Privacy & Data Protection Policy
Including Third-Party API Data Use, Google API Limited Use Disclosure, Microsoft API Data Use, and Vietnam Compliance Notice.
On Hand BI’s use and transfer of information received from Google APIs to any other application will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Read the full Google data section1. Introduction and Scope
On Hand BI Company Limited (“OHBI”, “we”, “our”, or “us”) provides a business intelligence and analytics platform that helps users connect, manage, embed, refresh, distribute, monitor, and analyze reports, dashboards, workspaces, datasets, and related data assets.
OHBI is designed for digital commerce analytics and business reporting. The platform may include governance features for Power BI workspaces and assets, report embedding, report sharing, data source connection, refresh workflows, health monitoring, alerting, audit logs, and AI-assisted analytics or support features.
This Privacy & Data Protection Policy explains how OHBI collects, uses, stores, protects, shares, transfers, retains, and deletes user data when users access our website, web application, reporting platform, data connectors, APIs, integrations, and related services.
As a company established and operating in Vietnam, OHBI complies with applicable Vietnamese laws and regulations on personal data protection, cybersecurity, consumer protection, electronic transactions, and enterprise operations. This Policy is also designed to address third-party platform requirements applicable to OHBI integrations, including Google API Services User Data Policy and Microsoft platform requirements.
2. Information We Collect
2.1 Account and Contact Information
- Name, email address, organization name, position or role, company information, login identifiers, billing or plan information, and information users provide when creating or managing an OHBI account.
- Support, sales, onboarding, feedback, and service communication information.
2.2 Authentication, Authorization, and Identity Information
- Login events, session information, user ID, organization ID, tenant or realm information, role assignments, group membership, access permissions, and authorization status.
- OAuth tokens, API tokens, service principal credentials, client secrets, or similar credentials only where users or organizations provide or authorize such credentials for integrations.
2.3 Report, Workspace, and Analytics Metadata
- Report names, report IDs, dashboard IDs, paginated report IDs, dataset IDs, workspace IDs, collection metadata, asset type, asset owner, lifecycle status, sharing status, and access control metadata.
- Data source type, credential status, refresh status, refresh history, schedule settings, health state, error status, operational logs, and audit logs.
2.4 Third-Party Integration Data
When users connect third-party services, OHBI may collect or process the minimum data required to provide the requested functionality. Third-party integration data may include:
- Selected Google Drive file metadata, Google Sheets spreadsheet metadata, and spreadsheet content or selected ranges required for user-configured reporting or data workflows.
- Microsoft Entra ID / Azure AD tenant and application information, Power BI workspace metadata, report metadata, dashboard metadata, dataset metadata, embed tokens, refresh status, and permission metadata.
- Connection metadata, API responses, refresh logs, error logs, diagnostic logs, and user-selected configuration settings.
2.5 Technical, Usage, and Security Information
- Browser type, device information, IP address, approximate location derived from network information, operating system, access time, feature usage, clickstream, error events, system logs, and diagnostic information.
- Audit logs and activity logs required for security, troubleshooting, governance, incident response, compliance, and platform reliability.
2.6 Personal Data and Sensitive Personal Data
Some information collected or processed by OHBI may qualify as personal data under applicable law. Certain information may qualify as sensitive personal data if it reveals or relates to sensitive categories under applicable Vietnamese regulations or other applicable laws. OHBI aims to limit the collection and processing of personal data and sensitive personal data to what is necessary for disclosed and legitimate purposes.
3. How We Use Information
OHBI uses collected information for the following purposes:
- Create, authenticate, secure, and manage user accounts.
- Provide reporting, embedding, sharing, refresh, delivery, monitoring, alerting, audit logging, and analytics features.
- Connect to user-authorized third-party services and maintain those connections where users request persistent workflows.
- Display, manage, refresh, distribute, and monitor analytics reports, dashboards, workspaces, datasets, and connected assets.
- Validate permissions, enforce role-based access control, and prevent unauthorized access.
- Operate health monitoring, incident detection, notifications, support workflows, and service reliability processes.
