Privacy Policy
Ottometric Chrome Extensions Suite
Effective Date: September 1, 2026 | Version 3.0
Document Classification: Internal Policy | Distribution: Authorized Personnel Only
đ Executive Summary
Ottometric's Chrome Extensions integrate your business email, calendar, meetings, and work productivity data with your company's Odoo CRM platform. Our extensions help streamline sales workflows, automate record-keeping, and provide productivity insights for internal business operations.
Key Principles: Your data is processed solely for business operations within Ottometric. We do not sell data, share with third-party advertisers, or use it for purposes unrelated to CRM and productivity management.
đ Table of Contents
- Scope and Applicability
- Extension Descriptions
- Data We Collect
- Legal Basis for Data Processing
- How We Use Your Data
- Data Collection Methods
- Data Storage and Retention
- Data Sharing and Third Parties
- International Data Transfers
- Security Measures and Incident Response
- AI and Automated Processing
- Workplace Monitoring and Employee Privacy
- Chrome Extension Permissions
- Google API Compliance
- Your Rights and Controls
- Data Subject Rights (GDPR/CCPA)
- Internal Use Policy
- Service Providers and Sub-Processors
- Legal and Regulatory Compliance
- Governing Law and Dispute Resolution
- Contact Information and Data Protection Officer
- Policy Updates and Version History
- Glossary of Terms
1. Scope and Applicability
This Privacy Policy governs the collection, use, storage, and disclosure of data through the following Ottometric Chrome Extensions:
Ottometric Gmail Extension (v2.5.3) â CRM integration for Gmail with email logging, tracking, and AI assistance capabilities.
Ottometric Outlook Extension â CRM integration for Outlook Web App, enabling automatic email logging and contact management.
Ottometric Meet Extension â Meeting recording and transcription for Google Meet with CRM integration.
These extensions connect to your organization's Odoo CRM instance hosted at odoo.ottometric.com.
2. Extension Descriptions
đ§ Gmail Extension
Integrates Gmail with Odoo CRM to automatically log business emails, track communication history, and provide AI-powered email assistance. The extension adds a sidebar to Gmail displaying CRM information for email contacts and allows one-click logging of emails to deals and opportunities.
Key Features: Automatic email-to-CRM logging, contact and deal matching, email open and click tracking via Odoo Marketing, reply detection and notification, AI email composition assistant (optional), and work time tracking with active/idle monitoring.
đŦ Outlook Extension
Provides similar CRM integration functionality for Outlook Web App (OWA), enabling automatic email logging and contact management for Outlook users.
đĨ Meet Extension
Enables recording, transcription, and CRM integration for Google Meet video conferences. Recordings are saved to your Google Drive and optionally linked to Odoo contacts and opportunities.
3. Data We Collect
The data we collect varies by extension. Below is a comprehensive breakdown of data types collected by each extension.
đ§ Gmail Extension
| Data Type | What We Collect | Purpose |
|---|---|---|
| Email Content | Subject lines, message bodies, draft text, attachments metadata | CRM logging, AI analysis, deal association |
| Email Metadata | From/To addresses, CC/BCC, timestamps, thread IDs, message IDs, labels | Contact matching, reply tracking, thread organization |
| Contact Information | Email addresses, display names, profile photos | CRM record matching and enrichment |
| Thread Context | Complete email conversation history | AI context analysis, reply detection |
| Work Time Data | Active vs. idle status, session timestamps | Accurate work hour calculation for productivity reporting |
| Authentication Tokens | OAuth 2.0 access tokens (Gmail API, Odoo API) | Secure API access without storing passwords |
đŦ Outlook Extension
Email content: Subject lines and message bodies for CRM logging purposes.
Email metadata: Sender information, recipients, timestamps, and conversation IDs for thread organization and tracking.
Contact information: Email addresses and display names for CRM record matching.
Authentication tokens: OAuth tokens for Microsoft Graph API and Odoo API secure access.
đĨ Meet Extension
Meeting recordings: Audio and video streams captured only when manually initiated by the user through explicit recording activation.
Meeting metadata: Meeting title, participant names and email addresses, start and end times, and meeting URL for organizational purposes.
Calendar data: Event details retrieved from Google Calendar for automatic recording file naming and organization.
Transcriptions: AI-generated meeting transcripts produced via AWS Bedrock speech-to-text processing.
Authentication tokens: OAuth tokens for secure access to Google Drive, Calendar, and Odoo APIs.
Email content may contain sensitive business information, personal identifiable information (PII), or confidential communications. We treat all collected data with appropriate security controls and access restrictions as outlined in Section 8 (Security Measures).
4. Legal Basis for Data Processing
Ottometric processes personal data collected through these extensions based on the following legal grounds, in compliance with applicable data protection regulations including the General Data Protection Regulation (GDPR) where applicable:
đ Legal Bases Under GDPR
1. Legitimate Interests
Primary Legal Basis: Ottometric's legitimate business interests in maintaining efficient customer relationship management, ensuring business productivity, protecting company assets, and improving internal operations.
Balancing Test: We have assessed that our legitimate interests in processing employee work-related communications and productivity data do not override the fundamental rights and freedoms of data subjects, considering:
- Data is collected only from work email accounts and during working hours
- Processing is limited to business-related communications and activities
- Users are fully informed of data collection practices
- Strong security measures protect collected data
- Users retain rights to access, rectify, and delete data
Applies to: Email content logging, CRM record matching, contact information enrichment, deal association, work time analytics, productivity reporting.
2. Consent
Explicit Consent: By voluntarily installing and authenticating these Chrome extensions, users provide explicit consent to data collection and processing described in this policy.
Consent Characteristics: Freely given (installation optional for authorized personnel), specific (limited to described purposes), informed (this policy provided before use), and unambiguous (requires active authentication steps).
Withdrawal Rights: Consent can be withdrawn at any time by disconnecting from Odoo, revoking OAuth permissions, or uninstalling the extension. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.
Applies to: Optional AI features (email composition assistant, meeting transcription), email tracking pixels, meeting recordings (explicit initiation required).
3. Contract Performance
Employment Contract: Processing necessary for performance of the employment contract between Ottometric and its employees, including fulfillment of work responsibilities, performance evaluation, and operational management.
Applies to: Work email logging for business continuity, customer relationship management activities, work time tracking for payroll and attendance purposes, productivity monitoring for performance reviews.
4. Legal Obligations
Compliance Requirements: Processing necessary to comply with legal obligations to which Ottometric is subject, including:
- Record-keeping requirements for business communications and transactions
- Employment law compliance (work hours, overtime tracking)
- Tax and accounting regulations
- Data retention obligations for legal proceedings
- Regulatory reporting and audit requirements
Applies to: Business email records, work time logs, transaction histories, compliance documentation.
5. How We Use Your Data
We use collected data solely for legitimate business purposes related to customer relationship management and operational efficiency. Data is never used for advertising, marketing to external parties, or purposes unrelated to business operations.
â Permitted Uses
Data may be used for CRM record creation and updating, sales pipeline management, customer communication tracking, internal productivity analytics, email quality improvement through AI analysis, reply detection and notifications, meeting documentation, and operational reporting purposes.
â Prohibited Uses
Data will never be used for third-party advertising, selling to data brokers, training external AI models, social media integration, marketing to competitors, public data aggregation, surveillance beyond legitimate work scope, or unauthorized data mining activities.
Specific Use Cases by Extension
Gmail & Outlook Extensions:
The Gmail and Outlook extensions facilitate CRM Logging by automatically creating Odoo activity records for business emails; Contact Matching to link email addresses with existing Odoo partner records; Deal Association connecting emails to active CRM opportunities based on participants; Reply Tracking through Gmail API monitoring to detect customer responses; AI Email Assistant for analyzing draft emails regarding tone, clarity, and grammar (Gmail only, opt-in feature); Email Tracking via Odoo Email Marketing pixel and click URL generation; and Work Time Analytics calculating active work hours versus idle periods for productivity insights.
