Follow On:

Select your language

Image
Image

Privacy Policy - Google Services

NEBULAS

Privacy Policy

ERP management software with Google Authentication, Gmail, Google Drive, and Google Calendar integrations

Data Controller BETA TECHNOLOGIES SRL
Version 1.0
Last updated 27/07/2026

Document prepared for publication on the website and for configuring the Google OAuth consent screen.

1. General information

This privacy notice describes how [FULL COMPANY NAME], acting as data controller for the processing activities under its responsibility, collects, uses, stores, protects, and shares the personal data of users of the ERP management software named “Nebulas”.

Nebulas is a platform primarily intended for companies, professionals, and organizations and provides, among other features, the management of customers and suppliers, quotations, orders, invoicing, payments, products, services, inventory, documents, communications, and appointments. The platform may also integrate with Google services, including Google Authentication, Gmail, Google Drive, and Google Calendar.

2. Data Controller

Company name BETA TECHNOLOGIES SRL
Registered office Via Predda Niedda 22B, Sassari 07100
Tax code / VAT number Tax Code 02412440907 - VAT No. 02412440907

3. Privacy roles when using the management software

For data entered by users into the management software on behalf of their organization, the Nebulas customer normally determines the purposes and essential means of processing and acts as the data controller. BETA TECHNOLOGIES SRL, when processing such data to provide the service, normally acts as data processor pursuant to Article 28 of Regulation (EU) 2016/679, on the basis of the applicable contract and data processing agreement.

For data processed for its own purposes, such as contract management, platform security, account administration, and legal compliance, BETA TECHNOLOGIES SRL instead acts as an independent data controller.

4. Categories of data processed

4.1 Nebulas account data

  • first and last name;
  • email address and, when provided, telephone number;
  • company or organization to which the user belongs;
  • role, profile, groups, and application permissions;
  • credentials or identifiers required for authentication;
  • account status, preferences, and settings;
  • date, time, and outcome of login attempts.

4.2 Business data entered into the platform

When using the ERP features, data relating to customers, prospective customers, suppliers, contacts, employees, collaborators, and other individuals may be processed, including:

  • identification, tax, and contact details;
  • quotations, orders, contracts, invoices, credit notes, and other administrative documents;
  • payments, due dates, and accounting information;
  • products, services, price lists, warehouses, stock levels, and inventory movements;
  • documents, attachments, notes, and communications;
  • appointments, activities, reminders, and organizational information.

The customer is responsible for the lawfulness, accuracy, relevance, and updating of the data entered into the system and for the information provided to data subjects.

4.3 Technical data, logs, and security

  • IP address and session identifiers;
  • browser, operating system, device, and application version;
  • date and time of operations;
  • pages and features used;
  • authentication, modification, synchronization, and export logs;
  • security events, application errors, and diagnostic data.

4.4 Support-related data

When a user requests support, identification and contact details, the content of the request, communications exchanged, screenshots, files, documents, and technical information necessary to diagnose and resolve the issue may be processed.

5. Data obtained through Google and Google Workspace

Nebulas allows users to connect their Google account through OAuth 2.0 and OpenID Connect. The connection may be used to authenticate the user and to enable specific integrations with Gmail, Google Drive, and Google Calendar. Access takes place only after the user has viewed the Google consent screen and authorized the requested permissions.

5.1 Google Authentication

When the user uses “Sign in with Google”, Nebulas may receive:

  • the unique identifier of the Google account;
  • first and last name;
  • email address and its verification status;
  • profile picture, where available;
  • basic information shown on the consent screen.

This data is used to identify the user, create or associate the Nebulas account, manage the session, display essential profile information, and prevent unauthorized access. Nebulas does not receive or store the password of the Google account.

5.2 Gmail

When the user enables the Gmail integration, Nebulas may access, within the limits of the authorized scopes, the following categories of data:

  • sender, recipient, carbon copy, and blind carbon copy addresses;
  • message subject, body, headers, metadata, date, and time;
  • labels, status, threads, and message identifiers;
  • attachments;
  • drafts and information required for sending.

Depending on the features actually implemented and authorized, Nebulas may:

  • display and search for messages connected with business activities;
  • associate messages and attachments with customers, suppliers, quotations, orders, invoices, cases, or other records;
  • import selected messages and attachments;
  • create drafts, send emails, reply to or forward messages;
  • update message labels, status, or archiving;
  • synchronize the information required for the requested feature.

Nebulas does not use Gmail data for personalized advertising, the sale of data, unsolicited commercial profiling, creditworthiness assessment, or the general training of artificial intelligence models. Messages and attachments are stored in Nebulas systems only when necessary for a feature requested by the user or for association with a business record.