- Troubleshoot errors, prevent abuse, improve security, improve platform performance, and maintain service quality.
- Provide customer support, onboarding, account administration, billing, and service communications.
- Comply with legal, regulatory, security, audit, accounting, tax, contractual, and dispute-resolution obligations.
OHBI does not sell personal information or third-party API user data. OHBI does not use Google Workspace API data, Microsoft API data, or user-connected report data for advertising or unrelated profiling.
4. Third-Party API Data Use
OHBI integrates with third-party APIs only when users or authorized administrators intentionally connect those services, grant permissions, or provide the necessary credentials. OHBI uses third-party API data only for the features requested by the user or the user’s organization.
4.1 General Third-Party API Principles
- Purpose limitation: OHBI uses third-party API data only for disclosed, user-facing product functionality.
- Data minimization: OHBI requests and processes only the data reasonably necessary for the configured feature.
- Access control: OHBI enforces account, role, organization, workspace, asset, and sharing permissions.
- Credential protection: OAuth tokens, API tokens, service principal credentials, and secrets are treated as sensitive credentials and protected by security controls.
- Revocation: Users or administrators can disconnect integrations or revoke access through OHBI or the relevant third-party provider.
- Transparency: OHBI discloses the categories of third-party data it accesses, uses, stores, shares, retains, and deletes.
4.2 Google Workspace APIs
OHBI may use Google Workspace APIs to allow users to connect selected Google files or spreadsheets for reporting, data preparation, data import, data refresh, dataset update, dashboard or report workflows, and related analytics use cases.
Depending on the feature used and the permissions granted by the user, OHBI may access limited Google user data such as:
- Selected Google Drive file metadata.
- Selected Google Sheets spreadsheet metadata.
- Spreadsheet values, sheet names, selected ranges, and related content required for user-configured report or data workflows.
- OAuth tokens required to maintain the authorized connection.
- Connection status, refresh status, error status, and operational logs related to the integration.
OHBI uses Google Workspace API data only to provide user-requested product functionality, such as connecting a Google Sheet as a data source, importing selected spreadsheet data, refreshing a connected dataset, updating a report workflow, or helping the user manage the connected analytics asset.
4.3 Microsoft Power BI and Microsoft APIs
OHBI integrates with Microsoft Power BI and Microsoft identity services to help users manage Power BI workspaces, reports, dashboards, paginated reports, datasets, embedded analytics, refresh workflows, and governance features.
Depending on the user’s configuration and permissions, OHBI may access Microsoft or Power BI data such as:
- Microsoft Entra ID / Azure AD tenant ID, application ID, service principal configuration, and permission metadata.
- Power BI workspace metadata, report metadata, dashboard metadata, paginated report metadata, dataset metadata, and capacity metadata.
- Embed tokens, runtime authorization data, dataset refresh status, refresh history, schedule status, and operational logs.
- User or organization permission metadata needed to manage report distribution, embedding, and access control.
OHBI uses Microsoft and Power BI API data only to provide reporting, embedding, governance, refresh, distribution, monitoring, alerting, and support features requested by the user or the user’s organization.
5. Google API Services User Data Policy and Limited Use Disclosure
OHBI’s use and transfer of information received from Google APIs to any other application will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
OHBI’s use of Google user data is limited to providing or improving user-facing features that are clearly disclosed in this Policy and requested by the user or the user’s organization.
5.1 What OHBI Will Not Do with Google User Data
- OHBI will not sell Google user data.
- OHBI will not use Google user data for advertising purposes.
- OHBI will not use Google user data to build unrelated user profiles.
- OHBI will not use Google user data for unrelated surveillance, creditworthiness, employment, insurance, or eligibility decisions.
- OHBI will not transfer Google user data to third parties except as necessary to provide or improve the requested functionality, comply with applicable law, protect against security threats, or as otherwise permitted by the Google API Services User Data Policy.
- OHBI will not allow humans to read Google user data unless required for security, legal compliance, user-requested support, troubleshooting with user consent, or other permitted purposes under applicable policy and law.
