Privacy policy
Applies to befocusy.com, the campus and the WorkOS platform (labs.befocusy.com).
Last updated: 2026-10-04
1. Data controller
The WorkOS platform is operated by SAL DIGITAL SKILLS, S.L., tax ID B39855788, registered at Plaza María Blanchard 2, 3F, 39600 Maliaño (Cantabria), España. You can reach us at eduardo@befocusy.com for anything regarding this policy, and at soporte@befocusy.com for product support.
2. Our role
Our role changes depending on where you are, and the distinction matters. On befocusy.com and the campus we are the data controller: we decide what data we ask for and why. On the WorkOS platform it is different: each customer company uses it with its own accounts and databases, so with regard to the content it enters or connects we act as a data processor on its behalf, under article 28 GDPR, and the controller is the customer company. We are the controller for that company own contact and billing details.
3. What data we process
- Account data: name, email address, company and interface preferences.
- Connection credentials (OAuth): the access tokens for the third-party services the user explicitly authorizes. They are stored encrypted and never shared between customers.
- Working content: the content of the services the user connects — messages, calendar events, documents, files — displayed and organized inside the platform.
- Technical data: IP address, device identifiers and activity logs, for security and troubleshooting.
- Billing data of the customer company. Full payment card details are held by the payment provider; we do not store them.
- Newsletter subscription data: your email address and, if you give it, your name.
- Training data: if you enrol in the campus, your enrolment and your progress through the courses.
- Support chat: the messages the user writes in the in-app support chat and the replies received from the automatic assistant or the support team.
4. What we use them for
Only to provide the features the user has requested: displaying and organizing their work in the interface, synchronizing it with their Notion workspace, sending the messages they compose, managing their calendar events and keeping their files organized. Also to bill the service, meet our legal obligations and keep the platform secure. When the customer company turns on the inbox, WorkOS also automatically processes each incoming email with AI (see section 5). We do not build advertising profiles.
4b. Support form
If you write to us through the support form on our public page, we process the name, email address and message you provide for the sole purpose of handling your enquiry and replying to you. The legal basis is your own consent when submitting it. We keep that correspondence for as long as necessary to resolve the matter and, afterwards, for the period during which liabilities may arise. We do not use it to send you marketing communications.
4c. Newsletter
If you subscribe to our newsletter on befocusy.com, we process your email address (and your name, if you give it) for the sole purpose of sending it to you. The legal basis is your consent, given when you sign up; if you are already a customer, we may inform you about services similar to those you have contracted, under article 21 of the Spanish LSSI. Delivery is handled by Substack, acting as a data processor, which does not use your address for anything else. We keep your data until you unsubscribe, which you can do with the link at the bottom of every newsletter or by writing to us. Newsletters may include open markers and tracking links that tell us, in aggregate, whether the message was read.
5. Google API data
WorkOS only accesses the Google accounts the user explicitly connects, and only the services authorized on the consent screen: Gmail, Google Calendar and Google Drive. Access can be revoked at any time from the Google account settings, and also by disconnecting the account inside WorkOS.
- Sign in with Google. If the user chooses “Continue with Google” to sign in to WorkOS, we only receive their email address (verified by Google) and their name, and use them solely to match an existing WorkOS account. We do not store any token from this connection or access any other data in their Google account.
- Gmail. We read the messages of the connected account to display them in the WorkOS inbox, link them to the matching contact and save them as records in the customer company's Notion workspace. If the company has the inbox turned on, each new email is automatically processed with AI to classify it, clean it up or translate it and, where relevant, suggest a task. Attachments are stored in Notion and, if the company sets it up, in its Google Drive. We mirror back to Gmail the actions the user performs here: marking as read, archiving, labelling or moving to trash. We only send messages the user composes and confirms; we never send email automatically or in bulk.
- Google Calendar. We display the calendars the user selects and create, reschedule or cancel events at their request, including attendees and video-call links. If the user marks a calendar with “creates task”, WorkOS periodically reads its events for the next 30 days and creates a task in Notion for each one, keeping its date up to date.