5.3 Google Drive

When the user enables the Google Drive integration, Nebulas may access, within the limits of the authorized scopes:

  • names, identifiers, types, formats, and sizes of files and folders;
  • creation and modification dates;
  • owners, people with whom the file is shared, and permissions;
  • metadata, links, and folder structure;
  • the content of selected, created, or otherwise accessible files according to the granted scope.

Depending on the enabled features, Nebulas may allow users to select files, import or associate documents with the management software, create files or folders, export documents, update or replace files, read metadata, manage sharing requested by the user, and delete files created or managed through Nebulas when the operation is expressly requested.

Where technically possible, Nebulas limits access to files created or selected by the user through the application, for example by using the “drive.file” scope and selection tools made available by Google.

5.4 Google Calendar

When the user enables the Google Calendar integration, Nebulas may access, within the limits of the authorized scopes:

  • the list, name, description, and settings of calendars;
  • event title, description, date, time, time zone, and location;
  • organizer, attendees, email addresses, and attendance status;
  • free/busy availability;
  • recurrences, reminders, attachments, links, and video conferences;
  • event and calendar identifiers.

Depending on the enabled features, Nebulas may display appointments and availability, synchronize events, create, modify, or delete events, invite attendees, update attendance status, manage recurrences, and associate events with records, activities, or business cases.

5.5 Tokens and authorization information

To keep integrations active, Nebulas may store access and refresh tokens, identifiers of the connected account, the list of granted scopes, integration status, date of the last synchronization, and any technical errors. Tokens are protected using appropriate technical measures and used exclusively to communicate with the authorized Google APIs.

6. Purposes and legal bases

Purpose Description Legal basis
Registration and service provision Creation and management of accounts, authentication, provision of ERP features and requested integrations. Contract or pre-contractual measures
Security and abuse prevention Protection of accounts, data, and infrastructure; fraud detection; backups; business continuity. Legitimate interest and legal obligations
Support and service communications Handling requests, troubleshooting, and technical, administrative, and security notices. Contract and legitimate interest
Administrative and legal compliance Invoicing, accounting, tax obligations, requests from authorities, and protection of rights. Legal obligation and legitimate interest
Service improvement Diagnostics, performance measurement, error correction, and aggregated statistics. Legitimate interest; consent where required
Commercial communications Sending promotional communications where permitted by law. Consent or another legal basis provided by law

7. Use and protection of Google data

Nebulas's use of information received from Google APIs must comply with the Google API Services User Data Policy and the applicable Limited Use requirements. Google data is used exclusively to provide or improve features requested by the user and clearly visible within the application.

  • Nebulas requests only the permissions necessary for the available features;
  • it does not sell Google data or license it to data brokers or advertising platforms;
  • it does not use Google data for personalized advertising;
  • it does not use the data for purposes incompatible with those authorized;
  • it restricts internal access to personnel and systems that genuinely need it;
  • it retains data only for the period necessary for the stated purposes;
  • it deletes or anonymizes data when it is no longer required, subject to applicable legal or contractual obligations.

7.1 Human access to Google data

BETA TECHNOLOGIES SRL personnel do not normally access the content of Google emails, files, or calendars. Human access may occur only when:

  • the user has provided explicit consent to receive support;
  • it is necessary to resolve a reported technical issue;
  • it is necessary to investigate a security incident, abuse, or fraud;
  • it is required by a legal obligation or a competent authority;
  • the data has been aggregated or anonymized so that the user cannot be identified.

7.2 Artificial intelligence

Nebulas does not use data obtained from Gmail, Google Drive, or Google Calendar to train general-purpose artificial intelligence models. Where an artificial intelligence feature processes Google data to perform a specific operation requested by the user, the processing will be limited to that feature, only the necessary data will be transmitted, and any providers involved will be subject to data protection and use-limitation obligations. Any use for training purposes would require separate, specific, and explicit consent and an update to this privacy notice.

8. Recipients and data sharing

Personal data may be disclosed, within the limits of necessity, to the following categories of recipients:

  • hosting, cloud infrastructure, backup, and security providers;
  • Google, for authentication and use of the authorized APIs;
  • email, communication, monitoring, and support service providers;
  • technical, legal, tax, and administrative advisers;
  • affiliated companies or partners involved in providing the service;
  • public, judicial, or supervisory authorities where required by law.

Providers that process data on behalf of the controller are appointed as data processors where required. Google data is not transferred to advertising platforms, data brokers, or parties that use it for their own independent commercial purposes.

9. International transfers

Some technology providers may process personal data in countries outside the European Economic Area. In such cases, the controller uses the safeguards provided for under Articles 44 et seq. of the GDPR, such as adequacy decisions, Standard Contractual Clauses, the Data Privacy Framework where applicable, and supplementary technical and organizational measures.