5.2 Minimum Necessary Access and Scope Use
OHBI requests access to Google data only where necessary for the relevant product feature. Where possible, OHBI uses limited, file-specific, context-specific, or user-selected permissions rather than broad access to a user’s entire Google Drive or Google Workspace account.
If OHBI requests read-only Google Sheets access, that access is used only for user-authorized and user-configured spreadsheet workflows, such as persistent connected data sources, manual refresh, scheduled refresh, report update, dataset update, or other analytics workflows that require reading spreadsheet content after the initial connection. OHBI does not use read-only spreadsheet access to scan unrelated files or discover unrelated user data.
5.3 Google Data Storage, Retention, and Deletion
- OHBI stores only the Google data or metadata necessary to operate the connected feature, such as spreadsheet ID, selected sheet or range, connection status, refresh status, and related operational logs.
- OAuth tokens and credentials are stored securely and protected by access control and encryption or equivalent safeguards.
- When a user disconnects a Google integration, OHBI stops using the disconnected API access and deletes or deactivates related credentials according to operational, legal, security, audit, and backup requirements.
- Users may request deletion of applicable Google integration data by contacting OHBI.
6. Microsoft Power BI and Microsoft API Data Use
OHBI’s Microsoft Power BI integration is a core part of the OHBI reporting governance and embedded analytics platform. Users or enterprise administrators may connect Power BI workspaces to OHBI using Microsoft identity, OAuth flows, or Azure service principal configuration, depending on the deployment and product feature.
6.1 Power BI Data Use Purposes
- Discover and synchronize Power BI workspaces, reports, dashboards, paginated reports, and datasets that the user or organization authorizes OHBI to access.
- Create, manage, embed, refresh, share, distribute, and monitor report assets inside OHBI.
- Generate embed tokens and enforce runtime permissions for report viewing or editing where supported.
- Track refresh status, health state, permission errors, workspace errors, and operational events.
- Support governance workflows, including asset lifecycle, workspace management, access control, audit logs, alerting, and incident handling.
6.2 Microsoft Data Restrictions
- OHBI does not sell Microsoft or Power BI user data.
- OHBI does not use Microsoft or Power BI API data for advertising or unrelated profiling.
- OHBI does not access a Microsoft or Power BI tenant unless the user or organization has granted the required permission or provided the required credentials.
- OHBI uses Microsoft and Power BI data only within the scope of the authorized integration and product functionality.
7. AI-Assisted Features and Analytics Processing
OHBI may provide AI-assisted features to help users understand reports, query connected analytics data, receive product guidance, detect issues, summarize metadata, or generate operational insights. These features are designed to support user-facing analytics and support workflows.
- OHBI uses AI-assisted processing only for disclosed product functionality requested or enabled by the user or organization.
- OHBI does not use Google Workspace API data, Microsoft API data, report data, or connected data sources to train general-purpose AI models for unrelated purposes.
- Where AI features process report metadata, warehouse data, event logs, refresh history, health state, datasource schema, or error mapping, such processing is limited to providing OHBI's analytics, support, monitoring, or governance features.
- Enterprise customers may have additional controls, contractual restrictions, or administrative settings regarding AI-assisted features where applicable.
8. Data Storage, Security, and Operational Controls
OHBI applies administrative, technical, and organizational safeguards to protect user data and integration credentials. Security measures may include:
- Encryption in transit using secure protocols.
- Encryption or secure storage of sensitive credentials, OAuth tokens, API tokens, service account keys, client secrets, and service principal credentials.
- Role-based access control and tenant/realm isolation.
- Audit logging, activity logging, security logging, monitoring, and alerting.
- Internal access restrictions and least-privilege operational practices.
- Credential masking in user interfaces and logs where applicable.
- Health monitoring, error mapping, incident handling, and recovery procedures.
- Periodic review of access, integrations, and operational controls where applicable.
