Nostocia and Claudia Privacy Policy
Last updated: October 5, 2026
This is an English translation of the Spanish policy published at nostocia.com/legal/privacidad/. If the two differ, the Spanish text prevails.
Nostocia is the platform a company uses to set up Claudia, an assistant that works for one person: it reads what that person authorises it to read, prepares drafts, proposes actions, and does not execute anything that leaves that person's account without their approval. This policy explains what data we process to make that work, including data from your Google account when you choose to connect it, how long we keep it, who we share it with, and how you can revoke access or ask us to delete it.
This policy covers the panel (panel.nostocia.com), the Claudia assistant and the connection services (connectors.nostocia.com). The access request form on nostocia.com has its own section at the end.
1. Who is responsible
Controller: Skydesk International ESPJ Tax ID (NIF): E94193349 Address: Rúa Paraíso 44, 36940 Cangas do Morrazo, Pontevedra, Spain Privacy contact: claudio@skydeskinternational.com Phone: +34 886 02 07 10
When a company contracts Nostocia for its employees, that company decides what Claudia is used for and we process the content of connected accounts on its instructions, under a data processing agreement. In that case the company is the controller of that content and we are the processor. We remain controller of your user account data, security logs and the commercial relationship. If you contract Nostocia as an individual, we are controller for everything described here.
2. What data we process
2.1 Your Nostocia account
Name, email address, the organisation you belong to, language, one-time access codes, technical session cookies, date and origin of sign-ins, and security logs (access attempts, administrative actions).
2.2 What you write to Claudia and what Claudia produces
Your chat messages with Claudia, files you upload to the panel, the drafts Claudia prepares (emails, documents, events), the decisions you approve or reject, the routines you schedule, the reports it generates for you and the memory notes Claudia keeps to remember what you told it.
2.3 Your Google account data (only if you connect it)
Claudia only accesses Google when you connect your account from the panel and accept Google's permission screen. We request three permissions. For each one, this is what Claudia does and does not do:
Gmail (gmail.modify scope: read, organise, draft and send).
- Reads and searches your mailbox to answer you, spot pending matters and prepare replies.
- Marks as read, archives, moves between labels and moves to trash, as part of the organisation you ask for.
- Creates draft replies.
- Sends an email only after you approve that specific send in the panel.
- Cannot permanently delete messages: the scope we request does not allow it.
- We request this scope, rather than a combination of "read-only" and "compose", because mailbox organisation (mark read, archive, move) is not covered by the narrower scopes.
Google Drive (drive scope: read and write files).
- Searches and reads files and folders to answer you and to file documents where you tell it to.
- Creates documents and uploads files to working folders.
- Sharing, moving, replacing or trashing a file requires your explicit approval each time.
Google Calendar (calendar.events scope: events on your primary calendar).
- Reads your events to know your availability and prepare what you ask for.
- Creating, updating or cancelling an event requires your explicit approval, because an event with guests sends invitations and cancellations to other people.
- We do not request the broader calendar scope, which would expose every calendar you can see.
When you connect the account we also receive the email address and name of the Google account you authorised, to associate it with your Claudia and to check that a reconnection matches the same account.
2.4 Third-party data
Emails, documents and events processed by Claudia contain data about other people (senders, recipients, guests, people mentioned). We process that data solely to provide the service to you; we do not build profiles of those people or use their data for any other purpose.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the service: authenticating your account, carrying out what you ask Claudia, keeping its working memory | Performance of the contract with your organisation or with you (Art. 6(1)(b) GDPR) |
| Accessing Gmail, Drive and Calendar on your behalf | Your consent, given on Google's permission screen and withdrawable at any time (Art. 6(1)(a) GDPR); the specific use is also governed by your organisation's instructions |
| Security: access logs, action audit trail, abuse detection | Legitimate interest in protecting the service and its users (Art. 6(1)(f) GDPR) |
| Billing and legal obligations | Compliance with legal obligations (Art. 6(1)(c) GDPR) |
| Support | Performance of the contract (Art. 6(1)(b) GDPR) |
We make no automated decisions with legal effects on you. Claudia proposes; the person decides.
4. How we use Google data: Limited Use commitment
Nostocia's use of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
Specifically:
- We use your Google account data only to provide the Claudia features you see in the panel. We do not use it for advertising or creditworthiness assessment, and we do not sell or transfer it to data brokers.
- We do not use your Google data to train or improve general-purpose artificial intelligence models, and we do not allow the providers that process data on our behalf to do so.
- No one on our team reads the content of your emails, files or events, unless you expressly authorise it to resolve an issue, it is necessary for security (investigating abuse or a bug) or the law requires it.
