Privacy Policy
Last updated: August 31, 2026 · German version available at amtigo.com/datenschutz
Controller
Efendi Group L.L.C-FZ
Represented by: Furkan Engizek (Manager)
Meydan Grandstand, 6th Floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.
License Number: 2526780.01 (Meydan Free Zone)
Privacy contact: privacy@efendi.group
Support: support@efendi.group
1. What data we process
Telegram and WhatsApp bot: User ID, display name, messages, uploaded documents (official letters, insurance notices, correspondence), voice messages.
Gmail data (optional, only with explicit consent): If you connect your Gmail account, we read only the emails that you actively forward or authorize us to process. We do not automatically scan your entire mailbox and do not access emails without your instruction. Only content that you submit for analysis is processed.
Payment data: Transaction status, amount, date. Credit card or bank account data is processed exclusively by Stripe and is not stored by us.
Technical usage data: IP address, date/time of access, browser and operating system.
2. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Provision of the service (drafting replies) | Art. 6(1)(b) GDPR (performance of a contract) |
| Payment processing | Art. 6(1)(b) GDPR (performance of a contract) |
| Technical operation, security | Art. 6(1)(f) GDPR (legitimate interest) |
| Gmail access (optional) | Art. 6(1)(a) GDPR (consent) |
3. Google API Services — Limited Use Compliance
Amtigo uses Google API Services (Gmail API) to provide users with optional Gmail features in chat. The use of this data is subject to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use Requirements.
Requested OAuth scopes
https://www.googleapis.com/auth/gmail.readonly— Reading emails and metadata exclusively to answer explicit user requests in chat (e.g. “What was in the latest invoice from Vodafone?”).https://www.googleapis.com/auth/gmail.send— Sending emails on behalf of the user exclusively after explicit approval in chat. Every send requires a preview of the complete email content (recipient, subject, body) and explicit confirmation by the user (“Yes, send”). There is no automatic sending, bulk sending, or marketing sending.
Triggers for Gmail use
Gmail access takes place exclusively in response to explicit user commands in chat, for example:
- /inbox — Overview of new emails
- /mail — Search emails
- /summary — Summary of a conversation
- /send or approval of an email draft requested by the user
Without such an explicit user command, the Gmail mailbox is not accessed.
What Amtigo does NOT do with Gmail data
- No use for advertising or marketing
- No sale or disclosure of Gmail data to third parties, except to processors necessary for operation
- No training or improvement of generalized AI/ML models using Gmail content
- No permanent storage of Gmail content; processing exclusively in memory to fulfill the respective user request
- No auto-send, no bulk sending, no scheduled sending
Preview and confirmation requirement when sending
Before an email is sent via gmail.send, Amtigo always displays the following in chat:
- The complete recipient (To and, where applicable, Cc/Bcc)
- The complete subject
- The complete message body
- An explicit confirmation button (“Yes, send” / “Edit”)
Only after explicit confirmation is the email sent via the Gmail API on behalf of the user. The user can edit or cancel any message before it is sent.
Revoking the Gmail connection
The user can revoke the Gmail connection at any time:
- In chat using the /disconnect command
- Via https://myaccount.google.com/permissions
Upon revocation, all access and refresh tokens are deleted.
Storage and security
- Gmail content is not stored persistently; processing takes place exclusively in memory (RAM).
- Access and refresh tokens are stored in the database with AES-256 encryption.
- Transmission takes place exclusively via TLS 1.2 or higher.
- Access to production systems follows the principle of least privilege.
Legal basis
Gmail data is processed on the basis of Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(a) GDPR (consent through OAuth consent).
4. Protection of sensitive data — Technical and organizational measures
4.1 Encryption
In transit: All connections are encrypted using TLS 1.2 or higher (Telegram Bot API, WhatsApp Cloud API, Google APIs, Stripe API, OpenAI API, internal service-to-service calls).
At rest: OAuth refresh tokens are stored in a token store whose access is controlled by an internal shared secret (server-to-server authentication). The underlying storage infrastructure (Railway, US-EAST) encrypts data at rest using AES-256.
