Respons

Legal information

Privacy Policy

Last updated 3 August 2026

Roles and responsibility

S5 Respons is developed and provided by S5 Studio AS. A business using S5 Respons is normally the controller of its customer and employee data. S5 Studio AS processes that data on the customer's documented instructions as a processor. S5 Studio AS is the controller of contact, contract, billing and security data relating to its own customer relationship.

Data we process

This may include account and company information, roles and access, customer enquiries, conversation history, response drafts, tasks, appointments, integration status, billing information and technical operations and security logs. A Google or Microsoft 365 connection processes the selected account identity, granted scopes and required encrypted OAuth tokens. Gmail and Outlook sending store delivery status and provider message/request identifiers. Calendar stores selected owned calendars and minimized event data such as time, busy status and S5 appointments that must be synchronized.

Purpose and use

We use data to provide and administer the service, authenticate users, perform requested actions, secure the platform, provide support and meet contractual and legal requirements. Customer businesses remain responsible for their lawful basis for customer and employee data.

Google Gmail and Calendar

The Gmail integration uses only gmail.send for messages a user has reviewed and approved. S5 Respons does not use the Gmail API to read, search, modify or delete the inbox. Incoming enquiries instead arrive through the business's explicit forwarding or other intake channels. Calendar shows only calendars owned by the connected account, checks availability and conflicts, creates and updates approved appointments, and can cancel an S5-managed appointment after explicit user approval.

Microsoft Outlook and Calendar

The Microsoft integration uses delegated Mail.Send and Calendars.ReadWrite for the connected work account. S5 does not request Mail.Read; incoming Outlook mail uses the same explicit forwarding and S5 intake as Gmail. Only editable calendars owned by the connected account can be selected. Microsoft tenant/user IDs are external identity evidence while S5 tenant and RBAC remain authoritative.

AI and processors

S5 Respons uses the OpenAI API for analysis and response drafts. Customer enquiries, relevant conversation history, approved business configuration and explicitly prepared image copies may be sent to OpenAI when AI is enabled. Raw Google or Microsoft calendar events, calendar IDs, Gmail/Graph data and OAuth tokens are not sent to AI. The model receives only minimized calendar evidence, such as whether the check succeeded and availability was found; the S5 server inserts validated times after the model call.

Data is not sold, used for advertising or sent to train or improve general AI models. We do not claim Zero Data Retention or an Enterprise setup; OpenAI's standard API terms and data controls apply unless otherwise agreed in writing.

Other providers and logs

Necessary providers may process data for hosting, database, private file storage, system email, payments, AI and security. The application stores redacted operations and security records in the S5 database and writes redacted events to platform logs. Token, authorization, email content, address and message fields are filtered from these logs. Customer content is not shared between businesses.

See our Google user data explanation for additional details.

Retention, tokens and deletion

Reusable OAuth tokens are encrypted with an organization-bound key and protected by role and tenant checks. Data is retained only as long as needed for its purpose, the customer relationship and documented legal obligations. An administrator can disconnect Gmail and Calendar separately under Settings → Integrations. Local token secrets are then overwritten and S5 attempts to revoke Google access. Historical case data is not deleted automatically; see how to disconnect or request deletion.

Contact and security

Requests concerning data controlled by a customer business should first be sent to that business. For data controlled by S5 Studio AS, or help identifying the controller, contact hei@s5respons.no. Access is isolated by business and role, integration secrets are encrypted and security-relevant actions are logged. Never send passwords, OAuth tokens or unnecessary customer content in a support request.

Google Limited Use

S5 Respons' use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

S5 Studio AS
Norwegian organization number 938 145 725
hei@s5respons.no
Back to the home page
Privacy Policy | S5 Respons