Legal
Privacy Policy
How ABLO AS collects, uses, shares, retains, and protects personal data.
- Version
- 1.0
- Last updated
- 2026-09-01
Who is responsible
ABLO AS is the controller for account administration, billing, security, product analytics, sales, and support data. When Ablo processes workspace or integration data under a business customer's instructions, the customer is normally the controller and Ablo acts as its processor.
Data we process
Ablo processes account and organization details, workspace content, AI request and execution data, integration data, billing records, technical and security data, analytics data where consented, and communications. The canonical descriptions and examples are maintained in Trust & Data.
Purposes and legal bases
We process data to provide and administer the contract, authenticate users, perform requested AI and integration work, bill customers, secure and support the service, meet legal obligations, and improve reliability. These activities rely on performance of the customer agreement, legitimate interests in operating and securing a B2B service, compliance with legal obligations, and consent where consent is required, including optional analytics.
AI processing
Prompts, relevant workspace context, tool results, and generated responses are sent to the AI routing and inference providers listed in the subprocessor register. Ablo requires eligible zero-data-retention processing and prohibits use of customer prompts, responses, and workspace content to train AI models. Operational metadata may still be retained as described in Trust & Data.
Google and Composio integrations
When a customer connects a supported service, Composio manages authentication and holds or refreshes the connected-account credential. Ablo stores connection identifiers and sends the inputs needed to perform a customer-requested action. Composio and the connected service receive that data to authenticate and execute the action. Ablo's Gmail integration is send-only and does not read the mailbox.
Ablo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the connected, user-facing feature and is not used to train generalized AI models.
A project owner can disconnect an integration from workspace settings. Ablo then revokes upstream access where supported and deletes the Composio connected account. Organization deletion includes the same integration cleanup. Provider-controlled payload-log retention and other current limitations are disclosed in Trust & Data.
Retention and deletion
Data is kept only while needed for the service, security, support, billing, and legal obligations. Organization deletion removes access immediately and is intended to complete across active systems within 30 days. Certain accounting records may be isolated and retained for five years or longer where law requires. Category-specific periods and provider limitations are in Trust & Data.
Your rights
Depending on applicable law and Ablo's role, individuals may have rights to access, correct, delete, restrict, or object to processing, obtain portable data, and withdraw consent without affecting earlier lawful processing. Where Ablo acts for a customer, requests may need to be handled through that customer. You may also complain to the Norwegian Data Protection Authority or another competent supervisory authority.
Security and changes
Ablo applies technical and organizational measures intended to protect data against unauthorized access, loss, misuse, and alteration. No service can guarantee absolute security. We may update this notice as our service or legal obligations change; the current version and date are shown above.
Company and contact
ABLO AS
Organization number 938 247 862
Malerhaugveien 20F, 0661 Oslo, Norway
Privacy: privacy@ablo.no
Support: support@ablo.no
See Trust & Data and the subprocessor register for the canonical description of Ablo's data practices.