Privacy notice (GDPR)
Version 2026-09-13. This notice is given under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).
1. Who we are
Controller: Dromix. Privacy contact: dromix.web@gmail.com. If the controller is not established in the EU/EEA, an Art. 27 representative is appointed when the processing is not occasional. Contact the privacy address above for the current representative details. On a licensed customer instance, the customer organisation is the controller of workspace accounts, messages, attendance, and directory data. Dromix (the vendor) is a processor only when it accesses that server for installation or support. Product site: https://dromix.net.
2. Two processing contexts
This public website (brochure, pricing, sales form) is controlled by the Dromix vendor. A customer’s self-hosted Dromix stores organisation data on that customer’s VPS or dedicated server. We do not read message contents from HQ. End-to-end encryption means ciphertext is stored on the customer machine; plaintext exists on user devices.
3. Categories of personal data
Account: name, work email, password hash, role, job title, department, optional phone/extension/office, avatar. Security: login times, IP, device label, MFA status, audit events. Workspace: chat membership, ciphertext of messages and notes, reactions, work-item metadata, meeting participation. Optional map location (latitude/longitude) while sharing is on. Attendance: clock-in/out time, optional GPS and IP as evidence of presence. Optional Google Calendar connection (only if you choose Connect Google): Google account email, OAuth access and refresh tokens, and upcoming primary-calendar event fields needed for reminders (event id, title/summary, start time, location, and event link). Sales site (HQ only): name, work email, company, optional phone, plan, seat estimate, domain, message, coarse IP.
4. Purposes and legal bases (Art. 6)
Contract / steps prior to contract (Art. 6(1)(b)): creating an invited account, signing in, delivering encrypted messaging and meetings, issuing a licence quote, and — if you connect Google Calendar — reading your upcoming events solely to send you personal calendar reminders inside Dromix. Legitimate interests (Art. 6(1)(f)): abuse prevention, audit logs, licence enforcement, answering a business inquiry; you may object. Consent (Art. 6(1)(a)): optional team-map location; cookie notice acknowledgement; optional Google Calendar connection (you may disconnect at any time); you may withdraw consent at any time. Legal obligation (Art. 6(1)(c)) and employment (Art. 88 / national labour law): attendance punch times may be kept by the employer even after an erasure request. We do not sell personal data and we do not run advertising profiles.
5. Google user data — access, use, and storage
When you connect Google Calendar, Dromix requests only the Google OAuth scopes openid, email, and https://www.googleapis.com/auth/calendar.readonly. We access your Google account email and read-only data from your primary Google Calendar. We use that Google user data only to (1) identify the connected calendar account and (2) deliver upcoming-event reminder messages to you in Dromix chat. We store encrypted OAuth tokens and the calendar email on the organisation’s Dromix server, plus short-lived reminder deduplication records (event id and start time). We do not store your full calendar history. You can disconnect Google Calendar in the product at any time; disconnecting deletes the stored tokens and connection for that account. Dromix’s use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
6. Sharing, transfer, and disclosure of Google user data
We do not sell, rent, or trade Google user data. We do not transfer or disclose Google user data to third parties for purposes other than providing or improving the calendar-reminder feature you requested. In particular, we do not share, transfer, or disclose Google user data to advertising platforms, data brokers, information resellers, credit or lending services, or for personalized/interest-based/retargeted ads, and we do not use Google user data to train generalized machine-learning or artificial-intelligence models. Recipients of Google user data are limited to: (a) you, the connecting user — reminder text (event title, time, optional location/link) is delivered only as a private Dromix message to you; (b) the organisation that operates this Dromix instance — Google user data stays on that organisation’s deployment (database and related infrastructure on the same server); organisation administrators may see connection metadata such as that Google Calendar is connected and the associated calendar email address, but not your full calendar contents through the admin UI; (c) Google — we call Google’s OAuth and Calendar APIs to obtain and refresh tokens and to read upcoming events; (d) the Dromix software vendor, only if the customer grants install/support access to that server (processor role), and only as needed for that support; (e) competent public authorities, if disclosure is required by applicable law. We do not otherwise share, transfer, or disclose Google user data to any third party.
