Last updated: 11 November 2025
Out of Band AS (Org.Number: 935632765) ("Out of Band", "we", "our", or "us") operates the Out of Band web and mobile applications (collectively, the "Service").
This Privacy Policy explains how we collect, use, share, and safeguard information in connection with your use of the Service.
By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please discontinue use of the Service.
Depending on the context, Out of Band may act as either a data controller (for our own operations and marketing) or a data processor (when providing the Service to enterprise customers).
We collect limited personal information that you provide when creating an account or using the Service, such as:
When the Service is used by clients, Out of Band primarily processes system metadata (e.g., event timestamps, user identifiers, connection logs) required for synchronization and communication. We do not permanently store customer content or incident data after synchronization is complete.
We automatically collect certain technical information to ensure functionality and security, including:
We use collected information to:
We use a limited number of trusted sub-processors who perform technical and operational functions on our behalf. Each is bound by written data processing agreements ensuring compliance with the EU General Data Protection Regulation (GDPR).
| Service Provider | Purpose | Data Location | Data Types / Notes |
|---|---|---|---|
| Stream (GetStream) | Communications and secure chat functionality | European Union (Ireland) | Communication content, user identifiers, metadata |
| Google Cloud Platform | Cloud infrastructure, data processing, and API services | EU | Basic user data, incident data, operational data |
| Google Firebase Messaging | Push notifications | As per Google's data center locations as notification delivery is a global service | Device tokens, notification content |
| Google Vertex AI | AI features | EU | Google does not use customer data to train or improve models; no data retention by AI system [1] |
| HubSpot | Customer relationship management (CRM) | EU | Contact information |
| Slack | Internal communications | EU | Internal communication |
| Microsoft Entra ID (Azure AD) | Enterprise identity and access management through our multi-tenant application | EU | User identities |
| Sentry | Application error tracking and performance monitoring | EU | Error logs |
| Cloudflare | DDoS protection / Proxy DNS | Global network | IP addresses, DNS queries |
Note: We may engage additional service providers as needed to enhance our Service. Any new providers will be subject to the same privacy and security standards outlined in this policy.
Out of Band uses Google Cloud's Vertex AI platform (see Section 4: Data Sharing and Sub-Processors for details) to provide AI-assisted incident summarization. This feature helps teams quickly understand incident context by automatically generating concise summaries from incident logs.
When an incident summary is requested, relevant incident log data is transmitted to Vertex AI (hosted in the EU region: europe-west4) where Google's Gemini model generates a natural language summary. The summary is returned and stored in your incident record. No training, fine-tuning, or long-term retention of your data occurs within the AI model.
This AI feature is designed to minimize risk while providing valuable incident management capabilities, fully aligned with GDPR and our broader data protection standards.
We apply appropriate technical and organizational measures to protect information, including:
While advanced safeguards are in place, no system can be made completely secure.
Information is retained only as long as necessary to deliver the Service or fulfill contractual and legal obligations.
Transient synchronization data and metadata are automatically deleted or anonymized once no longer required for operational purposes.
Depending on your jurisdiction, you may have the right to:
To exercise your rights, contact us using the details below.
Where data is transferred outside the European Economic Area (EEA), such transfers are conducted in accordance with GDPR Articles 46–49, including use of the EU Standard Contractual Clauses (SCCs) and other appropriate safeguards.
Our Service is not directed at children under the age of 13 (or applicable local minimum). We do not knowingly collect data from such individuals.
We may update this Privacy Policy periodically. The revised version will be posted on our website with a new "Last updated" date.
For users within the EU/EEA, processing of personal data is based on one or more of the following:
Out of Band AS
Org.Number: 935632765
Norway
For privacy-related inquiries, please contact us through our official support channels within the application or at contact@outofband.app