Privacy Policy — Endpoint DLP Plus browser extension
Last updated: 23 September 2026
Who this extension is for
Endpoint DLP Plus is installed and managed by OSOS ("we", "us", "the organization") on devices and browser profiles used by its employees. It is not intended for use by the general public: it is distributed as an unlisted extension and only works on devices the organization has enrolled.
What data this extension collects
Once a device is enrolled, the extension sends the following to the organization's own backend server. Nothing is sent to third-party analytics or advertising services.
- Device identity: a device ID and credential issued at enrollment, a device/user label provided by the administrator or user, the browser in use (for example Chrome or Edge, detected automatically), and the extension's version number.
- Upload events: whenever a file is selected for upload or dropped onto a web page, the destination website, the file's name and extension, the time, and whether the upload was allowed or blocked by policy. The contents of the file are never read or sent.
- Policy sync: the extension periodically contacts the server to fetch the current policy (trusted destinations and blocked file types) set by the administrator.
- Protection on/off events (only where the organization has enabled this option): the time each time local enforcement is turned off or back on.
- Computer name (only if the organization's endpoint agent is installed on the device): used solely to link this browser to the correct device in the administrator's console.
What this extension does not do
- It does not read, store, or transmit the contents of any file you upload or attach.
- It does not record your general browsing. The only website address it records is the destination of a file upload attempt. It does not collect page content, form data, keystrokes, or a list of pages you visit.
- It does not sell data or share it with third parties.
How the data is used
The data is used only to enforce the organization's data-loss-prevention policy and to let authorized administrators review upload activity and the health of enrolled devices. It is not used for advertising, profiling, creditworthiness, or any purpose unrelated to that.
Where the data is stored and how long it's kept
All data is sent over encrypted connections (HTTPS) to a server operated by OSOS, and is accessible only to the organization's authorized administrators. It is kept in line with the organization's internal record-keeping policies and deleted when it is no longer needed for security or compliance purposes.
Administrator controls
The organization's administrators can:
- Set and update the upload policy this extension enforces.
- View the log of upload attempts, both allowed and blocked.
- Optionally allow users to temporarily turn off local enforcement (off by default; every change is logged).
Contact
Questions about this policy or how your data is handled: itsupport@osos.om.
Changes to this policy
This policy will be updated if what the extension collects, or how that data is used, changes. The "Last updated" date above shows the most recent revision.