Skip to content

Privacy policy

Last updated 2 October 2026

OLO is a media library for teams, run by CNJ d.o.o., Slovenia (“we”). This policy explains what personal data we handle when you use OLO, why, and what you can do about it. Questions go to hello@olo.si.

Whose data it is

Files, descriptions and other content in a workspace belong to the organisation that owns that workspace. We store and process that content on the organisation’s instructions, as its processor. If your question is about a file in someone’s workspace, ask that organisation first.

For the data described below that we need to run the service, such as your account, we are the controller.

What we collect

  • Account details. Your name, email address and profile picture, the workspaces you belong to and your role in each.
  • Content you upload. Photos, videos, documents and the details attached to them: tags, descriptions, license information, and data saved inside the files such as the capture date, camera and location.
  • People in photos. If a workspace uses the People feature, OLO detects faces in its photos and groups similar ones so that members can name them. This runs on our own servers and is used only inside that workspace.
  • Activity. A record of actions in a workspace, for example who uploaded, changed, shared or downloaded a file, and when.
  • Technical data. IP address, browser type and error reports, which we need to keep the service secure and working.
  • Visitors to shared galleries. When someone opens a public link we record views and downloads. We do not ask visitors for an account.

Why we use it

  • To provide OLO to you and your organisation, which is the contract we have with the workspace owner.
  • To keep the service secure, find faults and prevent misuse, which is our legitimate interest.
  • To meet legal obligations, such as keeping invoices.

We do not sell personal data, show advertising or use your content to train AI models.

Who else handles it

We use a small number of providers to run OLO. Each one only receives what it needs for its task.

  • WorkOS for signing in and managing organisation membership.
  • Cloud storage providers that hold the files and their backup copies.
  • OpenAI, only in workspaces that switch on AI features. Photos are sent to be described and tagged, and audio to be transcribed.
  • Apple Maps to draw maps and look up place names. Your browser contacts Apple directly when you open a map.
  • Bunny Fonts to deliver typefaces, and Flare to collect error reports.

Some of these providers are based outside the European Economic Area. Where data leaves the EEA we rely on the European Commission’s standard contractual clauses or an adequacy decision.

How long we keep it

Content stays in a workspace until a member deletes it or the organisation closes the workspace. Deleted files stay in the trash, and then in backups, for a limited period so that mistakes can be undone, and are then erased. Account details are kept while your account exists. Activity records and technical logs are kept for as long as needed for security and accounting.

Cookies

OLO only sets cookies it needs to work: one that keeps you signed in, one that protects forms against forgery, and a few that remember your choices, such as language, light or dark mode, time zone, the sidebar and the workspace you last used. A password-protected gallery sets a cookie once you have entered the password. There are no advertising or tracking cookies.

Your rights

You can ask us for a copy of your personal data, ask us to correct or delete it, object to how we use it or ask us to restrict that use, and ask for it in a portable format. Write to hello@olo.si and we will answer within one month. You can delete your own account at any time in your account settings.

If you are unhappy with our answer, you can complain to the Information Commissioner of the Republic of Slovenia or to the data protection authority where you live.

Changes

When we change this policy we update the date at the top. If a change affects how we use your data in a significant way, we tell workspace owners by email first.