- Google Drive. We work inside the folder the user designates: we create its structure, upload attachments there, read the documents they choose to import, and move or rename folders when they reorganize their notes. We also detect files the user adds by hand to those folders and attach them to the matching record in Notion. Files that already existed in their Drive are neither moved nor deleted when imported. If the user deletes an attachment from WorkOS, that file is also permanently deleted from their Drive, without going through the trash.
Limited Use
SAL DIGITAL SKILLS, S.L. (WorkOS / Befocusy Labs) use of information received from Google APIs, and its transfer to any other application, adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, data obtained from Gmail, Google Calendar and Google Drive:
- Are used only to provide and improve the features the user has explicitly requested, or that their company has turned on, and that are visible in the interface.
- Are not transferred to third parties, except to the providers strictly necessary to deliver those features, where required by law, for security reasons, or with the express consent of the user.
- Are not used or transferred for advertising purposes, including personalized advertising and remarketing.
- Are not read by any human, except with the express consent of the user, for security reasons, to comply with the law, or when aggregated and anonymized for internal operations.
- Are not used to develop, improve or train generalized artificial intelligence models. When a feature requires AI processing — for example, classifying an incoming email, summarizing it or structuring a document into a note — the content is sent to the AI provider solely to generate that specific result, which is delivered to the user or their company; those providers do not use the data to train their models and only keep it temporarily to detect abuse, under their own terms.
6. Providers involved
To deliver the service we rely on the following providers, each under its own data processing agreement:
- Hostinger — platform hosting, within the European Union.
- Google LLC — the user Gmail, Calendar and Drive, when they connect their account.
- Microsoft — email and calendar, as an alternative to Google.
- Notion Labs — destination of the customer working content.
- OpenAI and Google (Gemini) — text generation, summarization, audio transcription and real-time web search for the AI features (including the Kairos assistant). They do not train their models on data sent through their APIs.
- Zernio — WhatsApp Business and Instagram messaging, social media publishing, and storage of the attachments WorkOS hosts to display them in the platform.
- Slack — channels and direct messages, when the user connects their account.
- Stripe — payment gateway that some of our customers activate, through a custom integration, to bill their own end customers; it does not process your WorkOS subscription payment.
- Qonto — banking and e-invoicing that some of our customers connect to manage their own invoices.
- Kit.com — newsletter delivery, when the customer uses that feature.
- Substack — delivery of our newsletter.
We never sell data to third parties under any circumstances. Some of these providers are located outside the European Economic Area; in those cases the transfer relies on the European Commission standard contractual clauses or on an adequacy decision.
7. How long we keep them
- Connection credentials are deleted as soon as the user disconnects the tool from WorkOS. If they revoke access from their Google account, the credentials stop working immediately and are deleted when the account is disconnected in WorkOS. Signing in with Google does not store any credentials.
- Working content is kept while the account is active. When the relationship ends it is deleted or returned to the customer, as they instruct.
- Technical logs are deleted automatically after 90 days at most.
- Conversations with the Kairos assistant (including the content of emails, documents or other data the user asks it to look up) are stored by OpenAI for up to 30 days to keep the conversation thread, and are deleted afterwards. OpenAI does not use them to train its models or for any other purpose.
- WorkOS also keeps the history of conversations with Kairos so the user can pick them up again. Nobody at the customer company can read it, not even whoever administers the account. The WorkOS technical team may only consult it when the user themselves asks for it to resolve an issue, to investigate a security problem or abuse, or when required by law, and every access is logged.
- Billing data is kept for the periods required by commercial and tax regulations.
- Support chat conversations are kept while the account is active; they are deleted automatically after 12 months without activity. Automatic replies are generated by an AI provider (OpenAI or Google) solely from the conversation itself and the public Help Center articles: no data from the user’s workspace is sent to it.
8. Security
Each customer company is isolated from the rest: its credentials and content are never shared or mixed with those of any other customer. Connection credentials are stored encrypted, access to the platform always uses a secure connection, and internal access is limited to the staff strictly necessary to provide support.
9. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to eduardo@befocusy.com. If the data was provided by the company you work for, address them as the controller; we will assist them. You may also lodge a complaint with the Spanish Data Protection Agency (aepd.es).
10. Changes to this policy
If we change this policy, we will publish the updated version here and change the date above. If the change significantly affects how data is processed, we will also notify customers by email.