Last updated · 28 August 2026
1. Who operates this service
Crownbridge Ltd (“Crownbridge”, “we”, “us”) operates crownbridgegroup.uk and the CRBG Command Centre Gateway. This policy applies to the public website and to the Google-connected functionality described below.
2. Information we process
Public website information. When the website is accessed, ordinary technical information may be processed for security, availability and abuse prevention. This can include IP address, browser and device information, timestamps, requested pages, diagnostic information and security events.
Authorised Google account information. If an authorised user chooses to connect an approved Google account, Crownbridge may receive the account identity presented by Google, the permissions granted by the user, OAuth token material required to maintain the authorised connection, and information made available through the approved Google scope.
3. Current Gmail access
The current Gmail integration requests https://www.googleapis.com/auth/gmail.readonly. Google describes this scope as permission to view a user’s email messages and settings.
The Gateway uses this access only for authorised Crownbridge business-communications functionality presented through the Command Centre, including retrieval, search, summarisation, evidence and provenance handling, controlled case or entity association, and related user-facing decision support.
The current integration does not grant the Gateway permission to send, draft, forward, delete, trash or modify Gmail messages.
4. Google authentication and credentials
Crownbridge does not ask users to disclose Google passwords, MFA codes, recovery codes or passkeys to the Command Centre. Google authentication and consent take place through Google’s own authentication and OAuth services.
Where persistent OAuth access is authorised, refresh-token material may be held in controlled encrypted custody so the approved connection can operate without repeatedly requesting the user’s Google credentials. Crownbridge applies account matching, access controls, session controls, audit logging and least-privilege principles to that custody.
5. How Google Workspace data is used
Crownbridge limits its use of information received from Google Workspace scopes to providing or improving the authorised, user-facing Crownbridge functionality for which access was granted.
The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
- Google Workspace user data is not sold to third parties, data brokers or information resellers.
- Google Workspace user data is not used for advertising, retargeting, personalised advertising or interest-based advertising.
- Google Workspace user data is not used to determine credit-worthiness or for lending decisions.
- Google Workspace user data is not used to create, train or improve a generalised machine-learning or artificial-intelligence model beyond an appropriate user-facing personalised use case permitted by Google policy.
- Human access to Google Workspace user data is restricted to circumstances permitted by Google policy, such as explicit user agreement, security investigation or legal requirements.
6. Sharing and service providers
Information may be processed by infrastructure or technical service providers where this is necessary to provide, secure or maintain Crownbridge functionality and where the processing is compatible with the user’s authorised use and applicable contractual, security and legal controls.
Google Workspace user data is not transferred for unrelated commercial purposes. Other disclosures may occur where required for security, to comply with law or regulation, or in another circumstance expressly permitted by applicable Google policy and law.
7. Retention and deletion
Crownbridge retains personal information only for as long as reasonably necessary for the relevant authorised purpose, security, audit, legal or regulatory requirement. Retention periods vary according to the type of information and the Crownbridge business context in which it is processed.
Google Workspace user data and derived data are retained only to the extent necessary for the permitted user-facing functionality or another use permitted by Google policy. Crownbridge does not treat OAuth access as permission to create an unrelated permanent archive of a user’s Google data.
8. Revoking Google access
An authorised user can revoke Crownbridge’s Google access through their Google Account permissions. Crownbridge may also suspend or revoke integration custody when authority ends, an account is no longer approved, or security or governance requires access to stop.
Revocation prevents future access through the revoked credential. Requests concerning deletion of Google-derived user data will be handled in accordance with applicable law, Google policy and any legitimate security or legal retention requirement.
9. Security
Crownbridge uses technical and organisational controls designed to protect information against unauthorised access, loss, alteration or disclosure. Controls relevant to the Command Centre include governed identity and device boundaries, least-privilege access, encrypted credential custody, account matching and auditable system events.
10. Your rights
Depending on applicable data-protection law and your relationship with Crownbridge, you may have rights concerning your personal information, including access, correction, deletion, restriction, objection or complaint. These rights may be subject to lawful exemptions and retention obligations.
11. Changes to this policy
This policy will be reviewed when the Crownbridge website, Google scopes or the way Crownbridge uses Google user data materially changes. Crownbridge will not use Google user data for a materially different purpose without updating the relevant disclosure and obtaining any consent required by law or Google policy.
12. Contact
Privacy and data enquiries can be sent to info@crownbridgegroup.uk.
