Privacy Policy

This policy explains how GEKALAB handles personal information across our AI, automation, software, web, consulting, and connected business services, including Google Calendar and Gmail, Microsoft and Outlook, other e-mail providers, AI services, CRM, payment, hosting, and other customer-authorized integrations.

1. About GEKALAB

GEKALAB is a Toronto-based AI, automation, and software agency. We provide consulting and strategy, AI chatbots and voice agents, AI agents and business assistants, workflow automation, CRM and business-system integrations, SaaS and custom software development, websites and web applications, APIs, cloud deployment, and related support. We also operate connected workspace features through chat.gekalab.com.

This Privacy Policy applies to gekalab.com, professional services delivered by GEKALAB, and GEKALAB-hosted services. A customer organization may act as the controller of information it submits, makes available for a project, or processes through its workspace, while GEKALAB processes that information to provide the contracted service. This policy does not replace a customer’s own privacy notices or other agreements that apply to its staff, customers, or end users.

2. Information We Collect

Depending on how you use GEKALAB, we may collect or process:

  • account and business profile details, such as name, work e-mail address, role, company, contact information, and workspace membership;
  • website enquiries and other information you choose to submit;
  • authentication, device, browser, IP address, security, audit, diagnostic, feature-usage, and service-performance records;
  • customer, lead, conversation, booking, calendar, e-mail, knowledge-base, notification, and workflow information;
  • project and consulting information, such as business requirements, operational processes, technical specifications, feedback, deliverables, and support requests;
  • customer-provided materials and authorized system information needed for development or integration work, such as brand assets, website content, documents, datasets, application configurations, repository or environment access, and test data;
  • subscription, billing, transaction-status, and payment-reference metadata, but not complete payment-card details handled directly by a payment processor; and
  • configuration data for integrations a workspace chooses to connect, including OAuth, e-mail, AI, payment, and Telegram settings.

3. Information Submitted Through Our Website

When you use our public contact form, we process the details you submit, which may include your name, e-mail address, phone number, company, selected service, budget or project information, and message. We use this information to respond, understand your request, provide proposals or services, prevent abuse, and maintain appropriate business records.

4. Information Processed Through GEKALAB Services

Professional and project engagements

When GEKALAB provides consulting, design, development, integration, deployment, maintenance, or support, we may process the business requirements, communications, content, technical documentation, authorized credentials or access, source materials, test information, and operational records reasonably needed to perform the engagement. This can involve customer-selected websites, cloud environments, CRM, e-commerce, billing, calendar, communications, databases, APIs, and other business systems. The applicable proposal, order, statement of work, or customer instructions determines the project scope.

Hosted products and connected workflows

A GEKALAB workspace may process business profiles, team-member access, chatbot configuration, customer conversations, leads, enquiries, support handoffs, bookings, e-mail messages and delivery records, automation rules, AI-generated drafts and classifications, uploaded documents and extracted knowledge, analytics, subscription information, and integration settings. The exact data depends on the features the customer enables and the information its users and visitors provide.

5. Google Account and Google API Data

Google access is optional and begins only when an authorized workspace user selects a Google capability and completes Google’s consent process. GEKALAB may receive a Google account identifier, e-mail address, and basic name or profile information where Google provides it. We use this identity information only to authenticate the connection, identify the connected account, and associate it with the correct GEKALAB workspace.

Depending on the capabilities selected, GEKALAB requests openid, basic e-mail/profile identity permissions, calendar.calendarlist.readonly, calendar.events.freebusy, calendar.events, gmail.send, and/or gmail.readonly. Access is limited by the permissions granted through Google and by the capabilities enabled in GEKALAB.

6. Google Calendar Data

When Google Calendar is connected, GEKALAB may:

  • list calendars the connected account can use and let an authorized user select the workspace booking calendar;
  • check free/busy information across the selected calendar to show availability and reduce conflicting or double bookings;
  • create a confirmed appointment event containing booking time, customer name, and relevant booking contact or service details;
  • update or reschedule the synchronized event when the corresponding booking changes; and
  • cancel or delete the synchronized event when the corresponding booking is cancelled or deleted, where that workflow applies.