4.2 Access controls
- Gmail content is accessed exclusively in response to a direct user command (chat commands /inbox, /mail, /summary).
- There is no automated background polling of the mailbox.
- OAuth refresh tokens are accessible only to the backend service; human staff do not have routine access. Access by the development team is limited to security incidents and maintenance and is logged.
- Communication between the bot service and OAuth service is secured by an internal shared secret (≥32 bytes, high entropy).
4.3 Retention period and data minimization
- Gmail content: is not stored persistently. Retrieved messages are processed in memory to create a draft reply and discarded after completion of the request. Only the OAuth refresh token and associated email address are stored persistently for as long as you actively use the service.
- Chat messages and uploaded documents: for the duration of the active conversation and for a maximum of 30 days for service quality and error analysis, after which they are deleted—unless statutory retention obligations (e.g. Section 147 AO for invoice-related records) apply.
- Voice messages: are deleted immediately after transcription. Transcripts are subject to the chat retention rule above.
- Payment data: in accordance with statutory retention periods (typically 10 years under Section 147 AO / Section 257 HGB), stored exclusively by Stripe.
4.4 No AI/ML training with user data
Gmail content and chat messages are not used to train or improve AI or ML models—neither by Efendi nor by our processors (in particular OpenAI). Our OpenAI API agreement contractually excludes training with submitted content (OpenAI API Data Usage Policy: API data is not used for training by default). This fulfills the Google Workspace API requirement for an “AI/ML Model Training Privacy Policy Disclosure.”
4.5 Revocation and deletion upon request
You can disconnect the Gmail connection at any time using /disconnect in the bot or at myaccount.google.com/permissions. Upon revocation, the refresh token and stored email address are deleted immediately.
You can request complete deletion of your account at any time at privacy@efendi.group. Deletion is completed within 30 days, subject to statutory retention obligations.
5. Processors
We use the following service providers as processors within the meaning of Art. 28 GDPR. Data processing agreements (DPAs) are in place with all processors.
| Provider | Purpose | Location | Third-country safeguards |
|---|---|---|---|
| OpenAI, L.L.C. | Language model for drafting replies; Whisper transcription of voice messages | USA | EU Standard Contractual Clauses (SCCs), API Data Processing Addendum |
| Meta Platforms Ireland Ltd. | WhatsApp Business Cloud API (message delivery) | Ireland / USA | EU-US Data Privacy Framework + SCCs |
| Telegram FZ-LLC | Telegram Bot API (message delivery) | UAE | Telegram Privacy Policy |
| Railway Corp. | Hosting of backend services (bot, OAuth) | USA | EU Standard Contractual Clauses (SCCs), Railway DPA |
| Stripe Payments Europe Ltd. | Payment processing | Ireland / USA | EU-US Data Privacy Framework + SCCs |
| Google LLC | Gmail API (only with user consent), domain verification | USA | EU-US Data Privacy Framework + SCCs |
| Vercel / Lovable / GoDaddy | Hosting of the efendi.group website, DNS | USA | EU Standard Contractual Clauses (SCCs) |
The EU Standard Contractual Clauses pursuant to Art. 46 GDPR apply to all transfers to third countries (in particular the USA), supplemented by company-specific safeguards (TLS encryption in transit, AES-256 at rest, data minimization).
6. Your rights
Under the GDPR, you have the following rights with respect to Efendi:
- Access to the personal data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (“right to be forgotten,” Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability in a structured, commonly used format (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
- Lodging a complaint with a data protection supervisory authority (Art. 77 GDPR), e.g. the authority responsible for your place of residence
Requests to: privacy@efendi.group. We generally respond within 7 days, but no later than within one month (Art. 12(3) GDPR).
7. Cookies and tracking
On the efendi.group website, we use only technically necessary cookies (session, language setting). No tracking cookies or advertising pixels are set without your consent. By clicking “Accept,” you optionally consent to the storage of anonymized reach statistics. You can withdraw this consent at any time through the cookie settings.
8. Changes to this Privacy Policy
This Privacy Policy will be updated in the event of material changes. The current version, including its version date, is always available at efendi.group/datenschutz. Active users will be notified of material changes via Telegram/WhatsApp message or email.