instant (soft) delete is performed, followed by permanent deletion within the timeframe stated above.
- System and security logs may be retained for a limited period (as required for compliance and auditing).
- Google account authorization (OAuth tokens) will be revoked and deleted promptly upon disconnection of the Google Workspace domain or termination of service.
Data Sharing and Subprocessors
We may engage trusted subprocessors (such as Google Cloud Platform and/or Microsoft Azure, depending on hosting configuration) to host and process data securely. Subprocessors are bound by contractual agreements ensuring GDPR compliance.
We do not sell, rent, or trade personal data with third parties. Data is only shared when required by law or with your explicit consent. Our access to and use of data obtained from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, meaning such data is used only to provide or improve the ExSign email signature feature visible to users, and is not used to serve ads or shared for purposes unrelated to the ExSign service.
International Data Transfers
In the course of providing the ExSign service for Google Workspace, Customer Data may be transmitted solely between the service components of ExSign, as necessary for the provision of the Services. Such transfers are strictly limited to internal communication between ExSign service components and shall never be transferred, disclosed, or made accessible outside of the ExSign service infrastructure, regardless of circumstance or reason.
The components of the ExSign cloud service may reside in diverse geographical regions, including regions outside of the European Economic Area (EEA) and the United Kingdom (e.g., North America). Where Customer Data is transferred outside the EEA/UK, Hosting Controller relies on one or more of the following legal mechanisms to ensure an adequate level of protection, as required by Chapter V of the GDPR:
- Standard Contractual Clauses (SCCs): the European Commission-approved SCCs (2021/914), incorporated into our Data Processing Agreement with customers and, where applicable, into our agreements with subprocessors.
- UK International Data Transfer Addendum: for transfers subject to UK GDPR, incorporating the UK Addendum to the EU SCCs issued by the UK Information Commissioner's Office.
- Adequacy Decisions: where the European Commission has recognized the destination country or an approved certification framework (e.g., the EU-U.S. Data Privacy Framework, where the receiving party is certified) as providing an adequate level of protection.
A copy of the relevant transfer mechanism/safeguards can be requested by contacting our DPO using the details provided above. Hosting Controller shall implement and maintain appropriate technical and organizational measures to ensure that all such transfers are secure, controlled, and fully compliant with applicable data protection legislation, including the GDPR and, where applicable, the UK GDPR and the Data (Use and Access) Act 2025.
Security of Personal Information
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction, including:
- Data encryption in transit and at rest.
- Role-based access control.
- Secure storage and handling of OAuth tokens and API credentials used to connect to Google Workspace.
- Regular audits, monitoring, and vulnerability management.
- High availability and redundancy through our cloud infrastructure.
Data Subject Rights
As a data subject, you (or your end-users) have the following rights under GDPR:
- Right of access - obtain a copy of personal data processed.
- Right to rectification - correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten").
- Right to restriction of processing.
- Right to data portability.
- Right to object to processing.
- Right to lodge a complaint with a Data Protection Authority.
Supervisory Authority. If you are located in the EEA, the UK, or another jurisdiction with a designated data protection authority, you have the right to lodge a complaint with your local supervisory authority. Where Hosting Controller Inc. or its EU/UK representative is established or has designated a lead supervisory authority, that authority is:
Authority Name: [Insert Lead Supervisory Authority, e.g., Office of the Data Protection Commissioner]
Website: [Insert Authority Website/Complaint Portal URL]
A list of EU supervisory authorities is also available via the European Data Protection Board at https://edpb.europa.eu, and UK data subjects may contact the Information Commissioner's Office (ICO) at https://ico.org.uk.
Requests should be directed to your organization as the Data Controller. Hosting Controller will assist the Data Controller in fulfilling these requests.
If a data subject request or other communication regarding the processing of customer data is made directly to us, we will promptly inform you and will advise the data subject to submit their request to you. You will be solely responsible for responding substantively to any such data subject requests or communications involving customer data.
Google Workspace Marketplace and API Disclosures
ExSign for Google Workspace is offered through the Google Workspace Marketplace and/or direct integration authorized by your Google Workspace administrator. By installing and authorizing ExSign, your administrator grants specific OAuth scopes required for signature deployment (e.g., Gmail API scopes for applying signatures, and, where applicable, Admin SDK/Directory API scopes for reading organizational unit or user profile data used in signature templates).
- We only request limited sensitive and limited non-sensitive scopes necessary to provide the ExSign service.
- Data obtained via Google Workspace APIs is not used for any purpose other than providing and improving the ExSign signature service, and is never used for advertising.
- Administrators may revoke ExSign's access to their Google Workspace domain at any time through the Google Workspace Admin Console or Google security settings, which will trigger deletion of associated authorization tokens as described in the Data Retention section above.
Cookies and Tracking
By default, we only use cookies that are strictly necessary for the proper functioning of our Billing Portal and ExSign Portal. These cookies enable essential features such as secure login and session management.
We may also use functional cookies to support specific site functionalities - for example, remembering your language preferences or interface settings. These cookies remain active to ensure a consistent user experience but do not store any personally identifiable information.
Functional cookies are stored on your device only with your prior consent. You can withdraw your consent or modify your cookie preferences at any time through your browser settings.
Changes to This Privacy Policy
We may update this Privacy Policy to reflect service improvements, legal requirements, or other factors. Updates will be posted on our website with a revised "Last Updated" date.
Contact Information
Hosting Controller Inc.
Email: sales@hostingcontroller.com
Telephone: +1 (647) 799-1000