Meet Extension:
The Meet extension provides Recording Storage capabilities to save meeting recordings to your personal Google Drive; Transcription services generating searchable text transcripts using AWS Bedrock AI; CRM Integration linking meeting records to Odoo contacts and opportunities; and Meeting Documentation maintaining a searchable archive of business meetings.
6. Data Collection Methods
Data collection occurs through multiple mechanisms, both automated and user-initiated. Understanding these methods helps clarify when and how your data is accessed.
A Automatic Collection
- Email monitoring: Extensions continuously monitor your Gmail/Outlook mailbox for new sent/received emails
- Work time tracking: When connected to Odoo, the extension tracks active vs. idle status via Chrome's idle detection API
- Reply detection: Background polling checks Gmail threads every 1 minute for new replies
- Token refresh: OAuth tokens are automatically renewed before expiration
M Manual/On-Demand Collection
- Meeting recordings: Only collected when you explicitly click "Start Recording" in Google Meet
- AI email assistance: Only activated when you click the AI assistant button in Gmail compose window
- Manual email logging: When you click "Log to Odoo" button in email sidebar
API API-Based Collection
Data is accessed through official platform APIs with your explicit OAuth consent:
- Gmail API:
gmail.readonlyscope for reading email threads - Microsoft Graph API: Mail.Read scope for Outlook data
- Google Calendar API: Calendar.ReadOnly for meeting metadata
- Google Drive API: Drive.File scope (limited to files created by the extension)
Most data collection begins only after you authenticate with Odoo via the extension options page. Before authentication, the extensions remain dormant and do not access your email or other data.
7. Data Storage and Retention
7.1 Storage Locations
đĸ Odoo CRM Server
Location: odoo.ottometric.com
Data Stored:
- Email logs and content
- Contact associations
- Meeting metadata
- Work time records
- Activity timestamps
âī¸ Google Drive
Location: Your personal Google Drive
Data Stored:
- Meeting video recordings
- Meeting transcripts (text files)
- Recording metadata
đģ Local Browser Storage
Location: Chrome secure storage on your device
Data Stored:
- OAuth access tokens (encrypted)
- Extension preferences
- Temporary cache
- Tracked thread mappings
đ¤ AWS Bedrock (Temporary)
Location: Amazon Web Services AI service
Data Stored:
- Meeting audio (temporary processing only)
- Not retained after transcription
- No permanent storage
7.2 Data Retention Periods
| Data Category | Retention Period | Deletion Method |
|---|---|---|
| CRM Logs & Emails | Indefinite (per company policy) | Admin request to IT |
| Work Time Data | Indefinite (historical reporting) | Admin request to IT |
| Meeting Recordings | Until manually deleted from Drive | User deletes from Google Drive |
| Local Settings & Tokens | Until extension uninstalled | Automatic on uninstall |
| OAuth Tokens | Until sign-out or expiration | Sign out or uninstall |
| AWS Transcription Audio | Immediately after processing | Automatic deletion |
CRM data in Odoo is retained indefinitely as part of business records for historical reporting, audit trails, and regulatory compliance. If you require data deletion, please contact your Ottometric administrator who can submit a formal data deletion request to the IT department.
8. Data Sharing and Third Parties
8.1 Parties With Data Access
â Authorized Recipients
1. Odoo CRM Server (odoo.ottometric.com)
Receives: Email content, metadata, contact info, meeting metadata, work time data
Purpose: CRM operations, business intelligence, productivity analytics
2. Google APIs
Receives: OAuth authentication requests only (no business data shared)
Purpose: User authentication and authorization
3. Microsoft Graph API (Outlook extension only)
Receives: OAuth authentication requests only
Purpose: User authentication for Outlook data access
4. AWS Bedrock (Amazon AI Services)
Receives: Meeting audio for transcription (temporary processing only)
Purpose: AI-powered speech-to-text transcription
5. Ottometric Employees & Authorized Personnel
Access Level: Based on Odoo role permissions (managers, administrators, IT staff)
Purpose: CRM management, technical support, system administration, business analytics
â Parties We DO NOT Share With
- Third-party analytics services (e.g., Google Analytics, Mixpanel)
- Advertising networks or ad tech platforms
- Data brokers or list aggregators
- Social media platforms
- Marketing automation platforms (external)
- AI training services (beyond AWS Bedrock transcription)
- Cloud storage providers (except Google Drive for recordings)
- Any external party not explicitly listed above
8.2 Legal Disclosures
We may disclose collected data if required by law, legal process, or government request, including:
- Court orders or subpoenas
- Regulatory investigations
- Law enforcement requests with proper legal authority
- Protection of legal rights, safety, or property of Ottometric or others
In such cases, we will make reasonable efforts to notify affected users unless prohibited by law.
9. International Data Transfers
Ottometric's operations and service providers may involve the transfer of personal data across international borders. This section explains how we ensure appropriate safeguards for cross-border data transfers in compliance with applicable data protection laws.
9.1 Data Transfer Locations
Primary Data Processing Locations
United States:
- Odoo CRM Server: Hosted at odoo.ottometric.com (data center location: USA)
- AWS Bedrock AI Services: Amazon Web Services US regions for meeting transcription
- Google Cloud Services: Google Drive (user-selected region), Gmail API, Calendar API (USA)
European Economic Area (EEA):
- No primary data processing servers located in EEA
- European employee data may be transferred to US-based systems (see safeguards below)
Other Regions:
- Data may transit through content delivery networks (CDNs) or cloud infrastructure in various countries
- All transfers subject to appropriate safeguards as described below
9.2 Legal Mechanisms for Data Transfers
Adequacy Decisions
Where available, we rely on European Commission adequacy decisions recognizing certain countries as providing adequate data protection:
- UK-EU adequacy decision (for UK employees)
- Switzerland adequacy decision (for Swiss employees)
- Other adequacy decisions as applicable to employee locations
9.3 Safeguards for International Transfers
Ottometric implements the following safeguards to protect personal data transferred internationally:
đ Technical Safeguards
- TLS 1.3 encryption for all data in transit
- Encrypted storage of sensitive data
- Access controls and authentication
- Regular security audits and penetration testing
đ Contractual Safeguards
- Standard Contractual Clauses with processors
- Data Processing Agreements (DPAs)
- Vendor security requirements
- Audit rights and compliance monitoring
đĄī¸ Organizational Safeguards
- Privacy by design principles
- Staff training on data protection
- Incident response procedures
- Regular compliance reviews
âī¸ Legal Safeguards
- Compliance with GDPR
- Transfer Impact Assessments (TIAs)
- Review of government access laws
- Transparent data handling practices
9.4 Government Access to Data
US Government Access: As data is processed in the United States, it may be subject to US laws regarding government access, including the Foreign Intelligence Surveillance Act (FISA) and the CLOUD Act. We assess these risks as part of our transfer impact assessments.
Mitigating Measures: To mitigate risks of government access:
- We use encryption to protect data in transit and at rest
- Our service providers (AWS, Google) maintain transparency reports on government data requests
- We commit to notifying affected individuals of lawful data requests unless legally prohibited
- We challenge overly broad or unlawful requests where legally permissible
10. Security Measures and Incident Response
We implement industry-standard security controls to protect collected data from unauthorized access, disclosure, alteration, or destruction.
