Published on
Friday, 22 March 2024
By
Nawid Sadat
Contact details
wesley@reshark.io
Address
John M. Keynesplein 12, 1066 EP Amsterdam

Re:Shark Privacy Policy

Effective Date: Friday, 22 March 2024

At Re:Shark, part of The Ocean B.V., headquartered at John M. Keynesplein 12, 1066 EP Amsterdam, The Netherlands (hereinafter referred to as "Re:Shark", "we", "us", or "our"), the privacy and security of our users ("you" or "your") are paramount. We are committed to protecting your personal data and respecting your privacy in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable local privacy laws.

This Privacy Policy outlines how we collect, use, process, and safeguard your personal data when you use our services, access our website at reshark.io, or interact with us in any other manner.

Data Controller Information

Re:Shark, as a data controller, manages your personal data in relation to our website operations and customer relationship management. In instances where we process personal data on behalf of our clients for their purposes, our clients act as the data controller under GDPR Article 4, while we operate as a data processor.

For any privacy-related inquiries, please contact us at: support@reshark.io.

Personal Data Collection

When you subscribe to or use our services, we may collect the following personal data:

We expressly avoid collecting sensitive personal data such as government identifiers, complete credit card or bank card numbers, or medical records.

Purposes and Legal Basis for Processing

Your personal data is processed for various purposes, each backed by a legal basis as outlined below:

Legitimate Interests: To enhance, personalize, and optimize your experience with our services; solve issues; improve site usability.

Legal Compliance: To ensure the integrity of our services by preventing, detecting, and investigating potentially prohibited or unlawful activities and ensuring adherence to our terms and conditions.

Cookies and Tracking Technologies

We use cookies and similar tracking technologies to analyze trends, administer the website, track users' movements around the site, and to gather demographic information about our user base as a whole.

Third-Party Disclosures

Personal data collected on our website is primarily used by Re:Shark for service execution and may also be shared with our partner companies to enhance service delivery and support.

Data Sharing and Protection

No Selling or Renting: We never sell or rent your personal data to any third parties for marketing purposes.

Controlled Disclosure: Your personal data is only disclosed to third parties under these conditions:

Data Retention Policy

Service Execution Data: Retained only as long as necessary to provide our services, not exceeding 3 years post-account closure, unless otherwise mandated by law.

Marketing Data: Data used for newsletters or direct marketing is kept for 3 years from the last interaction.

Evidentiary Data: Retained for the duration of the statutory limitation period, typically 5 years.

Data Subject's Rights: Identification proof for rights verification is deleted post-verification. Data related to direct marketing objections and GDPR rights requests are kept for 3 years.

Data Storage and Transfers

EU-Based Servers: All data processing and storage occur within the European Union.

International Transfers: When necessary, data may be transferred outside the EU under strict safeguards:

Security Measures

Re:Shark places paramount importance on the security and integrity of our customers' personal data. In line with the General Data Protection Regulation (GDPR), we are committed to implementing all necessary precautions to ensure the protection of your data against any form of unauthorized or illegal activity. This includes accidental destruction, loss, alteration, unauthorized disclosure, or access.

Industry Standards: We adopt industry-standard security measures to safeguard personal data against unauthorized disclosure. This includes the utilization of recommended encryption methods to secure payment-related information.

Comprehensive Protection: To prevent unauthorized access and ensure data accuracy and proper usage, Re:Shark has established a comprehensive set of electronic, physical, and managerial procedures. These measures are designed to maintain the security of the data collected through our services.

Transparency and Response: Despite our rigorous security measures, no system can be completely immune to breaches. If a security breach occurs, Re:Shark commits to promptly informing affected parties and taking immediate steps to address and mitigate the situation.

Legal Accountability: Any individual exploiting a security breach for unauthorized access will face legal consequences. Re:Shark will undertake all necessary legal actions to protect customer data, user rights, and limit the effects of the breach.

Google and Microsoft OAuth and Connected Email Services

Re:Shark allows users to sign in with Google or Microsoft and, if the user chooses, connect a Gmail or Microsoft Outlook / Microsoft 365 mailbox. OAuth is used to obtain the permissions required for the functionality selected by the user.

Authentication data

For sign-in, Re:Shark may process basic account information supplied through Google or Microsoft OAuth, such as your name, email address, account identifier and authentication tokens. This information is used to authenticate you, maintain your session and secure access to Re:Shark.

Google Gmail permissions

If you connect Gmail, Re:Shark uses gmail.send to send email on your behalf and gmail.readonly to identify and process replies, message identifiers, thread information, headers and message content relating to prospect communications that were initiated or managed through Re:Shark. The gmail.readonly permission technically permits broader mailbox read access than Re:Shark's intended product use. Re:Shark limits its actual use of that access to Re:Shark-managed prospect conversations and their replies.

