1. Who this policy covers
The Vivian Capital Group application is a private business platform operated by Vivian Capital Group for its employees and authorized affiliated sister organizations. In this policy, “Vivian,” “we,” “us,” and “our” refer to Vivian Capital Group as the platform operator.
The service is not open for public registration. Access is limited by an invitation, an approved business email domain, an organization membership, and role-based permissions. This policy is public so that users can review it before signing in or authorizing a Google account.
2. Information we collect
Depending on the features an authorized user chooses, we collect:
- Account information: name, business email address, profile image, organization, membership, role, and authentication identifiers.
- Google sign-in data: basic profile information provided through Google Sign-In, including name, email address, and profile image. Signing in does not by itself grant Vivian access to Gmail.
- Gmail data: when an authorized user or organization administrator separately connects a mailbox, Vivian may access the mailbox address, message and thread identifiers, senders, recipients, subject lines, timestamps, labels, message bodies, attachments, and drafts or messages composed and sent through Vivian.
- Calendar data: if a user separately connects Google Calendar, Vivian may access event titles, times, descriptions, attendees, meeting information, and the calendar identifiers needed to synchronize or create events.
- Business workspace data: clients, contacts, deals, documents, notes, tasks, pipeline activity, internal messages, and other records users enter or file in Vivian.
- Technical information: session records, IP address and request metadata, timestamps, error details, audit events, and information needed to secure and operate the service.
3. How Google data is used
Google account data is used only to provide the user-facing features that an authorized user or organization requests. Those features include authenticating a user, synchronizing a connected mailbox into the shared inbox, displaying and searching conversations, organizing mail, composing and sending messages, filing selected communications and attachments into the organization's business records, and synchronizing connected calendar events.
Vivian requests the Gmail permission needed by its shared-inbox features. The permission allows Vivian to read, compose, send, and organize email; Vivian does not request permission to bypass Gmail Trash and permanently delete messages. A mailbox connection is a separate authorization from Google Sign-In.
Vivian's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, use it for advertising, or transfer it to advertising platforms, data brokers, or information resellers.
4. How other information is used
We use information in Vivian to:
- provide, maintain, synchronize, and improve the service;
- route each user into the correct sister organization and enforce role-based access;
- support authorized communication, document management, workflow, collaboration, and audit-history features;
- detect abuse, investigate errors, protect accounts, and preserve the integrity of organization records;
- respond to support, privacy, and legal requests; and
- comply with applicable law and enforce our agreements.
5. Who can see organization data
Information in a sister organization's workspace is available only to authorized users according to their assigned role. Authorized administrators of Vivian Capital Group may access affiliated workspaces when necessary to administer the corporate group and the service. Users should connect a mailbox only when their organization has authorized the resulting shared access.
People with access to a shared inbox may be able to view messages and attachments imported from a connected shared or personal mailbox. The mailbox connection screen identifies the requested permissions before the user leaves Vivian for Google's consent screen.
7. Security
Vivian uses administrative, technical, and organizational safeguards designed to protect information. These include encrypted network transport, encryption at rest where supported by our infrastructure, application-level encryption for stored Google OAuth refresh tokens, tenant-scoped data access, role-based authorization, and audit and operational logging that is designed not to record OAuth secrets.
No method of storage or transmission is completely secure. Authorized organizations and users are also responsible for protecting their Google accounts, devices, and Vivian sessions and for promptly reporting suspected unauthorized access.
8. Retention, disconnection, and deletion
We retain information while it is needed to provide the service, maintain legitimate business and audit records, meet contractual obligations, resolve disputes, or comply with law. Retention may vary by record type and by the instructions of the organization that owns the workspace.
Disconnecting Gmail removes Vivian's stored refresh token and stops future mailbox synchronization. Previously imported messages and attachments may remain in the organization's workspace as business records until they are deleted under the organization's retention process or in response to an approved deletion request. Users can also revoke Vivian's Google access from their Google Account permissions.
To request access, correction, export, or deletion, contact the workspace administrator or email us. We may need to verify the request and coordinate it with the organization responsible for the workspace.
9. Your choices
- Do not connect Gmail or Calendar if you do not want it synchronized.
- Disconnect an integration in Vivian and revoke the grant in your Google Account when you no longer want future access.
- Ask an organization administrator to update your membership, role, or workspace records.
- Contact us about a privacy request or concern using the address below.
10. Changes to this policy
We may update this policy when the service, our data practices, or legal requirements change. We will publish the revised policy here, update the date above, and provide additional notice when required.
11. Contact us
Privacy questions and requests may be sent to privacy@viviancapitalgrp.com.