EbaSaiyoBack to EbaSaiyo

Privacy Policy

Last updated: 8 August 2026

Effective Date: 8 August 2026
Controller for EbaSaiyo account/website data: Gabriel Petrozziello, an individual entrepreneur (empresario individual / autónomo) established in Spain and trading as EbaSaiyo
NIF: Y9325381-E
Privacy contact: contact@ebasaiyo.com

1. Scope

This Privacy Policy explains how EbaSaiyo collects, uses, shares, and protects personal data when individuals visit our websites, create or use EbaSaiyo accounts, communicate with us, or otherwise interact with the Service.

When EbaSaiyo processes email content, customer records, documents, recipient details, or other personal data submitted by a business customer for that customer's purposes ("Customer Content"), EbaSaiyo generally acts as a processor or service provider on behalf of that customer. The customer is responsible for its own privacy notices and lawful basis for that processing. Our Data Processing Addendum governs that processing where applicable.

2. Personal Data We Process

Depending on how you interact with EbaSaiyo, we may process:

Account and identity data

  • name;
  • work email address;
  • profile image or avatar;
  • organization/workspace identity;
  • authentication identifiers;
  • role and membership information.

Commercial and billing data

  • subscription plan;
  • billing status;
  • billing contact details;
  • transaction identifiers;
  • tax/VAT details where required.

Payment-card details may be collected directly by a payment provider rather than stored by EbaSaiyo.

Service and device data

  • IP address;
  • browser and device information;
  • login events;
  • timestamps;
  • product usage events;
  • diagnostic logs;
  • security and abuse-prevention signals.

Support and communications data

  • messages sent to support;
  • feedback;
  • troubleshooting information;
  • call or meeting notes where applicable.

Connected-account metadata

When a user connects Google Workspace/Gmail or Microsoft 365/Outlook, we may process identifiers and tokens needed to maintain the authorized connection, the connected email address, provider information, sync status, and related metadata.

Customer Content processed on behalf of customers

Depending on enabled features, Customer Content may include:

  • email sender and recipient information;
  • subject lines;
  • message bodies and threads;
  • timestamps and message identifiers;
  • customer support inquiries;
  • AI Employee instructions and business rules;
  • AI-generated drafts and decisions;
  • human-edited replies;
  • audit data about AI and human actions;
  • documents or knowledge sources if and when those features are enabled.

3. How We Use Personal Data

We use personal data for purposes including:

  • providing, operating, and securing the Service;
  • creating and administering accounts and workspaces;
  • authenticating users;
  • connecting and maintaining authorized third-party integrations;
  • generating AI-assisted outputs requested by customers;
  • executing Customer-configured automated workflows;
  • providing support;
  • processing subscriptions and payments;
  • detecting fraud, abuse, security incidents, and technical failures;
  • improving reliability, performance, usability, and safety;
  • communicating about service changes, security, and account matters;
  • complying with legal obligations and enforcing agreements; and
  • establishing, exercising, or defending legal claims.

We do not sell personal data. We do not use Google user data obtained through Google API Services for advertising, retargeting, data brokerage, or other prohibited purposes.

4. Legal Bases for EEA/UK Processing

Where the GDPR, UK GDPR, or similar law applies and EbaSaiyo acts as controller, we rely on one or more of the following legal bases:

Contract. Processing necessary to provide the Service requested by a user or customer.

Legitimate interests. Operating, securing, improving, and administering a B2B SaaS service; preventing abuse; communicating with customers; and protecting legal rights, balanced against the rights of affected individuals.

Legal obligation. Processing required for tax, accounting, sanctions, law-enforcement, or other legal requirements.

Consent. Where required, for example for certain non-essential cookies or optional marketing communications. Consent can be withdrawn where applicable.

For Customer Content, the business customer determines the lawful basis as controller and instructs EbaSaiyo as processor.

5. AI Processing

The Service may send relevant Customer Content to an AI model provider to generate drafts, classifications, confidence information, decision explanations, or other enabled outputs.

For API-based OpenAI services, OpenAI states that inputs and outputs submitted through its API platform are not used to train OpenAI models by default unless the customer explicitly opts in to data sharing. Default API abuse-monitoring retention may apply subject to the provider's current policies and contractual settings.

EbaSaiyo will not intentionally opt Customer Content into third-party model training without an appropriate legal basis and customer-facing disclosure or agreement.

AI processing can involve errors. The Service may maintain audit records of AI-generated decisions and human overrides for safety, accountability, product operation, and future quality analysis, subject to applicable retention rules.

6. Google API Data

When EbaSaiyo accesses Google user data, our use is limited to providing and improving the user-facing features authorized by the user and must comply with the Google API Services User Data Policy, including applicable Limited Use requirements.

Depending on the Gmail scopes used, Google may classify certain permissions as sensitive or restricted and may require OAuth verification and additional security assessment. EbaSaiyo will request only permissions reasonably necessary for the enabled functionality.

7. Microsoft Graph Data

When EbaSaiyo accesses Microsoft 365/Outlook data through Microsoft Graph, access is based on permissions granted by the signed-in user or administrator. EbaSaiyo's intended model is delegated access, meaning the Service acts on behalf of the authorized user and does not obtain greater access than the granted permissions allow.

Permissions are selected based on enabled features, for example mail read/write permissions for reading or preparing replies and mail-send permission for sending messages.

8. Sources of Personal Data

We obtain personal data:

  • directly from users and customers;
  • from authorized account administrators;
  • from connected services such as Google or Microsoft at the user's direction;
  • from payment and authentication providers;
  • automatically through use of the Service; and
  • from support communications and product feedback.