- We transfer Google data to third parties only where necessary to provide the service to you (see section 6), for security, to comply with the law, or, with your prior consent, as part of a corporate reorganisation.
- If we ever needed to access a type of data this policy does not describe, we would update the policy and ask for your permission again before doing so.
5. Where data is stored and for how long
Nostocia's services run on servers of a hosting provider located in the European Union (Germany). The credentials Google gives us to act on your behalf are stored encrypted (AES-256-GCM) and never in plain text.
We do not copy your mailbox, your Drive or your calendar. Claudia queries Google when it needs to and works with the result. What we do keep is what Claudia produces while working for you:
| What | How long |
|---|---|
| Encrypted credentials for your Google account and the identity of the authorised account | Until you disconnect Google from the panel or close your account |
| Drafts, decisions, chat messages, uploaded files, reports, routines and Claudia's memory notes | While your account is active; deleted when you close it (see section 8) |
| Connector action log (which tool was used, on which service, when; never the content of an email or document) | 30 days; purged automatically |
| Panel access and security logs | While your account is active and for at most twelve months afterwards |
| Encrypted server backups | 14 days, then deleted |
| Billing data | The periods required by tax and commercial law |
6. Who we share data with
We do not sell personal data. We share data only with these categories of recipients, which process data on our behalf under a contract that binds them to our instructions:
- Hosting provider in the European Union, where the panel, Claudia and the connection services run.
- Artificial intelligence model providers. To answer you, Claudia sends the model the text it needs for that task: your question, the excerpt of the email, document or event the answer depends on, and the results of the tools it uses. The provider processes that data to generate the answer, on our behalf and under its contract with us, which prohibits using it to train its models. Where that provider is outside the European Economic Area, the transfer relies on a European Commission adequacy decision or on standard contractual clauses; you may ask us for a copy of those safeguards.
- Email delivery provider for panel access codes and notifications.
- Google, which receives the requests Claudia makes on your behalf, under its own privacy policy.
- Your organisation, which sees what its contract with us provides: who uses Claudia and the status of the service, not the private content of your mailbox, unless the service configuration in your organisation says otherwise and we have informed you of it.
- Public authorities, where a law obliges us.
7. How to revoke Google access
You can cut off Claudia's access to your Google account at any time, in two ways; we recommend using both:
- From the Nostocia panel: under Connections, disconnect Google. We immediately delete the credentials we held; Claudia can no longer read or write to your account.
- From your Google Account: go to https://myaccount.google.com/permissions, find Nostocia and choose "Remove access". Google stops issuing credentials to Nostocia. A credential already issued may remain valid for a short period (up to one hour) until it expires.
Revoking access deletes nothing from your Google account: your emails, files and events stay where they were. It also does not by itself delete what Claudia produced (drafts, notes); for that, request account closure (section 8).
8. Account closure and deletion
You can request closure of your Nostocia account by writing to claudio@skydeskinternational.com or through your organisation. On closure we delete your Google credentials, drafts, chat messages, uploaded files, memory notes and Claudia's logs within 30 days at most. Encrypted backups that may contain that data are deleted within 14 days of their creation. We keep only what a legal obligation requires (for example, billing data) and security logs for the period stated in section 5.
9. Your rights
You may ask us for access to your data, to rectify it, erase it, restrict its processing, object to it, and receive it in a portable format. Where processing is based on your consent, you may withdraw it at any time without affecting earlier processing. Write to claudio@skydeskinternational.com stating which right you wish to exercise; we will reply within one month. If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Authority (Agencia Española de Protección de Datos, www.aepd.es).
If your organisation is the controller of the content Claudia processes, we will forward your request to it and help it respond.
10. Security
Encryption in transit (TLS) and at rest for credentials; one Claudia per person, with no access to anyone else's data; separation between what the model may request and what can only be executed with your approval; audit logs without email or document content; encrypted backups. If a breach affecting your data occurred, we would inform you, your organisation and the supervisory authority where the law requires it.
11. Access request form on nostocia.com
If you fill in the form on the website, we process the email address you give us and what you tell us about your situation to handle your request and, where appropriate, start the commercial relationship. The legal basis is the pre-contractual measures you request. We do not add you to marketing lists without a valid legal basis. We keep that data while handling the request and, if no relationship follows, for at most twelve months after the last contact. The website is served by a hosting provider and form emails are sent through an email delivery provider; where either of them processes data outside the European Union, the transfer relies on contractual safeguards.
12. Changes to this policy
If we change the way we process Google data, we will update this policy and ask for your permission again before applying the change. For other material changes we will notify you in the panel or by email. The date of the last update appears at the top.