đ Encryption
- In Transit: All data transmission uses HTTPS/TLS 1.3 encryption
- At Rest: OAuth tokens encrypted in Chrome secure storage
- API Calls: All API requests use secure HTTPS endpoints
đ Authentication
- OAuth 2.0: Industry-standard secure authentication (no passwords stored)
- Token Rotation: Automatic refresh of expired tokens
- Scope Limitation: Request minimum necessary API permissions
đĨ Access Controls
- Role-Based Access: Odoo permissions limit data visibility
- Least Privilege: Users see only data needed for their role
- Audit Logs: Odoo tracks data access and modifications
đĄī¸ Infrastructure Security
- Network Isolation: Odoo CRM on secure internal network
- Firewall Protection: Access restricted to authorized IP ranges
- Regular Updates: Security patches applied promptly
Additional Security Practices
- Minimal Permissions: Extensions request only necessary Chrome permissions for core functionality
- Secure Storage: Chrome's secure storage API protects locally stored credentials
- No Plaintext Passwords: All authentication uses OAuth tokens, never passwords
- Regular Security Reviews: Code audits and vulnerability assessments conducted periodically
- Security Monitoring: Continuous monitoring of systems for suspicious activity and potential threats
- Vendor Management: Regular security assessments of third-party service providers (AWS, Google)
- Patch Management: Timely application of security patches and updates to all systems
10.1 Data Breach Response and Notification
In the event of a data breach that compromises the security of personal data collected through these extensions, Ottometric follows documented incident response procedures in compliance with applicable data breach notification laws.
Incident Response Process
1. Detection and Containment (0-24 hours)
- Immediate investigation upon discovery of security incident
- Containment measures to prevent further unauthorized access
- Preliminary assessment of breach scope and affected data
- Activation of incident response team
2. Assessment and Remediation (24-72 hours)
- Full forensic analysis to determine cause and extent of breach
- Identification of all affected individuals and data categories
- Implementation of remediation measures to prevent recurrence
- Risk assessment for affected individuals
3. Notification (72 hours for GDPR)
- Supervisory Authority Notification: If required under GDPR, notification to relevant data protection authority within 72 hours of breach discovery
- Individual Notification: If breach poses high risk to individuals , direct notification to affected persons without undue delay
- CCPA Notification: California residents notified within legally required timeframes if breach involves personal information
- Management Notification: Internal escalation to senior management and legal counsel
4. Post-Incident Review
- Root cause analysis and lessons learned documentation
- Update of security policies and procedures as needed
- Additional security controls implementation
- Staff retraining if human error contributed to breach
â ī¸ Notification Content
Breach notifications (when required) will include:
- Nature of the personal data breach and categories of data affected
- Approximate number of affected individuals and data records
- Name and contact details of Data Protection Officer or privacy contact
- Likely consequences of the breach
- Measures taken or proposed to address the breach and mitigate harm
- Recommended steps for affected individuals to protect themselves
If you become aware of a security vulnerability, data breach, or suspicious activity related to these extensions, immediately report it to security@ottometric.com. For critical incidents, also contact your direct manager or IT administrator. We maintain a responsible disclosure process for security researchers.
Users are responsible for securing their own devices, using strong passwords for Google/Microsoft accounts, enabling two-factor authentication where available, keeping browser and extensions updated, and reporting suspicious activity. Do not share OAuth tokens, authentication credentials, or install extensions from untrusted sources.
9. Chrome Extension Permissions Explained
Chrome extensions require explicit permissions to access certain browser features and web APIs. Below is a detailed explanation of each permission requested by Ottometric extensions and why it's necessary.
| Permission Identifier | API Namespace | Runtime Context | Technical Capability & Scope | Business Implementation & Data Flow |
|---|---|---|---|---|
| CORE INFRASTRUCTURE & AUTHENTICATION | ||||
storage |
chrome.storage.* | Persistent + Sync | Encrypted IndexedDB-backed key-value storage with sync.storage cross-device replication; quota-managed (5MB local, 100KB sync) | Persists OAuth access/refresh tokens, user preferences, CRM tenant URLs, activity timestamps, cache invalidation markers |
identity |
chrome.identity | Auth Handler | OAuth 2.0 authorization code + PKCE flow initiator; integrates Chrome's identity provider without credential exposure | Federated authentication with Google Workspace / Microsoft 365; silent token refresh via refresh_token grant type |
cookies |
chrome.cookies | Cross-Domain | Read/write access to HTTP cookies for permitted host patterns; observes SameSite, Secure, HttpOnly attributes | Session management for Odoo backend; CSRF token extraction for API request authentication; detects login state changes |
| WEB CONTENT INTEGRATION & DOM MANIPULATION | ||||
scripting |
chrome.scripting | Injected Script | Dynamic content script injection with document_start/document_end timing; CSS stylesheet insertion; isolated world execution | Renders CRM sidebar UI in Gmail/Outlook via InboxSDK; thread metadata extraction; compose window interception for logging |
activeTab |
chrome.tabs | User-Initiated | Temporary tab metadata access (URL, title, favIconUrl) granted only upon user-initiated action (icon click, keyboard shortcut) | Context-aware UI activation; detects Gmail/Outlook/Meet URLs for conditional feature loading without persistent tab monitoring |
tabs |
chrome.tabs | Background | Query/enumerate open tabs; listen to tab lifecycle events (onCreated, onUpdated, onRemoved, onActivated); manage tab state | Multi-tab coordination for Gmail reply tracking; ensures single active CRM sidebar instance; handles navigation state persistence |
contextMenus |
chrome.contextMenus | UI Extension | Browser right-click context menu customization; adds extension-specific menu items with icon, title, enabled state | Quick-action menu for "Log to CRM" on selected email text; "Create Lead from Contact" for highlighted email addresses |
| BACKGROUND PROCESSING, SCHEDULING & STATE MANAGEMENT | ||||
background |
service_worker | MV3 Worker | Manifest V3 service worker registration; event-driven architecture with automatic wake/sleep lifecycle management | Persistent background orchestrator; coordinates API requests, handles chrome.runtime message routing, manages WebSocket connections |
alarms |
chrome.alarms | Scheduled Task | Deferred callback execution with periodInMinutes or delayInMinutes scheduling; persists across service worker termination | Polls Gmail API every 2 minutes for reply detection; refreshes OAuth tokens 5 minutes before expiry; syncs CRM cache hourly |
windows |
chrome.windows | Multi-Window | Browser window enumeration and lifecycle tracking; onFocusChanged listener for window state awareness across displays | Activity monitor handles multi-monitor setups; coordinates focus tracking with idle detection for accurate work session analytics |
power |
chrome.power | System Level | Prevents system sleep/display dimming via requestKeepAwake("system"|"display"); release via releaseKeepAwake() | Meet extension keeps display active during recording sessions; prevents interruption of long-running video capture processes |
idle |
chrome.idle | State Detector | System activity state detection with configurable interval thresholds | Session timing accuracy |
notifications |
chrome.notifications | Desktop Alert | Rich notification templates (basic, image, list, progress) via native OS notification center; supports action buttons and icons | User alerts for tracked email replies, OAuth expiration warnings, CRM sync failures, meeting recording completion status |
| NETWORK REQUEST INTERCEPTION & FILTERING | ||||
declarativeNetRequest |
chrome.declarativeNetRequest | Net Modifier | Declarative request blocking/redirection/header modification rules processed in browser core; replaces blocking webRequest | Injects custom headers for CRM API authentication; blocks third-party trackers on Gmail pages to reduce network noise |
| MEDIA CAPTURE & RECORDING (MEET EXTENSION ONLY) | ||||
tabCapture |
chrome.tabCapture | MediaStream | Captures tab audio/video as MediaStream; requires user gesture; exposes getMediaStreamId() for offscreen document processing | Records Google Meet video/audio when user clicks "Start Recording"; encodes via MediaRecorder API; uploads to Drive |
desktopCapture |
chrome.desktopCapture | Screen Picker | Invokes system screen/window/app picker dialog; grants constrained MediaStream access to user-selected source post-approval | Includes screen-sharing in meeting recordings when presenter mode active; requires explicit user permission per capture session |
| HOST-SPECIFIC ACCESS PERMISSIONS & ORIGIN POLICIES | ||||
| host_permissions | Match patterns | CORS Bypass | Cross-origin resource sharing (CORS) exemptions for specified URL patterns; enables fetch() to external APIs |
|
We follow the principle of least privilege and request only permissions strictly necessary for core functionality. Permissions are reviewed with each extension update to ensure continued necessity.