8.1 Audit Logs and Activity Logs
OHBI may maintain audit logs and activity logs to record user actions, system actions, integration events, API calls, refresh activities, permission changes, sharing changes, security events, and operational incidents. These logs help OHBI provide governance, troubleshooting, compliance, security, and support functionality.
8.2 Incident Response
If OHBI becomes aware of a security incident affecting user data, OHBI will investigate, take appropriate containment and remediation steps, and notify affected users, organizations, or competent authorities where required by applicable law or contract.
9. Data Sharing, Transfer, Retention, and Deletion
9.1 Data Sharing
OHBI does not sell user data. OHBI may share limited data only where necessary to:
- Provide, operate, secure, support, or improve the requested service or integration.
- Use authorized infrastructure, hosting, monitoring, security, analytics, communication, payment, or support providers.
- Comply with applicable law, regulation, legal process, court order, administrative request, or government request.
- Protect the rights, safety, integrity, or security of OHBI, our users, customers, partners, or third parties.
- Work with authorized subprocessors or service providers under appropriate confidentiality, security, and data protection obligations.
9.2 Cross-Border Data Transfer
OHBI may use cloud infrastructure, third-party APIs, subprocessors, or service providers located outside Vietnam to provide its services, including but not limited to Google, Microsoft, cloud hosting, monitoring, security, analytics, communications, and support providers.
When personal data is transferred outside Vietnam, OHBI will apply appropriate safeguards and comply with applicable Vietnamese requirements on cross-border personal data transfer, including required internal documentation, security measures, vendor controls, and cooperation with competent authorities where legally required.
9.3 Data Retention
OHBI retains user data only for as long as necessary to provide the service, comply with legal obligations, maintain security, resolve disputes, enforce agreements, maintain business records, support audit requirements, and operate backup or disaster recovery processes.
9.4 Data Deletion
Users may request deletion of applicable account data, integration data, or personal data by contacting OHBI. Some data may be retained where necessary for legal, contractual, security, audit, accounting, tax, backup, dispute-resolution, fraud prevention, or compliance purposes.
10. User Control, Revocation, and Data Subject Rights
10.1 Integration Control and Revocation
- Users or authorized administrators may review and manage connected integrations in OHBI where supported.
- Users may disconnect third-party integrations from OHBI or revoke OAuth access through the relevant third-party account settings.
- For Google integrations, users may revoke OHBI's access from their Google Account permission settings.
- For Microsoft integrations, users or administrators may manage consent, enterprise applications, service principals, and Power BI access through Microsoft Entra ID / Azure AD and Power BI admin settings.
10.2 Data Subject Rights
Subject to applicable law, users may have rights to request access, correction, deletion, restriction, withdrawal of consent, objection to processing, or information about data processing. OHBI will process such requests in accordance with applicable legal, contractual, security, and operational requirements.
10.3 Effect of Revocation or Deletion
Disconnecting an integration, revoking access, withdrawing consent, or requesting deletion may affect OHBI’s ability to provide connected data sources, report refresh, embedded analytics, workspace management, alerting, notifications, AI-assisted features, account administration, or other product functionality.
11. Compliance with Vietnamese Laws and Regulations
OHBI is operated by On Hand BI Company Limited, a company established and operating in Vietnam. In addition to third-party platform policies, OHBI processes personal data and provides services in accordance with applicable laws and regulations of Vietnam.
These may include, where applicable:
- Decree No. 13/2023/ND-CP on Personal Data Protection.
- Law on Cybersecurity No. 24/2018/QH14.
- Decree No. 53/2022/ND-CP guiding the implementation of certain articles of the Law on Cybersecurity.
- Law on Protection of Consumers' Rights No. 19/2023/QH15.
- Law on Electronic Transactions and relevant regulations on e-commerce, information security, tax, accounting, and enterprise operation in Vietnam.
- Other applicable laws, regulations, decrees, circulars, and guidance issued by competent Vietnamese authorities.
11.1 Personal Data Protection under Vietnamese Law
Depending on the nature of the service and user configuration, OHBI may act as a personal data controller, personal data processor, or a party that both determines and processes personal data. OHBI will process personal data only for legitimate, disclosed, and necessary purposes related to providing, securing, improving, supporting, and administering the OHBI platform.
