Privacy Policy
Last updated: 14 September 2026
1. Purpose of the Application
SD5 Eco Project Email HERMES is an internal workflow system used to support communication between the SD5 Eco Project team and companies or organizations involved in fundraising and presentation activities.
The application helps identify incoming company email responses and match them with the relevant student group and coordinator.
2. Google User Data Accessed
The application may access the following Google services:
- Gmail: read-only access to email metadata and message information required to identify incoming company responses.
- Google Sheets: read-only access to designated spreadsheets containing company, student, group, and coordinator mapping information used for routing.
3. How Google User Data Is Used
Google user data is used solely to operate the internal email routing workflow.
The system may use information such as sender email address, email subject, message identifiers, timestamps, and company mapping information to determine which SD5 Eco Project group should be notified.
Email message content is not used for advertising, profiling, sale of data, or unrelated purposes.
4. Gmail Access Is Read-Only
The application uses read-only Gmail permissions.
It does not use Google API access to:
- send or reply to email;
- delete email;
- archive email;
- mark email as read or unread;
- modify Gmail labels;
- create drafts on behalf of users.
5. Data Storage
The application may locally retain limited operational data necessary to prevent duplicate processing, such as Google message identifiers, processing checkpoints, routing status, and pending notification status.
The application is not designed to create a separate archive of users' Gmail message bodies.
6. Data Sharing
Google user data is not sold, rented, or provided to advertisers.
Relevant routing information may be used to notify authorized Eco Project coordinators for the sole purpose of managing the project's company communications.
7. Google API Services User Data Policy
The application's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. Security
Access credentials and OAuth tokens are used only for authorized application functions. Access permissions are limited to the scopes necessary for the workflow.
9. Data Retention
Operational routing data is retained only as long as reasonably necessary to maintain reliable processing and avoid duplicate notifications.
10. User Control
Users may revoke the application's access to their Google Account through their Google Account security and permissions settings.
11. Changes to This Policy
This Privacy Policy may be updated if the application's workflow, Google API permissions, or data-handling practices materially change.
12. Contact
Questions about this Privacy Policy or the application's use of Google user data may be directed to:
SD5 Eco Project
Email:
sd5@saimerryung.sch.id