10. Processing methods and security

Data is processed using IT and electronic tools in compliance with the principles of lawfulness, fairness, transparency, data minimization, accuracy, storage limitation, integrity, and confidentiality. Measures adopted may include:

  • encrypted HTTPS/TLS connections;
  • authentication, authorization, and role-based access control;
  • logical separation of data belonging to different customers;
  • protection of credentials, secrets, and OAuth tokens;
  • logging and monitoring of relevant events;
  • backup, recovery, and business continuity;
  • updates, maintenance, and vulnerability management;
  • incident management procedures and restriction of administrative access.

No system can guarantee absolute security. Users must protect their credentials, use trusted devices, and promptly report any suspected unauthorized access.

11. Retention periods

Category Retention criterion
Account data For the duration of the relationship and for the subsequent period required to meet contractual and legal obligations.
Business data According to the customer's instructions and settings and the terms set out in the contract.
Tax and accounting documents For the period required by applicable law.
Google tokens For as long as the integration remains active or until revocation, disconnection, or the end of the relevant need.
Imported emails and attachments According to the rules applicable to the business record with which they are associated.
Imported or synchronized Drive files Until deletion, termination of the service, or expiry of the applicable contractual periods.
Synchronized Calendar events For as long as the integration or the corresponding business activity remains active.
Technical and security logs For a period proportionate to security, diagnostic, and service-protection requirements.
Backups Until natural rotation or overwriting in accordance with the adopted technical procedures.

12. Revocation of Google authorizations

The user may revoke the authorizations granted to Nebulas at any time:

  • through the integration settings available in Nebulas;
  • by disconnecting the Google account from the platform;
  • through the security and connection settings of their Google account;
  • by opening a ticket through the support portal.

Following revocation, Nebulas will no longer be able to make new access requests to the revoked services, the tokens will be revoked or deleted, and synchronizations will stop. Revocation does not automatically result in deletion of the Nebulas account or previously imported data where such data must be retained as part of documents, accounting records, business activities, or legal obligations.

13. Deletion of the account and Google data

The user may request deletion of the account or data obtained through Google by opening a ticket on the support portal. Where possible, the request must indicate the Nebulas account, the connected Google account, and the services concerned.

After verifying the identity and authority of the requester, Nebulas will, where applicable:

  • revoke and delete Google tokens;
  • disconnect the Google account;
  • stop synchronizations;
  • delete or anonymize Google data that is no longer required;
  • delete temporary copies according to technical rotation cycles;
  • provide confirmation that the request has been completed.

Some information may be retained where necessary to comply with accounting, tax, or legal obligations, instructions from the customer organization, protection of rights, fraud prevention, service security, or backup rotation.

14. Provision of data

The provision of data necessary for registration, authentication, and service delivery is required. Failure to provide such data may prevent account creation or use of Nebulas. Connecting individual Google services is optional, unless a specific purchased or configured feature depends on that integration.

15. Rights of data subjects

Where provided by law, the data subject may exercise the rights of access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and protection against decisions based solely on automated processing. Requests may be submitted through a support ticket. The controller may request information necessary to verify the identity of the requester.

Where the controller for the specific processing operation is the customer using Nebulas, the request may be forwarded to the customer or may need to be submitted directly to that customer.

16. Complaint to the supervisory authority

The data subject has the right to lodge a complaint with the Italian Data Protection Authority or the competent supervisory authority in the Member State in which they reside or work if they believe that the processing infringes applicable law. The right to seek judicial remedies remains unaffected.

17. Cookies and similar technologies

Nebulas may use cookies or similar technologies that are strictly necessary for authentication, session management, security, storage of technical preferences, fraud prevention, and proper operation. Any non-essential analytics or profiling cookies will be used in accordance with applicable law and, where required, with prior consent. For further information, see the Cookie Policy page.

18. Minors

Nebulas is intended for companies, professionals, and authorized users acting in a work or organizational context and is not directed specifically at minors. A customer that enters data relating to minors is responsible for ensuring an appropriate legal basis and compliance with applicable obligations.

19. Third-party services and links

Nebulas may contain links to or integrations with external services. Processing independently carried out by such parties is governed by their respective privacy notices. Use of Google services also involves processing by Google under the terms and notices applicable to the user's account.

20. Changes to this privacy notice

The controller may periodically update this Privacy Policy to reflect changes in law, new features, technical or organizational changes, changes in providers, or new processing activities. The updated version will be published together with the date of the latest update. In the event of material changes, users may be informed through Nebulas, by email, or through other appropriate channels.