1. General information

This document sets out the terms of use for the OAuth integration available in the CONREGO system and the rules for processing information associated with connecting the following accounts:

  • Google, including Gmail and Google Workspace accounts;
  • Microsoft, including Outlook.com, Microsoft 365, and Exchange Online accounts.

The provider of the system and the integration is:

CONREGO Spółka z ograniczoną odpowiedzialnością
Plac Jana Pawła II 108a/2
66-400 Gorzów Wielkopolski, Poland
National Court Register (KRS): 0000716221
Tax ID (NIP): PL5993215285
Business Registry Number (REGON): 369351080
Email: support@conrego.com

Questions concerning data protection may be addressed to the Data Protection Officer at dpo@conrego.com.

2. Purpose of the integration

The OAuth integration enables an authorized CONREGO user to connect a Google or Microsoft account that they own or manage to the CONREGO system.

The connection is used solely to send, through that account, email messages configured or initiated by the user in the CONREGO system.

The integration is not used to browse or analyze the user's mailbox.

3. Scope of account access

As part of the integration, CONREGO may receive the following from the account provider:

  • the email address of the connected account;
  • the account identifier;
  • basic information necessary to identify the connected account;
  • information about the granted permission scopes;
  • an OAuth access token;
  • an OAuth refresh token;
  • the token expiration date and technical information about the connection.

OAuth tokens are technical authentication credentials that enable operations approved by the user to be performed without storing the password to their Google or Microsoft account.

CONREGO does not receive or store the user's Google or Microsoft account password.

4. Google permissions

For Google accounts, CONREGO uses the following permission:

https://www.googleapis.com/auth/gmail.send

This permission allows CONREGO only to send email messages on the user's behalf.

CONREGO does not use the Google integration to:

  • read the inbox;
  • read previously sent messages;
  • browse correspondence history;
  • retrieve the address book or contacts;
  • read drafts;
  • delete or modify messages;
  • analyze Gmail account content;
  • create advertising profiles of users;
  • train artificial intelligence models.

CONREGO's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

5. Microsoft permissions

For Microsoft accounts, CONREGO uses the following delegated Microsoft Graph permission:

Mail.Send

This permission allows CONREGO to send email messages on behalf of the signed-in user.

CONREGO does not use the Microsoft integration to:

  • read the inbox;
  • retrieve correspondence history;
  • read contacts or calendars;
  • delete or modify existing messages;
  • analyze Microsoft account content;
  • use account data for advertising or profiling purposes;
  • train artificial intelligence models.

6. Content of sent messages

Message content, recipient data, and any attachments are not retrieved from the Google or Microsoft mailbox. They originate from the CONREGO system and are specified by the user operating CONREGO.

To deliver a message, CONREGO sends the following information to the selected email account provider:

  • recipient addresses;
  • the message subject;
  • the message content;
  • the sender's name and address;
  • the reply-to address;
  • attachments, if added by the user.

Google or Microsoft processes this information in accordance with the terms of service and privacy policies applicable to the respective provider.

7. Token storage and security

OAuth tokens are stored by CONREGO in encrypted form. Access to them is restricted to the system components necessary to deliver messages and renew authorization.

CONREGO applies technical and organizational safeguards that include, in particular:

  • transmission encryption;
  • encryption of stored tokens;
  • system access controls;
  • restricted access for employees and contractors;
  • infrastructure security monitoring;
  • backups;
  • incident response procedures.

No method of transmitting or storing information can eliminate all risk. Nevertheless, CONREGO applies safeguards appropriate to the nature of the information processed.

8. Retention period

Active OAuth connection data is retained while the integration is in use.

When the account is disconnected in the CONREGO settings, active OAuth tokens are removed from the system's operational configuration. Limited technical information may be retained for as long as necessary to:

  • ensure security;
  • diagnose errors;
  • handle complaints;
  • establish, pursue, or defend against claims;
  • comply with legal obligations.

Residual data may temporarily remain in protected backups until overwritten in accordance with the applicable retention schedule.

9. Disconnecting and revoking access

The user may disconnect a Google or Microsoft account at any time in the email integration section of the CONREGO system.

Disconnecting an account in CONREGO removes the locally stored active connection data but does not always automatically revoke the consent recorded by the account provider.

The user may additionally revoke access:

  • in the security settings of their Google Account;
  • in the application and consent settings of their Microsoft or Microsoft 365 account.

After access is revoked, CONREGO will no longer be able to send messages through the account until it is authorized again.

10. Disclosure of information

CONREGO does not sell information received in connection with the OAuth integration.

This information is not used for:

  • targeted advertising;
  • remarketing;
  • creating advertising profiles;
  • assessing creditworthiness;
  • data brokerage;
  • training general-purpose artificial intelligence or machine learning models.

Information may be disclosed only:

  • to Google or Microsoft to the extent necessary to deliver messages;
  • to entities providing CONREGO with essential infrastructure, hosting, or security services;
  • to competent authorities where disclosure is required by law;
  • to detect and prevent abuse or security incidents.

Entities supporting CONREGO may process information only under appropriate agreements and in accordance with CONREGO's instructions.

11. User obligations

A user who uses the integration represents that:

  • they have the right to use the connected account;
  • they are authorized to send messages from the relevant address;
  • they will send messages only to recipients for whom they have an appropriate legal basis;
  • they will not use the integration to send spam, malware, or unlawful content;
  • they are responsible for the message content, recipient list, and compliance of their communications with applicable law.

The user should immediately disconnect the integration if they lose control of the connected account or suspect unauthorized access.

12. Limitations of the integration

The operation of the integration depends on services provided by Google or Microsoft. These providers may change their APIs, security requirements, permission scopes, limits, or terms of service.

CONREGO may temporarily restrict or disable the integration where necessary for security, technical, or legal reasons, or because of changes introduced by the account provider.

13. User rights

To the extent provided by applicable law, the user may request:

  • information about the data being processed;
  • access to the data;
  • rectification of the data;
  • restriction of processing;
  • erasure of the data;
  • the right to object;
  • data portability, where applicable.

Requests may be sent to dpo@conrego.com or support@conrego.com.

The user also has the right to lodge a complaint with the competent data protection authority.

14. Changes to this document

CONREGO may update this document in response to changes in the integration's functionality, Google or Microsoft requirements, the safeguards applied, or applicable law.

The current version of the document will be published on the CONREGO website. Users may also be notified of material changes through the system or by email.

15. Acceptance of the terms

Connecting a Google or Microsoft account to CONREGO constitutes acceptance of these terms and consent to the operations displayed on the relevant provider's authorization screen.

A user may decline these terms by not connecting an account or by disconnecting a previously connected account.

16. Contact

Questions concerning the OAuth integration may be sent to: support@conrego.com

Questions concerning data protection may be sent to: dpo@conrego.com