Last updated: 21 August 2026
Effective Date: 21 August 2026
Controller for EbaSaiyo account/website data: Gabriel Petrozziello, an individual entrepreneur (empresario individual / autónomo) established in Spain and trading as EbaSaiyo
NIF: Y9325381-E
Professional address: Calle Encarna Albarracin, 6, 46025 Valencia, Spain
Privacy contact: contact@ebasaiyo.com
Full provider identification is also set out in our Legal Notice.
This Privacy Policy explains how EbaSaiyo collects, uses, shares, and protects personal data when individuals visit our websites, create or use EbaSaiyo accounts, communicate with us, or otherwise interact with the Service.
When EbaSaiyo processes email content, customer records, documents, recipient details, or other personal data submitted by a business customer for that customer's purposes ("Customer Content"), EbaSaiyo generally acts as a processor or service provider on behalf of that customer. The customer is responsible for its own privacy notices and lawful basis for that processing. Our Data Processing Addendum governs that processing where applicable.
Depending on how you interact with EbaSaiyo, we may process:
Payment-card details may be collected directly by a payment provider rather than stored by EbaSaiyo.
When a user connects Google Workspace/Gmail, Microsoft 365/Outlook, or WhatsApp Business Platform, we may process identifiers and tokens needed to maintain the authorized connection, the connected email address or business phone number, provider information, sync/webhook status, and related metadata.
Depending on enabled features, Customer Content may include:
We use personal data for purposes including:
We do not sell personal data. We do not use Google user data obtained through Google API Services for advertising, retargeting, data brokerage, or other prohibited purposes.
Where the GDPR, UK GDPR, or similar law applies and EbaSaiyo acts as controller, we rely on one or more of the following legal bases:
Contract. Processing necessary to provide the Service requested by a user or customer.
Legitimate interests. Operating, securing, improving, and administering a B2B SaaS service; preventing abuse; communicating with customers; and protecting legal rights, balanced against the rights of affected individuals.
Legal obligation. Processing required for tax, accounting, sanctions, law-enforcement, or other legal requirements.
Consent. Where required, for example for certain non-essential cookies or optional marketing communications. Consent can be withdrawn where applicable.
For Customer Content, the business customer determines the lawful basis as controller and instructs EbaSaiyo as processor.
The Service may send relevant Customer Content to an AI model provider to generate drafts, classifications, confidence information, decision explanations, or other enabled outputs.
For API-based OpenAI services, OpenAI states that inputs and outputs submitted through its API platform are not used to train OpenAI models by default unless the customer explicitly opts in to data sharing. Default API abuse-monitoring retention may apply subject to the provider's current policies and contractual settings. EbaSaiyo does not claim that third parties train on Customer Content; configuration follows the provider's current default API/business terms and EbaSaiyo's contractual settings.
EbaSaiyo will not intentionally opt Customer Content into third-party model training without an appropriate legal basis and customer-facing disclosure or agreement.
Google Workspace/Gmail user data obtained through Google API Services is used only to provide or improve user-facing features of the Service for the authorizing customer/user, in accordance with the Google API Services User Data Policy (including Limited Use). That Google user data is not used to train, improve, or develop generalized or shared AI models or foundation models.
AI processing can involve errors. The Service may maintain audit records of AI-generated decisions and human overrides for safety, accountability, product operation, and future quality analysis, subject to applicable retention rules.
When EbaSaiyo accesses Google user data (including Google Workspace/Gmail data), our use is limited to providing or improving user-facing features of the Service that are prominent and authorized by that customer/user. Our use complies with the Google API Services User Data Policy, including the Limited Use requirements. Google user data obtained through Google API Services is not used to train, improve, or develop generalized or shared AI models or foundation models, and is not transferred for those purposes.
Depending on the Gmail scopes used, Google may classify certain permissions as sensitive or restricted and may require OAuth verification and additional security assessment. EbaSaiyo will request only permissions reasonably necessary for the enabled functionality.
When EbaSaiyo accesses Microsoft 365/Outlook data through Microsoft Graph, access is based on permissions granted by the signed-in user or administrator. EbaSaiyo's intended model is delegated access, meaning the Service acts on behalf of the authorized user and does not obtain greater access than the granted permissions allow.
Permissions are selected based on enabled features, for example mail read/write permissions for reading or preparing replies and mail-send permission for sending messages.
