Last updated: 8 August 2026
Effective Date: 8 August 2026
Controller for EbaSaiyo account/website data: Gabriel Petrozziello, an individual entrepreneur (empresario individual / autónomo) established in Spain and trading as EbaSaiyo
NIF: Y9325381-E
Privacy contact: contact@ebasaiyo.com
This Privacy Policy explains how EbaSaiyo collects, uses, shares, and protects personal data when individuals visit our websites, create or use EbaSaiyo accounts, communicate with us, or otherwise interact with the Service.
When EbaSaiyo processes email content, customer records, documents, recipient details, or other personal data submitted by a business customer for that customer's purposes ("Customer Content"), EbaSaiyo generally acts as a processor or service provider on behalf of that customer. The customer is responsible for its own privacy notices and lawful basis for that processing. Our Data Processing Addendum governs that processing where applicable.
Depending on how you interact with EbaSaiyo, we may process:
Payment-card details may be collected directly by a payment provider rather than stored by EbaSaiyo.
When a user connects Google Workspace/Gmail or Microsoft 365/Outlook, we may process identifiers and tokens needed to maintain the authorized connection, the connected email address, provider information, sync status, and related metadata.
Depending on enabled features, Customer Content may include:
We use personal data for purposes including:
We do not sell personal data. We do not use Google user data obtained through Google API Services for advertising, retargeting, data brokerage, or other prohibited purposes.
Where the GDPR, UK GDPR, or similar law applies and EbaSaiyo acts as controller, we rely on one or more of the following legal bases:
Contract. Processing necessary to provide the Service requested by a user or customer.
Legitimate interests. Operating, securing, improving, and administering a B2B SaaS service; preventing abuse; communicating with customers; and protecting legal rights, balanced against the rights of affected individuals.
Legal obligation. Processing required for tax, accounting, sanctions, law-enforcement, or other legal requirements.
Consent. Where required, for example for certain non-essential cookies or optional marketing communications. Consent can be withdrawn where applicable.
For Customer Content, the business customer determines the lawful basis as controller and instructs EbaSaiyo as processor.
The Service may send relevant Customer Content to an AI model provider to generate drafts, classifications, confidence information, decision explanations, or other enabled outputs.
For API-based OpenAI services, OpenAI states that inputs and outputs submitted through its API platform are not used to train OpenAI models by default unless the customer explicitly opts in to data sharing. Default API abuse-monitoring retention may apply subject to the provider's current policies and contractual settings.
EbaSaiyo will not intentionally opt Customer Content into third-party model training without an appropriate legal basis and customer-facing disclosure or agreement.
AI processing can involve errors. The Service may maintain audit records of AI-generated decisions and human overrides for safety, accountability, product operation, and future quality analysis, subject to applicable retention rules.
When EbaSaiyo accesses Google user data, our use is limited to providing and improving the user-facing features authorized by the user and must comply with the Google API Services User Data Policy, including applicable Limited Use requirements.
Depending on the Gmail scopes used, Google may classify certain permissions as sensitive or restricted and may require OAuth verification and additional security assessment. EbaSaiyo will request only permissions reasonably necessary for the enabled functionality.
When EbaSaiyo accesses Microsoft 365/Outlook data through Microsoft Graph, access is based on permissions granted by the signed-in user or administrator. EbaSaiyo's intended model is delegated access, meaning the Service acts on behalf of the authorized user and does not obtain greater access than the granted permissions allow.
Permissions are selected based on enabled features, for example mail read/write permissions for reading or preparing replies and mail-send permission for sending messages.
We obtain personal data:
We may disclose personal data to:
Providers that support hosting, databases, authentication, AI processing, email connectivity, support, security, and related infrastructure. Current categories and providers are listed in our Subprocessor disclosure.
Payment information may be processed by a payment service provider. Depending on the data and service, the payment provider may act as an independent controller, a processor, or both under its own terms.
