EbaSaiyoBack to EbaSaiyo

Privacy Policy

Last updated: 21 August 2026

Effective Date: 21 August 2026

Controller for EbaSaiyo account/website data: Gabriel Petrozziello, an individual entrepreneur (empresario individual / autónomo) established in Spain and trading as EbaSaiyo
NIF: Y9325381-E
Professional address: Calle Encarna Albarracin, 6, 46025 Valencia, Spain
Privacy contact: contact@ebasaiyo.com

Full provider identification is also set out in our Legal Notice.

1. Scope

This Privacy Policy explains how EbaSaiyo collects, uses, shares, and protects personal data when individuals visit our websites, create or use EbaSaiyo accounts, communicate with us, or otherwise interact with the Service.

When EbaSaiyo processes email content, customer records, documents, recipient details, or other personal data submitted by a business customer for that customer's purposes ("Customer Content"), EbaSaiyo generally acts as a processor or service provider on behalf of that customer. The customer is responsible for its own privacy notices and lawful basis for that processing. Our Data Processing Addendum governs that processing where applicable.

2. Personal Data We Process

Depending on how you interact with EbaSaiyo, we may process:

Account and identity data

  • name;
  • work email address;
  • profile image or avatar;
  • organization/workspace identity;
  • authentication identifiers;
  • role and membership information.

Commercial and billing data

  • subscription plan;
  • billing status;
  • billing contact details;
  • transaction identifiers;
  • tax/VAT details where required.

Payment-card details may be collected directly by a payment provider rather than stored by EbaSaiyo.

Service and device data

  • IP address;
  • browser and device information;
  • login events;
  • timestamps;
  • product usage events;
  • diagnostic logs;
  • security and abuse-prevention signals.

Support and communications data

  • messages sent to support;
  • feedback;
  • troubleshooting information;
  • call or meeting notes where applicable.

Connected-account metadata

When a user connects Google Workspace/Gmail, Microsoft 365/Outlook, or WhatsApp Business Platform, we may process identifiers and tokens needed to maintain the authorized connection, the connected email address or business phone number, provider information, sync/webhook status, and related metadata.

Customer Content processed on behalf of customers

Depending on enabled features, Customer Content may include:

  • email sender and recipient information;
  • subject lines;
  • message bodies and threads;
  • timestamps and message identifiers;
  • customer support inquiries;
  • AI Employee instructions and business rules;
  • AI-generated drafts and decisions;
  • human-edited replies;
  • audit data about AI and human actions;
  • documents or knowledge sources if and when those features are enabled.

3. How We Use Personal Data

We use personal data for purposes including:

  • providing, operating, and securing the Service;
  • creating and administering accounts and workspaces;
  • authenticating users;
  • connecting and maintaining authorized third-party integrations;
  • generating AI-assisted outputs requested by customers;
  • executing Customer-configured automated workflows;
  • providing support;
  • processing subscriptions and payments;
  • detecting fraud, abuse, security incidents, and technical failures;
  • improving reliability, performance, usability, and safety;
  • communicating about service changes, security, and account matters;
  • complying with legal obligations and enforcing agreements; and
  • establishing, exercising, or defending legal claims.

We do not sell personal data. We do not use Google user data obtained through Google API Services for advertising, retargeting, data brokerage, or other prohibited purposes.

4. Legal Bases for EEA/UK Processing

Where the GDPR, UK GDPR, or similar law applies and EbaSaiyo acts as controller, we rely on one or more of the following legal bases:

Contract. Processing necessary to provide the Service requested by a user or customer.

Legitimate interests. Operating, securing, improving, and administering a B2B SaaS service; preventing abuse; communicating with customers; and protecting legal rights, balanced against the rights of affected individuals.

Legal obligation. Processing required for tax, accounting, sanctions, law-enforcement, or other legal requirements.

Consent. Where required, for example for certain non-essential cookies or optional marketing communications. Consent can be withdrawn where applicable.

For Customer Content, the business customer determines the lawful basis as controller and instructs EbaSaiyo as processor.

5. AI Processing

The Service may send relevant Customer Content to an AI model provider to generate drafts, classifications, confidence information, decision explanations, or other enabled outputs.

For API-based OpenAI services, OpenAI states that inputs and outputs submitted through its API platform are not used to train OpenAI models by default unless the customer explicitly opts in to data sharing. Default API abuse-monitoring retention may apply subject to the provider's current policies and contractual settings. EbaSaiyo does not claim that third parties train on Customer Content; configuration follows the provider's current default API/business terms and EbaSaiyo's contractual settings.

