Privacy Policy
Last updated: 23 September 2026
This Privacy Policy applies to the website cyberlab.team, our client portal my.cyberlab.team (the "Platform"), and the software application CyberLab Client Cabinet that requests Google OAuth access. It explains how CyberLab.Team OÜ ("we", "us") collects, uses, and protects your personal data in strict accordance with the EU General Data Protection Regulation (GDPR) and Google's API data policies.
1. Controller Information
CyberLab.Team OÜ
Registry code: 14647320
Address: Sepapaja tn 6, Tallinn 15551, Estonia
General contact and privacy inquiries: info@cyberlab.team
2. Information We Collect
We collect personal data when you visit our Website, register on the Platform, or communicate with us.
2.1. Website and Account Data. Name, email address, business name, phone number, and IP address. If you choose to log in using "Sign in with Google", we receive your basic profile information (name and email) to create and authenticate your account, but we never receive or have access to your Google password.
2.2. Lead Forms and Inquiries. If you request a quote, book a consultation, or fill out a contact form on our public Website, we collect the information you provide (such as name, email, company name, and project details) to respond to your inquiry and propose our digital marketing services.
2.3. Payment Information.
- For card payments, we do not collect or store full credit card numbers; these are handled entirely by our secure payment processor, Stripe.
- For bank transfers to our corporate accounts at Revolut or Wise, we process your bank account details (e.g., IBAN, bank name) strictly for invoicing and accounting purposes under EU and Estonian financial regulations.
2.4. What We Do Not Collect. We do not collect passwords to your Google accounts (we use secure OAuth 2.0 tokens), nor do we collect personal identification documents used for Google Advertiser Verification.
2.5. Account Security Responsibility. You are strictly responsible for maintaining the confidentiality and security of your Platform login credentials. We are not liable for any data breaches, unauthorized access, or resulting damages that occur due to your failure to secure your account, compromised passwords, or shared access.
2.6. B2B Team Members Data. If you (as a business client) invite other team members to the Platform, you warrant and guarantee that you have obtained their lawful consent to share their contact details (e.g., email address, name) with us in accordance with the GDPR.
2.7. Third-Party Payment Processors. Financial data processed via Stripe is governed exclusively by Stripe's Privacy Policy. We do not control and are not responsible for the data collection practices or fraud-prevention algorithms utilized by Stripe.
3. Google API Services User Data Policy (Limited Use)
CyberLab.Team OÜ's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3.1. Data Access and Purpose (Scopes). Specifically, we request access to the following OAuth scopes: https://www.googleapis.com/auth/adwords (to manage advertising campaigns and fetch reporting) and https://www.googleapis.com/auth/business.manage (to synchronize your physical business locations with ad assets). This means we access: identifiers of your business locations, business addresses, aggregated statistics (routes, calls), and advertising campaign metrics. This data is accessed strictly to provide the Platform's core functionality (managing campaigns, syncing location assets, and displaying reporting dashboards).
3.2. No Data Brokerage. We categorically do not sell your Google user data to data brokers, nor do we share it for credit scoring or third-party ad targeting.
3.3. No AI/ML Training. User data obtained via Google Workspace APIs is not used to develop, improve, or train generalized Artificial Intelligence (AI) or Machine Learning (ML) models. Furthermore, Google API User Data is never transmitted to external third-party AI APIs (e.g., OpenAI, Anthropic) under any circumstances.
3.4. No Human Access. Humans are strictly prohibited from reading user data obtained via Google APIs unless: (a) we have your affirmative agreement, (b) it is necessary for security purposes (investigating abuse), (c) it is required by applicable law, or (d) the data is aggregated and used for our internal operations. Agency context: as a digital marketing agency, our authorized staff (marketers) access your data strictly through the Platform's reporting dashboards to render the contracted services. No staff member has direct access to your raw OAuth tokens or the underlying database containing them.
3.5. Security. All OAuth tokens (access and refresh tokens) are encrypted at rest (AES-256) in our databases.
3.6. No Data Transfer for Advertising. We strictly do not use or transfer the data obtained from Google Workspace or Google APIs for serving ads, including retargeting, personalized, or interest-based advertising.