10. Google API Services User Data Policy Compliance
Our extensions comply with the Google API Services User Data Policy, including the Limited Use requirements that restrict how we handle data obtained from Google APIs.
Limited Use Disclosure
Ottometric Chrome Extensions' use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.
API Scopes and Usage
đ§ Gmail API (gmail.readonly)
Scope Purpose: Monitor email threads for replies to tracked business emails
Data Accessed: Thread metadata, message headers, message bodies, attachment metadata
Usage: Auto-log business communications to Odoo CRM, detect replies, provide AI email composition assistance
Limited Use Compliance: Data used ONLY for CRM logging and email management features. Not used for:
- Advertising or targeting
- Training external AI models (beyond AWS Bedrock for transcription)
- Selling to data brokers
- Creditworthiness or lending purposes
âī¸ Google Drive API (drive.file)
Scope Purpose: Save meeting recordings created by the extension
Data Accessed: Only files created by this extension (limited scope)
Usage: Write-only access to store meeting videos and transcripts in user's personal Google Drive
đ
Google Calendar API (calendar.readonly)
Scope Purpose: Fetch meeting details for recording file naming
Data Accessed: Event titles, start/end times, participant names
Usage: Read-only access to automatically name meeting recordings with event details
Data Handling Commitments
- â Gmail data is accessed ONLY for features clearly visible to the user (email logging, AI assistant)
- â No data transfer to third parties except Odoo CRM (internal business system)
- â No use of Gmail data for serving advertisements
- â No sale or transfer of user data to data brokers or information resellers
- â Human readable data (emails, calendar events) used only for stated business purposes
- â Compliance with all other Google API Services User Data Policy requirements
11. Your Rights and Controls
You have several options to control your data and manage how the extensions function. Below are the actions you can take to exercise your rights.
11.1 Data Control Actions
đ Disable Extension
How: Navigate to chrome://extensions/, find Ottometric extension, toggle OFF or click "Remove"
Effect: Stops all data collection immediately; local data deleted
đ Disconnect from Odoo
How: Open extension options page, click "Disconnect" or "Sign Out"
Effect: Stops CRM logging and work time tracking; OAuth tokens revoked
đ Revoke OAuth Access
How: Visit Google Account Permissions or Microsoft App Permissions
Effect: Extension can no longer access Gmail/Outlook data until re-authorized
đī¸ Delete Local Data
How: Uninstall the extension completely
Effect: All browser-stored data (tokens, settings, cache) permanently deleted
đ Delete CRM Data
How: Contact your Ottometric administrator to submit data deletion request
Effect: Email logs and work time data removed from Odoo CRM
đ¤ Opt Out of AI Features
How: Simply don't click AI assistant buttons in Gmail compose window
Effect: AI analysis not performed unless explicitly requested
11.2 Data Access and Portability
As an Ottometric employee, you can access all your logged data directly in the Odoo CRM system at odoo.ottometric.com. To request a data export or deletion, contact your administrator.
Data Export Requests:
- Email your request to: admin@ottometric.com
- Include: Your name, email address, data types requested (email logs, work time data, etc.)
- Response time: 14 business days
- Format: CSV or JSON export from Odoo
12. Internal Use Policy
â ī¸ IMPORTANT: Internal Business Tools Only
These Chrome extensions are designed exclusively for use by authorized Ottometric employees and business partners as internal business productivity tools. They are NOT intended for consumer use, public distribution, or installation by the general public.
Who Should Use These Extensions:
- Current Ottometric employees with active company email accounts
- Authorized contractors or consultants with Odoo CRM access
- Business partners explicitly approved by Ottometric management
If You Are NOT an Ottometric Employee:
- â Do not install these extensions
- â Do not attempt to connect to odoo.ottometric.com
- â Do not use these extensions for personal purposes
- â Do not distribute or share these extensions publicly
Internal Data Governance
All data collected by these extensions is subject to Ottometric's internal data governance, security policies, and employee handbook provisions. By using these extensions, you acknowledge:
- Your work email communications may be logged to CRM for business purposes
- Work time data is collected for productivity reporting and operational insights
- Authorized managers and administrators can access logged data via Odoo
- Data handling complies with applicable employment laws and company policies
- Extensions are provided for business use during working hours
13. Legal and Regulatory Compliance
Ottometric Chrome Extensions are developed and operated in compliance with relevant laws, regulations, and industry standards.
â Compliance Frameworks
- â Chrome Web Store Developer Program Policies - Adheres to all Chrome extension guidelines
- â Google API Services User Data Policy - Including Limited Use requirements for Gmail/Calendar/Drive APIs
- â OAuth 2.0 Security Best Practices - Secure authentication and token management
- â Microsoft Graph API Terms of Service - Compliant use of Outlook/Office 365 data
- â Ottometric Internal Data Governance Policies - Aligns with company security and privacy standards
- â Applicable Employment Laws - Work time tracking complies with labor regulations
Privacy Regulations
While these extensions are internal business tools (not consumer-facing products), we recognize the importance of data protection principles:
- GDPR Principles: Data minimization, purpose limitation, transparency (applicable to EU employees)
- CCPA Awareness: California employees have rights to data access and deletion
- Employment Privacy: Work-related data collection disclosed to employees
Security Standards
- HTTPS/TLS 1.3 encryption for data in transit
- OAuth 2.0 secure authentication (no password storage)
- Regular security code reviews and vulnerability assessments
- Incident response procedures for security breaches
14. Contact Information
For questions, concerns, or requests related to this Privacy Policy or data handling practices, please contact: info@ottometric.com
Response Time: We aim to respond to all inquiries within 5 business days. For urgent security issues, contact security@ottometric.com immediately.
15. Policy Updates and Changes
We may update this Privacy Policy periodically to reflect changes in our extensions, data practices, regulatory requirements, or company policies. Material changes will be communicated to users through appropriate channels.
How We Notify Users of Changes
- Material Changes: Email notification to all active users + in-extension notification banner
- Minor Updates: Updated "Last Updated" date on this page + changelog in extension release notes
- Compliance Changes: Immediate notification if required by law or regulatory guidance
What Constitutes a Material Change
- New types of data collection (e.g., adding browsing history tracking)
- Changes to data sharing practices (e.g., new third-party recipients)
- Significant changes to data retention periods
- New purposes for using collected data
- Changes to security practices that may affect user privacy
Continued use of the extensions after a Privacy Policy update constitutes acceptance of the revised terms. If you do not agree with changes, you may discontinue use and uninstall the extension.
Version History
| Version | Date | Changes |
|---|---|---|
| 3.0 | September 1, 2026 | Comprehensive update: Added legal basis for data processing, international data transfers, enhanced security and incident response procedures, detailed breach notification protocols |
| 2.5 | July 30, 2026 | Added AI enhancement and analysis features; updated permissions section |
| 2.0 | July 21, 2026 | Major update for Gmail extension v2.5 features |
| 1.0 | January 15, 2026 | Initial policy release |
â Acknowledgment and Consent
By installing and using Ottometric Chrome Extensions, you acknowledge that you have read, understood, and agree to this Privacy Policy. You confirm that you are an authorized Ottometric employee or business partner with permission to use these internal business tools.