We obtain personal data:
We may disclose personal data to:
Providers that support hosting, databases, authentication, AI processing, email connectivity, support, security, and related infrastructure. Current categories and providers are listed in our Subprocessors disclosure.
Payment information may be processed by a payment service provider. Depending on the data and service, the payment provider may act as an independent controller, a processor, or both under its own terms.
Where a user instructs EbaSaiyo to interact with Google Workspace, Microsoft 365, or another integrated service, data is exchanged with that platform as necessary to perform the requested action.
Lawyers, accountants, auditors, insurers, and consultants subject to appropriate confidentiality duties.
Where reasonably necessary to comply with law, legal process, enforce our rights, protect users, investigate fraud or security incidents, or prevent harm.
In connection with an actual or proposed merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and legal safeguards.
We do not sell Customer Content to data brokers or advertising networks.
EbaSaiyo and its service providers may process personal data in countries outside the country where the individual is located.
Where the GDPR applies and personal data is transferred to a country that has not received an adequacy decision, EbaSaiyo will use an appropriate transfer mechanism where required, such as the European Commission's Standard Contractual Clauses, together with supplementary measures where appropriate.
Further details are available in the Data Processing Addendum.
We retain personal data only as long as reasonably necessary for the purposes described in this policy, including contractual, security, tax, accounting, support, and legal requirements. Deletion and retention follow the product deletion workflow described below and in the Data Processing Addendum.
Typical retention and deletion principles include:
More specific retention periods may be published in product documentation or provided on request where required.
We use administrative, technical, and organizational measures designed to protect personal data. Depending on the component, these may include encryption in transit, encrypted storage of sensitive OAuth credentials, access controls, tenant scoping, server-side secret handling, audit logging, and provider-level security controls.
No system is perfectly secure. Users should promptly report suspected security issues to contact@ebasaiyo.com.
Depending on applicable law, individuals may have rights to:
Where EbaSaiyo processes personal data only as a processor for a customer, requests relating to that Customer Content should generally be directed to the relevant customer/controller. We will assist the customer as required by applicable law and the Data Processing Addendum.
To exercise rights relating to data for which EbaSaiyo is controller, contact contact@ebasaiyo.com.
Where permitted by law, we may send product or commercial communications to business contacts. Recipients can opt out of non-essential marketing communications using the available unsubscribe method or by contacting us.
Service, security, billing, and legal communications are not marketing and may still be sent where necessary.
We use essential technologies required for authentication, security, session management, and core functionality. We may use optional analytics or similar technologies only as described in the Cookie Policy and, where required, after obtaining consent.
The Service is designed for business users and is not intended for children. Users must be at least 18 years old or the age of legal majority required to enter a business contract in their jurisdiction.
Customers must not intentionally use EbaSaiyo to process children's data in a manner that violates applicable law.
EbaSaiyo may automate operational actions such as classifying an email, generating a draft, escalating a conversation, or sending an email when the Customer has configured autonomous behavior.
These features are designed to execute the Customer's business workflow rather than make legally binding decisions about individuals on behalf of EbaSaiyo. Customers are responsible for assessing whether their particular use constitutes automated decision-making subject to Article 22 GDPR or other sector-specific restrictions, and for implementing required safeguards.
Where EbaSaiyo functionality causes an AI system to interact directly with natural persons, applicable transparency obligations may require individuals to be informed that they are interacting with AI unless an exception applies or the AI nature is obvious from the context.
EbaSaiyo customers are responsible for determining and implementing legally required recipient-facing disclosures for their communications. EbaSaiyo may provide product controls or suggested language, but does not provide legal advice.
The Service may link to third-party sites or operate with third-party services. Their privacy practices are governed by their own policies. EbaSaiyo is not responsible for third-party privacy practices outside EbaSaiyo's role as a customer or integrator of those services.
We may update this Privacy Policy as the Service, law, or processing practices change. We will update the effective date and provide additional notice where required for material changes.
Privacy questions and requests may be sent to contact@ebasaiyo.com. Controller identity and professional address appear at the top of this Privacy Policy and in the Legal Notice.
Individuals in the EEA also have the right to lodge a complaint with their local data-protection authority. Given EbaSaiyo's establishment in Spain, the Spanish data-protection authority (AEPD) is the relevant lead supervisory authority for complaints concerning EbaSaiyo as controller.