Skip to content

Legal

Privacy policy

Last updated 16 September 2026

This policy covers the Caspian website and Caspian Connector's Google Workspace integration. It explains the Google data we access, why we use it, how we store and share it, and how to request its removal. Your company's agreement with Caspian also governs product processing. Privacy protections for anonymous browser and device telemetry do not mean that employee directory or Google audit records are anonymous.

Who we are

Caspian BV ("we") operates Caspian and getcaspian.io. We are a Belgian company, registered under number 1042.322.507, at Brusselsesteenweg 6, bus 104, 9050 Gent (Gentbrugge), Belgium. For privacy questions or deletion requests, write to hello@getcaspian.io.

We act as controller for our website, business correspondence and account administration. When we synchronize an organization's Google Workspace data, we process that data on the organization's behalf to provide its Caspian workspace. The organization controls who connects the integration and who may access its workspace data.

Website data we collect, and why

The work email you leave on the start page. We use it to contact you about setting up Caspian — that first conversation is the whole purpose of the form. The legal basis is your consent, given by submitting the form; withdraw it at any time: tell us, and we delete the address.

If you sign up with a company address, we use it once more to send you a Slack Connect invite to a channel shared between your company's Slack workspace and ours. Only people from your company and Caspian are let into that channel. Picking Microsoft Teams opens a chat on your side; we send nothing extra.

If you book a demo, Calendly handles the booking under its own privacy policy, and we receive the details you enter there.

Email you send us, which we keep as ordinary correspondence.

Technical server logs (IP address, request, user agent) that our hosting provider keeps for a short period to run and secure the site. The legal basis is our legitimate interest in operating it.

Website tracking

This site sets no analytics, advertising or tracking cookies, and runs no third-party trackers. There is no consent banner because there is nothing to consent to.

Website service providers

Form submissions land in Attio, our CRM, and a notification with your email reaches our team's Slack workspace. The site is hosted on Amazon Web Services in the EU; our email runs on Google Workspace. These providers process data on our behalf under data processing agreements, and transfers outside the EEA are covered by the European Commission's standard contractual clauses. We never sell personal data, and nobody else receives it.

Website retention

A lead's email stays in our CRM while the conversation is live. If nothing comes of it, we delete it within 24 months of last contact — sooner if you ask. Server logs rotate away within 90 days.

Connecting Google Workspace

An authorized Google Workspace administrator connects Caspian Connector through Google's OAuth consent screen. Google supplies the administrator's sign-in identity, email and profile information. We use these to identify the connecting account and organization. Connector credentials let us synchronize the authorized organization without requiring a new sign-in for every sync.

The integration serves IT administrators: it brings employees, groups, company email domains, connected applications, their permissions and available audit history into one organizational inventory. Google directory and audit data can identify individual employees and actors. They are not anonymous device telemetry.

Google employee directory

With admin.directory.user.readonly, we read employee identifiers, names, business email addresses and available directory attributes, such as organization information and account status. We use these to populate the Users inventory, identify the connected organization, check the consenting administrator and associate application authorizations with the right employee.

Google groups and memberships

With admin.directory.group.readonly, we read group identifiers, names, email addresses, members and membership roles. We show a user's group memberships as organizational context in the user details. Group membership by itself does not prove that someone has access to a third-party application.

Application authorizations and permissions

With admin.directory.user.security, we read which applications users have authorized, their application identifiers and the OAuth permissions they received. We show these in Connected apps and application details so IT can understand which applications may access company Google data. Where an authorized administrator requests supported remediation, this permission also permits revoking the selected application authorization. It does not mean we change permissions automatically during inventory sync.

Google does not offer a narrower read-only scope for the API endpoint listing these authorizations. Permissions shown for another application belong to that application's Google authorization. They do not give Caspian access to that application's data or establish an administrator-managed application assignment.

Company email domains

With admin.directory.domain.readonly, we read the connected Google organization's domains and domain aliases. We show company email domains in workspace settings and use them to distinguish company email domains from external domains. Google's consent wording about customer domains refers to the connected Google Workspace organization, not to a list of that company's customers.

Google audit history

With admin.reports.audit.readonly, we read available OAuth authorization and revocation events, Google login events and SAML events. Records may include event identifiers, timestamps, actors, application information and technical parameters supplied by Google, including IP addresses, user agents or event status when present. We use these for application discovery, relevant observed activity and dated authorization history in application timelines.

An authorization event means that a user granted an application permissions. It is not proof of using that application. We do not turn authorization dates into a Last used value. We do not request Gmail message-content or Google Drive file-content permissions for this connector.

Google data storage and security

We store source records and derived inventory and history records associated with the connected Caspian workspace. Connector refresh credentials are encrypted when stored. Access through product features is subject to workspace access controls. We use this data to provide the features described above, not to advertise to employees, sell their data or assess their creditworthiness.

Product service providers and AI

Our product uses Amazon Web Services for hosting, storage, backups and Amazon Bedrock AI processing; Clerk for authentication; and Cloudflare for CDN, DNS and edge security. Google Workspace supports our business email and support correspondence. Our public trust center lists these subprocessors and their processing locations. Product hosting and Bedrock are listed in the EU; authentication and other service processing may involve the USA or global locations. The website provider list above is not a list of recipients of synchronized Google product data.

When you use Caspian's AI chat, your messages and relevant workspace data returned by authorized tools may be processed by Amazon Bedrock to answer your request. This can include Google-derived inventory or audit information available to you. We do not use Google API data to train general-purpose AI models. AI processing is for the user-facing product feature, not an unrelated use of your Google data.

We share Google-derived data only as necessary for the user-facing features you authorize, to protect security, to comply with applicable law, or in another circumstance allowed by Google's Limited Use requirements. Human access is limited to those requirements, including your explicit consent for particular data, security investigation, legal obligations, or permitted internal operations using aggregated and anonymized data.

Caspian subprocessors and processing locations

Disconnecting and deleting Google data

Disconnecting Google Workspace in Caspian removes the locally stored refresh credential and stops future connector synchronization. It does not itself revoke Caspian's authorization at Google or erase previously synchronized inventory and audit history. You can also remove Caspian's authorization through Google's account or Workspace administrator controls.

Synchronized records are retained to provide your workspace inventory and history until the organization requests deletion or the applicable customer agreement requires their removal. The audit collection lookback window is not an automatic deletion deadline. To request deletion of stored Google data, contact hello@getcaspian.io and identify the relevant organization. We verify your authority before handling organizational data requests.

Deletion of active workspace records and expiry of protected backup copies are separate processes. Backup copies can remain until the applicable backup lifecycle expires. Where a legal obligation requires retention, that obligation can limit deletion. Disconnecting or removing authorization at Google does not replace a request to delete data already stored by Caspian.

Google API Limited Use

Caspian's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google API Services User Data Policy

Your rights

Under the GDPR you can ask for access to, correction of, deletion of, or a copy of your personal data, restrict or object to its processing, and withdraw consent at any time. One email to hello@getcaspian.io does it. You can also complain to your data protection authority, though we’d rather hear from you first.

For data your employer or another organization controls in its Caspian workspace, you can also contact that organization directly. We assist its authorized instructions for data-subject requests. Removing OAuth authorization stops future authorized Google API access; it does not automatically delete stored records.

Changes

When this policy changes, the date above changes with it. A material change to what we collect will be visible on this page before it applies.