Last Updated: September 1, 2026 | Version: 3.0 | Effective Date: September 1, 2026
Privacy Policy
Ottometric Chrome Extensions Suite
Effective Date: September 1, 2026 | Version 3.0
Document Classification: Internal Policy | Distribution: Authorized Personnel Only
đ Executive Summary
Ottometric's Chrome Extensions integrate your business email, calendar, meetings, and work productivity data with your company's Odoo CRM platform. Our extensions help streamline sales workflows, automate record-keeping, and provide productivity insights for internal business operations.
Key Principles: Your data is processed solely for business operations within Ottometric. We do not sell data, share with third-party advertisers, or use it for purposes unrelated to CRM and productivity management.
đ Table of Contents
- Scope and Applicability
- Extension Descriptions
- Data We Collect
- Legal Basis for Data Processing
- How We Use Your Data
- Data Collection Methods
- Data Storage and Retention
- Data Sharing and Third Parties
- International Data Transfers
- Security Measures and Incident Response
- AI and Automated Processing
- Workplace Monitoring and Employee Privacy
- Chrome Extension Permissions
- Google API Compliance
- Your Rights and Controls
- Data Subject Rights (GDPR/CCPA)
- Internal Use Policy
- Service Providers and Sub-Processors
- Legal and Regulatory Compliance
- Governing Law and Dispute Resolution
- Contact Information and Data Protection Officer
- Policy Updates and Version History
- Glossary of Terms
1. Scope and Applicability
This Privacy Policy governs the collection, use, storage, and disclosure of data through the following Ottometric Chrome Extensions:
Ottometric Gmail Extension (v2.5.3) â CRM integration for Gmail with email logging, tracking, and AI assistance capabilities.
Ottometric Outlook Extension â CRM integration for Outlook Web App, enabling automatic email logging and contact management.
Ottometric Meet Extension â Meeting recording and transcription for Google Meet with CRM integration.
These extensions connect to your organization's Odoo CRM instance hosted at odoo.ottometric.com.
2. Extension Descriptions
đ§ Gmail Extension
Integrates Gmail with Odoo CRM to automatically log business emails, track communication history, and provide AI-powered email assistance. The extension adds a sidebar to Gmail displaying CRM information for email contacts and allows one-click logging of emails to deals and opportunities.
Key Features: Automatic email-to-CRM logging, contact and deal matching, email open and click tracking via Odoo Marketing, reply detection and notification, AI email composition assistant (optional), and work time tracking with active/idle monitoring.
đŦ Outlook Extension
Provides similar CRM integration functionality for Outlook Web App (OWA), enabling automatic email logging and contact management for Outlook users.
đĨ Meet Extension
Enables recording, transcription, and CRM integration for Google Meet video conferences. Recordings are saved to your Google Drive and optionally linked to Odoo contacts and opportunities.
3. Data We Collect
The data we collect varies by extension. Below is a comprehensive breakdown of data types collected by each extension.
đ§ Gmail Extension
| Data Type | What We Collect | Purpose |
|---|---|---|
| Email Content | Subject lines, message bodies, draft text, attachments metadata | CRM logging, AI analysis, deal association |
| Email Metadata | From/To addresses, CC/BCC, timestamps, thread IDs, message IDs, labels | Contact matching, reply tracking, thread organization |
| Contact Information | Email addresses, display names, profile photos | CRM record matching and enrichment |
| Thread Context | Complete email conversation history | AI context analysis, reply detection |
| Work Time Data | Active vs. idle status, session timestamps | Accurate work hour calculation for productivity reporting |
| Authentication Tokens | OAuth 2.0 access tokens (Gmail API, Odoo API) | Secure API access without storing passwords |
đŦ Outlook Extension
Email content: Subject lines and message bodies for CRM logging purposes.
Email metadata: Sender information, recipients, timestamps, and conversation IDs for thread organization and tracking.
Contact information: Email addresses and display names for CRM record matching.
Authentication tokens: OAuth tokens for Microsoft Graph API and Odoo API secure access.
đĨ Meet Extension
Meeting recordings: Audio and video streams captured only when manually initiated by the user through explicit recording activation.
Meeting metadata: Meeting title, participant names and email addresses, start and end times, and meeting URL for organizational purposes.
Calendar data: Event details retrieved from Google Calendar for automatic recording file naming and organization.
Transcriptions: AI-generated meeting transcripts produced via AWS Bedrock speech-to-text processing.
Authentication tokens: OAuth tokens for secure access to Google Drive, Calendar, and Odoo APIs.
Email content may contain sensitive business information, personal identifiable information (PII), or confidential communications. We treat all collected data with appropriate security controls and access restrictions as outlined in Section 8 (Security Measures).
4. Legal Basis for Data Processing
Ottometric processes personal data collected through these extensions based on the following legal grounds, in compliance with applicable data protection regulations including the General Data Protection Regulation (GDPR) where applicable:
đ Legal Bases Under GDPR
1. Legitimate Interests
Primary Legal Basis: Ottometric's legitimate business interests in maintaining efficient customer relationship management, ensuring business productivity, protecting company assets, and improving internal operations.
Balancing Test: We have assessed that our legitimate interests in processing employee work-related communications and productivity data do not override the fundamental rights and freedoms of data subjects, considering:
- Data is collected only from work email accounts and during working hours
- Processing is limited to business-related communications and activities
- Users are fully informed of data collection practices
- Strong security measures protect collected data
- Users retain rights to access, rectify, and delete data
Applies to: Email content logging, CRM record matching, contact information enrichment, deal association, work time analytics, productivity reporting.
2. Consent
Explicit Consent: By voluntarily installing and authenticating these Chrome extensions, users provide explicit consent to data collection and processing described in this policy.
Consent Characteristics: Freely given (installation optional for authorized personnel), specific (limited to described purposes), informed (this policy provided before use), and unambiguous (requires active authentication steps).
Withdrawal Rights: Consent can be withdrawn at any time by disconnecting from Odoo, revoking OAuth permissions, or uninstalling the extension. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.
Applies to: Optional AI features (email composition assistant, meeting transcription), email tracking pixels, meeting recordings (explicit initiation required).
3. Contract Performance
Employment Contract: Processing necessary for performance of the employment contract between Ottometric and its employees, including fulfillment of work responsibilities, performance evaluation, and operational management.
Applies to: Work email logging for business continuity, customer relationship management activities, work time tracking for payroll and attendance purposes, productivity monitoring for performance reviews.
4. Legal Obligations
Compliance Requirements: Processing necessary to comply with legal obligations to which Ottometric is subject, including:
- Record-keeping requirements for business communications and transactions
- Employment law compliance (work hours, overtime tracking)
- Tax and accounting regulations
- Data retention obligations for legal proceedings
- Regulatory reporting and audit requirements
Applies to: Business email records, work time logs, transaction histories, compliance documentation.
5. How We Use Your Data
We use collected data solely for legitimate business purposes related to customer relationship management and operational efficiency. Data is never used for advertising, marketing to external parties, or purposes unrelated to business operations.
â Permitted Uses
Data may be used for CRM record creation and updating, sales pipeline management, customer communication tracking, internal productivity analytics, email quality improvement through AI analysis, reply detection and notifications, meeting documentation, and operational reporting purposes.
â Prohibited Uses
Data will never be used for third-party advertising, selling to data brokers, training external AI models, social media integration, marketing to competitors, public data aggregation, surveillance beyond legitimate work scope, or unauthorized data mining activities.
Specific Use Cases by Extension
Gmail & Outlook Extensions:
The Gmail and Outlook extensions facilitate CRM Logging by automatically creating Odoo activity records for business emails; Contact Matching to link email addresses with existing Odoo partner records; Deal Association connecting emails to active CRM opportunities based on participants; Reply Tracking through Gmail API monitoring to detect customer responses; AI Email Assistant for analyzing draft emails regarding tone, clarity, and grammar (Gmail only, opt-in feature); Email Tracking via Odoo Email Marketing pixel and click URL generation; and Work Time Analytics calculating active work hours versus idle periods for productivity insights.
