Privacy Policy

Last updated: August 31, 2026 · German version available at amtigo.com/datenschutz

Controller

Efendi Group L.L.C-FZ

Represented by: Furkan Engizek (Manager)

Meydan Grandstand, 6th Floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.

License Number: 2526780.01 (Meydan Free Zone)

1. What data we process

Telegram and WhatsApp bot: User ID, display name, messages, uploaded documents (official letters, insurance notices, correspondence), voice messages.

Gmail data (optional, only with explicit consent): If you connect your Gmail account, we read only the emails that you actively forward or authorize us to process. We do not automatically scan your entire mailbox and do not access emails without your instruction. Only content that you submit for analysis is processed.

Payment data: Transaction status, amount, date. Credit card or bank account data is processed exclusively by Stripe and is not stored by us.

Technical usage data: IP address, date/time of access, browser and operating system.

2. Purposes and legal bases

PurposeLegal basis
Provision of the service (drafting replies)Art. 6(1)(b) GDPR (performance of a contract)
Payment processingArt. 6(1)(b) GDPR (performance of a contract)
Technical operation, securityArt. 6(1)(f) GDPR (legitimate interest)
Gmail access (optional)Art. 6(1)(a) GDPR (consent)

3. Google API Services — Limited Use Compliance

Amtigo uses Google API Services (Gmail API) to provide users with optional Gmail features in chat. The use of this data is subject to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use Requirements.

Requested OAuth scopes

  • https://www.googleapis.com/auth/gmail.readonly — Reading emails and metadata exclusively to answer explicit user requests in chat (e.g. “What was in the latest invoice from Vodafone?”).
  • https://www.googleapis.com/auth/gmail.send — Sending emails on behalf of the user exclusively after explicit approval in chat. Every send requires a preview of the complete email content (recipient, subject, body) and explicit confirmation by the user (“Yes, send”). There is no automatic sending, bulk sending, or marketing sending.

Triggers for Gmail use

Gmail access takes place exclusively in response to explicit user commands in chat, for example:

  • /inbox — Overview of new emails
  • /mail — Search emails
  • /summary — Summary of a conversation
  • /send or approval of an email draft requested by the user

Without such an explicit user command, the Gmail mailbox is not accessed.

What Amtigo does NOT do with Gmail data

  • No use for advertising or marketing
  • No sale or disclosure of Gmail data to third parties, except to processors necessary for operation
  • No training or improvement of generalized AI/ML models using Gmail content
  • No permanent storage of Gmail content; processing exclusively in memory to fulfill the respective user request
  • No auto-send, no bulk sending, no scheduled sending

Preview and confirmation requirement when sending

Before an email is sent via gmail.send, Amtigo always displays the following in chat:

  1. The complete recipient (To and, where applicable, Cc/Bcc)
  2. The complete subject
  3. The complete message body
  4. An explicit confirmation button (“Yes, send” / “Edit”)

Only after explicit confirmation is the email sent via the Gmail API on behalf of the user. The user can edit or cancel any message before it is sent.

Revoking the Gmail connection

The user can revoke the Gmail connection at any time:

Upon revocation, all access and refresh tokens are deleted.

Storage and security

  • Gmail content is not stored persistently; processing takes place exclusively in memory (RAM).
  • Access and refresh tokens are stored in the database with AES-256 encryption.
  • Transmission takes place exclusively via TLS 1.2 or higher.
  • Access to production systems follows the principle of least privilege.

Legal basis

Gmail data is processed on the basis of Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(a) GDPR (consent through OAuth consent).

4. Protection of sensitive data — Technical and organizational measures

4.1 Encryption

In transit: All connections are encrypted using TLS 1.2 or higher (Telegram Bot API, WhatsApp Cloud API, Google APIs, Stripe API, OpenAI API, internal service-to-service calls).

At rest: OAuth refresh tokens are stored in a token store whose access is controlled by an internal shared secret (server-to-server authentication). The underlying storage infrastructure (Railway, US-EAST) encrypts data at rest using AES-256.

