Privacy Policy

This policy explains what information OneBee, Inc. (“OneBee,” “we,” “us”) collects, how we use it, and the choices and rights you have.

Effective date: June 2, 2026 · Last updated: September 10, 2026

Scope: the two roles we play

OneBee handles data in two distinct roles, and your rights depend on which applies.

As a controller. For information about you as a website visitor, prospect, or account holder, such as your name, work email, and how you use our marketing site and product, OneBee decides why and how that data is processed. This policy governs that data.

As a processor. For data inside the systems you connect to OneBee (your CRM records, emails, documents, and the content your agents read or act on), you are the controller and OneBee is your processor. We process that data only on your instructions and only to run the agents you have configured. That relationship is governed by your service agreement and Data Processing Addendum (DPA), not this policy. Where the two overlap, the DPA controls for connected-system data.

If you are an end user whose data was loaded into OneBee by one of our customers, contact that customer to exercise your rights. We will support them in responding.

1. Information we collect

Account and contact data. Name, work email, company, and role, collected when you request an audit, create an account, or contact us.

Audit inputs. The tools, workflows, and processes you describe during an ROI audit.

Usage and device data. Product interactions, server-side usage and log data (including agent action logs and the usage ledger), IP address, and browser and device information.

Cookies and similar technologies. See Section 5.

Connected-system data. Data from the tools you connect (for example CRM, email, calendar, and documents). We process this only as your processor, under Section 3.

We collect this information from you directly, automatically as you use the product, and, for connected-system data, from the services you authorize us to access.

2. How we use information, and our legal bases

We use controller data to:

  • Provide, operate, secure, and improve the service. Legal basis: performance of a contract; our legitimate interest in operating and improving the product.
  • Communicate with you about your account, support requests, and service changes. Legal basis: performance of a contract; legitimate interest.
  • Send product and marketing updates, where permitted. Legal basis: consent, or legitimate interest where allowed by law. You can opt out at any time.
  • Meet legal, tax, and security obligations. Legal basis: compliance with a legal obligation; legitimate interest.

We do not sell your personal information. We do not use customer data to train machine-learning models, ours or anyone else’s.

3. Connected systems and your agents

When you connect a tool, OneBee accesses only the data needed to perform the tasks you authorize, under least-privilege, scoped permissions you can revoke at any time. Connected-system data is processed to execute the agent actions you have configured, never to train models, ours or a third party’s.

OneBee’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google user data

What we access. When you connect a Google service, OneBee accesses only the Google data covered by the scopes you approve — for example Gmail messages, Google Calendar events, and Google Drive, Docs, and Sheets files, along with BigQuery data where you connect it.

How we use it. We use this data solely to perform the agent actions you configure. Running an agent may send the relevant data to the AI model providers we use to power it, but those providers process it only to return the agent’s result. We never use Google user data — and neither we nor our AI providers train, develop, or improve any machine-learning model on it — beyond the specific user’s own request. We never use it for advertising.

How we share it. We do not transfer Google user data to others except as necessary to provide or improve the service (through the vetted subprocessors in Section 6), to comply with applicable law, or as part of a merger or acquisition with notice to you.

How we protect, retain, and delete it. We secure Google user data as described in Section 10 and retain and delete it as described in Section 8, including deletion within 30 days of your request or the end of your subscription. OneBee’s use and transfer of raw or derived user data received from Google APIs, including Google Workspace APIs, adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Technical detail is on our Trust and Security page.

4. AI agents and automated decisions

OneBee runs AI agents that can take actions inside your connected systems. You control what each agent may do on its own and what requires a person to approve it. Approval gates (human-in-the-loop) can be required on any agent action.

We do not use solely automated processing, including profiling, to make decisions that produce legal or similarly significant effects about an individual without a lawful basis and appropriate safeguards. Consistent with our Acceptable Use Policy, the Service may not be used as the sole or automated means of making consequential decisions about individuals (such as employment, credit, housing, insurance, healthcare, or legal status), or to provide medical, mental health, legal, or other professional advice to individuals, without qualified human review. Where you configure agents to act autonomously, you remain responsible as the controller for those decisions and for providing any notice, human review, or disclosure your own obligations require.

5. Cookies and analytics

OneBee uses only strictly necessary, first-party cookies required to operate the service: to keep you signed in, remember your active workspace, secure OAuth connection flows, and run the audit wizard. We do not use advertising, marketing, or third-party analytics cookies (no Google Analytics, Tag Manager, or similar), and we do not sell or share cookie data. Because we set only essential cookies, no cookie-consent banner is required. You can block cookies in your browser, but doing so will prevent sign-in and core features from working.

