Have questions about data privacy and security for content syncing? This FAQ covers Google Drive and SharePoint integrations to address common concerns about data storage, access, encryption, and more.
đ Quick-Jump Topics
- Data Storage & Protection: Where data is stored and how it is secured
- Data Access: Who can access data and under what conditions
- Data Retention: How long data is kept within Spekit's ecosystem
- Third-Party Data Sharing: Whether and why data is shared with third parties
- Account Termination: What happens to your data when you terminate your account
- Authentication Methods: How Spekit ensures only authorized users access linked content
- Role-Based Access Controls (RBAC): How user permissions are managed
- Data Encryption: How data is protected during transfer and at rest
- Activity Monitoring: How Spekit detects and prevents unauthorized access
- Spekit Permissions: What specific permissions Spekit requests from connected accounts
- Data Transfer: How data moves between Spekit and integrations
- Data Transfer Limits: What types of data can and cannot be transferred
- Revoking Access: How to disconnect Spekit from your Google Drive or SharePoint account
Data Storage & Protection
Where is the data stored, and how is it protected?
Imported data is stored securely through AWS using industry-standard security measures, including AES-256 encryption for data at rest and TLS 1.2 or higher for data in transit.
Data Access
Who has access to the data, and under what conditions?
Access is limited to authorized personnel for purposes such as support, maintenance, and product enhancements. Access conditions include strict adherence to confidentiality agreements and internal company policies.
Data Retention
How long is the data retained within Spekit's ecosystem?
Data is retained as long as necessary to provide the Spekit services. Specific retention details are discussed in Spekit's contractual agreements with customers.
Third-Party Data Sharing
Is my data shared with any third parties? If so, who and for what purposes?
Data may be shared with third-party sub-processors in order to provide the Spekit Services. A list of Spekit's sub-processors and the purpose of the data sharing can be found here.
Account Termination
What happens to my data if I decide to terminate my Spekit account?
Upon termination, data is deleted according to the user's request or in accordance with Spekit's data retention policies. Customers may request a data export before termination.
Authentication Methods
What authentication methods are used to ensure only authorized users can access linked content?
Spekit employs secure role-based authentication methods, including strong password and multi-factor authentication, to ensure that only authorized users access the content.
- For connections to Google Drive: Spekit uses Google's OAuth mechanism, ensuring that your credentials are secure and inaccessible to Spekit.
- For connections to SharePoint: Spekit uses Microsoft's OAuth mechanism, ensuring that your credentials are secure and inaccessible to Spekit.
Role-Based Access Controls (RBAC)
Are there role-based access controls (RBAC) in place?
â Yes. RBAC is implemented to manage user permissions and access levels based on roles within the organization.
Data Encryption
Is the data encrypted during transfer and at rest?
â Yes. Data is encrypted during transfer and at rest using industry-standard encryption protocols.
Activity Monitoring
Is there monitoring of user activity to detect and prevent unauthorized access or anomalies?
â Yes. Spekit monitors user activity to detect and prevent unauthorized access, ensuring data security and integrity.
Spekit Permissions
What specific permissions does Spekit request?
- Google Drive: Spekit requests permissions to access files and organize them for syncing purposes.
- SharePoint: Spekit requests permissions to read site structures and file access levels for integration.
Data Transfer
How is data transferred between Spekit and integrations?
Data is securely transferred using a third-party integration interface with encrypted protocols, ensuring safe and seamless syncing.
Data Transfer Limits
Are there any limits on the types of data that can be transferred?
Controls are in place to ensure compliance with usage policies by managing the types of data that can be transferred. Only data that a user explicitly chooses to synchronize to Spekit is shared.
Revoking Access
Can users easily revoke Spekit's access to their connected accounts?
Google Drive
Users can revoke Spekit's access to their Google Drive account in one of two ways:
- Via Google Account Settings: Navigate to your Google account, locate the list of connected apps, and revoke Spekit's permissions.
- Within Spekit: Disconnect the integration directly from the Spekit platform.
SharePoint
Users can revoke Spekit's access to SharePoint in one of two ways:
- Via Microsoft Account Settings: Access your Microsoft account, find connected apps, and remove Spekit's permissions.
- Within Spekit: Disconnect the SharePoint integration through the Spekit settings.