Data & Privacy Policy
This policy explains what personal data we collect, why we collect it, who else sees it, and what you can ask us to do about it. We follow the GDPR and Dutch data protection law.
We decide what we're collecting data for before we collect it, and we write that purpose down here. We only collect what the purpose needs. Where the law requires your consent, we ask for it.
We protect your data and hold the companies working for us to the same standard. You can ask to see your data, correct it, or have it deleted. Our Security page covers how we protect it, and Contact is where you send a data protection request.
One Horizon BV
Chamber of Commerce: 98539175
D-U-N-S Number: 473610620
High Tech Campus 5
5656AE Eindhoven
The Netherlands
Our two roles
We're the controller for the data we decide about ourselves: your account details, billing, support, security monitoring, and our own marketing. That's what this policy covers.
We're a processor for the content and integration data you bring into your workspace. You decide what that's for, and we act on your instructions. The data processing agreement in our Terms of Use covers that role. It applies automatically, so you don't need to sign anything separate.
Companies that process data for us
These are our subprocessors. Every company below handles some part of your data on our behalf.
| Company | What they do for us | Where they process it |
|---|---|---|
| Fly.io | Hosting and Redis caching | EU (Amsterdam) |
| Supabase | Database hosting and logins | EU (AWS eu-central-1) |
| AI models and Google sign-in | EU (Netherlands) | |
| Cloudflare | Proxy and edge network | Global edge network |
| Customer.io | Product messaging and email campaigns | EU |
| HubSpot | Marketing and CRM | EU |
| Postmark | Sending transactional email | United States |
| Google Analytics | Website and docs analytics | United States |
| People Data Labs | Profile enrichment for sales and marketing | United States |
| Perplexity.ai | Company information for sales and marketing | United States |
| Stripe | Payment processing | EU and United States |
Most of this happens in the EU. The rows marked United States or Global are the exceptions, and those transfers rely on an adequacy decision or the European Commission's standard contractual clauses. We give you notice before we add or replace a subprocessor. The data processing agreement in the Terms of Use sets out how that works and how you can object.
Services you connect
One Horizon works by connecting to tools you already use. You choose which ones to connect, and we respect the access limits set on your account in each of those tools. Here's what we take from each and what we do with it.
Signing in. When you sign in with Google, we get your email address to identify your account, your name to display in the app, and your profile picture for your avatar.
Calendar. To build your Recap and record work you've finished, we read event titles and descriptions, start and end times, attendees where they matter for team context, meeting room or location, and whether an event is confirmed, tentative, or cancelled.
Meet. Our Meet add-on reads meeting metadata: the meeting ID, start time, and participant count. It also reads meeting links so you can join from One Horizon, and basic meeting details for context in standups.
AI features. Recaps, standup summaries, and work insights run on Google's AI services. When you use one, we send the data that feature needs, such as calendar event titles, work item metadata, and communication context. We send the minimum required to produce the result. Google's data processing terms and its GDPR obligations apply to that processing.
Limited Use. One Horizon's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide and improve the features described above. We don't transfer or sell Google data, we don't use it for advertising, and we don't use it for anything unrelated to what One Horizon does.
GitHub
From the repositories you give us access to, we read commits you wrote including the code changes, pull requests you opened or commented on, repository and branch details, and issue assignments and status.
We use it to summarise your development work, show your assigned pull requests in your Recap and on team standup boards, add comments to commits when you ask us to, and give context to team insights.
We don't store your code. We store metadata only: commit hashes, repository names, and commit messages for work summaries.
Jira and Linear
We read projects, tickets, and issue metadata, sprint and cycle timelines, status, priority, and assignment, tags, labels, and custom fields, plus ticket descriptions and comments for context.
We use it to show in-flight and blocked issues in your Recap, put team blockers and progress on standup boards, and generate work summaries from ticket activity.