6. Sharing and subprocessors

We share information with a short, vetted set of subprocessors that help us operate the service, under contracts requiring protections equivalent to those in this policy. None of our subprocessors use your data to train their models. Some retain data for a limited period to provide their service, subject to those contractual protections. We maintain a current, public list and notify customers before material changes.

The complete, current list of subprocessors, with the role each one plays, its processing location, and its retention, is published as Annex 3 of our Data Processing Addendum at onebee.ai/dpa.

We may also disclose information where required by law, to protect our rights or safety or those of others, or in connection with a merger, acquisition, or sale of assets, in which case we will notify you.

7. International data transfers

OneBee processes personal data in the United States, and some of our subprocessors may process it in the United States or other countries. If we process personal data of individuals in the EEA, the UK, or Switzerland, we rely on appropriate safeguards for any transfer outside their region, including the European Commission’s Standard Contractual Clauses and the UK Addendum, with supplementary measures where needed. You can request a copy of the relevant transfer mechanism using the contact details in Section 14.

8. Retention and deletion

We retain personal information for as long as your account is active and as needed to provide the service, then delete it as described below or as required by law.

Account and connected-system data. We retain this data for the life of your subscription. When your subscription ends, we delete your data within 30 days, except for limited security, audit, billing, and agent execution records retained for the periods described below or where a longer period is required by law or an applicable agreement. You can also request export or deletion of your data at any time, and we complete the request within 30 days, subject to those same limited exceptions.

Operational, security, billing, and agent records. Application logs are generally retained for 90 days. Security and cloud audit records are retained for up to 13 months for security investigation, compliance, and audit purposes. Billing and transaction records may be retained for up to seven years for tax, accounting, and legal compliance. Agent action records (which agent acted, in which connected system, what action it took, and when, without the content of the data processed) are retained for the duration of the customer relationship plus one year to provide an operational and audit record. The content of agent messages and tool calls is customer data and is deleted with it as described above and in the DPA. These records are then securely deleted unless a longer period is required by law or an applicable agreement.

Backups. Database backups are retained for 14 days, with 7-day point-in-time recovery; older copies are automatically purged. Deleted data is removed from backups within that window.

Sessions and tokens. Authentication sessions and connection tokens expire automatically on a short schedule.

9. Your privacy rights

EEA, UK, and Switzerland (GDPR / UK GDPR)

You may have the right to access, correct, delete, or port your personal data, and to object to or restrict certain processing. Where we rely on consent, you can withdraw it at any time without affecting prior processing. You may also lodge a complaint with your local supervisory authority.

California (CCPA / CPRA)

If you are a California resident, you may have the right to:

  • Know the categories and specific pieces of personal information we collect, the sources, the purposes, and the categories of third parties we disclose it to.
  • Delete personal information we hold about you, subject to legal exceptions.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of personal information. We do not sell or share your personal information as those terms are defined under the CCPA, including for cross-context behavioral advertising.
  • Limit the use of sensitive personal information. We do not use sensitive personal information for purposes that would trigger this right.
  • Not receive discriminatory treatment for exercising any of these rights.

Categories of personal information we collect are listed in Section 1. We disclose personal information only to the subprocessors described in Section 6, for the business purposes described in Section 2.

How to exercise your rights

Submit a request by emailing [email protected]. You may use an authorized agent; we will ask the agent for proof of authorization and may ask you to verify your identity directly. We verify requests using information already associated with your account before acting. We respond within the timeframe the applicable law requires (generally 30 days under the GDPR and 45 days under the CCPA, extendable where permitted). If we decline a request, we will explain why, and California residents may appeal by replying to our response.

10. Security

We protect information with encryption in transit (TLS 1.2 or higher) and at rest (AES-256), role-based access controls, least-privilege allow-lists, human-in-the-loop approvals, and full action audit logging. Sensitive credentials, secrets, and access tokens are encrypted and maintained in access-controlled secret storage, and controlled processes make them available only to authorized services and personnel. Our security program is built to the SOC 2 standard; a SOC 2 Type I examination is in progress.

11. Data breach notification

If we become aware of a security incident affecting your personal data, we will notify affected customers without undue delay and provide the information needed to meet your own notification obligations, consistent with applicable law and your DPA.

12. Children’s privacy

OneBee is a business product not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact us and we will delete it.

13. Changes to this policy

We may update this policy as our product, practices, or the law change. We will post the updated version with a new effective date and, for material changes, provide additional notice. Continued use of the service after an update means you accept the revised policy.

14. Contact

Questions about this policy or your data:

OneBee, Inc.
14 Altamont Ave
Melrose, MA 02176
[email protected]

Security and compliance inquiries: [email protected]

We do not maintain an EU or UK representative, as we do not target or monitor individuals in those regions.