Privacy Policy

This Privacy Policy explains how CoRAI Labs S.R.L. (“CoRAI Labs”, “we”, “us”), a company registered in Romania, collects, uses, stores, and protects personal data when you use AIxOffice (the “Service”), our business software platform for catalog, offer, and supplier-feed management. CoRAI Labs is the data controller for the personal data described in this policy, except where we act as a processor on behalf of the business customer (tenant) that gave you access to the Service.

For privacy questions or requests, contact us at [email protected].

1. Who the Service is for

AIxOffice is a business-to-business service. You use it through an account provisioned by your organization. The business data your organization stores in AIxOffice (products, prices, customers, offers, supplier feeds) is owned by your organization; we process it only to provide the Service.

2. Information we collect

3. Connected email accounts

AIxOffice lets your organization connect email mailboxes — for example a Gmail account, a Microsoft 365 / Outlook account, or any mailbox reachable over IMAP — so the Service can read incoming supplier emails (for example price lists, stock feeds, and order confirmations) and turn them into structured business data. This section describes exactly what we access and how we handle it, regardless of provider.

3.1 What we access

3.2 How we use it

Mailbox data is used only to provide user-facing features that you or your organization explicitly initiate:

As part of these features, message content may be processed by artificial-intelligence models operated by our subprocessors, acting under our instructions, solely to produce the results you requested. Mailbox data is never used to develop, improve, or train generalized artificial-intelligence or machine-learning models.

3.3 What we store

We do not maintain a copy of your mailbox. Messages are fetched on demand, processed, and not retained beyond what is described above.

3.4 What we never do with mailbox data

3.5 Revoking access and deletion

You can disconnect a mailbox at any time from the Service’s connection settings, which deletes the stored credentials. For OAuth-connected accounts you can also revoke AIxOffice’s access directly with your provider — for Google at myaccount.google.com/permissions, for Microsoft at myaccount.microsoft.com. Upon disconnection or revocation, we no longer access the mailbox. You may additionally request deletion of previously extracted data by writing to [email protected]; we honor such requests within 30 days.

3.6 Additional disclosures for Google accounts

When the connected mailbox is a Gmail account, access is obtained through Google’s OAuth consent flow using the gmail.readonly scope (read-only mailbox access) and basic profile scopes (openid, email, profile) used solely to identify the connected account. All commitments in Sections 3.1–3.5 apply to this Google user data in full.

AIxOffice’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Legal bases for processing (GDPR)

5. Sharing and subprocessors

We do not sell personal data and do not share it with third parties for their own purposes. We use a small number of subprocessors to operate the Service, each bound by data-processing agreements:

We may disclose data where required by law or to protect the rights, safety, or property of CoRAI Labs, our customers, or the public.

6. International transfers

Data is hosted in the European Union. Where a subprocessor processes data outside the EU/EEA, we rely on appropriate safeguards under GDPR, such as the European Commission’s Standard Contractual Clauses.

7. Security

We protect data with industry-standard measures, including encryption in transit (TLS) and at rest, encrypted storage of all mailbox credentials and tokens, strict per-organization data isolation, role-based access control, and audit logging. Access to production systems is limited to authorized personnel.

8. Retention

We keep personal data only as long as needed for the purposes above: account data for the life of your account; connected-mailbox tokens until disconnection or revocation; extracted business data for as long as your organization keeps it in the Service; technical logs for a limited period for security purposes. When your organization’s contract ends, its data is deleted in accordance with that contract.

9. Your rights

Under the GDPR you have the right to access, rectify, erase, and receive a copy of your personal data, to restrict or object to its processing, and to withdraw consent at any time. To exercise these rights, contact [email protected]. You also have the right to lodge a complaint with your supervisory authority; in Romania this is the National Supervisory Authority for Personal Data Processing (ANSPDCP, dataprotection.ro).

10. Cookies

The Service uses only cookies and similar storage that are strictly necessary for authentication, session management, and remembering the language you choose on our public pages. We do not use advertising or cross-site tracking cookies.

11. Children

The Service is intended for business use by adults and is not directed at children under 18. We do not knowingly collect data from children.

12. Changes to this policy

We may update this policy from time to time. Material changes will be announced through the Service or by email before they take effect. This page always shows the current version.

13. Language

This policy is published in several languages. In case of any discrepancy between versions, the English version prevails.

14. Contact

CoRAI Labs S.R.L., Romania
Email: [email protected]