Legal
Privacy Policy
Last updated: June 2026
Introduction
Galini Tech ("we", "us", "our") operates Aitarax, an AI-powered customer communication platform accessible at app.aitarax.com. This Privacy Policy explains how we collect, use, store, and protect personal data when you use the Service.
Galini Tech is the data controller responsible for your personal data. We are based in the Netherlands and are subject to the General Data Protection Regulation (GDPR).
If you have any questions about this policy, contact us at hello@aitarax.com.
Data We Collect
Account data
When you create an account, we collect your email address and any organisation or brand information you provide. We use magic-code login — no password is stored.
Customer data you upload
As a B2B platform, you upload your own customers' data (names, email addresses, event history such as bookings, orders, and service records) to power the Service. You are the data controller for this data; Aitarax acts as the processor. See Section 9 for details on our data processing obligations.
Usage data
We collect data about how you use the Service, including log data, API request timestamps, email delivery events (sent, opened, clicked), and error logs. This is used to operate, improve, and troubleshoot the Service.
Billing data
Payment details are handled entirely by Stripe. We do not store credit card numbers or bank details. We retain billing records (amounts charged, subscription periods, and Stripe customer IDs) for legal and accounting purposes.
Communication data
If you contact us via email or otherwise, we store that correspondence to handle your request and improve our support.
How We Use Your Data
We use your data for the following purposes:
- Providing the Service: processing events, generating AI email content, scheduling and sending emails on your behalf
- Account management: authentication, billing, and subscription administration
- Service improvement: analysing usage patterns to improve features, reliability, and AI output quality
- Legal compliance: retaining records required by Dutch and EU law
- Support: responding to your questions and resolving issues
- Service communications: notifying you of significant changes to the Service, pricing, or these policies
We do not use your data or your customers' data for marketing to third parties, and we do not sell personal data.
Legal Basis for Processing
We process your personal data on the following legal bases under GDPR Article 6:
- Contract (Art. 6(1)(b)): processing necessary to provide the Service you have subscribed to, including account management and billing
- Legitimate interests (Art. 6(1)(f)): service improvement, fraud prevention, and security monitoring, where these do not override your fundamental rights
- Legal obligation (Art. 6(1)(c)): retaining financial records for statutory accounting and tax compliance
Data Storage and Security
Where your data is stored
All personal data is stored within the European Union. Specifically:
- Application database and infrastructure: Railway EU West (Amsterdam, Netherlands)
- Brand images and logos: AWS S3, eu-central-1 (Frankfurt, Germany). No customer personal data is stored here.
- Content delivery and DNS: Cloudflare (EU edge nodes where applicable)
Image processing
When you upload brand logos or header images, they are stored on AWS S3 in Frankfurt (eu-central-1) and served via Cloudflare's CDN. Images are resized and optimised as part of the upload process. No customer personal data is contained in or associated with uploaded images.
Security measures
We implement appropriate technical and organisational security measures, including:
- Encryption of all data in transit using TLS/HTTPS
- Encrypted database storage at rest
- API keys are hashed — plaintext keys are never stored
- Access controls and role-based permissions
- Regular dependency and security updates
No system is completely secure. In the event of a data breach that affects your data, we will notify you without undue delay.
Data Shared with AI Providers
To generate personalised email content, we share a limited set of customer data with AI providers (Anthropic, OpenAI, Google, or others — configurable per brand). This data is provided by you as a business using the Service. You are responsible for ensuring you have appropriate grounds to share this data.
Data we DO share with AI providers
- Customer first name
- Language preference
- Event details (service type, date and time, status, quantities)
- Metadata you provide (e.g. staff name, notes, communication type)
- Previous email history (subject lines, whether emails were opened or clicked)
- Brand name and context
- Email tone, style, and prompt instructions configured per brand
Data we do NOT share with AI providers
- Customer email addresses
- Phone numbers
- Physical addresses
- Payment or financial information
- Any other direct contact details
All AI providers are used via API endpoints that operate under a zero data retention policy. Data sent to AI providers is not stored by them beyond the duration of the API call and is not used to train AI models.
Data Shared with Email Provider (Resend)
We use Resend to send emails on your behalf. The following data is shared with Resend:
- Recipient email address (your customer's email)
- Sender email address (your configured brand email)
- Generated email content — this includes the customer's first name as used in the email greeting and body
Raw customer records, event history, and other personal data are not shared with Resend. Email delivery data (opens, clicks, bounces) is returned to us via webhook for tracking purposes and is visible in your dashboard.
