Privacy Policy
Office Admin · Majestic Biopharma
Effective date: 9 July 2026
This Privacy Policy explains how Office Admin (the “Service,” “we,” “us”), an internal administrative task, project, and meeting management application operated by Majestic Biopharma at office.majestic.bio, collects, uses, stores, and protects information — including information obtained from Google APIs when you connect your Google Calendar. Office Admin is provided for use by Majestic Biopharma personnel.
1. Information we collect
- Account & directory data: your name, work email, mobile number, job title, and department, provided by Majestic Biopharma’s central identity system, used to authenticate you and to assign and display tasks and meetings.
- Application content you create: tasks, projects, comments, attachments, meetings, agendas, and their metadata.
- Google account data (only if you choose to connect Google Calendar): your Google account email address and basic profile identifier (via the
openidanduserinfo.emailscopes), and access to create, read, and update calendar events (via thehttps://www.googleapis.com/auth/calendar.eventsscope). We also store the OAuth access and refresh tokens Google issues so the Service can keep your meetings in sync.
2. How we use Google user data
When you connect your Google Calendar, we use the granted access solely to:
- create, update, and cancel Google Calendar events that correspond to meetings you create or edit in Office Admin, and send calendar invitations to the attendees you select;
- read those events to detect reschedules or cancellations made in Google Calendar and reflect them back into Office Admin (two-way synchronization);
- display your connected Google account email so you know which calendar is linked.
We do not use Google user data for advertising, we do not sell it, and we do not use it to train generalized artificial-intelligence or machine-learning models.
3. Limited Use disclosure
Office Admin’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. How we store and protect data
- Application data is stored in a private, access-controlled PostgreSQL database on Majestic Biopharma infrastructure.
- Google OAuth access and refresh tokens are encrypted at rest using AES-256-GCM and are never exposed to the browser or to third parties.
- All traffic is served over HTTPS/TLS. Access to the Service requires authentication, and administrative functions are permission-gated.
5. Sharing and disclosure
We do not share your personal information or Google user data with third parties, except as required to provide the Service (for example, transmitting your calendar events to Google’s Calendar API at your direction) or where required by law. We do not sell personal information.
6. Data retention and deletion
- You can disconnect Google at any time from Board Calendar → Meetings → Disconnect. Disconnecting immediately deletes your stored Google OAuth tokens from our systems and stops all synchronization.
- You may also revoke Office Admin’s access directly at myaccount.google.com/permissions.
- To request deletion of your application data, contact us using the details below.
7. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the effective date above.
8. Contact us
Majestic Biopharma — Administration Department
Email: admin@majestic.bio