Legal
Privacy Policy
Effective date: September 9, 2026
This Privacy Policy explains how Ganymedus (“Ganymedus”, “we”, “us”) handles personal data when you visit our website or use the Ganymedus service. If an organization provides your access, that organization may separately act as the controller of workspace data and determine why and how that data is used.
1. Information we collect
We may process account and identity information, workspace memberships, people and responsibility records, goals, work items, messages, meeting transcripts submitted by users, uploaded files, integration metadata, usage records, and technical information such as IP address, browser type, timestamps, and security logs.
2. Connected services
If you connect Google Drive or another third-party service, we access data only within the permissions you grant. Google Drive files are permission-aware: a person can discover and use only files available to their connected Google identity. You can disconnect an integration at any time. Third-party services also process data under their own privacy terms.
3. How we use information
- Provide, secure, maintain, and improve the service.
- Generate plans, summaries, recommendations, transcriptions, and work reviews requested by users.
- Authenticate users, manage workspace permissions, and prevent abuse.
- Send service messages and notifications selected by a workspace.
- Meet legal obligations and protect the rights and safety of users and the service.
4. AI processing
Content submitted to AI-enabled features may be sent to contracted AI service providers to produce the requested output. Ganymedus is designed to keep consequential actions subject to permissions or human approval. AI output may be inaccurate and should be reviewed before it is relied upon.
5. Legal bases
Where applicable under European data protection law, we process personal data to perform a contract, pursue legitimate interests such as service security and improvement, comply with legal obligations, or based on consent when consent is required. Workspace customers are responsible for establishing an appropriate legal basis for data they add to the service.
6. Sharing and processors
We may share data with infrastructure, authentication, communications, analytics, transcription, and AI providers that help us operate the service; with a workspace administrator according to workspace permissions; when required by law; or as part of a corporate transaction. We do not sell personal data.
7. Retention and security
We retain data for as long as needed to provide the service, meet legal requirements, resolve disputes, and protect the service. Retention may also be controlled by the organization responsible for a workspace. We use technical and organizational safeguards, but no internet service can guarantee absolute security.
8. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data, and to withdraw consent. Workspace data requests may need to be directed to the organization that controls the workspace. You may also disconnect integrations and leave workspaces, subject to applicable record-retention requirements.
9. Cookies
We use essential session cookies to authenticate users, protect accounts, and maintain the service. If we introduce optional analytics or advertising cookies, we will provide any notice and choice required by law.
10. International transfers
Our providers may process information in countries other than yours. Where required, we use appropriate transfer safeguards, such as contractual protections.
11. Children
Ganymedus is a business service and is not directed to children. Users must be legally able to enter into the applicable agreement or be authorized by their organization.
12. Changes and contact
We may update this policy as the service develops. Material changes will be communicated as required by law. Questions or privacy requests can be sent to privacy@ganymedus.com.