SOVA Intelligence
SOVA Intelligence WorkspaceInternal business platform
Effective 28 September 2026

Privacy Policy

This Privacy Policy explains how SOVA Intelligence (M) Sdn. Bhd. handles information used by SOVA Outreach Automation, including information received through Google APIs.

1. Scope

SOVA Outreach Automation is an internal business application for authorised SOVA personnel. It supports lead management, client-project workflows and outbound business email.

2. Google user data we access

When the official SOVA Gmail account is authorised, the application requests permission to send email through Gmail and basic account identity information needed to confirm that the authorised account is the official SOVA mailbox.

The application is not designed to read the Gmail inbox, retrieve email history, delete email, manage contacts, or access unrelated Google Drive, Calendar or other Google data.

3. How Google user data is used

Google user data is used only to authenticate the official SOVA mailbox and to send outbound emails that an authorised SOVA user has selected and confirmed in the workspace. Gmail access is not used for advertising, profiling or sale of data.

4. How authorisation is stored

The Gmail password is never collected or stored by the SOVA workspace. Google handles the account sign-in directly. After consent, an OAuth refresh permission may be stored in SOVA's protected Supabase backend so the official mailbox can remain connected without asking the CEO to sign in for every sending session. That refresh permission is not exposed to normal browser users.

5. Email and campaign records

The workspace may store operational records such as recipient company, recipient email address, campaign subject, attachment filename, sender email address, send time and the Gmail message identifier. These records support audit history, follow-up management and duplicate-send prevention. Email attachments selected for a campaign are transmitted for sending and are not intentionally stored as permanent database files by this workflow.

6. Sharing and disclosure

SOVA does not sell Google user data. Data is shared only with service providers needed to operate the application, such as Google for Gmail delivery, Supabase for the protected backend/database, and Cloudflare for website delivery, subject to their respective service terms and security controls.

7. Data retention and deletion

OAuth authorisation is retained while the official SOVA mailbox remains connected. A SOVA administrator can disconnect the mailbox, which removes the stored connection from the application and attempts to revoke the Google OAuth permission. The Google Account owner can also revoke the application's access from Google Account security settings.

Operational campaign records are retained for legitimate business administration, audit and duplicate prevention. Requests concerning deletion or correction can be sent to sova.myhq@gmail.com.

8. Security

Access to the internal workspace is restricted to authorised accounts with role-based permissions. Sensitive OAuth credentials and refresh permissions are kept in the server-side backend and are not intentionally exposed in frontend code.

9. Google API Services User Data Policy

SOVA's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

10. Changes and contact

This policy may be updated if the application's data practices change. Questions about privacy, Google authorisation or this application can be sent to sova.myhq@gmail.com.