4.2 Access controls

  • Gmail content is accessed exclusively in response to a direct user command (chat commands /inbox, /mail, /summary).
  • There is no automated background polling of the mailbox.
  • OAuth refresh tokens are accessible only to the backend service; human staff do not have routine access. Access by the development team is limited to security incidents and maintenance and is logged.
  • Communication between the bot service and OAuth service is secured by an internal shared secret (≥32 bytes, high entropy).

4.3 Retention period and data minimization

  • Gmail content: is not stored persistently. Retrieved messages are processed in memory to create a draft reply and discarded after completion of the request. Only the OAuth refresh token and associated email address are stored persistently for as long as you actively use the service.
  • Chat messages and uploaded documents: for the duration of the active conversation and for a maximum of 30 days for service quality and error analysis, after which they are deleted—unless statutory retention obligations (e.g. Section 147 AO for invoice-related records) apply.
  • Voice messages: are deleted immediately after transcription. Transcripts are subject to the chat retention rule above.
  • Payment data: in accordance with statutory retention periods (typically 10 years under Section 147 AO / Section 257 HGB), stored exclusively by Stripe.

4.4 No AI/ML training with user data

Gmail content and chat messages are not used to train or improve AI or ML models—neither by Efendi nor by our processors (in particular OpenAI). Our OpenAI API agreement contractually excludes training with submitted content (OpenAI API Data Usage Policy: API data is not used for training by default). This fulfills the Google Workspace API requirement for an “AI/ML Model Training Privacy Policy Disclosure.”

4.5 Revocation and deletion upon request

You can disconnect the Gmail connection at any time using /disconnect in the bot or at myaccount.google.com/permissions. Upon revocation, the refresh token and stored email address are deleted immediately.

You can request complete deletion of your account at any time at privacy@efendi.group. Deletion is completed within 30 days, subject to statutory retention obligations.

5. Processors

We use the following service providers as processors within the meaning of Art. 28 GDPR. Data processing agreements (DPAs) are in place with all processors.

ProviderPurposeLocationThird-country safeguards
OpenAI, L.L.C.Language model for drafting replies; Whisper transcription of voice messagesUSAEU Standard Contractual Clauses (SCCs), API Data Processing Addendum
Meta Platforms Ireland Ltd.WhatsApp Business Cloud API (message delivery)Ireland / USAEU-US Data Privacy Framework + SCCs
Telegram FZ-LLCTelegram Bot API (message delivery)UAETelegram Privacy Policy
Railway Corp.Hosting of backend services (bot, OAuth)USAEU Standard Contractual Clauses (SCCs), Railway DPA
Stripe Payments Europe Ltd.Payment processingIreland / USAEU-US Data Privacy Framework + SCCs
Google LLCGmail API (only with user consent), domain verificationUSAEU-US Data Privacy Framework + SCCs
Vercel / Lovable / GoDaddyHosting of the efendi.group website, DNSUSAEU Standard Contractual Clauses (SCCs)

The EU Standard Contractual Clauses pursuant to Art. 46 GDPR apply to all transfers to third countries (in particular the USA), supplemented by company-specific safeguards (TLS encryption in transit, AES-256 at rest, data minimization).

6. Your rights

Under the GDPR, you have the following rights with respect to Efendi:

  • Access to the personal data stored about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (“right to be forgotten,” Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability in a structured, commonly used format (Art. 20 GDPR)
  • Objection to processing based on legitimate interests (Art. 21 GDPR)
  • Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
  • Lodging a complaint with a data protection supervisory authority (Art. 77 GDPR), e.g. the authority responsible for your place of residence

Requests to: privacy@efendi.group. We generally respond within 7 days, but no later than within one month (Art. 12(3) GDPR).

7. Cookies and tracking

On the efendi.group website, we use only technically necessary cookies (session, language setting). No tracking cookies or advertising pixels are set without your consent. By clicking “Accept,” you optionally consent to the storage of anonymized reach statistics. You can withdraw this consent at any time through the cookie settings.

8. Changes to this Privacy Policy

This Privacy Policy will be updated in the event of material changes. The current version, including its version date, is always available at efendi.group/datenschutz. Active users will be notified of material changes via Telegram/WhatsApp message or email.