Legal
Privacy Policy
1. Introduction
GAIO Tech BV ("we," "our," or "us") operates the GAIO Tech platform (the "Service"), providing AI-powered brand intelligence and search optimisation services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
By accessing or using our Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you disagree with any part of this policy, please discontinue use of our Service immediately.
2. Information We Collect
2.1 Personal Information
We collect the following personal information when you:
- Create an account: Name, email address, company information, job title
- Use Google OAuth: Profile information from your Google account
- Subscribe to plans: Billing information, payment details
- Contact us: Communication preferences, inquiry details
2.2 Technical Information
- Device information: IP address, browser type, operating system
- Usage data: Pages visited, time spent, feature interactions
- Cookies and tracking technologies: Session data, preferences
- API usage: Request logs, response times, error rates
2.3 Business Data
- Brand URLs and website content you submit for analysis
- Brand intelligence data points and analysis results
- Knowledge tree structures and brand book content
- Usage patterns and optimisation preferences
3. How We Use Your Information
3.1 Service Provision
- Provide AI-powered brand analysis and optimisation services
- Generate knowledge trees and brand intelligence reports
- Process subscription plans and billing
- Maintain user accounts and authentication
3.2 AI Training and Improvement
Important Notice:
- We may use aggregated, anonymized data to improve our AI models
- Your specific brand data is NOT used to train third-party AI services
- We implement data isolation to prevent cross-customer data exposure
- You can opt-out of AI training data usage by contacting us
3.3 Communication
- Send service updates, security notifications, and account information
- Provide customer support and respond to inquiries
- Send marketing communications (with your consent)
- Notify founding partners of program benefits and updates
4. Information Sharing and Disclosure
4.1 Third-Party Services
We share limited data with trusted service providers:
- OpenAI: Brand content for AI analysis (processing only, not training)
- Google OAuth: Authentication services
- SendGrid: Email delivery services
- Neon Database: Secure data storage
- Slack: Internal team notifications for customer success
- Google Analytics 4: Aggregated website measurement (page views, interactions, Core Web Vitals). Only active if you allow the Analytics category in our cookie banner. Google Signals and ad personalisation are disabled, so it is not used for advertising or cross-site profiling
- Apollo.io: Website visitor company identification on our public website, used for business follow-up. Only active if you allow the Visitor identification category — a separate choice from Analytics. See our Cookie Policy
4.2 Legal Requirements
We may disclose information when required by law or to:
- Comply with legal obligations or court orders
- Protect our rights, property, or safety
- Prevent fraud or security threats
- Enforce our Terms of Service
4.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.
5. Data Security
We implement enterprise-grade security measures including:
- End-to-end encryption for data transmission and storage
- Multi-factor authentication and session management
- Regular security audits and penetration testing
- Access controls and employee security training
- Automated threat detection and response systems
- Comprehensive audit logging for compliance monitoring
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security.
6. International Data Transfers
As a Belgium-based company, we primarily process data within the EU and EEA. However, some service providers may process data in other jurisdictions, including the United States.
When we transfer personal data outside the EU/EEA, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by regulatory authorities
- Adequacy decisions for certain countries
- Additional technical and organisational measures for data protection
Two website measurement providers involve a transfer to the United States, and each depends on a consent choice you control independently:
- Apollo.io, Inc. — your IP address and page views, where you allowed Visitor identification
- Google LLC (Analytics) — aggregated usage and performance measurement, where you allowed Analytics
Declining or withdrawing a category prevents that transfer entirely, because the corresponding script is never loaded in the first place.
7. Your Rights
7.1 GDPR Rights (EU/EEA Residents)
- Access: Request copies of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your personal data
- Portability: Receive your data in a structured format
- Restriction: Limit how we process your data
- Objection: Object to processing for legitimate interests
- Withdraw consent: For processing based on consent
7.2 How to Exercise Your Rights
To exercise any of these rights, contact us at:
- Email: [email protected]
- Response time: Within 30 days of receipt
- Identity verification may be required for security
8. Data Retention
We retain personal information for as long as necessary to:
- Provide our services and maintain your account
- Comply with legal obligations (typically 6-7 years for business records)
- Resolve disputes and enforce agreements
- Meet regulatory requirements for financial services
When data is no longer required, we securely delete or anonymize it according to our data retention schedule and applicable legal requirements.
9. Cookies and Tracking
We use cookies and similar technologies to:
- Maintain user sessions and authentication
- Remember your preferences and settings
- Analyze site usage with Google Analytics
- Provide personalized content and recommendations
You can control cookies through your browser settings. However, disabling cookies may limit your ability to use certain features of our Service.
10. Children's Privacy
Our Service is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will take steps to delete such information promptly.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the updated policy on our website
- Sending email notifications to registered users
- Providing in-app notifications for significant changes
Changes become effective 30 days after posting, unless a shorter period is required by law.
12. Contact Information
Data Controller: GAIO Tech BV
Registered Address: SQ Antwerp Tower - Frankrijklei 5, Office 3.08, 2000 Antwerp, Belgium
Company Registration: Company number 1039.003.127 · VAT BE1039.003.127
Privacy Officer: [email protected]
General Contact: [email protected]
Data Protection Authority: If you are not satisfied with our response to your privacy concerns, you have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit) at gegevensbeschermingsautoriteit.be or your local data protection authority.
13. Legal Basis for Processing
We process personal data based on the following legal grounds:
- Contract: To perform our services and manage subscriptions
- Consent: For marketing communications and optional features
- Legitimate Interest: For service improvement and fraud prevention
- Legal Obligation: To comply with applicable laws and regulations

