Privacy Policy
This Privacy Policy explains how CoRAI Labs S.R.L. (“CoRAI Labs”, “we”, “us”), a company registered in Romania, collects, uses, stores, and protects personal data when you use AIxOffice (the “Service”), our business software platform for catalog, offer, and supplier-feed management. CoRAI Labs is the data controller for the personal data described in this policy, except where we act as a processor on behalf of the business customer (tenant) that gave you access to the Service.
For privacy questions or requests, contact us at [email protected].
1. Who the Service is for
AIxOffice is a business-to-business service. You use it through an account provisioned by your organization. The business data your organization stores in AIxOffice (products, prices, customers, offers, supplier feeds) is owned by your organization; we process it only to provide the Service.
2. Information we collect
- Account information — name, work email address, and organization membership, provided when your organization creates your account. Sign-in is handled through Microsoft Entra ID; we do not store your password.
- Business data — content your organization uploads or creates in the Service (catalogs, price lists, offers, customer records, supplier feeds).
- Connected mailbox data — described in detail in Section 3 below, collected only if your organization connects an email account to the Service.
- Technical data — server logs (IP address, timestamps, requests) kept for security and troubleshooting.
3. Connected email accounts
AIxOffice lets your organization connect email mailboxes — for example a Gmail account, a Microsoft 365 / Outlook account, or any mailbox reachable over IMAP — so the Service can read incoming supplier emails (for example price lists, stock feeds, and order confirmations) and turn them into structured business data. This section describes exactly what we access and how we handle it, regardless of provider.
3.1 What we access
- Mailbox content, read-only — message lists, message content, and attachments of the connected mailbox. The Service never sends, deletes, modifies, or labels email in a connected account.
- Account identity — the email address of the account being connected, used solely to display which mailbox is linked.
3.2 How we use it
Mailbox data is used only to provide user-facing features that you or your organization explicitly initiate:
- reading supplier and partner emails in the connected mailbox to extract business information (prices, product data, stock levels, documents) into your organization’s workspace;
- displaying relevant messages and attachments to authorized users of your organization inside the Service.
As part of these features, message content may be processed by artificial-intelligence models operated by our subprocessors, acting under our instructions, solely to produce the results you requested. Mailbox data is never used to develop, improve, or train generalized artificial-intelligence or machine-learning models.
3.3 What we store
- the credentials needed to access the mailbox (an OAuth refresh token, or IMAP credentials where OAuth is not available), encrypted at rest;
- the email address of the connected account;
- business data extracted from messages (for example a price list from an attachment), stored as part of your organization’s records.
We do not maintain a copy of your mailbox. Messages are fetched on demand, processed, and not retained beyond what is described above.
3.4 What we never do with mailbox data
- We never sell it.
- We never use it for advertising of any kind.
- We never transfer it to third parties except to subprocessors listed in Section 5, acting on our instructions, or where required by law.
- No human at CoRAI Labs reads it, except (a) with your explicit consent, (b) where necessary for security purposes such as abuse investigation, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymized for internal operations.
3.5 Revoking access and deletion
You can disconnect a mailbox at any time from the Service’s connection settings, which deletes the stored credentials. For OAuth-connected accounts you can also revoke AIxOffice’s access directly with your provider — for Google at myaccount.google.com/permissions, for Microsoft at myaccount.microsoft.com. Upon disconnection or revocation, we no longer access the mailbox. You may additionally request deletion of previously extracted data by writing to [email protected]; we honor such requests within 30 days.
3.6 Additional disclosures for Google accounts
When the connected mailbox is a Gmail account, access is obtained through Google’s OAuth consent flow using the gmail.readonly scope (read-only mailbox access) and basic profile scopes (openid, email, profile) used solely to identify the connected account. All commitments in Sections 3.1–3.5 apply to this Google user data in full.
AIxOffice’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. Legal bases for processing (GDPR)
- Performance of a contract — providing the Service to your organization and to you as its authorized user.
- Legitimate interests — securing and improving the Service, preventing abuse, and keeping technical logs.
- Consent — connecting a mailbox happens only after you authorize access (through the provider’s consent screen for OAuth accounts, or by supplying credentials for IMAP accounts); you may withdraw consent at any time as described in Section 3.5.
- Legal obligation — where retention or disclosure is required by applicable law.
5. Sharing and subprocessors
We do not sell personal data and do not share it with third parties for their own purposes. We use a small number of subprocessors to operate the Service, each bound by data-processing agreements:
- Microsoft Azure — cloud hosting, storage, and identity services (data hosted in the European Union);
- AI model providers — processing of content you ask the Service to analyze, solely to deliver the requested feature, with no training on your data.
We may disclose data where required by law or to protect the rights, safety, or property of CoRAI Labs, our customers, or the public.
6. International transfers
Data is hosted in the European Union. Where a subprocessor processes data outside the EU/EEA, we rely on appropriate safeguards under GDPR, such as the European Commission’s Standard Contractual Clauses.
7. Security
We protect data with industry-standard measures, including encryption in transit (TLS) and at rest, encrypted storage of all mailbox credentials and tokens, strict per-organization data isolation, role-based access control, and audit logging. Access to production systems is limited to authorized personnel.
8. Retention
We keep personal data only as long as needed for the purposes above: account data for the life of your account; connected-mailbox tokens until disconnection or revocation; extracted business data for as long as your organization keeps it in the Service; technical logs for a limited period for security purposes. When your organization’s contract ends, its data is deleted in accordance with that contract.
9. Your rights
Under the GDPR you have the right to access, rectify, erase, and receive a copy of your personal data, to restrict or object to its processing, and to withdraw consent at any time. To exercise these rights, contact [email protected]. You also have the right to lodge a complaint with your supervisory authority; in Romania this is the National Supervisory Authority for Personal Data Processing (ANSPDCP, dataprotection.ro).
10. Cookies
The Service uses only cookies and similar storage that are strictly necessary for authentication, session management, and remembering the language you choose on our public pages. We do not use advertising or cross-site tracking cookies.
11. Children
The Service is intended for business use by adults and is not directed at children under 18. We do not knowingly collect data from children.
12. Changes to this policy
We may update this policy from time to time. Material changes will be announced through the Service or by email before they take effect. This page always shows the current version.
13. Language
This policy is published in several languages. In case of any discrepancy between versions, the English version prevails.
14. Contact
CoRAI Labs S.R.L., Romania
Email: [email protected]