Where a user instructs EbaSaiyo to interact with Google Workspace, Microsoft 365, or another integrated service, data is exchanged with that platform as necessary to perform the requested action.
Lawyers, accountants, auditors, insurers, and consultants subject to appropriate confidentiality duties.
Where reasonably necessary to comply with law, legal process, enforce our rights, protect users, investigate fraud or security incidents, or prevent harm.
In connection with an actual or proposed merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and legal safeguards.
We do not sell Customer Content to data brokers or advertising networks.
EbaSaiyo and its service providers may process personal data in countries outside the country where the individual is located.
Where the GDPR applies and personal data is transferred to a country that has not received an adequacy decision, EbaSaiyo will use an appropriate transfer mechanism where required, such as the European Commission's Standard Contractual Clauses, together with supplementary measures where appropriate.
Further details are available in the Data Processing Addendum.
We retain personal data only as long as reasonably necessary for the purposes described in this policy, including contractual, security, tax, accounting, support, and legal requirements.
Typical retention principles include:
EbaSaiyo applies retention periods appropriate to each category above. More specific periods may be published or provided on request where required.
We use administrative, technical, and organizational measures designed to protect personal data. Depending on the component, these may include encryption in transit, encrypted storage of sensitive OAuth credentials, access controls, tenant scoping, server-side secret handling, audit logging, and provider-level security controls.
No system is perfectly secure. Users should promptly report suspected security issues to contact@ebasaiyo.com.
Depending on applicable law, individuals may have rights to:
Where EbaSaiyo processes personal data only as a processor for a customer, requests relating to that Customer Content should generally be directed to the relevant customer/controller. We will assist the customer as required by applicable law and the Data Processing Addendum.
To exercise rights relating to data for which EbaSaiyo is controller, contact contact@ebasaiyo.com.
Where permitted by law, we may send product or commercial communications to business contacts. Recipients can opt out of non-essential marketing communications using the available unsubscribe method or by contacting us.
Service, security, billing, and legal communications are not marketing and may still be sent where necessary.
We use essential technologies required for authentication, security, session management, and core functionality. We may use optional analytics or similar technologies only as described in the Cookie Policy and, where required, after obtaining consent.
The Service is designed for business users and is not intended for children. Users must be at least 18 years old or the age of legal majority required to enter a business contract in their jurisdiction.
Customers must not intentionally use EbaSaiyo to process children's data in a manner that violates applicable law.
EbaSaiyo may automate operational actions such as classifying an email, generating a draft, escalating a conversation, or sending an email when the Customer has configured autonomous behavior.
These features are designed to execute the Customer's business workflow rather than make legally binding decisions about individuals on behalf of EbaSaiyo. Customers are responsible for assessing whether their particular use constitutes automated decision-making subject to Article 22 GDPR or other sector-specific restrictions, and for implementing required safeguards.
Where EbaSaiyo functionality causes an AI system to interact directly with natural persons, applicable transparency obligations may require individuals to be informed that they are interacting with AI unless an exception applies or the AI nature is obvious from the context.
EbaSaiyo customers are responsible for determining and implementing legally required recipient-facing disclosures for their communications. EbaSaiyo may provide product controls or suggested language, but does not provide legal advice.
The Service may link to third-party sites or operate with third-party services. Their privacy practices are governed by their own policies. EbaSaiyo is not responsible for third-party privacy practices outside EbaSaiyo's role as a customer or integrator of those services.
We may update this Privacy Policy as the Service, law, or processing practices change. We will update the effective date and provide additional notice where required for material changes.
Privacy questions and requests:
Gabriel Petrozziello, trading as EbaSaiyo
NIF: Y9325381-E
Calle Encarna Albarracin, 6, 46025 Valencia, Spain
contact@ebasaiyo.com
Individuals in the EEA also have the right to lodge a complaint with their local data-protection authority. Given EbaSaiyo's establishment in Spain, the Spanish data-protection authority (AEPD) is the relevant lead supervisory authority for complaints concerning EbaSaiyo as controller.