Slack
When you add One Horizon to your Slack workspace, we read messages in the channels, private groups, and direct messages where One Horizon is present. We also read basic workspace details such as name, domain, and user list, user profiles and email addresses so we can link them to One Horizon accounts, and emoji reactions used in confirmation workflows.
We use it to send daily recaps and standup reminders, answer mentions and slash commands, create temporary channels or group messages for team discussions, react to confirm a work summary update, and match your Slack identity with your GitHub and Jira accounts.
Slack permissions are set at workspace level by your administrators, not by individual users.
Services we use to run One Horizon
These aren't integrations you pick. They're the companies we've hired to run parts of our business, and they're all in the subprocessor table above.
Email we send you
We use Postmark to send transactional email: sign-in links, notifications, and account messages. Postmark receives the recipient's address, the sender address, the subject line, and the body of the message.
Postmark is based in the United States and doesn't offer an EU region, so this data leaves the EU under standard contractual clauses. Postmark keeps message content, metadata, and delivery events for 45 days and then deletes them.
Marketing email doesn't go through Postmark. That's Customer.io and HubSpot.
Product messaging and marketing
We use Customer.io for product messaging and email campaigns, and HubSpot for marketing and CRM. Both hold your name, email address, and records of what we've sent you and how you responded. Both process in the EU.
You can unsubscribe from anything promotional at any time. See Marketing email below.
Website and product analytics
We use Google Analytics on our public website and docs, and our own analytics inside the product. What we collect and how you turn it off is in Analytics and usage statistics below.
Profile enrichment
We use People Data Labs and Perplexity.ai to fill in business details for sales and marketing. Starting from your email address, People Data Labs can return your job title and employer, professional profiles such as LinkedIn and X, industry and company size, location, and revenue estimates. Perplexity.ai adds company-level information: a description, founding details, industry classification, company social profiles, and employee and revenue estimates.
We use this to understand who our customers are and to make our sales and marketing relevant. Both companies process in the United States.
This processing is based on our legitimate interest under Article 6(1)(f) GDPR in understanding our commercial market. You can object to it at any time through Send us a message, and we'll stop and delete what we've gathered.
Payments
We use Stripe to take payments. See Subscriptions below.
Your account settings
In account settings you can change how your account is set up. For this we use your email address, IP address, profile picture, and name, based on our legitimate interest in running the service. We keep it until you stop using One Horizon.
Subscriptions
You can take out a paid subscription. Stripe handles the payment. We never see or store your card details. Stripe tells us that a payment succeeded and what your subscription status is, and that's all we receive.
How long we keep your data
We keep your account details until you delete your account or leave every workspace. Workspace data stays until an administrator deletes the workspace. Integration data stays while you're actively using the service. Subscription status stays until you cancel.
Cancelling isn't deleting. A cancelled workspace drops to the free plan and keeps its data. Deleting is a separate thing you have to do yourself.
When you delete. We remove your data soon after you delete an account or workspace. Two exceptions: encrypted backups expire on their own rolling schedule, and we keep whatever tax, accounting, security, or other law says we must keep.
Inactive free workspaces. If a free workspace has no activity for 12 months, we may delete it after giving the owner fair warning. Any activity resets the clock. We never delete a workspace with a paid subscription for inactivity.
What we keep from your integrations
We keep the minimum metadata our features need, plus AI-generated summaries that may quote parts of your calendar events or other connected content. We don't keep full copies of what's in your other tools.
Where we process it
One Horizon is EU-first. Our application hosting and main data storage run in the EU: Fly.io in Amsterdam and Supabase in eu-central-1.
Some of the companies in the table above process outside the EU. Those are the exceptions, and they're covered by an adequacy decision or standard contractual clauses.
Services you connect yourself, such as GitHub, Slack, Jira, Linear, coding agents, and MCP servers, run under their own terms and may process outside the EU. That's your choice to make.
Sharing your data with others
We don't publish your data, and we don't give it to anyone outside the subprocessors listed above unless the law requires it, for example when authorities demand access during a criminal investigation.
