Data Processing & Security

Azindoo — Operated by Obimanso Technologies (UK-registered company, based in Leeds)
Last Updated: 10 May 2026

This document explains, in operational detail, what data we process, where it lives, who touches it, and how it is protected. It complements our Privacy Policy and forms part of our Data Processing Addendum (DPA) for business customers.

1. Roles

2. Data Categories We Process

CategoryExamplesSource
Account dataName, email, hashed password, team membershipYou
Authentication tokensGoogle OAuth access & refresh tokens (encrypted)Google, on your authorisation
Email contentSubject, cleaned plain-text body (HTML/quotes/signatures stripped, capped at 8 KB), sender, to/cc recipients, timestamps, direction. We do not store HTML, Bcc, Gmail labels, or attachment contents.Gmail API
Derived intelligenceCommitments, emotional scores, summaries, trust edges, alerts, SLA recordsGenerated by Azindoo
Usage / telemetryIP, browser, feature events, error logsYour device

3. Data Flow

  1. You log into azindoo.com and authorise Gmail via Google OAuth (read-only).
  2. Our backend (US) calls the Gmail API, downloads recent messages and stores them in our PostgreSQL database (US).
  3. Selected modules send email content to the Abacus.AI LLM endpoint (US) for analysis.
  4. Structured outputs are written back to your account in the database.
  5. You view results in the dashboard at azindoo.com.
  6. You can disconnect, export, or delete data at any time from Settings › Privacy & Data.

4. Sub-Processors

Sub-ProcessorFunctionLocation
Abacus.AIApplication hosting, managed PostgreSQL, LLM inferenceUnited States (AWS)
Amazon Web ServicesUnderlying compute, storage, networkUnited States
Google LLCSource data (Gmail API), Google Sign-InGlobal (Google-managed)

5. Technical & Organisational Security Measures

6. Data Retention

7. International Transfers

Data is stored and processed in the United States. For users in the EU, UK, Switzerland or any other jurisdiction, transfers rely on the EU–US / UK / Swiss Data Privacy Framework where the sub-processor is certified, Standard Contractual Clauses where required, and your explicit consent obtained at sign-up.

8. Subject Rights Handling

Subject-access, rectification, erasure, portability and objection requests are handled within 30 days. Most actions are available self-service from Settings › Privacy & Data. For other requests, write to [email protected].

9. Breach Notification

If we confirm a personal-data breach likely to result in risk to your rights and freedoms, we will notify affected customers without undue delay and at most within 72 hours of confirmation, with the information required by GDPR Art. 33 and equivalent laws.

10. Audit & Compliance Roadmap

11. Contact