Meet Extension:
The Meet extension provides Recording Storage capabilities to save meeting recordings to your personal Google Drive; Transcription services generating searchable text transcripts using AWS Bedrock AI; CRM Integration linking meeting records to Odoo contacts and opportunities; and Meeting Documentation maintaining a searchable archive of business meetings.
6. Data Collection Methods
Data collection occurs through multiple mechanisms, both automated and user-initiated. Understanding these methods helps clarify when and how your data is accessed.
A Automatic Collection
- Email monitoring: Extensions continuously monitor your Gmail/Outlook mailbox for new sent/received emails
- Work time tracking: When connected to Odoo, the extension tracks active vs. idle status via Chrome's idle detection API
- Reply detection: Background polling checks Gmail threads every 1 minute for new replies
- Token refresh: OAuth tokens are automatically renewed before expiration
M Manual/On-Demand Collection
- Meeting recordings: Only collected when you explicitly click "Start Recording" in Google Meet
- AI email assistance: Only activated when you click the AI assistant button in Gmail compose window
- Manual email logging: When you click "Log to Odoo" button in email sidebar
API API-Based Collection
Data is accessed through official platform APIs with your explicit OAuth consent:
- Gmail API:
gmail.readonlyscope for reading email threads - Microsoft Graph API: Mail.Read scope for Outlook data
- Google Calendar API: Calendar.ReadOnly for meeting metadata
- Google Drive API: Drive.File scope (limited to files created by the extension)
Most data collection begins only after you authenticate with Odoo via the extension options page. Before authentication, the extensions remain dormant and do not access your email or other data.
7. Data Storage and Retention
7.1 Storage Locations
đĸ Odoo CRM Server
Location: odoo.ottometric.com
Data Stored:
- Email logs and content
- Contact associations
- Meeting metadata
- Work time records
- Activity timestamps
âī¸ Google Drive
Location: Your personal Google Drive
Data Stored:
- Meeting video recordings
- Meeting transcripts (text files)
- Recording metadata
đģ Local Browser Storage
Location: Chrome secure storage on your device
Data Stored:
- OAuth access tokens (encrypted)
- Extension preferences
- Temporary cache
- Tracked thread mappings
đ¤ AWS Bedrock (Temporary)
Location: Amazon Web Services AI service
Data Stored:
- Meeting audio (temporary processing only)
- Not retained after transcription
- No permanent storage
7.2 Data Retention Periods
| Data Category | Retention Period | Deletion Method |
|---|---|---|
| CRM Logs & Emails | Indefinite (per company policy) | Admin request to IT |
| Work Time Data | Indefinite (historical reporting) | Admin request to IT |
| Meeting Recordings | Until manually deleted from Drive | User deletes from Google Drive |
| Local Settings & Tokens | Until extension uninstalled | Automatic on uninstall |
| OAuth Tokens | Until sign-out or expiration | Sign out or uninstall |
| AWS Transcription Audio | Immediately after processing | Automatic deletion |
CRM data in Odoo is retained indefinitely as part of business records for historical reporting, audit trails, and regulatory compliance. If you require data deletion, please contact your Ottometric administrator who can submit a formal data deletion request to the IT department.
8. Data Sharing and Third Parties
8.1 Parties With Data Access
â Authorized Recipients
1. Odoo CRM Server (odoo.ottometric.com)
Receives: Email content, metadata, contact info, meeting metadata, work time data
Purpose: CRM operations, business intelligence, productivity analytics
2. Google APIs
Receives: OAuth authentication requests only (no business data shared)
Purpose: User authentication and authorization
3. Microsoft Graph API (Outlook extension only)
Receives: OAuth authentication requests only
Purpose: User authentication for Outlook data access
4. AWS Bedrock (Amazon AI Services)
Receives: Meeting audio for transcription (temporary processing only)
Purpose: AI-powered speech-to-text transcription
5. Ottometric Employees & Authorized Personnel
Access Level: Based on Odoo role permissions (managers, administrators, IT staff)
Purpose: CRM management, technical support, system administration, business analytics
â Parties We DO NOT Share With
- Third-party analytics services (e.g., Google Analytics, Mixpanel)
- Advertising networks or ad tech platforms
- Data brokers or list aggregators
- Social media platforms
- Marketing automation platforms (external)
- AI training services (beyond AWS Bedrock transcription)
- Cloud storage providers (except Google Drive for recordings)
- Any external party not explicitly listed above
8.2 Legal Disclosures
We may disclose collected data if required by law, legal process, or government request, including:
- Court orders or subpoenas
- Regulatory investigations
- Law enforcement requests with proper legal authority
- Protection of legal rights, safety, or property of Ottometric or others
In such cases, we will make reasonable efforts to notify affected users unless prohibited by law.
9. International Data Transfers
Ottometric's operations and service providers may involve the transfer of personal data across international borders. This section explains how we ensure appropriate safeguards for cross-border data transfers in compliance with applicable data protection laws.
9.1 Data Transfer Locations
Primary Data Processing Locations
United States:
- Odoo CRM Server: Hosted at odoo.ottometric.com (data center location: USA)
- AWS Bedrock AI Services: Amazon Web Services US regions for meeting transcription
- Google Cloud Services: Google Drive (user-selected region), Gmail API, Calendar API (USA)
European Economic Area (EEA):
- No primary data processing servers located in EEA
- European employee data may be transferred to US-based systems (see safeguards below)
Other Regions:
- Data may transit through content delivery networks (CDNs) or cloud infrastructure in various countries
- All transfers subject to appropriate safeguards as described below
9.2 Legal Mechanisms for Data Transfers
Adequacy Decisions
Where available, we rely on European Commission adequacy decisions recognizing certain countries as providing adequate data protection:
- UK-EU adequacy decision (for UK employees)
- Switzerland adequacy decision (for Swiss employees)
- Other adequacy decisions as applicable to employee locations
9.3 Safeguards for International Transfers
Ottometric implements the following safeguards to protect personal data transferred internationally:
đ Technical Safeguards
- TLS 1.3 encryption for all data in transit
- Encrypted storage of sensitive data
- Access controls and authentication
- Regular security audits and penetration testing
đ Contractual Safeguards
- Standard Contractual Clauses with processors
- Data Processing Agreements (DPAs)
- Vendor security requirements
- Audit rights and compliance monitoring
đĄī¸ Organizational Safeguards
- Privacy by design principles
- Staff training on data protection
- Incident response procedures
- Regular compliance reviews
âī¸ Legal Safeguards
- Compliance with GDPR
- Transfer Impact Assessments (TIAs)
- Review of government access laws
- Transparent data handling practices
9.4 Government Access to Data
US Government Access: As data is processed in the United States, it may be subject to US laws regarding government access, including the Foreign Intelligence Surveillance Act (FISA) and the CLOUD Act. We assess these risks as part of our transfer impact assessments.
Mitigating Measures: To mitigate risks of government access:
- We use encryption to protect data in transit and at rest
- Our service providers (AWS, Google) maintain transparency reports on government data requests
- We commit to notifying affected individuals of lawful data requests unless legally prohibited
- We challenge overly broad or unlawful requests where legally permissible
10. Security Measures and Incident Response
We implement industry-standard security controls to protect collected data from unauthorized access, disclosure, alteration, or destruction.
