Privacy Notice for Aspia’s use of Google Workspace SSO
This page explains how Aspia AB uses personal data related to the use of Google Workspace SSO login, “Google User Data”. Aspia process Google User Data as controller for its own use of Google Workspace SSO login and as a processor for our clients when using Google Workspace SSO login in accordance with the client’s instructions.
How we use Google User Data
Aspia will only use Google User Data for the purposes of enabling secure login to relevant applications.
When Aspia is acting as a controller, we process the Googe User Data on the basis of our own and our client’s legitimate interest.
Types of Google User Data
We will collect the following Google User Data:
Group and membership data:
- Group-ID
- Showing name
- Member type
- Member ID
End user data:
- Google immutable ID
- Email addrss
- Name
- Suspended-status
- Preferred language
- Phone number (if available)
Security
We maintain security measures (including physical, technical, electronic, and administrative measures) that are appropriate to protect Google User Data from loss, destruction, misuse, and unauthorized access or disclosure. For example, we limit access to personal data to those authorized employees and service providers who need to know the information in the course of their work tasks.
Transfer and disclosure of personal data
Data processors
We do not transfer or disclose Google User Data information to third parties for any other purpose than set out in this Privacy Notice.
To meet the purposes of our processing of the Google User Data, we engage suppliers of IT services and systems which process personal data on our behalf (data processors). Our data processors may only process personal data in accordance with our instructions and are required by law to take appropriate technical and organisational security measures to protect the personal data.
Other data controllers and authorities
We may disclose Google User Data to recipients other than processors and who act as independent data controllers well as to other recipients to comply with applicable law, a request/order by a competent court or government authority, and to ensure our legitimate interest to establish, exercise or defend legal claims.
Transfers of personal data outside the EU or EEA
We process the Google User Data primarily in the EU or European Economic Area. We may, however, transfer Google User Data outside these areas if our partner, or service provider, who processes personal data, is located fully or partly (e.g., for technical administration) in a third country.
In these cases, we will take necessary steps to provide appropriate safeguards for international data transfers, for example transfer Google User Data to countries that have been deemed to provide an adequate level of protection of personal data by the European Commission (“countries with adequate protection”).
Retention
Since the Google User Data is linked to an end user account, we will retain Google User Data as long as necessary to maintain the end user account.
Data Subject Rights
The rights related to the processing of Google User Data:
- The right to access (a copy of the Google User Data) – the data subject has a right to request information about what personal data we process.
- The right to rectification - the data subject has a right to request rectification of or to complete possible incorrect Google User Data.
- The right to object to processing based on legitimate interest - the data subject has a right to object to the processing of Google User Data unless there is interests that outweigh the data subject’s privacy interests.
- Restriction of the processing - the data subject has a right to request restriction, for example, if the personal data is incorrect or no longer necessary for the purpose for which it is being processed.
- The right to erasure - the data subject has a right to request the Google User Data to be erased, e.g. if it is no longer necessary for the purpose for which it is processed or if processing is incompatible with applicable data protection law.
Changes
We may update this notice at any time, if required in order to reflect the changes in our data processing practices. You can find the latest version at our website.
The last update of this Statement was on October 9th, 2026.
Contact details
If you have any questions regarding this notice, please contact us at groupprivacy@aspia.se.