Sorsend Privacy Policy

At Sorsend, we take your privacy seriously and are committed to protecting your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). This Privacy Policy explains how we collect, use, store, share, and safeguard your personal data when you use our services as a natural person (individual), not acting on behalf of an organisation.

1. Who We Are – Data Controller

This Privacy Policy applies to Sorsend as the data controller for personal data processed in connection with the services we offer to individuals within the European Union.

Controller Contact Details:

  • Name: Sortask GmbH
  • Address: Münzgrabenstraße 44/12
  • Postal code: 8010
  • City: Graz
  • Country: Austria
  • E-Mail: office@Sorsend.com

2. Personal Data We Collect

We may collect and process the following categories of personal data:

  • a. Identity and Contact Data
    • Full name, email address
    • Contact details you submit via contact forms or support requests
  • b. User Content and Account Data
    • Emails and task content you upload or sync with our platform
    • Preferences, labels, and tags you apply
  • c. Device and Technical Data
    • Log data on your activity (e.g., access timestamps, clicked features)
    • Internet Protocol (IP) address, used only to infer your country so we can show the German or English marketing site
  • d. Usage and Interaction Data
    • Interaction patterns with features and settings
    • User behavior data for troubleshooting and optimization
  • e. Third-party Integration Data
    • Information retrieved from services you connect to Sorsend (e.g., Gmail, Outlook)
  • f. Marketing and Communication Preferences
    • Records of your communication choices (e.g., newsletter opt-ins)

3. How and Why We Use Your Personal Data

We process your personal data for the following purposes and under the respective lawful bases defined in Article 6 of the GDPR:

PurposeLegal Basis
To create and maintain your account and user profilePerformance of a contract (Art. 6(1)(b))
To provide services (task categorization, email sorting, project features)Performance of a contract (Art. 6(1)(b))
To respond to support requests or inquiriesLegitimate interest or pre-contractual steps (Art. 6(1)(f) or Art. 6(1)(b))
To send transactional notifications (e.g., service updates, security alerts)Legitimate interest (Art. 6(1)(f))
To send marketing communications (only with consent)Consent (Art. 6(1)(a))
To analyze service usage and improve performanceLegitimate interest (Art. 6(1)(f))
To comply with legal obligations (e.g., tax, fraud prevention)Legal obligation (Art. 6(1)(c))
To choose German or English on the marketing website from the country inferred from your IP address (DACH defaults to German; all other countries default to English)Legitimate interest (Art. 6(1)(f))

Website language and IP address

When you visit sorsend.com, we read the IP address of your request and infer only your country. This happens on our own infrastructure using a local country database. We do not send your IP address to an external geolocation provider for this purpose.

If the inferred country is Germany, Austria, Switzerland, or Liechtenstein (the DACH region), we show the German version of the marketing site. Visitors from all other countries see English. We do not store the IP address or the inferred country after the request is handled for this purpose.

You can switch language at any time with the language control. Your choice is stored in a strictly necessary first-party cookie named sorsend_locale so we do not need to infer your country again on later visits. Visiting an explicit German URL such as /de does not by itself lock you into German.

The legal basis is our legitimate interest in presenting the marketing site in a language likely to be useful (Art. 6(1)(f) GDPR). This is not automated decision-making with legal or similarly significant effects under Art. 22 GDPR. You may object by contacting office@sorsend.com or by selecting your preferred language.

4. Google User Data and Limited Use

This section was updated on 17 August 2026 to document the Google OAuth permissions Sorsend requests and our compliance with Google's Limited Use requirements.

When you connect a Google account to Sorsend, we request the five OAuth permissions listed below. We use each permission only to operate user-facing features in the Sorsend application.

Sorsend's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Permissions we request

  • Associate you with your personal info on Google (openid)
    • What we access: An OpenID identifier that associates your Google Account with your Sorsend account.
    • Why we use it: To sign you in securely and keep your Google identity linked to the correct Sorsend user.
    • How it is stored: Stored as part of your authentication records.
  • See your primary Google Account email address (email)
    • What we access: Your primary Google Account email address.
    • Why we use it: To create and identify your Sorsend account, display the connected mailbox, and route synced mail to the correct user.
    • How it is stored: Stored on your user and mailbox records.
  • See your personal info, including any personal info you've made publicly available (profile)
    • What we access: Your Google name and profile photo, if available.
    • Why we use it: To display your account identity inside Sorsend.
    • How it is stored: Your name and avatar may be stored on your user profile.
  • View your email messages and settings (gmail.readonly)
    • What we access: Gmail message content, headers, labels, and mailbox settings needed to sync Inbox and Sent mail.
    • Why we use it: To show your mailbox in Sorsend, categorize emails, create tasks and projects, and provide email intelligence features.
    • How it is stored: Synced message content and metadata are stored in your Sorsend workspace while your account remains active, or until you delete the data.
  • Send email on your behalf (gmail.send)
    • What we access: Permission to send email from your connected Gmail account. This scope does not by itself grant permission to read mail.
    • Why we use it: To let you compose and send replies and new messages from Sorsend using your own Gmail address (the Reply System).
    • How it is stored: Messages you send through Sorsend are stored in Sorsend and appear in your Gmail Sent folder. We do not send mail from your account unless you initiate that send in the product.

