Legal
Privacy Policy
Effective date: April 11, 2026. This Privacy Policy explains how OceanLabs collects, uses, and protects your information when you use our products and services.
1. Overview
OceanLabs ("Company," "we," "us," or "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy describes the types of information we collect, how we use it, and the choices you have regarding your information when you access or use any OceanLabs product, platform, or service (collectively, the "Service").
By using the Service, you acknowledge that you have read and understand this Privacy Policy. If you do not agree with its terms, please do not use our Service.
2. Information We Collect
We collect information in the following ways:
2.1 Information You Provide
- —Account details — name, work email address, and password created upon accepting an invitation.
- —Profile information — job title, team, and role within your organization.
- —Communications — messages, feedback, or support requests you send to us.
- —Customer Data — leads, contacts, pipeline entries, notes, and any other data you input into the Service.
2.2 Information Collected Automatically
- —Log data — IP address, browser type, operating system, referring URLs, and pages visited.
- —Usage data — features accessed, actions performed, timestamps, and session duration.
- —Device data — device identifiers, screen resolution, and language settings.
- —Cookies and similar tracking technologies — see Section 8 for details.
2.3 Information from Third Parties
If you integrate third-party services (such as email providers or calendar tools) with the Service, we may receive information from those providers in accordance with their privacy policies and your authorization.
3. How We Use Your Information
We use the information we collect to:
- —Provide, operate, and maintain the Service.
- —Create and manage user accounts and authenticate sessions.
- —Process and fulfill your instructions within the platform.
- —Send transactional communications such as account setup emails, invitation notices, and security alerts.
- —Monitor and analyze usage patterns to improve performance, reliability, and features.
- —Detect, investigate, and prevent fraudulent transactions, abuse, and other illegal activities.
- —Comply with legal obligations and enforce our Terms & Conditions.
- —Respond to your support inquiries and resolve disputes.
- —Generate aggregated, anonymized analytics that do not identify any individual.
We will not use your personal information for marketing or advertising purposes without your explicit consent.
4. Legal Basis for Processing
Where applicable law requires a legal basis for processing personal data (for example, under the GDPR), we rely on the following:
- —Contract. Processing is necessary to provide the Service you have agreed to use.
- —Legitimate interests. We process data to operate and improve our business, provided your rights and interests are not overridden.
- —Legal obligation. Processing is necessary to comply with applicable laws and regulations.
- —Consent. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
6. Data Retention
We retain personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
- —Active accounts. Data is retained for the duration of your use of the Service.
- —After termination. Customer Data is retained for 30 days following account termination to allow export, after which it is permanently deleted from our systems.
- —Logs and analytics. Aggregated, anonymized usage data may be retained indefinitely for product improvement purposes.
- —Legal holds. We may retain data for longer periods when required by applicable law or to resolve disputes.
7. Security
OceanLabs implements commercially reasonable administrative, technical, and physical safeguards designed to protect your personal information from unauthorized access, disclosure, alteration, and destruction. These measures include:
- —Encryption of data in transit using TLS 1.2 or higher.
- —Encryption of sensitive data at rest.
- —Session token-based authentication with HMAC signature verification.
- —Role-based access controls limiting data access to authorized personnel.
- —Regular security reviews and vulnerability assessments.
Despite these measures, no method of transmission over the internet or electronic storage is 100% secure. If you believe your account has been compromised, contact us immediately at security@oceanlabs.io.
9. International Transfers
OceanLabs operates globally. Your personal information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your jurisdiction.
When we transfer personal data across borders, we implement appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent mechanisms, to ensure your data receives an adequate level of protection.
10. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- —Access. Request a copy of the personal information we hold about you.
- —Rectification. Request correction of inaccurate or incomplete information.
- —Erasure. Request deletion of your personal information ("right to be forgotten"), subject to legal retention obligations.
- —Restriction. Request that we restrict the processing of your data in certain circumstances.
- —Portability. Receive your personal data in a structured, commonly used, machine-readable format.
- —Objection. Object to processing based on legitimate interests or for direct marketing purposes.
- —Withdraw consent. Where processing is based on consent, withdraw it at any time without affecting prior processing.
- —Lodge a complaint. File a complaint with your local data protection authority if you believe your rights have been violated.
To exercise any of these rights, please contact us at privacy@oceanlabs.io. We will respond to your request within 30 days.
11. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us immediately at privacy@oceanlabs.io and we will take prompt steps to delete it.
12. Third-Party Links
The Service may contain links to third-party websites, integrations, or services that are not owned or controlled by OceanLabs. This Privacy Policy applies only to our Service. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
We encourage you to review the privacy policies of any third-party services you interact with through the Service.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, regulatory, or operational reasons. When we make material changes, we will update the "Last updated" date at the top of this page and notify you via in-app notice or email.
Your continued use of the Service after such changes constitutes your acceptance of the updated Privacy Policy. If you do not agree with the changes, you should discontinue use of the Service.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out: