This policy covers the AIRON platform — the application that customer companies use to work with their agents — and not the public website, which has its own separate privacy policy.
1. Who processes the data, and in what role
AIRON TEAM SL («AIRON»), registered office at Plaza Mayor 23, 1.º A, 47001 Valladolid, España. Tax ID: En trámite de asignación (sociedad de reciente constitución).
- AIRON acts as processor (Art. 28 GDPR) for the data each customer company brings into the platform: emails, invoices, CRM records, documents, messages. The controller is the customer company, which decides the purposes and means. The framework for that relationship is the data processing agreement.
- AIRON acts as controller only for its own account data: identification of the users, billing of the service, security and the audit log.
No Data Protection Officer has been appointed, as none of the cases in Art. 37 GDPR applies. The internal privacy lead is the management of AIRON TEAM SL. Contact: privacidad@airon.team — if you get no reply, please also write to info@airon.team.
2. What data is processed
- Identification and contact: name, email, phone, role, company.
- Commercial and billing: invoices, amounts, line items, due dates and possible bank details.
- Communication content: email bodies and subjects, attachments, WhatsApp and Instagram messages.
- CRM data: company and person records, commercial activity, notes.
- Marketing and analytics: campaign metrics, aggregated audiences, search queries.
- Voice: transient call audio and its transcripts.
- Usage metadata: access logs, actions, IP addresses, session identifiers.
The service is not designed to process special categories of data (Art. 9 GDPR). However, because it synchronises mailboxes, such data may appear incidentally inside a message. This is a circumstance the customer, as controller, must weigh in its own risk assessment.
3. Purposes
Solely to provide the contracted service and the features the customer activates: reading and organising the connected sources, drafting replies, proposing actions, generating documents and sites, answering users’ questions and keeping the audit trail. AIRON does not process customer data for its own purposes, nor to build commercial profiles, nor to train its own or third-party models.
4. Artificial intelligence and human review
- You know you are talking to an AI. In accordance with Art. 50 of Regulation (EU) 2024/1689 (the AI Act), the platform displays a permanent notice in the chat and on the other surfaces, and AIRON records the evidence of that notice. AIRON is a provider of a limited-risk AI system.
- Generated content is marked. Generated PDFs and websites embed metadata identifying them as AI-generated content.
- Nothing is sent automatically without approval. No email or WhatsApp message to a third party goes out on its own: it requires explicit approval by a person. Where a customer exceptionally configures an automatic reply, the message says so in its footer.
- No automated decisions under Art. 22 GDPR. The platform makes no decisions based solely on automated processing that produce legal or similarly significant effects.
- Limitations. Generative models can produce inaccurate content. The platform does not replace human verification of what is communicated to third parties.
5. Sub-processors
To provide the service AIRON relies on the providers listed below, under the customer’s general authorisation and with 30 days’ notice of any change. The always-current version, with its change log, is the sub-processor list.
| Provider | Entity and country | Function | Status |
|---|---|---|---|
| OpenAI | OpenAI, L.L.C. — United States | Language-model inference: prompts, contexts (fragments of email, invoices or CRM) and generated outputs. | In use |
| Alibaba Cloud | Alibaba Cloud — Singapore | Qwen model endpoint listed in the catalogue, disabled and not assigned to production. | Not in use (disabled) |
| Groq | Groq, Inc. — United States | Fallback inference. It would receive prompts and contexts only if activated. | No traffic |
| NVIDIA | NVIDIA Corporation — United States | Hosted-model inference (NIM). It would receive prompts and contexts only if activated. | No traffic |
| ElevenLabs | ElevenLabs — United States | Speech synthesis: the text to be voiced and, where applicable, reference audio. | Subject to customer activation |
| RunPod | RunPod — United States | On-demand GPU compute: the optional “AIRON (Qwen3.5-27B)” mode of the Assistant, enabled only for pilot accounts, and occasional training of our own search models with queries from pilot customers. | Limited use (pilot) |
| Meta (WhatsApp e Instagram) | Meta Platforms Ireland Ltd. — Ireland (with processing also in the United States) | WhatsApp Business and Instagram messaging: messages, phone numbers and contact identifiers. | Subject to customer activation |
| Google Ireland Ltd. — Ireland (part of the processing by Google LLC, United States) | OAuth sign-in, Gmail, Drive, Calendar, Google Ads, GA4, Search Console, YouTube and Business Profile: email content, files, events, metrics and audiences. Since 19 September 2026, Google Cloud Vertex AI (europe-west3, Frankfurt) computes the search embeddings: it receives the text of indexed fragments and of queries. | In use, subject to customer activation | |
| Microsoft | Microsoft Ireland Operations Ltd. — Ireland | Microsoft 365, OneDrive and Outlook: email content, files and calendar. | Subject to customer activation |
| Twilio | Twilio Ireland Ltd. — Ireland / Twilio Inc. — United States | Telephony and voice: phone numbers, call audio and call metadata. | Subject to customer activation |
| IONOS | IONOS SE — Germany | Server hosting: all the platform’s infrastructure, databases and files. | In use |
| GitHub | GitHub, Inc. (Microsoft) — United States | Export of websites built with Web Studio to the customer’s own repository. | Subject to customer activation |
| Telegram | Telegram (Bot API) — contracting entity being determined | Internal operator messaging channel: operator messages and chat identifiers. It is not used to communicate with third parties. | In use (internal) |
| Stripe | Stripe Payments Europe Ltd. — Ireland / Stripe, Inc. — United States | AIRON’s own billing to its customers: contact and payment data. In this processing AIRON acts as controller, not as processor. | Limited use (own billing) |
The embeddings of indexed documents are generated with Google Cloud Vertex AI in the europe-west3 region (Frankfurt, Germany), with Google acting as sub-processor: document content does not leave the European Union in order to be vectorised.
6. Where data is processed, and international transfers
The infrastructure, databases and files live on a server in Frankfurt am Main (Germany, EU). Language-model inference takes place in the United States. Every transfer outside the European Economic Area relies on the safeguards of Chapter V GDPR: the EU-US Data Privacy Framework where the provider is certified, or the Standard Contractual Clauses of Implementing Decision (EU) 2021/914, Module 3, together with any necessary supplementary measures. The per-provider detail is in the sub-processor list.
7. How long data is kept
| Category | Period |
|---|---|
| Chat history and messages with the agents | 24 months from the last message in the thread |
| Prompts, contexts and reasoning traces | 90 days |
| Feedback on the agents’ answers | 12 months |
| Record of lessons learned from usage | 550 days |
| Synchronised emails and their attachments | For as long as the mailbox connection lasts, plus 30 days after disconnecting it |
| Documents and fragments indexed for search (RAG) | Until the source is removed or the connector is disconnected |
| Voice audio | 24 hours: deleted once transcribed |
| Voice transcripts | 30 days |
| Audit log (access and actions) | 3 years |
| AI compliance evidence | 3 years |
| Encrypted backups | 30 days |
Effective deletion = period + 30 days. When a period expires, the data stops being reachable from the application, but it remains in the encrypted backups until those expire. Promising you instant deletion would be untrue.
These are the periods approved by management on 2 September 2026. Some are already enforced automatically and others are being rolled out progressively; in the meantime deletion is carried out on request and as part of account closure. You can ask for the roll-out status at privacidad@airon.team.
8. Data subject rights
If your data is in the platform because a customer company brought it in (you are one of its contacts, customers or suppliers), your counterpart is that company, not AIRON: it is the controller. If you contact us, we will not answer on the merits and will forward your request to the controller within a maximum of 3 working days, assisting it so that it can answer within its own one-month deadline.
You may exercise the rights of access, rectification, erasure, restriction, objection and portability, as well as withdraw consent and not be subject to automated decisions. You may also lodge a complaint with the Spanish Data Protection Agency (AEPD), www.aepd.es.
For extraction of your data in an open format, see portability and switching providers.
9. Security
TLS 1.2 and 1.3 on every public endpoint, encrypted secrets and tokens, databases listening only on localhost, default-deny access control, tenant segregation applied in enforcing mode, an audit log, and encrypted off-machine backups with a tested restore. The full summary — with the gaps declared — is in security measures. In the event of a breach affecting you, AIRON notifies the customer controller without undue delay, aiming not to exceed 48 hours.
10. Messaging channels and Colombia
If you write to us on WhatsApp, Instagram or Telegram addressing a business that uses AIRON, see the messaging privacy notice. If you are in Colombia, the Personal Data Processing Policy (Colombia) applies in parallel, under Law 1581 of 2012.
11. Google user data
When a person connects their Google account, AIRON requests only the permissions of the service they turn on, and uses them solely for the features that person sees and controls in the platform:
- Gmail (read and send): synchronise the connected mailbox so the agents can summarise it, search it and prepare draft replies; send an email only when the person approves it.
- Google Drive: search and read the customer’s documents to answer from them, and save the documents the person asks to generate.
- Google Calendar: check the calendar and create or change events when the person asks.
- Google Analytics, Search Console, Google Ads, YouTube and Business Profile: read metrics for marketing reports and analysis; in Google Ads and Business Profile, apply changes or reply to reviews only with approval.
- Identity (account email): show which account each service is connected with.
AIRON’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- Google data is used only to provide and improve the user-facing features described above;
- it is not sold, and it is not used for advertising, to determine creditworthiness or for lending purposes;
- it is not used to develop, improve or train generalised AI or machine-learning models, whether our own or third parties’;
- it is transferred to third parties only as necessary to provide those features (the sub-processors in section 5, for example the language-model provider that writes a draft), to comply with the law, or as part of a merger or acquisition with prior notice;
- AIRON staff do not read it, except with the person’s explicit consent for specific items, for security purposes (for example investigating abuse), to comply with the law, or when the data has been aggregated and anonymised for internal operations.
You can revoke access at any time by disconnecting the service in the platform or from your Google account permissions. After disconnection the periods in section 7 apply; for immediate deletion, write to privacidad@airon.team.
12. Changes
We will update this policy whenever the product, the providers or the applicable law change. Material changes are notified to customers 30 days in advance, and the version in force is always the one published here.