9. How We Share Personal Data

We may disclose personal data to:

Service providers and subprocessors

Providers that support hosting, databases, authentication, AI processing, email connectivity, support, security, and related infrastructure. Current categories and providers are listed in our Subprocessor disclosure.

Payment providers

Payment information may be processed by a payment service provider. Depending on the data and service, the payment provider may act as an independent controller, a processor, or both under its own terms.

Connected third-party platforms

Where a user instructs EbaSaiyo to interact with Google Workspace, Microsoft 365, or another integrated service, data is exchanged with that platform as necessary to perform the requested action.

Professional advisers

Lawyers, accountants, auditors, insurers, and consultants subject to appropriate confidentiality duties.

Authorities and legal recipients

Where reasonably necessary to comply with law, legal process, enforce our rights, protect users, investigate fraud or security incidents, or prevent harm.

Corporate transactions

In connection with an actual or proposed merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and legal safeguards.

We do not sell Customer Content to data brokers or advertising networks.

10. International Transfers

EbaSaiyo and its service providers may process personal data in countries outside the country where the individual is located.

Where the GDPR applies and personal data is transferred to a country that has not received an adequacy decision, EbaSaiyo will use an appropriate transfer mechanism where required, such as the European Commission's Standard Contractual Clauses, together with supplementary measures where appropriate.

Further details are available in the Data Processing Addendum.

11. Data Retention

We retain personal data only as long as reasonably necessary for the purposes described in this policy, including contractual, security, tax, accounting, support, and legal requirements.

Typical retention principles include:

  • account data: for the account relationship plus a reasonable post-termination period;
  • billing and transaction records: as required by tax and accounting law;
  • security logs: for a limited period appropriate to incident detection and investigation;
  • OAuth credentials/tokens: until disconnected, revoked, deleted, or no longer required, subject to technical backup cycles;
  • Customer Content: according to customer instructions, product settings, subscription terms, and the Data Processing Addendum;
  • AI audit records: for the period reasonably needed to support customer auditability, security, troubleshooting, and legal obligations.

EbaSaiyo applies retention periods appropriate to each category above. More specific periods may be published or provided on request where required.

12. Data Security

We use administrative, technical, and organizational measures designed to protect personal data. Depending on the component, these may include encryption in transit, encrypted storage of sensitive OAuth credentials, access controls, tenant scoping, server-side secret handling, audit logging, and provider-level security controls.

No system is perfectly secure. Users should promptly report suspected security issues to contact@ebasaiyo.com.

13. Your Data Protection Rights

Depending on applicable law, individuals may have rights to:

  • access personal data;
  • correct inaccurate data;
  • request deletion;
  • restrict processing;
  • object to certain processing;
  • obtain data portability;
  • withdraw consent where processing is based on consent; and
  • complain to a competent supervisory authority.

Where EbaSaiyo processes personal data only as a processor for a customer, requests relating to that Customer Content should generally be directed to the relevant customer/controller. We will assist the customer as required by applicable law and the Data Processing Addendum.

To exercise rights relating to data for which EbaSaiyo is controller, contact contact@ebasaiyo.com.

14. Marketing Communications

Where permitted by law, we may send product or commercial communications to business contacts. Recipients can opt out of non-essential marketing communications using the available unsubscribe method or by contacting us.

Service, security, billing, and legal communications are not marketing and may still be sent where necessary.

15. Cookies and Similar Technologies

We use essential technologies required for authentication, security, session management, and core functionality. We may use optional analytics or similar technologies only as described in the Cookie Policy and, where required, after obtaining consent.

16. Children

The Service is designed for business users and is not intended for children. Users must be at least 18 years old or the age of legal majority required to enter a business contract in their jurisdiction.

Customers must not intentionally use EbaSaiyo to process children's data in a manner that violates applicable law.

17. Automated Decision-Making

EbaSaiyo may automate operational actions such as classifying an email, generating a draft, escalating a conversation, or sending an email when the Customer has configured autonomous behavior.

These features are designed to execute the Customer's business workflow rather than make legally binding decisions about individuals on behalf of EbaSaiyo. Customers are responsible for assessing whether their particular use constitutes automated decision-making subject to Article 22 GDPR or other sector-specific restrictions, and for implementing required safeguards.

18. EU AI Act Transparency

Where EbaSaiyo functionality causes an AI system to interact directly with natural persons, applicable transparency obligations may require individuals to be informed that they are interacting with AI unless an exception applies or the AI nature is obvious from the context.

EbaSaiyo customers are responsible for determining and implementing legally required recipient-facing disclosures for their communications. EbaSaiyo may provide product controls or suggested language, but does not provide legal advice.

19. Third-Party Links and Services

The Service may link to third-party sites or operate with third-party services. Their privacy practices are governed by their own policies. EbaSaiyo is not responsible for third-party privacy practices outside EbaSaiyo's role as a customer or integrator of those services.

20. Changes to this Privacy Policy

We may update this Privacy Policy as the Service, law, or processing practices change. We will update the effective date and provide additional notice where required for material changes.

21. Contact and Complaints

Privacy questions and requests:

Gabriel Petrozziello, trading as EbaSaiyo
NIF: Y9325381-E
Calle Encarna Albarracin, 6, 46025 Valencia, Spain
contact@ebasaiyo.com

Individuals in the EEA also have the right to lodge a complaint with their local data-protection authority. Given EbaSaiyo's establishment in Spain, the Spanish data-protection authority (AEPD) is the relevant lead supervisory authority for complaints concerning EbaSaiyo as controller.