3.7. Permitted Transfers. We will only transfer Google API data to third parties if it is strictly necessary to provide or improve user-facing features that are prominent in the requesting application's user interface, to comply with applicable laws, or as part of a merger, acquisition, or sale of assets.
3.8. Data Storage and Isolation. Data retrieved from Google APIs (such as advertising metrics and location data) is securely stored on our servers strictly to render your reporting dashboards and automate your specific campaigns. We categorically do not aggregate your Google data with other clients' data for cross-client profiling, nor do we sell it to data brokers.
3.9. API Dependency and Deprecation. The functionality of our Client Cabinet relies heavily on access to Google APIs. Should Google unilaterally modify, restrict, or deprecate certain API endpoints or change their data sharing policies, certain features or historical data within our Platform may become unavailable. We are not liable for any data access loss resulting from Google's infrastructural or policy changes, and such changes do not affect the validity of this Privacy Policy.
4. Legal Basis for Processing (GDPR)
We process your data under the following legal bases:
- Contract performance (Art. 6(1)(b)): to provide the Client Cabinet, authenticate users, process payments, and deliver our services.
- Legitimate interest (Art. 6(1)(f)): for website security (Cloudflare), fraud prevention, and aggregate analytics.
- Legal obligation (Art. 6(1)(c)): for accounting and tax compliance (e.g., storing invoices and bank transfer data under the Estonian Accounting Act).
We do not use your personal data for automated decision-making or profiling that produces legal effects concerning you (GDPR Art. 22).
5. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right to be informed: knowing how we use your data.
- Right of access: requesting a copy of the data we hold about you.
- Right to rectification: correcting inaccurate or incomplete data.
- Right to erasure: the "right to be forgotten", subject to our legal retention obligations.
- Right to restrict processing: blocking or suppressing further processing of your data.
- Right to data portability: receiving your data in a structured, machine-readable format.
- Right to object: objecting to processing for direct marketing or legitimate interests.
- Rights related to automated decision-making: protection against solely automated decisions.
To exercise these rights, email us at info@cyberlab.team. You also have the right to lodge a complaint with a supervisory authority, such as the Estonian Data Protection Inspectorate (www.aki.ee).
6. International Data Transfers
While we are based in Estonia (EU), some of our subprocessors (e.g., Google Cloud, Stripe) may process data outside the EEA. Such transfers are strictly safeguarded by the EU-US Data Privacy Framework (DPF) or Standard Contractual Clauses (SCCs) approved by the European Commission. The full list of subprocessors is in our Data Processing Agreement.
7. Data Retention and Data Deletion Policy
7.1. Data Retention. We retain account and billing data (including bank transfer details) for 7 years as required by Estonian accounting laws. Aggregated advertising analytics may be kept for up to 24 months for year-over-year reporting.
7.2. Data Deletion Policy (Right to Be Forgotten). You have the right to request the complete deletion of your account and all associated personal data. You can exercise this right directly through the Platform settings or by sending a deletion request to info@cyberlab.team. Upon request, your data will be permanently deleted or irreversibly anonymized within 30 days, barring data we are legally mandated to keep.
7.3. Revoking Google OAuth Access and Deletion. You can revoke our application's access to your Google data at any time via your Google Account security settings (myaccount.google.com/permissions). Once revoked, our system automatically detects the revocation and immediately initiates a cascading deletion protocol, guaranteeing the removal of all your OAuth tokens and cached Google API data from our active databases. Furthermore, if you request account deletion directly within our Platform, we not only delete your data from our servers but also proactively send a secure HTTP revocation request to Google's API to ensure the OAuth token is definitively invalidated on Google's side as well.
7.4. Automatic Token Deletion (Inactive or Canceled Accounts). In strict adherence to data minimization principles, if a client formally cancels their service contract with CyberLab.Team OÜ, or if an account remains entirely inactive for a period exceeding 6 months, we will automatically delete their Google OAuth tokens (access and refresh) and all cached Google API data from our systems within 30 days.
8. Children's Privacy
Our Platform and services are intended strictly for business professionals and adults over the age of 18. We do not knowingly collect personal data from children under 18. If we become aware that we have collected such data, we will take immediate steps to delete it.