đ Encryption
- In Transit: All data transmission uses HTTPS/TLS 1.3 encryption
- At Rest: OAuth tokens encrypted in Chrome secure storage
- API Calls: All API requests use secure HTTPS endpoints
đ Authentication
- OAuth 2.0: Industry-standard secure authentication (no passwords stored)
- Token Rotation: Automatic refresh of expired tokens
- Scope Limitation: Request minimum necessary API permissions
đĨ Access Controls
- Role-Based Access: Odoo permissions limit data visibility
- Least Privilege: Users see only data needed for their role
- Audit Logs: Odoo tracks data access and modifications
đĄī¸ Infrastructure Security
- Network Isolation: Odoo CRM on secure internal network
- Firewall Protection: Access restricted to authorized IP ranges
- Regular Updates: Security patches applied promptly
Additional Security Practices
- Minimal Permissions: Extensions request only necessary Chrome permissions for core functionality
- Secure Storage: Chrome's secure storage API protects locally stored credentials
- No Plaintext Passwords: All authentication uses OAuth tokens, never passwords
- Regular Security Reviews: Code audits and vulnerability assessments conducted periodically
- Security Monitoring: Continuous monitoring of systems for suspicious activity and potential threats
- Vendor Management: Regular security assessments of third-party service providers (AWS, Google)
- Patch Management: Timely application of security patches and updates to all systems
10.1 Data Breach Response and Notification
In the event of a data breach that compromises the security of personal data collected through these extensions, Ottometric follows documented incident response procedures in compliance with applicable data breach notification laws.
Incident Response Process
1. Detection and Containment (0-24 hours)
- Immediate investigation upon discovery of security incident
- Containment measures to prevent further unauthorized access
- Preliminary assessment of breach scope and affected data
- Activation of incident response team
2. Assessment and Remediation (24-72 hours)
- Full forensic analysis to determine cause and extent of breach
- Identification of all affected individuals and data categories
- Implementation of remediation measures to prevent recurrence
- Risk assessment for affected individuals
3. Notification (72 hours for GDPR)
- Supervisory Authority Notification: If required under GDPR, notification to relevant data protection authority within 72 hours of breach discovery
- Individual Notification: If breach poses high risk to individuals , direct notification to affected persons without undue delay
- CCPA Notification: California residents notified within legally required timeframes if breach involves personal information
- Management Notification: Internal escalation to senior management and legal counsel
4. Post-Incident Review
- Root cause analysis and lessons learned documentation
- Update of security policies and procedures as needed
- Additional security controls implementation
- Staff retraining if human error contributed to breach
â ī¸ Notification Content
Breach notifications (when required) will include:
- Nature of the personal data breach and categories of data affected
- Approximate number of affected individuals and data records
- Name and contact details of Data Protection Officer or privacy contact
- Likely consequences of the breach
- Measures taken or proposed to address the breach and mitigate harm
- Recommended steps for affected individuals to protect themselves
If you become aware of a security vulnerability, data breach, or suspicious activity related to these extensions, immediately report it to security@ottometric.com. For critical incidents, also contact your direct manager or IT administrator. We maintain a responsible disclosure process for security researchers.
Users are responsible for securing their own devices, using strong passwords for Google/Microsoft accounts, enabling two-factor authentication where available, keeping browser and extensions updated, and reporting suspicious activity. Do not share OAuth tokens, authentication credentials, or install extensions from untrusted sources.
9. Chrome Extension Permissions Explained
Chrome extensions require explicit permissions to access certain browser features and web APIs. Below is a detailed explanation of each permission requested by Ottometric extensions and why it's necessary.
| Permission Identifier | API Namespace | Runtime Context | Technical Capability & Scope | Business Implementation & Data Flow |
|---|---|---|---|---|
| CORE INFRASTRUCTURE & AUTHENTICATION | ||||
storage |
chrome.storage.* | Persistent + Sync | Encrypted IndexedDB-backed key-value storage with sync.storage cross-device replication; quota-managed (5MB local, 100KB sync) | Persists OAuth access/refresh tokens, user preferences, CRM tenant URLs, activity timestamps, cache invalidation markers |
identity |
chrome.identity | Auth Handler | OAuth 2.0 authorization code + PKCE flow initiator; integrates Chrome's identity provider without credential exposure | Federated authentication with Google Workspace / Microsoft 365; silent token refresh via refresh_token grant type |
cookies |
chrome.cookies | Cross-Domain | Read/write access to HTTP cookies for permitted host patterns; observes SameSite, Secure, HttpOnly attributes | Session management for Odoo backend; CSRF token extraction for API request authentication; detects login state changes |
| WEB CONTENT INTEGRATION & DOM MANIPULATION | ||||
scripting |
chrome.scripting | Injected Script | Dynamic content script injection with document_start/document_end timing; CSS stylesheet insertion; isolated world execution | Renders CRM sidebar UI in Gmail/Outlook via InboxSDK; thread metadata extraction; compose window interception for logging |
activeTab |
chrome.tabs | User-Initiated | Temporary tab metadata access (URL, title, favIconUrl) granted only upon user-initiated action (icon click, keyboard shortcut) | Context-aware UI activation; detects Gmail/Outlook/Meet URLs for conditional feature loading without persistent tab monitoring |
tabs |
chrome.tabs | Background | Query/enumerate open tabs; listen to tab lifecycle events (onCreated, onUpdated, onRemoved, onActivated); manage tab state | Multi-tab coordination for Gmail reply tracking; ensures single active CRM sidebar instance; handles navigation state persistence |
contextMenus |
chrome.contextMenus | UI Extension | Browser right-click context menu customization; adds extension-specific menu items with icon, title, enabled state | Quick-action menu for "Log to CRM" on selected email text; "Create Lead from Contact" for highlighted email addresses |
| BACKGROUND PROCESSING, SCHEDULING & STATE MANAGEMENT | ||||
background |
service_worker | MV3 Worker | Manifest V3 service worker registration; event-driven architecture with automatic wake/sleep lifecycle management | Persistent background orchestrator; coordinates API requests, handles chrome.runtime message routing, manages WebSocket connections |
alarms |
chrome.alarms | Scheduled Task | Deferred callback execution with periodInMinutes or delayInMinutes scheduling; persists across service worker termination | Polls Gmail API every 2 minutes for reply detection; refreshes OAuth tokens 5 minutes before expiry; syncs CRM cache hourly |
windows |
chrome.windows | Multi-Window | Browser window enumeration and lifecycle tracking; onFocusChanged listener for window state awareness across displays | Activity monitor handles multi-monitor setups; coordinates focus tracking with idle detection for accurate work session analytics |
power |
chrome.power | System Level | Prevents system sleep/display dimming via requestKeepAwake("system"|"display"); release via releaseKeepAwake() | Meet extension keeps display active during recording sessions; prevents interruption of long-running video capture processes |
idle |
chrome.idle | State Detector | System activity state detection with configurable interval thresholds | Session timing accuracy |
notifications |
chrome.notifications | Desktop Alert | Rich notification templates (basic, image, list, progress) via native OS notification center; supports action buttons and icons | User alerts for tracked email replies, OAuth expiration warnings, CRM sync failures, meeting recording completion status |
| NETWORK REQUEST INTERCEPTION & FILTERING | ||||
declarativeNetRequest |
chrome.declarativeNetRequest | Net Modifier | Declarative request blocking/redirection/header modification rules processed in browser core; replaces blocking webRequest | Injects custom headers for CRM API authentication; blocks third-party trackers on Gmail pages to reduce network noise |
| MEDIA CAPTURE & RECORDING (MEET EXTENSION ONLY) | ||||
tabCapture |
chrome.tabCapture | MediaStream | Captures tab audio/video as MediaStream; requires user gesture; exposes getMediaStreamId() for offscreen document processing | Records Google Meet video/audio when user clicks "Start Recording"; encodes via MediaRecorder API; uploads to Drive |
desktopCapture |
chrome.desktopCapture | Screen Picker | Invokes system screen/window/app picker dialog; grants constrained MediaStream access to user-selected source post-approval | Includes screen-sharing in meeting recordings when presenter mode active; requires explicit user permission per capture session |
| HOST-SPECIFIC ACCESS PERMISSIONS & ORIGIN POLICIES | ||||
| host_permissions | Match patterns | CORS Bypass | Cross-origin resource sharing (CORS) exemptions for specified URL patterns; enables fetch() to external APIs |
|
We follow the principle of least privilege and request only permissions strictly necessary for core functionality. Permissions are reviewed with each extension update to ensure continued necessity.
