Skip to Content

Risco ERP — Google Contacts & CRM Privacy Policy

Effective date: 3 September 2026

1. Service and contact details

Risco ERP provides the Gmail CRM Syncs contact-management integration at riscoerp.com. Its Google OAuth configuration uses the application name POS. This notice covers that integration, not unrelated website shopping, payment, analytics, or advertising services.

Our published business contact address is Versailles Center, ground floor, Jounieh, Lebanon. Privacy questions and deletion requests can be sent to info@riscotech-lb.com with the subject Risco ERP Privacy Request. Our telephone numbers are +961 9 641 333 and +961 70 540 587. Our Contact us page provides these contact details.

When a business manages a workspace, its administrator also determines which contacts are imported and which authorized staff use them. That business remains responsible for its own handling of those contacts.

2. Google data and permissions

For contact-management features, the integration processes names, email addresses, telephone numbers, organizations, job titles, websites, notes, contact labels and groups, and the identifiers needed to link Google and Risco ERP records. It maintains connected-account identifiers, synchronization results and timestamps, and OAuth credentials needed for the authorized connection.

The integration accesses Google Contacts and the account information needed to maintain the connection. It does not access Gmail message bodies or attachments, Google Drive files, or calendar events.

The account holder authorizes access through Google. Risco ERP does not request the account holder's Google password as part of contact synchronization. Depending on the permissions granted and the selected features, authorized operations include reading, creating, updating, or deleting contacts and managing contact groups. Scheduled synchronization may repeat configured operations while authorization remains valid.

3. Purposes and permitted uses

Contact data is used to display and organize contacts, maintain linked CRM records, synchronize selected changes, and show connection or synchronization results. Changes can affect local records and connected Google accounts, depending on the selected action and configuration.

Google-derived data is used for these disclosed contact-management features only. Connection consent does not authorize marketing to every person in an address book. Google-derived contacts are not supplied to marketing broadcasts or advertising audiences.

4. Google data restrictions and sharing

Risco ERP's use and transfer of information obtained through Google APIs will adhere to the Google API Services User Data Policy, including applicable Limited Use requirements.

Google-derived data will not be sold, supplied to data brokers, used to serve ads, or used for credit or lending assessments. Transfers will be limited to permitted purposes: the disclosed features with appropriate user consent, security, legal obligations, or a business transfer with the consent Google requires. Human access will be restricted to circumstances allowed by Google's policy; staff permissions alone are not a substitute for the required user authorization.

5. Storage, service providers, and access

Local copies are maintained in the Risco ERP contact-management environment, and synchronized copies may exist in the connected Google account. Google operates its services under its own Privacy Policy.

Service providers support infrastructure hosting, database and backup operations, integration maintenance, and technical support, only to the extent needed to provide the disclosed service. Providers with access are subject to appropriate confidentiality, security, and processing restrictions, with no independent reuse of Google-derived information. Workspace access reflects the account holder's authorization and the appropriate staff roles.

6. Security

Risco ERP uses secure transmission, appropriate protection for stored contact data and OAuth credentials, least-privilege access, and controlled administrative and backup access. Full access or refresh tokens are not included in ordinary application logs. Access needed for troubleshooting is limited to the relevant authorized purpose.

No internet service can promise absolute security. Users should protect their account credentials and review access to their workspace and connected accounts.

7. Retention and disconnection

Imported local contacts are kept while needed for the authorized workspace's contact-management purposes. We review continued need and delete them from active systems within 30 days of a verified deletion request or workspace termination, subject to a specific applicable legal obligation.

Disconnection stops future synchronization. Previously imported local contacts remain unless deletion is requested; disconnection and deletion are separate actions.

We stop using OAuth credentials when authorization ends and remove stored connection credentials within 24 hours of a confirmed disconnection or deletion instruction. Google-side revocation is also performed where applicable and authorized.

Routine synchronization logs are kept for no longer than 30 days, avoid unnecessary contact content, and exclude full tokens.

Deleted data expires from backup copies through a rotation period of no more than 90 days. Backup access is restricted, backups are not used for ongoing business processing, and completed deletions are reapplied after restoration.

A documented legal requirement may justify retaining particular business records for longer. It does not justify keeping all Google-derived data indefinitely. We explain any such exception and its effect on a request to the requester.

8. Revocation and deletion requests

An account holder can revoke access using Google Account connections. Revocation prevents continuing access under that authorization; it does not automatically delete local imports or undo previous changes in Google.

To request deletion from Risco ERP, email the contact in section 1 and identify the relevant account or workspace. Do not provide passwords, authentication codes, or tokens. Risco ERP will verify identity and authority proportionately, clarify the requested scope, and coordinate with the workspace administrator where needed.

We acknowledge requests within five business days and complete eligible active-system deletion within 30 days after verification, or sooner where applicable law requires. Backup treatment follows section 7. We explain any lawful exception.

Removing a local list membership, deleting a native Odoo contact, and deleting a Google contact are different actions. A local deletion request is not treated as authority to delete records from Google or another person's account without the corresponding authorization.

9. Other requests and policy changes

Depending on applicable law, individuals may have rights to access, correction, deletion, restriction, objection, or a copy of their information. Requests and concerns can be sent to the contact in section 1. This notice does not limit statutory rights.

This policy shows its effective date, which we update when the policy changes. New Google-data purposes or categories require updated disclosures and any required new consent before they are introduced. Editing a policy does not itself create user consent.