Resend processes this data according to their Privacy Policy.
Data Shared with Payment Processor (Stripe)
We use Stripe to process subscription payments. When you subscribe, the following data is shared with Stripe:
- Your email address (for receipts and payment notifications)
- Organisation name (for invoice display)
- Payment method details (card number, expiry, CVC — entered directly on Stripe's secure checkout, not visible to us)
- Billing amounts and subscription periods
No customer personal data is shared with Stripe. We do not store full payment card details on our servers. Payment records are retained separately by Stripe for financial compliance, even after account deletion.
Stripe processes data according to their Privacy Policy. Stripe is certified under the EU-U.S. Data Privacy Framework and uses Standard Contractual Clauses for international transfers.
Our Role as Data Processor
When you use Aitarax to process your customers' personal data, you are the data controller and Galini Tech is the data processor. As processor, we:
- Process customer data only on your documented instructions
- Do not use customer data for our own purposes
- Do not sell or share customer data with unauthorised parties
- Assist you in fulfilling data subject rights requests
- Notify you without undue delay of any personal data breach affecting your customers
- Delete all customer data when you delete a brand or close your account
A full Data Processing Agreement is embedded in our Terms of Service (Section 5). By using the Service, you agree to those terms.
International Data Transfers
Most of your data and your customers' data is stored and processed within the EU. However, AI providers (Anthropic, OpenAI, Google) are based outside the EEA and may process limited data in the United States or elsewhere.
Where such transfers occur, we ensure appropriate safeguards are in place:
- AI providers (Anthropic, OpenAI, Google): Data transfers are covered by Standard Contractual Clauses (SCCs) and their respective Data Processing Agreements. Zero data retention applies.
- Stripe: Certified under the EU-U.S. Data Privacy Framework and uses Standard Contractual Clauses.
- Cloudflare: Uses Standard Contractual Clauses and is certified under the EU-U.S. Data Privacy Framework.
Automated Processing
Aitarax uses automated processing in the following ways:
- Email content generation: AI automatically generates personalised email content based on customer and event data you have provided. Depending on your settings, you can review and edit generated content before sending, or enable auto-approve for fully automated operation.
- Send timing prediction: The re-engagement engine automatically calculates per-customer behavioural patterns to determine the optimal moment to send a message, based on historical event intervals.
These automated processes do not produce legal or similarly significant effects on individuals under GDPR Article 22. If you have concerns about automated processing, please contact us.
Data Retention
We retain data for as long as necessary for the purposes described in this policy:
- Account data: retained for the duration of your account, plus up to 30 days after deletion to allow for account recovery
- Customer data: deleted immediately when you delete a brand or close your account; individual records can be deleted at any time through the Service or via the API
- Billing records: retained for 7 years in accordance with Dutch accounting law (Burgerlijk Wetboek 2:10)
- Email delivery logs: retained for up to 90 days for debugging and delivery troubleshooting
- Usage/access logs: retained for up to 30 days
Deleting your account
To delete your account:
- Cancel your active subscription via the billing settings
- Delete all brands and associated customer data
- Delete your account via your profile settings
Payment records retained by Stripe are kept separately for financial compliance and are not deleted when you delete your Aitarax account.
Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access: you can request a copy of the personal data we hold about you
- Right to rectification: you can ask us to correct inaccurate data
- Right to erasure: you can request deletion of your personal data, subject to legal retention obligations
- Right to restriction: you can ask us to restrict how we process your data in certain circumstances
- Right to data portability: you can request your data in a machine-readable format
- Right to object: you can object to processing based on legitimate interests
- Right to withdraw consent: where processing is based on consent, you can withdraw it at any time
To exercise any of these rights, contact us at hello@aitarax.com. We will respond within 30 days.
You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.
Children's Privacy
The Service is intended for business users and is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child's data has been submitted, please contact us and we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes at least 30 days before they take effect by email or through a prominent notice in the Service. The "last updated" date at the top of this page reflects the most recent revision.
Contact
For questions, requests, or complaints about this Privacy Policy or our data practices, contact us at:
Galini Tech
Aitarax is a product of Galini Tech
KvK: 93756054
BTW: NL001748469B65
Email: hello@aitarax.com
Questions about your data? hello@aitarax.com
