1. Scope, controller, and processor roles
Ones N Zero is the controller for account, billing, security, support, and product-usage data. For post content, media, and other personal data a customer places in a Space, the customer normally determines the purpose and OneSchedule acts as its processor. Contact assist@onesnzero.com. If we process data for your organization, direct requests to that organization first; we will assist it as required.
2. Data we handle and where it comes from
We receive account and profile details; sessions and trusted-edge IP information; Space memberships, roles, invitations, and audit events; posts, schedules, media, and filenames; connected-account identifiers, permissions, and encrypted OAuth credentials; subscription and transaction status; support communications; and operational diagnostics. Data comes from you, authorized teammates, your device, selected social networks, Polar, and service providers involved in your request. Do not upload unnecessary sensitive or special-category data.
3. Purposes and legal bases
We process data to create and secure accounts, provide collaboration, storage, scheduling and publishing, administer subscriptions, deliver service messages, answer support requests, prevent abuse, investigate incidents, establish or defend claims, and comply with tax, accounting, sanctions, and other law. The legal basis is performance of our contract, compliance with legal obligations, our legitimate interests in operating and protecting the service, or consent where the law requires it. You may withdraw consent prospectively.
5. International transfers
Providers may process data outside your country. Where EEA, UK, or Swiss transfer rules apply, we rely on an adequacy decision, approved standard contractual clauses, or another lawful mechanism and assess supplementary technical and organizational measures. Contact us for information about the safeguard relevant to your data. Our subprocessor and transfer records are reviewed when providers, locations, or access patterns change.
6. Retention and erasure
We keep data only for the service, legal, security, and dispute periods that apply. Browser composer recovery expires after 24 hours and is cleared at sign-out; notifications after 7 days; completed email deliveries after 30 days; billing webhook payloads are minimized after 7 days and records removed after 90 days; and audit history follows the Space plan. A deleted Space has a 30-day recovery window, after which current and historical S3 object versions are permanently erased before database records are purged. Backups expire on a controlled schedule and are isolated from ordinary processing.
7. Your rights and choices
Depending on applicable law, you may request access, correction, erasure, restriction, objection, or portability, withdraw consent, opt out of direct marketing, and complain to a supervisory authority. Use Personal settings or email assist@onesnzero.com. We verify identity proportionately, protect other people's rights, explain lawful refusals, and normally respond within one month under GDPR; a complex request may be extended as the law permits. Erasure is not absolute where retention is required for law, security, claims, or another overriding ground.
Questions about these documents can be sent to assist@onesnzero.com.