1. Who is responsible for your data?
Excelso is the data controller for personal information processed in connection with accounts, authentication, and use of our public websites and applications described in this Policy, unless we act solely as a processor on behalf of an organization (e.g. a corporate client of Excelso Vault) under a written agreement—in that case, the organization’s privacy notice may also apply.
Contact (privacy requests and general inquiries): admin@excelso.space
2. Excelso Open, Excelso Vault, and multiple apps
We may process similar categories of data across apps (e.g. email, name, technical logs). Excelso Open-related processing typically supports community accounts, repositories, demos, and public-facing content. Excelso Vault-related processing may support contractual delivery, support tickets, billing, and stricter access controls.
Signing in with Google or another provider through Auth0 (or a comparable platform) may allow the same identity to be recognized across multiple Excelso apps you authorize. We do not use that fact to profile you for unrelated third-party advertising.
3. What data we collect
Account and identity data: name, email address, profile image URL if provided by Google or another OAuth provider, internal user identifiers, organization name (if applicable), role, language, and preferences.
Authentication data: tokens and session identifiers managed through Auth0 or our systems; security logs related to sign-in attempts; device and browser metadata needed to protect accounts.
Data you submit in each Service: messages to support, project or application content you create, uploads, and configuration you save—depending on which product you use.
Technical and usage data: IP address, approximate location derived from IP, user agent, timestamps, diagnostic and error logs, cookies or local storage, and product analytics needed to operate and secure the Services.
Payment data: where purchases exist, payment details are processed by payment partners; we typically receive limited metadata (e.g. transaction status) rather than full card numbers.
We do not knowingly collect sensitive categories of data unless a specific Service requires it and we provide a clear, lawful basis.
4. Purposes: why we use data (including non-spam commitment)
To create and maintain your account; authenticate you; link sessions across authorized apps; prevent fraud and abuse.
To provide the features of Excelso Open and/or Excelso Vault that you choose to use; to respond to support requests; to manage subscriptions or contracts where applicable.
To secure the Services, troubleshoot, monitor performance, and improve reliability.
To communicate with you about the Services (transactional messages, security alerts, and—where permitted—product updates relevant to apps you use).
To comply with law and enforce our Terms.
We do not sell your personal information as “sale” is commonly defined in privacy laws, and we do not use your personal data for spam or for malicious purposes. Marketing communications, if any, will relate to Excelso services you use or have requested, and you can opt out where required by law.
5. Legal bases: Argentina, EEA/UK/Switzerland, and beyond
Argentina: where Law 25.326 applies, we process personal data on bases such as your consent (e.g. optional cookies or marketing where required), the performance of a contract or pre-contractual steps, our legitimate interests in securing and improving the Services (balanced against your rights), or legal obligations. You may exercise rights of access, rectification, updating, suppression, confidentiality, and blocking of excessive or unlawful processing, and to withdraw consent where processing is consent-based, as provided by Law 25.326 and regulatory guidance from the enforcement authority (Agency for Access to Public Information / AAIP in its role regarding personal data protection).
EEA/UK/Switzerland: where GDPR-style rules apply, we rely on contract, legitimate interests, consent where required, or legal obligation as appropriate.
Brazil and other regions: where the LGPD or other local laws apply, we align processing with their requirements, including lawful bases and rights described in this Policy and in supplementary notices where needed.
6. Cookies and similar technologies
We use cookies and similar technologies for authentication, session management, security, preferences, and analytics where enabled. You can control some cookies through browser settings; blocking essential cookies may affect functionality.
7. Sharing and subprocessors
We share personal information with service providers who process it on our instructions, including identity (e.g. Auth0), OAuth providers you choose (e.g. Google), hosting, databases, email delivery, payments, analytics, and security vendors.
We may disclose information if required by law, legal process, or to protect rights, safety, and security.
If Excelso is involved in a merger, acquisition, or asset sale, personal information may be transferred as part of that transaction with appropriate safeguards and notice where required.
8. International transfers
Our providers may process data in countries other than your own, including the United States and the European Economic Area. For transfers from Argentina, we adopt measures consistent with Law 25.326 and applicable regulations. For transfers from the EEA/UK/Switzerland, we use appropriate safeguards such as Standard Contractual Clauses where required.
9. Retention
We retain personal information for as long as your account is active and for a reasonable period afterward to resolve disputes, enforce agreements, and comply with legal obligations. Backups may persist for a limited additional period.
You may request deletion of your account or certain data subject to legal retention needs.
10. Security
We implement technical and organizational measures designed to protect personal information. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
11. Your rights
Argentina: you may exercise the rights recognized under Law 25.326, including access, rectification, updating, suppression, confidentiality, blocking, and objection to unlawful processing, and may lodge a complaint with the AAIP as the enforcement authority, in accordance with current procedures.
EEA/UK/Switzerland and other regions: you may have rights of access, rectification, erasure, restriction, objection, portability, and withdrawal of consent where processing is consent-based, and the right to lodge a complaint with a supervisory authority.
To exercise rights, contact admin@excelso.space. We may need to verify your request.
12. California and other U.S. state privacy laws (summary)
If the CCPA/CPRA or similar U.S. state laws apply, you may have rights regarding access, deletion, correction, and opt-out of certain processing. Contact admin@excelso.space. We do not “sell” or “share” personal information for cross-context behavioral advertising as defined under CPRA in the way we operate the Services today; if that changes, we will update this Policy and provide appropriate choices.
13. Children
The Services are not directed to children under the age of digital consent. We do not knowingly collect personal information from children. If you believe we have collected such information, contact us and we will take appropriate steps to delete it.
14. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated version here and update the “Last updated” date. Where changes are material, we will provide additional notice as required by law (including, where applicable, registration with databases or authorities as required in Argentina).
15. Contact
Privacy questions and requests: admin@excelso.space