Microsoft Outlook / Microsoft 365 permissions

If you connect a Microsoft mailbox, Re:Shark uses Microsoft Graph delegated Mail.Send to send email as the signed-in user and delegated Mail.Read to identify and process replies, message information, thread information and message content for prospect communications initiated or managed through Re:Shark. Re:Shark limits its actual use of that permission to Re:Shark-managed prospect conversations and their replies.

How we use connected mailbox access

Connected mailbox access is used only for user-facing Re:Shark functionality: authenticating your account, sending prospect emails that you create, approve, schedule, launch or otherwise manage through Re:Shark, and identifying and processing replies to those Re:Shark-managed prospect communications.

We do not use Gmail or Microsoft mailbox permissions to browse, monitor, profile or analyze your general inbox. We do not intentionally retrieve, analyze, display, retain or otherwise use unrelated emails, attachments or conversations, including internal company correspondence or messages that you independently send or receive outside Re:Shark. A mailbox may be queried only to the extent technically necessary to identify replies or messages that belong to Re:Shark-managed prospect threads.

Low-volume sending

Re:Shark is not designed or intended for bulk email distribution through connected Gmail or Microsoft accounts. Outbound email through these connected accounts is limited to a maximum of ten (10) prospect emails per user per day. Messages are initiated and controlled by the user and are sent as individual business communications through the user's connected mailbox. Re:Shark does not use connected accounts to circumvent provider sending limits, spam controls, abuse-prevention mechanisms, filters or other platform restrictions.

Purpose limitation, storage and sharing

We request and use only the Google and Microsoft permissions necessary for the connected functionality. Google and Microsoft user data is used only to provide or improve the visible user-facing Re:Shark functionality described in this Privacy Policy. We do not sell or rent connected-mailbox data and do not use it for advertising, retargeting, unrelated profiling, surveillance, creditworthiness or lending decisions.

OAuth tokens and connected-account data are retained only for as long as reasonably necessary to provide the connected functionality or comply with applicable legal obligations. Connected-account data may be shared with authorized sub-processors only where necessary to provide or secure Re:Shark's user-facing functionality and subject to appropriate contractual and data-protection safeguards, for security purposes, or where required by law.

Artificial intelligence and model training

Re:Shark does not transfer, sell or use Google user data obtained through Google Workspace APIs to create, train or improve a general-purpose or shared machine-learning or artificial-intelligence model. Email content may be processed, including by authorized service providers, only where necessary to provide the relevant user-facing functionality for the specific user, such as identifying or processing a prospect reply.

Human access

Re:Shark personnel do not read Google or Microsoft mailbox content unless you explicitly request support or otherwise affirmatively authorize access to specific messages or data, access is strictly necessary for security or abuse investigation or to resolve a technical incident, or access is required by applicable law. Any such access is limited to what is reasonably necessary for that purpose.

Security of connected accounts

OAuth credentials, tokens and connected-account data are protected by appropriate technical and organizational measures. Re:Shark protects OAuth tokens against unauthorized access and uses encryption in transit and, where applicable, at rest when such tokens are transmitted or stored.

Disconnecting your account and deleting connected data

You may disconnect your Google or Microsoft account from Re:Shark or revoke Re:Shark's authorization through your Google Account or Microsoft Account settings. Once authorization is revoked or the mailbox is disconnected, Re:Shark will cease future API access to that account. OAuth tokens that are no longer required will be revoked where applicable and permanently deleted. You may request deletion of connected-account data retained by Re:Shark by contacting support@reshark.io. Data retained solely for the integration will be deleted or anonymized when it is no longer required, subject to applicable legal retention obligations.

Google API Services User Data Policy

Re:Shark's use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including the applicable Limited Use requirements.

Your Data Protection Rights

Under the GDPR and Dutch data protection laws, you have several rights regarding your personal data:

Right to Be Informed: Our privacy policy is designed to provide transparency around what data we collect and how it's used.

Right of Access, Rectification, Erasure, and More: You can access, update, or delete your personal data. Additionally, you have rights to restrict processing, data portability, and to object to data processing.

Right to Withdraw Consent: You can withdraw consent at any time, affecting the lawfulness of processing based on consent before its withdrawal.

Right to File a Complaint: If you believe your data protection rights have been breached, you have the right to file a complaint with the supervisory authority.

How to Exercise Your Rights

Contact us via the support options on our website or by emailing support@reshark.io to exercise your rights. Our team is committed to addressing your requests promptly.

You can exercise your rights by sending an email to support@reshark.io or via our support chat on the website. Your request will be processed within 30 days.

Contact and Newsletter Subscription

For assistance, queries, or more information about our services, you can reach out through our contact form or schedule a meeting. You can subscribe to our newsletter for updates and tips directly through our website.

Changes to This Policy

Re:Shark reserves the right to update our privacy policy in response to new legal requirements or changes to our services. Any significant changes will be communicated with a thirty (30) day notice in advance before these changes will be effective.

Contact Us

If you have any questions regarding our privacy policy you can contact us through email via support@reshark.io. Or send us letter to Re:Shark Attn: Data Protection Officer, John M. Keynesplein 12, 1066 EP Amsterdam.