OficinaViva

OficinaViva

Privacy Policy

Last updated: October 9, 2026

Official website: https://oficinaviva.app

1. Scope and operator

This policy describes the processing of information by OficinaViva at https://oficinaviva.app. OficinaViva is a trade name. The operator’s legal identity is [Operator legal name — pending], with address [Operator address — pending]. These missing details are not replaced by the product name.

OficinaViva is a multi-organization workspace for AI agents, task delegation, conversations, files, brand references, creative projects and sales workflows. Organization administrators control membership and connected accounts. Features requiring an external provider remain dependent on an enabled, authorized connection; this policy does not claim every integration is live or verified.

2. Information processed

  • Accounts: name, email, authentication identifiers and session information. Password authentication is handled by the authentication service; integration passwords are not requested for Gmail OAuth.
  • Organizations: memberships, roles, agent configurations, tool permissions and plan/usage records.
  • Workspace content: instructions, conversations, tasks, delegated work, agent memory, results, uploaded documents, extracted text, brand assets, reference images and creative outputs.
  • Sales data: prospect details entered by users, campaigns, message drafts, delivery records, activity and do-not-contact lists.
  • Integration information: connected account identifiers, email, granted permissions, connection status and encrypted OAuth credentials.
  • Operational records: approvals, task/job status, usage and cost accounting, security/audit records and diagnostic logs.

You choose what content to provide. Upload only information you are entitled to process and avoid unnecessary sensitive personal data, including data about third parties.

3. Purposes and AI processing

We process information to authenticate users, maintain their organization, retrieve authorized file context, perform requested agent tasks, generate deliverables, manage sales records, enforce permissions and budgets, and investigate failures or misuse.

Agents may delegate tasks, use permitted tools and retain task history or workspace memory. Relevant instructions, authorized file excerpts and other task context may be sent through the AI gateway to the model provider used for that task. For an authorized media task, selected reference assets and prompts may be sent to the connected media provider. OAuth access and refresh tokens are not provided to the model as task context.

AI outputs can contain personal data supplied in the task. They are stored as workspace results and made accessible according to organization permissions. Connecting Gmail does not give the AI model access to the Gmail inbox.

4. Google Sign-In is separate from Gmail

Google Sign-In is used for account authentication and the basic identity information returned by Google. Connecting Gmail is a separate consent flow for sending email. Signing in with Google alone does not authorize Gmail sending. The account shown during Gmail authorization can differ from the account used to sign in to OficinaViva.

5. GOOGLE USER DATA — Gmail OAuth access

Gmail connections request the following permissions:

  • https://www.googleapis.com/auth/gmail.send: send emails from the connected Gmail account.
  • openid and email: identify the account and display its email address.

We obtain the Google account identifier and email, granted scope information, access/refresh tokens and token expiry information. Gmail sending returns message identifiers used to record the operation. We do not request permission to read, search or download inbox messages, inspect contacts, or manage mailbox contents. The unified sales inbox in OficinaViva is not a synchronization of your Gmail inbox.

We process the recipient, subject and message content supplied or prepared within OficinaViva to submit an authorized email to Google. A connection belongs to a specific organization and records who connected it; multiple Gmail accounts can be linked. Agents require explicit permission for the selected connection. Connecting an account does not itself send an email or bypass approval, suppression or sending-limit checks.

6. GOOGLE USER DATA — use, sharing and Limited Use

Information received through Google APIs is used only to provide and secure the user-facing functions described here: identifying the connected account, maintaining the authorized connection, submitting authorized email and recording its outcome. It is not sold, used for advertising, or used to train generalized AI or machine-learning models.

Google-derived identity and connection information is stored by our infrastructure providers to operate this integration. Tokens are used only by the server-side integration to communicate with Google; they are not shared with other organizations or exposed to AI models. Google receives the email content and recipients submitted for an authorized send. Content supplied by you to ask an AI agent to draft a message may be processed by the relevant AI provider for that request; this does not enable inbox access.

Any transfer of Google user data is limited to providing or improving the integration’s user-facing features, meeting applicable law, security purposes such as investigating abuse, or a merger/acquisition or asset sale subject to prior notice and consent where required by Google’s policy. Human access to Google user data is restricted to authorized circumstances: your explicit consent for specific data, necessary security investigation, legal obligations, or permitted internal operations involving aggregated and anonymized data.

OficinaViva’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. This statement does not claim Google verification, certification or completion of a third-party security assessment.

7. Security and access controls

Integration credentials are stored encrypted server-side and scoped to their connection and organization. Server-side authorization and organization-scoped access rules restrict data operations; agent tool permissions and approval checks are revalidated when actions run. Private files use controlled access rather than intentionally public download links.

Authorized organization members may access shared workspace data and integration account information according to their roles; encrypted tokens are not displayed in the interface. We use these safeguards to reduce unauthorized access, but no system can guarantee absolute security. Do not share credentials or upload material your organization is not authorized to use.

8. Providers and disclosures

OficinaViva relies on Lovable Cloud for application infrastructure, authentication, database and private file storage; the Lovable AI gateway and the model providers serving requested AI tasks; Google for Google authentication and Gmail; and external media services only when connected and used for an authorized task. Different providers may process data in different countries and apply their own retention and security terms.

We do not promise that all providers retain data for the same period or that every model has zero retention. Provider selection and workspace privacy settings affect available AI services. Data may also be disclosed when required by law or to protect security and legal rights, subject to the Google-specific restrictions above where applicable.

9. Storage, retention and disconnection

Workspace records, task history, results, uploaded files, message records and audit/usage logs are retained to operate the workspace and support security and accountability. There is not currently a published, verified fixed retention schedule or an automatic account-deletion deadline; we do not promise immediate permanent deletion.

Disconnecting Gmail disables the connection and removes locally stored OAuth credentials. The service attempts token revocation with Google, but a failed remote revocation must not be interpreted as confirmed Google-side revocation. You can independently remove access in your Google Account’s third-party connections settings.

Disconnecting does not delete existing organization tasks, email records, connected-account metadata or audit history, and it does not recall emails already delivered by Gmail. Deleting a file from the Library may archive it for restoration rather than immediately erase every stored version. A separate erasure request is needed for permanent deletion, subject to lawful retention and backup limitations.

10. Choices, rights and deletion requests

You can choose whether to connect Gmail, deny OAuth consent, disconnect a connection and manage organization/agent permissions if your role permits it. You may request access, correction, export or deletion of personal information, or exercise other rights provided by applicable law. Organization-controlled information may require coordination with your organization administrator.

The privacy contact is [Verified privacy contact email — pending]. Until that contact is provided, this page does not offer a complete operational privacy-request channel. The operator must supply it, the applicable jurisdiction and a retention/deletion procedure before seeking Google OAuth verification. Google authorization can still be revoked directly through your Google Account.

11. Sessions and technical storage

Authentication uses browser session storage and/or cookies as needed by the sign-in flow. The workspace also stores local preferences such as the selected organization and records operational product events. This policy does not claim a separate advertising or tracking program. Browser-native dictation, when available and selected, is handled by the browser’s speech service and its applicable terms.

12. Updates and operator contact

Changes will be reflected on this page with an updated date; material changes require appropriate notice. No new use of Google user data outside the disclosed purposes is authorized by this text alone.

Trade name: OficinaViva. Website: https://oficinaviva.app.

Legal operator: [Operator legal name — pending]. Address: [Operator address — pending]. Privacy contact: [Verified privacy contact email — pending]. Applicable jurisdiction: [Jurisdiction — pending].