Scope and our role
This Privacy Policy applies to the Ofisync website, platform, applications, support channels and related services (collectively, the “Services”). “Customer” means the person or organization that has an Ofisync account or agreement, and “Customer Data” means all information uploaded, entered, generated or stored in the Services by or for that Customer.
For Customer Data, the Customer determines what is collected and how it is used. Ofisync processes that data only to provide, secure, maintain and support the Services, and in accordance with the Customer's instructions.
Your data belongs to you
All Customer Data added to Ofisync belongs exclusively to the Customer. Using the Services does not transfer ownership of that data to Ofisync. We claim no ownership rights in Customer Data.
The Customer grants Ofisync only the limited permission needed to host, process, transmit and display Customer Data for the purpose of delivering the Services.
Information we collect
We may process the following categories of information:
- Account information: name, work email, telephone number, organization, role and login credentials.
- Customer Data: records, files, documents, contacts, transactions, communications and other content the Customer chooses to place in Ofisync.
- Service and device data: IP address, browser type, device information, timestamps, diagnostic logs and security events.
- Support and billing information: enquiries, support correspondence, subscription details and payment status. Payment card details may be handled by a payment provider and are not stored by Ofisync unless expressly stated.
How we use information
We use information only as needed to:
- provide, configure and support the Services;
- authenticate users and protect accounts;
- maintain performance, reliability and security;
- respond to enquiries and service requests;
- administer subscriptions and our contractual relationship;
- comply with applicable law and enforce our agreements; and
- improve the Services using technical or aggregated information that does not identify a Customer's records.
We do not use Customer Data for advertising, sell it, or use it to train public or third-party artificial intelligence models.
No sharing of Customer Data
Customer Data is not sold, rented, disclosed or shared with any other entity for that entity's own use, marketing or commercial benefit under any circumstance.
Where technical infrastructure is required to operate the Services, providers may process data solely on Ofisync's behalf, under confidentiality and data-protection obligations, and only to the minimum extent required to deliver that infrastructure. They receive no independent right to use Customer Data.
If Ofisync is legally compelled to disclose information, we will limit disclosure to what the law strictly requires and, where legally permitted, notify the affected Customer before doing so.
Security and six-hour backups
Ofisync uses reasonable administrative, technical and physical safeguards designed to protect information against unauthorized access, alteration, loss or destruction. Access is restricted to authorized personnel who need it to operate or support the Services and who are subject to confidentiality obligations.
We ordinarily create backups of Customer Data every six hours. Backups are maintained for service continuity and disaster recovery. The schedule may be delayed during maintenance, incidents or circumstances outside our reasonable control, and a backup is not a substitute for any export or archive the Customer is required to maintain.
Access and data export
Customer Data can be made available to the Customer upon request, subject to reasonable identity and authority verification. We will provide the data in a commonly used format where reasonably practicable. Requests may be sent to info@ofisync.com. We may ask an organization's account owner or authorized representative to approve a request made by one of its users.
Retention and deletion
Upon a verified Customer request or termination of the Customer's contract, Ofisync will destroy all active records and Customer Data belonging to that Customer. Customers should request and download any required export before deletion, because deletion is irreversible.
Deleted data may remain temporarily in protected backup copies until those backups are overwritten through the normal backup rotation. During that period, the data will remain isolated from ordinary use and will be deleted rather than restored to the production service, except where recovery is required to address a disaster or security incident. We may retain only information that applicable law requires us to keep, and will isolate and protect it for the required period.
Customer responsibilities
The Customer is responsible for having the authority and lawful basis to add personal information to Ofisync, providing any notices required to its own users or data subjects, maintaining accurate account details, assigning appropriate access permissions and protecting login credentials. Users should notify us promptly if they suspect unauthorized account access.
Privacy rights and requests
Depending on applicable law, an individual may have rights to access, correct, delete, restrict or object to the processing of personal information. If your information was placed in Ofisync by a Customer, please direct your request to that Customer first. We will assist the Customer with a valid request where required. You may also contact us at info@ofisync.com.
Changes and contact
We may update this policy to reflect changes to the Services, our practices or applicable law. The effective date above will be revised when we do. Material changes will be communicated through the Services or another appropriate channel.
Questions, export requests and deletion requests may be sent to info@ofisync.com or Ofisync at +254 705 627 634.