If we're legally required to hand over your data, we'll tell you within 14 days of the request, unless a non-disclosure order stops us or telling you would cause harm.
Analytics and usage statistics
We measure how our website and product get used so we can fix what's broken and build the right things.
Website and docs. Pages you can see without signing in may set analytics cookies for Google Analytics, Customer.io, and HubSpot. The consent banner on those pages controls this.
Inside the product. This is off unless you turn it on at Settings → Preferences → Privacy → Share usage analytics. When it's on, we record which features get used and how flows end. Events can include internal user and workspace identifiers, feature and outcome categories, your plan at the time, and timestamps. They never include prompts, code, documents, card details, or any of your work content.
What's excluded. We don't record product analytics for demo workspaces. Operational logging, security monitoring, and audit or changelog records are separate from this setting and keep running either way.
Turning it off. Go back to Settings → Preferences → Privacy and switch it off. The change applies everywhere you're signed in: Dashboard web, Desktop, and any other client on your account.
How long we keep it. Product analytics events are deleted 24 months after we record them, on a rolling basis.
Marketing email
We may tell you about new products or features by email and on social media.
You can opt out of anything promotional whenever you like. Every email has an unsubscribe link. On social media, block us or use the platform's own opt-out.
Using your name and logo
If you're on a free plan, we may name you as a customer and show your logo on our website and in presentations. Tell us to stop and we will. If you're on a paid or enterprise plan, we ask you first and only use your name or logo if you say yes.
What we won't do:
- We won't sell, rent, or export your company information to anyone
- We won't share your usage data, your users' data, or any other customer information
- We won't share your confidential or proprietary business information
- We won't use your information for anything beyond naming you as a customer
To opt out, use Send us a message or your account settings. We'll take your logo down within 30 days.
This processing is based on our legitimate interest under Article 6(1)(f) GDPR in showing who uses One Horizon. We've assessed that this interest doesn't override your privacy rights.
Cookies
Cookies are small files a site keeps in your browser. We use two kinds.
Essential cookies keep you signed in and keep the product working. They're always on.
Our app needs cookies to sign you in. It won't work without them.
Analytics cookies are only set on our public website and docs, and only if you accept. The banner has an Accept button and a Decline button, and nothing analytics-related is stored until you press Accept. Declining leaves the site fully working. Accepting turns on Google Analytics, Customer.io, and HubSpot.
You can clear or block cookies in your browser too. Blocking essential ones means you won't be able to sign in.
Security
Your data is encrypted in transit and at rest, access is limited to the people who need it, and we monitor for unusual activity. Our Security page has the detail.
No system is perfect. If a breach affects your personal data, we'll investigate and tell you and the regulator within the deadlines the GDPR sets.
Your data rights
Seeing and taking your data
You can ask for a copy of everything we hold about you, and export it in a format other software can read.
Correcting and deleting
You can correct anything that's wrong, ask us to delete your personal data, and delete your account and everything attached to it whenever you want.
Consent and control
You can withdraw consent where we relied on it, object to how we're using your data, and control which integrations have access.
Connected services
You can disconnect any service from One Horizon at any time. Deleting your One Horizon account removes the data we hold from every connected service. You can also ask us to delete specific data from a single connected service.
When you send a request, include enough detail for us to confirm it's really you. That's what stops someone else changing or deleting your data.
Dutch law applies
This policy is governed by Dutch law. The GDPR and Dutch data protection law both apply to how we handle your personal data.
Changes to this policy
We update this policy when the way we handle data changes. If a change affects you in a way that matters, we'll tell you by email or in the app before it takes effect.
Complaints
If you think we're mishandling your data, tell us through Send us a message.
Contact us
Privacy questions, data protection requests, marketing opt-outs, and any other legal matter go through Send us a message on our support page. Tell us what you need and it reaches the right person.
By post:
One Horizon BV
High Tech Campus 5
5656AE Eindhoven
The Netherlands