Where is the privacy policy?
Our current privacy policy is on graph.one.
Purpose limits, sensitive data, human access, privacy rights, retention, deletion, and transfers.
Our current privacy policy is on graph.one.
Depending on the purpose, we rely on contract, consent, legal duty, or legitimate interests.
The privacy policy gives the full purpose and legal basis details. A business customer remains responsible for its own basis when it gives us data to process on its instructions.
We collect and send the data a chosen feature needs, and we use it for the stated service purpose.
Default connected-account permissions avoid email bodies. Broader access needs a new consent step tied to a feature.
We limit enrichment requests to the lookup fields needed for the result. Our DPA also limits customer-data use to the customer's instructions and the agreed service.
No. The service is built for professional network and business relationship data.
Our standard DPA does not allow protected health records or GDPR special-category data unless we first agree the extra legal and security terms that the use needs.
Do not connect or upload that data without a written agreement from us.
Yes. A user's work sources or lists can include professional data about other people.
This can include a name, work email, role, employer, meeting or contact signals, and a professional link to a user. Public or paid professional sources can add profile details.
A person does not need a Graph One account to ask what we hold or to use a privacy right. Email us with enough detail to find the record.
We do not sell customer personal data or use it for cross-context behavioural advertising.
Our DPA also bars us from sharing customer personal data for that kind of advertising. We do not use Google user data for advertising or to train public AI models.
Only approved staff may access production data, and only when support, security, or law requires it.
Staff may not browse customer data for general use. Our rules require an approved account, a work need, and an audit trail for admin actions.
Google user data has stricter limits: human access needs the user's clear consent for a specific case, a security need, a legal duty, or anonymised internal use allowed by Google's policy.
No. Our scores, matches, and search rankings are aids for the user, not decisions about a person's rights.
We derive relationship strength, likely identity matches, and search order from professional signals. A user decides what to do with those results.
Our current privacy review treats this as user-led analysis, not automated decision-making with a legal or similarly serious effect.
Email contact@graph.one to ask for access, correction, deletion, restriction, objection, or a portable copy.
Give enough detail to find the record. We may need to check identity before giving out or changing personal data. The right that applies can depend on the law and the reason for processing.
Our GDPR process aims to answer within 30 calendar days. We track the request, the action taken, and the response.
We keep core account and connected data while the account or source is active. We set shorter limits for short-lived security and service data.
Some records may stay longer where law, fraud prevention, security, a legal claim, or a contract requires it.
Main retention points
|
Data
|
Usual limit
|
|---|---|
| Account and connected data | Until account deletion or source removal, unless law or a dispute requires more |
| Signed-in session | Up to 14 days |
| Deletion confirmation link | 24 hours |
| Service and security logs | Usually 30 days |
| Customer data after a contract ends | The DPA terms apply; the current template uses 30 days after a written request |
| Backups | Removed through the normal backup cycle rather than changed in place |
We stop using that connection and remove data owned by that source under its cleanup rules.
Some merged people or user-made records may also contain data from another active source. Removing one source does not remove data that belongs to a different source or a record the user made.
The user starts deletion in the account and confirms it by email. We then remove the account in the background.
If a deletion step fails, the job records the failed step for follow-up instead of reporting a false success.
Deleted data ages out as the normal backup copies expire; we do not edit each backup in place.
Our current database backup cycle keeps copies for 30 days. Until a copy expires, we keep it protected and use it only for recovery, legal, security, or dispute needs.
Primary production storage stays in Germany and Finland, but some providers may process limited data elsewhere.
We use contract terms and, where needed, EU Standard Contractual Clauses or another lawful transfer method. The provider list shows the usual area for each service.