EbaSaiyo will not intentionally opt Customer Content into third-party model training without an appropriate legal basis and customer-facing disclosure or agreement.

Google Workspace/Gmail user data obtained through Google API Services is used only to provide or improve user-facing features of the Service for the authorizing customer/user, in accordance with the Google API Services User Data Policy (including Limited Use). That Google user data is not used to train, improve, or develop generalized or shared AI models or foundation models.

AI processing can involve errors. The Service may maintain audit records of AI-generated decisions and human overrides for safety, accountability, product operation, and future quality analysis, subject to applicable retention rules.

6. Google API Data

When EbaSaiyo accesses Google user data (including Google Workspace/Gmail data), our use is limited to providing or improving user-facing features of the Service that are prominent and authorized by that customer/user. Our use complies with the Google API Services User Data Policy, including the Limited Use requirements. Google user data obtained through Google API Services is not used to train, improve, or develop generalized or shared AI models or foundation models, and is not transferred for those purposes.

Depending on the Gmail scopes used, Google may classify certain permissions as sensitive or restricted and may require OAuth verification and additional security assessment. EbaSaiyo will request only permissions reasonably necessary for the enabled functionality.

7. Microsoft Graph Data

When EbaSaiyo accesses Microsoft 365/Outlook data through Microsoft Graph, access is based on permissions granted by the signed-in user or administrator. EbaSaiyo's intended model is delegated access, meaning the Service acts on behalf of the authorized user and does not obtain greater access than the granted permissions allow.

Permissions are selected based on enabled features, for example mail read/write permissions for reading or preparing replies and mail-send permission for sending messages.

8. Sources of Personal Data

We obtain personal data:

  • directly from users and customers;
  • from authorized account administrators;
  • from connected services such as Google or Microsoft at the user's direction;
  • from payment and authentication providers;
  • automatically through use of the Service; and
  • from support communications and product feedback.

9. How We Share Personal Data

We may disclose personal data to:

Service providers and subprocessors

Providers that support hosting, databases, authentication, AI processing, email connectivity, support, security, and related infrastructure. Current categories and providers are listed in our Subprocessors disclosure.

Payment providers

Payment information may be processed by a payment service provider. Depending on the data and service, the payment provider may act as an independent controller, a processor, or both under its own terms.

Connected third-party platforms

Where a user instructs EbaSaiyo to interact with Google Workspace, Microsoft 365, or another integrated service, data is exchanged with that platform as necessary to perform the requested action.

Professional advisers

Lawyers, accountants, auditors, insurers, and consultants subject to appropriate confidentiality duties.

Authorities and legal recipients

Where reasonably necessary to comply with law, legal process, enforce our rights, protect users, investigate fraud or security incidents, or prevent harm.

Corporate transactions

In connection with an actual or proposed merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and legal safeguards.

We do not sell Customer Content to data brokers or advertising networks.

10. International Transfers

EbaSaiyo and its service providers may process personal data in countries outside the country where the individual is located.

Where the GDPR applies and personal data is transferred to a country that has not received an adequacy decision, EbaSaiyo will use an appropriate transfer mechanism where required, such as the European Commission's Standard Contractual Clauses, together with supplementary measures where appropriate.

Further details are available in the Data Processing Addendum.

11. Data Retention

We retain personal data only as long as reasonably necessary for the purposes described in this policy, including contractual, security, tax, accounting, support, and legal requirements. Deletion and retention follow the product deletion workflow described below and in the Data Processing Addendum.

Typical retention and deletion principles include:

