/ /

Osano’s processing of Personal Information

Updated 15 days ago

Data Processing Overview

Osano processes personal information solely to deliver its services. Each application within the platform processes personal information according to its specific function, ensuring that only the minimum necessary data is used to perform its services and help customers maintain records of processing activities.

This policy adheres to the following principle: Osano does not use any data collected in a third-party context—such as IP addresses or user identifiers—for purposes beyond delivering its services (e.g., consent management, DSAR, Authorized Users, and Data Discovery). This means that Osano does not use or share data for tracking specific users or devices across different services.

Authorized Users

Osano collects personal information from customer-authorized users, including name, work email, password, and phone number. This data is required to verify secure access to customer accounts, facilitate communication, and provide customer support. Information submitted from outside the United States is transferred to the US for processing. This data is deleted when the customer relationship ends or if the customer removes the authorized user from their account.

Consent Management - Cookie Consent and Unified Consent

Cookie Consent

To display a cookie banner on a customer’s website and record visitor preferences, Osano collects the visitor’s IP address and unique device identifier. This information is encrypted in transit and at rest and is de-identified by Osano in AWS (Dublin, Ireland) as part of consent record-keeping. The hashed, de-identified data is stored in AWS (EU). Because the data is hashed and de-identified, Osano does not retain personal information; only the customer can identify an individual's consent by providing the original IP address at the time of consent to match against hashed records. No personal information from the EU or UK is transferred to the US.

Unified Consent

When users record their privacy choices, Osano may collect their email or phone number(for verification purposes, though this is optional), as well as an IP address and the user agent (the browser used to submit consents). All data is stored in AWS-managed services and protected by AWS: encrypted at rest using AES-256 (via AWS Key Management Service) and encrypted in transit using TLS. When identifiers such as IP address, email, phone, or subject ID are used to look up a consumer's consent records, they are stored as one-way hashes.

Unlike cookie consent, consents are recorded in either the EU (Frankfurt) or the US (N. Virginia, US), depending on the end user's jurisdiction at the time of consent. In cookie consent, all consent recording occurs in the EU (Ireland). Data is not transferred between regions in Unified Consent; all non-US consents remain in the EU. No personal information from the EU or the UK is transferred to the US.

Data Subject Access Requests (DSAR)

For individuals submitting Data Subject Access Requests (DSAR), Osano processes only the personal information necessary to verify identity and fulfill the request, including name, email address, location, and a unique identifier. Customers may customize DSAR forms to request additional details. This data is used solely for authentication and request fulfillment, and is processed and stored in AWS (N. Virginia, US). All data is encrypted in transit and at rest.

Because a requester may appeal a decision and needs continued access to the request portal, the request record and its associated personal information remain available for the full retention period rather than being de-identified at the point of fulfillment. 

The following data is retained for up to 730 days after request creation, in line with Osano's retention policy: requester email, first name, last name, country of residence, state/province/territory, proof of identity, and secure messaging attachments. Attachments associated with the Subject Rights Manager or with actions taken on a request are retained on the same 730-day schedule.

At the end of the 730-day period, all personal information associated with the request is permanently deleted. The only element retained after deletion is the unique request identifier assigned by the Osano platform, which contains no personal information and is kept for reporting and audit purposes. To maintain an auditable log of received requests and the responses they received, non-personal record data, including the unique request identifier, request dates, status, and the actions taken, is retained indefinitely and used in aggregate reporting metrics.

For a complete overview of DSAR and Discovery retention policies, refer to the Subject Rights Retention Policy.

Data Discovery

The Data Discovery feature helps customers locate and classify personal information within their integrated services. This enables customers to respond to DSARs and better understand the data they manage. The application searches for pre-identified fields that likely contain personal information, tags those fields, and suggests appropriate classifications.

Osano collects this data when customers enable an integration. The information is encrypted in transit and at rest and is stored in AWS (N. Virginia, US). A sample of data is pulled to ensure accurate classification. Depending on the data stored by the customer, the tool may process sensitive personal information to fulfill queries.

For a complete overview of DSAR and Discovery retention policies, refer to the Subject Rights Retention Policy.

Was this article helpful?
Subscribe to receive updates on this article