Google Workspace / Google API User Data Privacy Addendum
Effective Date: July 15, 2026
This Google Workspace / Google API User Data Privacy Addendum (the “Addendum“) describes how XM Cyber Ltd. (“XM Cyber“, “we“, “our“, or “us“) processes Google Workspace user data accessed through Google APIs in connection with the XM Cyber Security Posture Management Extension (the “Extension“) and the XM Cyber Continuous Exposure Management Platform (the “Service“).
This Addendum supplements XM Cyber’s Privacy Policy and applies specifically to information obtained through Google APIs.
- Data Access: What Google user data is accessed
The Extension requests only the minimum Google API permissions and OAuth scopes necessary to provide the functionality described in this Addendum.
Using the Google Admin SDK Directory API and the Cloud Identity API, the Extension accesses the following Google Workspace administrative information on a read-only basis:
- Users and basic directory attributes;
- Groups and group memberships;
- Organizational units;
- Administrator roles and role assignments;
- Registered domains and the Google Workspace customer ID; and
- Cloud Identity security policies and configuration information.
The Extension does not access user content, including:
- Gmail messages or attachments;
- Google Drive files or file contents;
- Google Calendar events or event contents;
- Google Chat messages;
- Google Contacts;
- Google Docs, Sheets, Slides, or other Workspace document contents; or
- The contents of any user-created files or communications.
All Google Workspace access is read-only. The Extension does not create, modify, delete, or otherwise alter customer Google Workspace data.
Google Workspace data is retrieved only during:
- the customer’s initial authorization; and
- customer-initiated or scheduled synchronizations necessary to provide the Service.
- Data Use: How Google user data is used
Google Workspace user data is used solely to provide the Service.
Specifically, XM Cyber uses Google Workspace user data to:
- assess the customer’s Google Workspace security posture;
- map identities, administrative privileges, organizational structure, and access relationships;
- identify security misconfigurations, excessive privileges, compliance risks, and potential attack paths;
- generate exposure analysis and security findings; and
- present recommendations and security insights to the customer’s authorized administrators.
Google Workspace user data is not used:
- for advertising or marketing purposes;
- to build marketing or behavioral profiles;
- for any purpose unrelated to providing or securing the Service;
- to sell or promote products or services; or
- to develop, improve, or train generalized artificial intelligence or machine learning models.
- Data Sharing: With whom Google user data is shared
Google Workspace user data is transmitted securely to the XM Cyber platform for processing and presentation to the customer’s authorized users.
XM Cyber does not sell, rent, license, or otherwise monetize Google Workspace user data.
Google Workspace user data is disclosed only:
- to the customer’s own authorized users within the Service;
- to XM Cyber’s affiliates, service providers, and subprocessors that provide hosting, infrastructure, cloud services, security, customer support, or other operational services necessary to provide the Service, and only under written agreements requiring appropriate confidentiality, security, and data protection obligations;
- where reasonably necessary to investigate security incidents, prevent fraud or abuse, or protect the security or integrity of the Service; or
- where required by applicable law, regulation, court order, or other valid legal process.
XM Cyber does not transfer Google Workspace user data to any third-party artificial intelligence or machine learning service for the purpose of training generalized models.
- Data Protection
Google Workspace user data is protected using administrative, technical, and organizational safeguards appropriate to the sensitivity of the data.
These safeguards include:
- Encryption in transit using TLS;
- Encryption at rest;
- Authentication and role-based access controls;
- Least-privilege access controls;
- Logging and monitoring of administrative access;
- Security monitoring and incident response procedures; and
- Periodic review of access permissions.
Google Workspace user data is not routinely accessed by XM Cyber personnel.
Access by authorized personnel is permitted only when reasonably necessary to:
- provide customer support;
- maintain or secure the Service;
- investigate technical issues or security incidents; or
- comply with applicable legal obligations.
Any such access is:
- limited to authorized personnel;
- protected by authentication and access controls;
- logged where appropriate; and
- subject to XM Cyber’s internal security procedures.
- Data Retention and Deletion
Google Workspace user data is retained only for as long as necessary to provide the Service.
Information is refreshed during scheduled synchronizations so that the Service reflects the customer’s current Google Workspace environment.
Upon termination of the Service or receipt of a verified customer deletion request, XM Cyber will delete or anonymize Google Workspace user data from active production systems using commercially reasonable and technically practicable methods.
Our target timeframe for deletion from active production systems is within sixty (60) days after service termination or verification of the deletion request, unless continued retention is:
- required by applicable law; or
- necessary to establish, exercise, or defend legal claims.
Google Workspace user data that has been deleted from production systems may remain in encrypted backup media for disaster recovery and business continuity purposes until overwritten or deleted in accordance with XM Cyber’s backup retention schedule.
Regarding backups:
- backup retention is generally limited to no more than one (1) year;
- backup copies remain encrypted;
- backup copies are not used for operational processing; and
- backup copies are accessed only as necessary for disaster recovery, disaster recovery testing, or maintaining system continuity.
- Google API Services User Data Policy (Limited Use)
XM Cyber’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use Requirements, available at:
https://developers.google.com/terms/api-services-user-data-policy
Accordingly, Google Workspace user data obtained through Google APIs:
- is used only to provide customer-requested, user-facing functionality of the Service;
- is not sold, rented, licensed, or otherwise monetized;
- is not used for advertising or marketing;
- is not used to create user profiles unrelated to providing the Service;
- is not transferred to third-party artificial intelligence or machine learning services for training generalized models; and
- is not used for any purpose prohibited by the Google API Services User Data Policy.
- Contact
If you have questions regarding this Addendum or XM Cyber’s processing of Google Workspace user data, please contact us using the contact information provided in XM Cyber Ltd.’s Privacy Policy ([email protected])