Limited Use commitments

Sorsend complies with Google's Limited Use requirements for Gmail and other restricted Google user data:

  • User-facing features only. We use Gmail and other Google user data solely to provide or improve user-facing features that are prominent in the Sorsend application, including mailbox sync, email display, AI-assisted categorization and task creation, and sending replies you compose.
  • No advertising. We do not use or transfer Google user data, including Gmail content, to serve advertisements. This includes retargeting, personalized ads, and interest-based advertising.
  • No unauthorized transfers. We do not transfer Google user data to third parties except: (a) to provide or improve user-facing features that are prominent in Sorsend's user interface, such as AI infrastructure that processes email content to generate tasks under a data processing agreement; (b) to comply with applicable laws; (c) as part of a merger, acquisition, or sale of assets with notice to users; or (d) for security purposes such as investigating abuse.
  • No human reading of Gmail data except as allowed. Sorsend does not allow humans to read Gmail data unless: (a) you give us affirmative agreement for specific messages, for example when you contact support and choose to share them; (b) it is necessary for security purposes such as investigating a bug, abuse, or spam; (c) it is necessary to comply with applicable law; or (d) the data is aggregated and used for internal operations in a way that does not disclose identifying information to humans, consistent with the rest of the Limited Use requirements.
  • No independent model training. We do not use Google user data to train generalized AI or machine learning models. Email content processed by AI providers is used only to deliver the requested user-facing feature.

You may revoke Sorsend's Google access at any time in your Google Account permissions and by disconnecting the mailbox in Sorsend. Google Account permissions.

Google API Services User Data Policy, including Limited Use requirements

5. Data Sharing and Transfers

We only share personal data with trusted third parties when necessary to provide the service or when required by law. These include:

  • a. Sub-processors (Data Processors)
    • Cloud service providers (e.g., AWS, Azure)
    • Email delivery providers
    • AI infrastructure providers
    • Analytics and diagnostics tools (e.g., Google Analytics, Microsoft Clarity)
    All sub-processors are contractually bound under Art. 28 GDPR with data processing agreements ensuring adequate protection.
  • b. Third-party Integrations

    If this feature is available you may enable integrations with email services or productivity tools, we access only the data required for the feature and based on your instructions.

  • c. Legal or Regulatory Authorities

    If legally obliged, we may disclose your data to courts, law enforcement, or public authorities under Art. 6(1)(c) GDPR.

6. International Data Transfers

Your data may be transferred to countries outside the EU/EEA. In such cases, we rely on appropriate safeguards, such as:

  • European Commission adequacy decisions
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Additional technical and contractual protections

7. Data Retention

  • Active user data is retained for the duration of the account
  • Upon account deletion, data is permanently removed within 30 days (unless otherwise required by law)

You may export or delete your data at any time through your account or by contacting us.

8. Security Measures

We implement technical and organizational measures under Art. 32 GDPR to protect your data, including:

  • Encryption of data in transit and at rest
  • Access controls and role-based authorization
  • Intrusion detection and logging
  • Secure development and deployment practices
  • Incident response protocols
  • Employee confidentiality agreements and training

9. Your Rights Under the GDPR

As a data subject, you have the following rights:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR – 'right to be forgotten')
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent at any time (Art. 7(3) GDPR)
  • Right to lodge a complaint with your local Data Protection Authority (Art. 77 GDPR)

To exercise these rights, contact: office@Sorsend.com.

10. Automated Decision-Making and Profiling

We use AI to categorize emails and tasks automatically. However, no decisions with legal or similarly significant effects are made solely based on automated processing.

12. Children’s Data

Our services are not intended for users under the age of 16. If we learn we have processed data of a child under 16 without verified parental consent, we will delete that data promptly.

13. Responsible Use of AI and Protection of Your Data

Sorsend leverages artificial intelligence (AI) to enhance service capabilities, such as automated email categorization and task creation and prioritization. Our AI models are designed to improve productivity and support your user experience through contextual understanding and pattern recognition while respecting the principles set forth in the EU AI Act.

We are committed to the ethical and privacy-conscious use of AI and observe the following principles:

  • We do not use your personal data to train our AI models. This means:
    • Your emails, tasks, and metadata are not used to refine, retrain, or expand any machine learning model.
    • We do not transfer your personal data into shared training environments.
    • Our AI models are trained using synthetic or anonymized datasets that are independent of user content.

14. Updates to This Policy

We may update this Privacy Policy to reflect changes in legal, technical, or business developments. We will notify you via the platform or email if changes are material.

Privacy Policy | Sorsend