Privacy Policy

How we protect your personal data

Last updated: 07 September 2026

1. Introduction

Stamova, operated by GLOBAL DIGITAL SERVICES LIMITED (hereafter "we", "our" or "Stamova"), is committed to protecting the privacy of its users. This privacy policy explains how we collect, use, store and protect your personal data when you use our business automation platform.

By using our services, you accept the practices described in this policy. If you do not accept these terms, please do not use our platform.

For European residents

Although our company is established in Hong Kong, we undertake to comply with the General Data Protection Regulation (GDPR) for all our users residing in the European Union.

2. Data controller

The controller of your personal data is:

GLOBAL DIGITAL SERVICES LIMITED

RM D5, /F, King Yip Factory Building

No. 59 King Yip Street, Kwun Tong

Hong Kong

Registration number: 70126319

Email: [email protected]

3. Data we collect

3.1 Data you give us

  • Identification data: surname, first name, email address, telephone number
  • Sign-in data: username, password (encrypted)
  • Business data: company name, job title, sector of activity
  • Billing data: billing address, payment details (handled by our secure payment provider)

3.2 Data collected automatically

  • Technical data: IP address, browser type, operating system, device used
  • Browsing data: pages visited, time spent, actions taken
  • Sign-in data: date and time of sign-in, session history

3.3 Data from third-party services

When you connect Google services to our platform, we access certain data according to the permissions you grant. See section 4 for the detail.

4. Google OAuth integration

Our platform uses Google OAuth 2.0 to let you connect your Google services and automate your business processes. This section sets out precisely which data we access and how we use it.

Google services integrated

Gmail (read-only)
Google Calendar
Google Drive
Google Sheets
Google Tasks

4.1 Gmail (read-only)

Data accessed: email content, senders, recipients, attachments, labels.

Use: automatic extraction of business information (order confirmations, invoices, notifications) to feed your automation workflows.

What we do NOT do: we never modify, delete or send emails on your behalf.

4.2 Google Calendar

Data accessed: calendar events, dates, attendees, descriptions.

Use: checking your availability and automatically creating events (appointments, reminders) based on your workflows.

4.3 Google Drive

Data accessed: only the files and folders created by our application.

Use: storing generated reports, data exports and documents produced by your automations.

What we do NOT do: we do not access the existing files in your personal Drive.

4.4 Google Sheets

Data accessed: the content of the spreadsheets you connect.

Use: reading data to feed it into your workflows, and automatically updating tracking and reporting sheets.

4.5 Google Tasks

Data accessed: task lists, descriptions, due dates.

Use: automatically creating tasks from business events (an email arriving, a meeting ending, and so on).

4.6 Storage of access tokens

When you authorise access to a Google service, we securely store:

  • An access token (valid for about an hour) to carry out the authorised operations
  • A refresh token to renew access without asking for your authorisation again

These tokens are encrypted in the database and give access only to the permissions you have explicitly granted.

Revoking Google access

You can revoke Stamova's access to your Google services at any time:

Manage Google access

5. How we use your data

We use your personal data to:

  • Provide our services: run the automations you set up, manage your account, process your payments
  • Improve our platform: analyse usage in order to refine our features
  • Communicate with you: send important notifications, answer your support requests
  • Keep things secure: detect and prevent fraud, protect our systems
  • Meet our legal obligations: tax compliance, responding to requests from the authorities

Legal basis: the processing of your data rests on the performance of the contract (our terms and conditions of sale), your consent (for the Google services), and our legitimate interests (improving the services, security).

6. How long we keep it

  • Account data: kept for the whole duration of your subscription, then for 3 years after it ends
  • Google OAuth tokens: kept for as long as the authorisation is active, deleted immediately if it is revoked
  • Billing data: kept for 10 years (legal obligation)
  • Sign-in logs: kept for 1 year
  • Browsing data: kept for 13 months at most

7. Sharing your data

We never sell your personal data.

We may share it with:

  • Service providers: hosting (Hetzner Online GmbH), payment (Airwallex), email delivery
  • Google services: only in order to run the automations you have set up
  • Legal authorities: where required by law or by a court decision

All our providers are bound by confidentiality obligations and may use your data only for the services they provide to us.

8. Data security

We put technical and organisational security measures in place:

  • Encryption: HTTPS/TLS connections, hashed passwords (bcrypt), encrypted OAuth tokens
  • Access control: mandatory authentication, role and permission management
  • Monitoring: detection of suspicious activity, security logs
  • Backups: regular, encrypted backups
  • Secure hosting: Hetzner servers (Germany) in ISO 27001 certified data centres

9. Your rights

Your rights over your data

  • Right of access: obtain a copy of your personal data
  • Right to rectification: correct inaccurate or incomplete data
  • Right to erasure: ask for your data to be deleted
  • Right to portability: receive your data in a structured format
  • Right to object: object to the processing of your data
  • Right to restriction: restrict the processing of your data
  • Right to withdraw your consent: at any time, for processing based on consent

To exercise these rights, contact us at [email protected].

We undertake to answer any request within 30 days.

For European residents

You also have the right to lodge a complaint with a data protection supervisory authority in your country of residence (for example, the CNIL in France).

10. Cookies

Our platform uses cookies to:

  • Essential cookies: keep you signed in, remember your preferences
  • Security cookies: protect against CSRF attacks, detect suspicious sign-ins
  • Analytics cookies: understand how you use our platform (anonymised)

You can manage cookies in your browser settings. Please note that blocking essential cookies may prevent the platform from working properly.

11. Changes to this policy

We may change this privacy policy to reflect changes in our practices or for legal reasons. Where a change is substantial, we will tell you by email or through a notification on the platform.

The date of the last update is shown at the top of this page. We encourage you to read this policy regularly.

12. Contact

For any question about this privacy policy or about your personal data:

Data protection officer

Email: [email protected]

Address: GLOBAL DIGITAL SERVICES LIMITED

RM D5, /F, King Yip Factory Building, No. 59 King Yip Street, Kwun Tong

Hong Kong