Where required by Vietnamese law, OHBI will apply appropriate measures regarding:
- Transparency of personal data processing purposes.
- User consent where consent is legally required.
- User rights relating to access, correction, deletion, restriction, objection, and withdrawal of consent.
- Protection of basic personal data and sensitive personal data.
- Internal access control, confidentiality, and security safeguards.
- Incident handling and breach response.
- Processing records and internal compliance documentation.
- Data transfer and disclosure controls.
- Cooperation with competent Vietnamese authorities where legally required.
11.2 Consent and Withdrawal under Vietnamese Law
Where Vietnamese law requires consent, OHBI will seek user consent before collecting or processing relevant personal data, unless another lawful basis or permitted exception applies. Users may withdraw consent or request that OHBI stop processing certain personal data, subject to legal, contractual, security, operational, accounting, tax, audit, or dispute-resolution obligations.
11.3 Data Localization and Cybersecurity
OHBI is committed to complying with applicable Vietnamese cybersecurity and data storage requirements. Where Vietnamese law requires certain categories of data to be stored in Vietnam or requires specific cybersecurity measures, OHBI will evaluate and implement appropriate technical, organizational, and contractual measures.
11.4 Consumer Protection
For users who qualify as consumers under Vietnamese law, OHBI is committed to respecting applicable consumer protection requirements. OHBI will make reasonable efforts to provide clear information about service provider identity, service features and limitations, pricing, plans, applicable fees, terms of service, support channels, complaint handling processes, data protection practices, cancellation, account termination, and deletion procedures.
11.5 Cooperation with Vietnamese Authorities
OHBI may disclose information where required by applicable Vietnamese law, court order, administrative request, cybersecurity investigation, or other valid legal process. Where legally permitted, OHBI will limit such disclosure to the information reasonably required and will apply appropriate internal review procedures before responding to official requests.
11.6 Conflict between Policies
If this Policy refers to third-party platform policies, such as Google or Microsoft policies, those policies apply only to the relevant third-party API data and platform usage. Nothing in this Policy limits OHBI’s obligation to comply with applicable laws and regulations of Vietnam. If there is any conflict between this Policy and mandatory Vietnamese legal requirements, OHBI will comply with the mandatory legal requirements.
12. Children's Privacy
OHBI is intended for business and professional analytics use. OHBI is not directed to children and does not knowingly collect personal information from children. If OHBI becomes aware that it has collected personal information from a child in violation of applicable law, OHBI will take appropriate steps to delete such information or obtain legally required consent.
13. Changes to This Policy
OHBI may update this Policy from time to time. When material changes are made, OHBI will update the “Last updated” date and may notify users through the OHBI platform, email, website notice, or other appropriate channels.
If OHBI changes the way it uses Google user data, Microsoft API data, or other third-party API data in a materially different way, OHBI will update this Policy and, where required, request additional user or administrator consent before using the data for the new purpose.
14. Contact Us
If you have questions about this Policy or how OHBI handles user data, please contact us:
Google OAuth Disclosure Summary
This section summarizes how OHBI explains its Google API data practices for OAuth verification and user transparency.
- Limited Use statement
- OHBI's use and transfer of information received from Google APIs to any other application will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- Purpose of Google access
- Connect user-authorized Google Sheets or selected Google files to OHBI reporting, data import, dataset refresh, and analytics workflows.
- Data accessed
- Selected Drive file metadata, spreadsheet metadata, spreadsheet values, sheet names, selected ranges, OAuth tokens, connection status, refresh status, and operational logs.
- Data not used for
- Advertising, selling user data, unrelated profiling, surveillance, or unrelated AI model training.
- User controls
- Users can disconnect Google integrations in OHBI where supported and revoke OAuth access from Google Account permission settings.
- Retention
- Google integration data is retained only as necessary for the connected service, security, audit, legal, and operational purposes. Credentials are stopped or deleted/deactivated after disconnect according to applicable requirements.