Legal · privacy and data use

Privacy Policy

This policy explains how Brosoft Technologies LLP handles information when organizations and their users use ORGIO, OrgioOne and connected mailbox services.

Effective date: 18 September 2026Controller/service provider: Brosoft Technologies LLP

1. Who we are

ORGIO and OrgioOne are developed and operated by Brosoft Technologies LLP, UG-45, Ozone Center, Sector 12, Faridabad, Haryana 121001, India. Questions and privacy requests can be sent to info@orgio.in.

2. Scope of this policy

This policy applies to the ORGIO website, ORGIO business platform, OrgioOne desktop application, OrgioChat, OrgioMail, related APIs and support services. An organization using ORGIO may control employee records and other business information entered by its users. In that situation, the organization determines the purpose of processing and Brosoft Technologies LLP processes the information to provide the contracted service.

3. Information we process

Account and organization information

This may include name, employee identifier, work email address, organization/domain, role, profile image, contact details, authentication information and account status.

Business and collaboration information

This may include chats, files, call and meeting details, tasks, approvals, comments, attendance information, notifications and business records a user is authorized to access or share.

Connected mailbox information

When a user connects a mailbox, we process the mailbox address, provider, display name, connection settings, encrypted credentials or OAuth tokens, token expiry, preferences, signatures, mailbox rules and contact metadata needed to provide OrgioMail.

Messages and attachments

Email lists, message bodies, message state, folders and attachments are retrieved from the connected mail provider when needed to display, search, organize, send or synchronize mail. Attachments may be temporarily processed for download and security scanning. If a user intentionally shares an email into chat, creates a task from it, attaches its content to another ORGIO record or invokes another workflow, that resulting content may be stored as part of the selected ORGIO feature.

Technical information

We may process device, application version, IP address, session, security, diagnostic and error information required to operate, protect and troubleshoot the service.

4. Google user data

When a user chooses to connect a Google account, OrgioOne requests authorization using Google OAuth. The application currently requests identity information necessary to identify the mailbox and Gmail access through the https://mail.google.com/ scope.

Google data is used only to provide and improve user-facing mailbox functionality, including:

  • identifying and connecting the mailbox selected by the user;
  • listing folders and messages and displaying requested message content;
  • searching mail and synchronizing read, unread and starred state;
  • moving, organizing, drafting and deleting messages at the user’s direction;
  • sending messages initiated by an authorized user;
  • downloading attachments requested by the user and scanning them for malicious content; and
  • providing notifications, mailbox rules and user-requested integrations with other ORGIO features.
Google API Limited Use disclosure: OrgioOne’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

We do not sell Google user data, use it for targeted advertising, determine creditworthiness, or use it to train general-purpose artificial-intelligence or machine-learning models. We do not allow humans to read Google user data except when the user has given specific consent for support, when required for security or abuse investigation, when necessary to comply with applicable law, or where the data has been aggregated and anonymized for internal operations in a manner that cannot identify a person.

5. Microsoft and other connected mailboxes

When users connect Microsoft or standards-based IMAP/SMTP mailboxes, we process equivalent account, token, message, folder and attachment information only as needed to provide the mailbox functionality requested by the user. Provider credentials are used only for the connected service and are protected using server-side encryption mechanisms.

6. Why we process information

  • To provide, synchronize and maintain the services requested by users and their organizations.
  • To authenticate users, enforce permissions and protect accounts.
  • To deliver messages, notifications, calls, meetings, tasks and approvals.
  • To provide customer support and investigate errors.
  • To prevent fraud, abuse, malicious files and security incidents.
  • To comply with applicable legal obligations.

7. Storage, protection and retention

We use access controls, transport encryption and protected storage for sensitive connection secrets. OAuth access and refresh tokens are stored in protected form on the Orgio server and are not embedded in the desktop installer.

Connected-mailbox configuration is retained while the mailbox remains connected. Removing a mailbox from OrgioOne deletes its stored connection record and associated mailbox configuration. Information copied into other ORGIO features at the user’s direction follows the retention rules of that feature and the customer organization. Security, audit, backup and legally required records may be retained for a limited additional period.

No security control can guarantee absolute protection. Organizations and users should protect their devices and credentials, apply updates and promptly report suspected misuse.

8. Sharing and disclosure

We may disclose information only as necessary to:

  • the customer organization and authorized users according to configured roles;
  • cloud, hosting, communications, security and support providers acting under appropriate obligations;
  • Google, Microsoft or another provider when a user directs OrgioOne to perform an action with that provider;
  • professional advisers, regulators or authorities where lawfully required; or
  • a successor in a corporate transaction, subject to appropriate confidentiality and notice requirements.

We do not sell personal information or connected-mailbox content.

9. User and administrator controls

Depending on the service and applicable law, users may request access, correction, export or deletion of personal information. Some employment and organizational records are controlled by the user’s employer or customer organization, so those requests should first be directed to the organization’s administrator.

A user can disconnect a mailbox in OrgioOne. Google access can also be revoked from the user’s Google Account connections. Revoking provider access stops new mailbox access but does not automatically delete information that the user deliberately copied into another ORGIO feature.

10. International processing and children

Information may be processed where Brosoft Technologies LLP or its contracted service providers operate, subject to appropriate safeguards. ORGIO is a business service and is not directed to children.

11. Changes to this policy

We may update this policy as the services, legal requirements or data practices change. The effective date above will be updated, and material changes will be communicated through an appropriate service or customer channel.

12. Contact

Brosoft Technologies LLP
UG-45, Ozone Center, Sector 12
Faridabad, Haryana 121001, India
Email: info@orgio.in
Telephone: +91 98713 34386