10. Google API Services User Data Policy Compliance
Our extensions comply with the Google API Services User Data Policy, including the Limited Use requirements that restrict how we handle data obtained from Google APIs.
Limited Use Disclosure
Ottometric Chrome Extensions' use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.
API Scopes and Usage
đ§ Gmail API (gmail.readonly)
Scope Purpose: Monitor email threads for replies to tracked business emails
Data Accessed: Thread metadata, message headers, message bodies, attachment metadata
Usage: Auto-log business communications to Odoo CRM, detect replies, provide AI email composition assistance
Limited Use Compliance: Data used ONLY for CRM logging and email management features. Not used for:
- Advertising or targeting
- Training external AI models (beyond AWS Bedrock for transcription)
- Selling to data brokers
- Creditworthiness or lending purposes
âī¸ Google Drive API (drive.file)
Scope Purpose: Save meeting recordings created by the extension
Data Accessed: Only files created by this extension (limited scope)
Usage: Write-only access to store meeting videos and transcripts in user's personal Google Drive
đ
Google Calendar API (calendar.readonly)
Scope Purpose: Fetch meeting details for recording file naming
Data Accessed: Event titles, start/end times, participant names
Usage: Read-only access to automatically name meeting recordings with event details
Data Handling Commitments
- â Gmail data is accessed ONLY for features clearly visible to the user (email logging, AI assistant)
- â No data transfer to third parties except Odoo CRM (internal business system)
- â No use of Gmail data for serving advertisements
- â No sale or transfer of user data to data brokers or information resellers
- â Human readable data (emails, calendar events) used only for stated business purposes
- â Compliance with all other Google API Services User Data Policy requirements
11. Your Rights and Controls
You have several options to control your data and manage how the extensions function. Below are the actions you can take to exercise your rights.
11.1 Data Control Actions
đ Disable Extension
How: Navigate to chrome://extensions/, find Ottometric extension, toggle OFF or click "Remove"
Effect: Stops all data collection immediately; local data deleted
đ Disconnect from Odoo
How: Open extension options page, click "Disconnect" or "Sign Out"
Effect: Stops CRM logging and work time tracking; OAuth tokens revoked
đ Revoke OAuth Access
How: Visit Google Account Permissions or Microsoft App Permissions
Effect: Extension can no longer access Gmail/Outlook data until re-authorized
đī¸ Delete Local Data
How: Uninstall the extension completely
Effect: All browser-stored data (tokens, settings, cache) permanently deleted
đ Delete CRM Data
How: Contact your Ottometric administrator to submit data deletion request
Effect: Email logs and work time data removed from Odoo CRM
đ¤ Opt Out of AI Features
How: Simply don't click AI assistant buttons in Gmail compose window
Effect: AI analysis not performed unless explicitly requested
11.2 Data Access and Portability
As an Ottometric employee, you can access all your logged data directly in the Odoo CRM system at odoo.ottometric.com. To request a data export or deletion, contact your administrator.
Data Export Requests:
- Email your request to: admin@ottometric.com
- Include: Your name, email address, data types requested (email logs, work time data, etc.)
- Response time: 14 business days
- Format: CSV or JSON export from Odoo
12. Internal Use Policy
â ī¸ IMPORTANT: Internal Business Tools Only
These Chrome extensions are designed exclusively for use by authorized Ottometric employees and business partners as internal business productivity tools. They are NOT intended for consumer use, public distribution, or installation by the general public.
Who Should Use These Extensions:
- Current Ottometric employees with active company email accounts
- Authorized contractors or consultants with Odoo CRM access
- Business partners explicitly approved by Ottometric management
If You Are NOT an Ottometric Employee:
- â Do not install these extensions
- â Do not attempt to connect to odoo.ottometric.com
- â Do not use these extensions for personal purposes
- â Do not distribute or share these extensions publicly
Internal Data Governance
All data collected by these extensions is subject to Ottometric's internal data governance, security policies, and employee handbook provisions. By using these extensions, you acknowledge:
- Your work email communications may be logged to CRM for business purposes
- Work time data is collected for productivity reporting and operational insights
- Authorized managers and administrators can access logged data via Odoo
- Data handling complies with applicable employment laws and company policies
- Extensions are provided for business use during working hours
13. Legal and Regulatory Compliance
Ottometric Chrome Extensions are developed and operated in compliance with relevant laws, regulations, and industry standards.
â Compliance Frameworks
- â Chrome Web Store Developer Program Policies - Adheres to all Chrome extension guidelines
- â Google API Services User Data Policy - Including Limited Use requirements for Gmail/Calendar/Drive APIs
- â OAuth 2.0 Security Best Practices - Secure authentication and token management
- â Microsoft Graph API Terms of Service - Compliant use of Outlook/Office 365 data
- â Ottometric Internal Data Governance Policies - Aligns with company security and privacy standards
- â Applicable Employment Laws - Work time tracking complies with labor regulations
Privacy Regulations
While these extensions are internal business tools (not consumer-facing products), we recognize the importance of data protection principles:
- GDPR Principles: Data minimization, purpose limitation, transparency (applicable to EU employees)
- CCPA Awareness: California employees have rights to data access and deletion
- Employment Privacy: Work-related data collection disclosed to employees
Security Standards
- HTTPS/TLS 1.3 encryption for data in transit
- OAuth 2.0 secure authentication (no password storage)
- Regular security code reviews and vulnerability assessments
- Incident response procedures for security breaches
14. Contact Information
For questions, concerns, or requests related to this Privacy Policy or data handling practices, please contact: info@ottometric.com
Response Time: We aim to respond to all inquiries within 5 business days. For urgent security issues, contact security@ottometric.com immediately.
15. Policy Updates and Changes
We may update this Privacy Policy periodically to reflect changes in our extensions, data practices, regulatory requirements, or company policies. Material changes will be communicated to users through appropriate channels.
How We Notify Users of Changes
- Material Changes: Email notification to all active users + in-extension notification banner
- Minor Updates: Updated "Last Updated" date on this page + changelog in extension release notes
- Compliance Changes: Immediate notification if required by law or regulatory guidance
What Constitutes a Material Change
- New types of data collection (e.g., adding browsing history tracking)
- Changes to data sharing practices (e.g., new third-party recipients)
- Significant changes to data retention periods
- New purposes for using collected data
- Changes to security practices that may affect user privacy
Continued use of the extensions after a Privacy Policy update constitutes acceptance of the revised terms. If you do not agree with changes, you may discontinue use and uninstall the extension.
Version History
| Version | Date | Changes |
|---|---|---|
| 3.0 | September 1, 2026 | Comprehensive update: Added legal basis for data processing, international data transfers, enhanced security and incident response procedures, detailed breach notification protocols |
| 2.5 | July 30, 2026 | Added AI enhancement and analysis features; updated permissions section |
| 2.0 | July 21, 2026 | Major update for Gmail extension v2.5 features |
| 1.0 | January 15, 2026 | Initial policy release |
â Acknowledgment and Consent
By installing and using Ottometric Chrome Extensions, you acknowledge that you have read, understood, and agree to this Privacy Policy. You confirm that you are an authorized Ottometric employee or business partner with permission to use these internal business tools.
Last Updated: September 1, 2026 | Version: 3.0 | Effective Date: September 1, 2026