Ownward Desk

Ownward Desk — Privacy policy

Last updated: 5 October 2026

This policy explains which data Ownward Desk (the desktop app and its back office at admin.ownward.ch) processes, why, and how you stay in control, in accordance with the EU GDPR and the Swiss Federal Act on Data Protection (nFADP).

Who is responsible

Ownward (company in formation), publication director Julien Cyr. Contact: the contact form on www.ownward.ch.

Data we process

Your Ownward account (name, e-mail) and the work data you enter in the app: projects, todos, time tracked, planned days, meetings and minutes, reports. If you connect Google Calendar: the e-mail address and Google account identifier of each connected account, the list of your calendars (name, colour) and the details of the events of the calendars you choose to display (title, date and time, place or video link, description excerpt, organiser and attendees' names and e-mail addresses).

How we use Google data

Google Calendar access is read-only (scope calendar.readonly). Events are read only to show them to you in Ownward Desk so that you can choose which ones to link to Ownward meetings. Only the events you import or link are stored, as Ownward meetings (title, time, place, attendees, and the Google event identifier and link, so the meeting follows later time changes). Events you do not select are displayed and not kept. Ownward Desk never writes to your Google calendars.

Google API Services User Data Policy

Ownward Desk's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Google user data is used only to provide the features described above, is not sold, is not used for advertising, is not used to build user profiles, and is not used to develop, improve or train generalised artificial-intelligence or machine-learning models. No human reads it, except with your explicit consent for a specific event, for security purposes, to comply with the law, or when the data has been aggregated and anonymised.

Where data is stored and how it is protected

Data is stored in our Supabase database, hosted in the European Union (Paris region), and served by Vercel. Google access tokens are encrypted (AES-256-GCM) and readable only by the back office's server code; they are never sent to the app. Access to Ownward data is restricted by account and role.

Sharing

We do not sell or rent data. Meeting minutes are visible to the client concerned only when an Ownward team member explicitly shares them. Service providers that host the service (Supabase, Vercel) process data on our behalf. Data received from Google is not shared with third parties.

Retention and deletion

Disconnecting a Google account in Ownward Desk (Sync › Google Calendars › Disconnect) revokes Ownward's access at Google and deletes the account, its tokens and its calendar list immediately. You can also revoke access at any time from your Google Account (Security › Third-party apps). Meetings you imported stay in Ownward until they are deleted; on request we delete them, or remove their link to Google. Work data is kept for the duration of the business relationship and the legal retention periods that apply.

Your rights

You may request access, rectification, erasure, restriction or portability of your data, and object to its processing, through the contact form. You may also lodge a complaint with your supervisory authority (CNIL in France, FDPIC in Switzerland).

Changes

If this policy changes, the new version is published on this page with its date. Significant changes are announced in the app.

Terms of serviceContact