  • Account data: retained for the duration of the account relationship and as needed to administer membership, authentication, and related account functions, then deleted or anonymized according to the workspace/account deletion workflow below (subject to legal retention exceptions).
  • Billing and invoices: retained as required by applicable tax and accounting law, including after workspace deletion where necessary. An anonymized workspace record may be retained so that historical invoices remain linkable for those obligations.
  • Security logs: retained for a limited period appropriate to incident detection and investigation. Security logs are not email message bodies or ordinary correspondence content.
  • OAuth credentials/tokens: on mailbox disconnect, or when the related AI Employee or workspace is deleted, EbaSaiyo performs a best-effort remote revoke and wipes tokens from active systems (including overwriting encrypted stored credentials). Residual copies may remain temporarily subject to technical backup cycles.
  • Mailbox disconnect: deletes that connection's synced messages and threads and related AI reply artifacts from active systems, and stops further processing for that connection. Disconnect does not delete Knowledge, other email connections, business settings, or the workspace.
  • AI Employee deletion: purges that employee's email connections (including the disconnect wipe described above), knowledge files for that employee, learning/memory scoped to that employee, and related decision records from active systems. EbaSaiyo may retain anonymized usage aggregates (without email bodies) and minimal consent or audit metadata.
  • Workspace / account deletion: authorized owners can delete a workspace, and account holders can delete their account, through product controls. Operational Customer Content is purged from active systems according to the product deletion workflow. Removing a member from a workspace does not by itself delete the workspace or other members' data; deleting a workspace (or the last remaining member via account deletion) triggers workspace purge. Invoices and billing audit records are retained as required by applicable law; an anonymized organization shell may remain for invoice linkage.
  • Customer Content generally: retained while needed to provide the active Service, then deleted or retained according to the product controls above (mailbox disconnect, AI Employee deletion, workspace/account deletion), customer instructions, subscription terms, and the Data Processing Addendum.
  • Backups: deleted data may remain temporarily in protected provider backups until normal backup expiry. Backup copies are not restored for ordinary business use except for disaster recovery, security investigation, or legal necessity.
  • AI usage aggregates: may be retained for a limited period for cost analytics and abuse investigation. These aggregates do not include prompt text or email bodies.

More specific retention periods may be published in product documentation or provided on request where required.

12. Data Security

We use administrative, technical, and organizational measures designed to protect personal data. Depending on the component, these may include encryption in transit, encrypted storage of sensitive OAuth credentials, access controls, tenant scoping, server-side secret handling, audit logging, and provider-level security controls.

No system is perfectly secure. Users should promptly report suspected security issues to contact@ebasaiyo.com.

13. Your Data Protection Rights

Depending on applicable law, individuals may have rights to:

  • access personal data;
  • correct inaccurate data;
  • request deletion;
  • restrict processing;
  • object to certain processing;
  • obtain data portability;
  • withdraw consent where processing is based on consent; and
  • complain to a competent supervisory authority.

Where EbaSaiyo processes personal data only as a processor for a customer, requests relating to that Customer Content should generally be directed to the relevant customer/controller. We will assist the customer as required by applicable law and the Data Processing Addendum.

To exercise rights relating to data for which EbaSaiyo is controller, contact contact@ebasaiyo.com.

14. Marketing Communications

Where permitted by law, we may send product or commercial communications to business contacts. Recipients can opt out of non-essential marketing communications using the available unsubscribe method or by contacting us.

Service, security, billing, and legal communications are not marketing and may still be sent where necessary.

15. Cookies and Similar Technologies

We use essential technologies required for authentication, security, session management, and core functionality. We may use optional analytics or similar technologies only as described in the Cookie Policy and, where required, after obtaining consent.

16. Children

The Service is designed for business users and is not intended for children. Users must be at least 18 years old or the age of legal majority required to enter a business contract in their jurisdiction.

Customers must not intentionally use EbaSaiyo to process children's data in a manner that violates applicable law.

17. Automated Decision-Making

EbaSaiyo may automate operational actions such as classifying an email, generating a draft, escalating a conversation, or sending an email when the Customer has configured autonomous behavior.

These features are designed to execute the Customer's business workflow rather than make legally binding decisions about individuals on behalf of EbaSaiyo. Customers are responsible for assessing whether their particular use constitutes automated decision-making subject to Article 22 GDPR or other sector-specific restrictions, and for implementing required safeguards.

18. EU AI Act Transparency

Where EbaSaiyo functionality causes an AI system to interact directly with natural persons, applicable transparency obligations may require individuals to be informed that they are interacting with AI unless an exception applies or the AI nature is obvious from the context.

EbaSaiyo customers are responsible for determining and implementing legally required recipient-facing disclosures for their communications. EbaSaiyo may provide product controls or suggested language, but does not provide legal advice.

19. Third-Party Links and Services

The Service may link to third-party sites or operate with third-party services. Their privacy practices are governed by their own policies. EbaSaiyo is not responsible for third-party privacy practices outside EbaSaiyo's role as a customer or integrator of those services.

20. Changes to this Privacy Policy

We may update this Privacy Policy as the Service, law, or processing practices change. We will update the effective date and provide additional notice where required for material changes.

21. Contact and Complaints

Privacy questions and requests may be sent to contact@ebasaiyo.com. Controller identity and professional address appear at the top of this Privacy Policy and in the Legal Notice.

Individuals in the EEA also have the right to lodge a complaint with their local data-protection authority. Given EbaSaiyo's establishment in Spain, the Spanish data-protection authority (AEPD) is the relevant lead supervisory authority for complaints concerning EbaSaiyo as controller.