7. Cookies and similar storage
The strictly necessary cookie “whatsup_session” keeps you signed in (HttpOnly, SameSite=Lax). Local storage on the device holds encryption keys for the vault, UI preferences, and consent flags. There are no advertising cookies and no third-party analytics cookies on this product. See the Cookie policy.
8. Recipients (other personal data)
On a customer instance, data stays on that organisation’s server (PostgreSQL, object storage, Redis, TURN/LiveKit on the same deployment). Staff of that organisation with admin roles can see directory fields, attendance, and audit metadata — not message plaintext. The vendor sees sales-form data on HQ, and may see server logs during contracted install/support (processor). Email delivery, if configured, uses the SMTP host the operator sets. For Google user data recipients, see section 6.
9. International transfers (Chapter V)
The customer chooses where the VPS is hosted. If that machine is outside the EU/EEA, the customer must use an appropriate safeguard (for example Standard Contractual Clauses) with the hoster. HQ sales records are stored on the vendor’s Dromix HQ server. We do not transfer message plaintext to third countries because we do not hold it. Google API requests are sent to Google; Google’s processing of those requests is governed by Google’s terms and privacy policy. Any Google user data stored by Dromix remains on the organisation’s chosen server location.
10. Retention
Sales inquiries: typically up to two years after last contact, or longer if a contract and invoices require it. Session cookies: hours or the remember-me period your organisation sets. Login events: about 12 months. Live map location: cleared when you stop sharing and swept if older than 24 hours. Messages and media: according to the organisation’s retention setting (or kept until erasure/offboarding). Consent records: kept as proof for up to three years. Audit events: kept for security and accountability. Google Calendar tokens and connection data: kept while the connection remains active and deleted when you disconnect or when the account is erased.
11. Your rights (Arts. 12–22)
You may request access, rectification, erasure, restriction of processing, data portability, and objection, and you may withdraw consent without affecting processing before withdrawal. Signed-in users can download an archive (Security → Download my data) and submit a request in the same screen or at /privacy/request. We respond within 30 days (Art. 12(3)), extendable by 60 days for complex cases. Erasure may be refused or limited where Art. 17(3) applies (legal obligation, establishment/exercise of legal claims, other people’s rights in a conversation).
12. How to exercise your rights
Email dromix.web@gmail.com or use the privacy request form. Identify the email address the data relates to. We may ask you to confirm identity. Complaints: you may lodge a complaint with the data protection authority of your EU/EEA member state (see https://www.edpb.europa.eu/about-edpb/about-edpb/members_en).
13. Automated decisions
We do not make solely automated decisions that produce legal or similarly significant effects (Art. 22). Account lockout after repeated failed logins is a security control, not profiling.
14. Children
Dromix is a workplace product. It is not directed at children under 16. Do not invite minors.
15. Security (Art. 32)
Passwords are stored with Argon2id. Messages use client-side end-to-end encryption; the server stores ciphertext. Private keys are wrapped with a key derived from your password. Google OAuth tokens are stored encrypted at rest. Transport uses TLS on production URLs. Access is invite-only. Optional MFA (TOTP) can be required by the organisation.
16. Personal data breaches (Arts. 33–34)
The controller will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach, unless it is unlikely to result in a risk to rights and freedoms. High-risk breaches are communicated to affected people. On a customer instance, that duty sits with the customer; the vendor assists as processor when it is involved.
17. Changes
We will update this notice when processing changes. The current version is 2026-09-13. Material changes will be pointed to from the product or this website. If we change how we use Google user data, we will update this notice and obtain any consent required before using that data in a new way.
Sales: dromix.web@gmail.com