Calendar access is user-authorized, workspace-scoped, and used for the connected workspace’s booking and scheduling functionality. GEKALAB stores the selected calendar identifier and name, synchronized provider event identifiers, and synchronization status needed to maintain the link between a GEKALAB booking and its calendar event.

7. Gmail Data

Gmail Send

If an authorized user connects Gmail with send access, GEKALAB uses gmail.send to send business communications initiated, approved, or configured by that workspace. These may include user-composed e-mails, replies, booking confirmations and reminders, and approved or automation-enabled follow-up messages. GEKALAB does not use this permission to send arbitrary messages unrelated to the workspace’s configured business workflows.

Gmail Read-Only

If an authorized user separately grants gmail.readonly, GEKALAB may list messages in the connected inbox and retrieve message content to synchronize it into the GEKALAB E-Mail workspace, display messages, identify replies, correlate threads, and provide context for user-facing reply and follow-up functionality. Stored records may include provider message and thread identifiers, message headers, sender and recipient details, subject, text or HTML body, received time, and read state.

gmail.readonly does not itself allow GEKALAB to modify, archive, delete, or send Gmail messages. Sending requires the separately authorized gmail.send permission. GEKALAB’s interface may let a user manage the copy synchronized into GEKALAB; that does not modify the original Gmail message through the read-only permission.

8. How We Use Google User Data

GEKALAB uses Google user data only to:

  • establish, maintain, refresh, display, and secure the connection selected by an authorized user;
  • provide the Calendar, Gmail, booking, inbox, reply, notification, and follow-up features described above;
  • troubleshoot, protect, and improve those user-facing features; and
  • comply with applicable law, enforce agreements, or protect users and the service when necessary.

Google user data is not used for advertising, sold, or used to build marketing profiles unrelated to the requested GEKALAB functionality.

9. AI Processing and Google Workspace Data

GEKALAB includes AI-assisted features such as message classification, follow-up drafting, reply drafting, chatbot responses, and knowledge retrieval. When a user invokes or enables one of these features, the minimum relevant context may be sent securely to the workspace’s configured AI service provider. Depending on the feature and workspace settings, this can include a message subject and body, a limited portion of recent message or conversation history, previous sent-message context, lead and business details, booking context, user instructions, and relevant excerpts from selected knowledge documents.

Inbound replies may be classified automatically when a workspace has enabled an e-mail sequence or follow-up workflow. AI-generated reply suggestions are stored as drafts for human review and are not sent by the drafting operation itself. Other follow-up messages may be sent only according to the workspace’s configured and authorized automation rules and safety controls.

GEKALAB does not use Google Workspace API data to develop, improve, or train generalized or non-personalized AI or machine-learning models. Google Workspace data is not sold or used for advertising. GEKALAB processes it only as necessary to provide or improve the user-facing feature requested or enabled by the customer. AI providers act as service providers for the request; their own data handling is governed by the applicable service configuration and contractual terms.

10. Google API Services User Data Policy

GEKALAB's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Consistent with Limited Use, Google user data is used only to provide or improve prominent, user-facing features; transfers are limited to service providers necessary to provide those features, security purposes, legal compliance, or a business transfer where the user has appropriate notice and protections.

11. Microsoft / Outlook Data

If a workspace connects a Microsoft account, GEKALAB may receive basic Microsoft account details and, depending on the permissions selected, access Outlook calendars, send e-mail, and read inbox messages. GEKALAB uses Microsoft calendar data for availability and booking-event synchronization, Microsoft send access for authorized business messages, and read access for inbox synchronization, reply identification, display, and related user-facing workflows. Microsoft OAuth access and refresh tokens are protected in the same manner as Google connection tokens.

12. Other E-Mail Providers (SMTP / IMAP)

A workspace may configure SMTP for outbound mail and IMAP for inbound-mail synchronization. GEKALAB stores the server and account configuration needed for the connection and encrypts stored passwords or secret configuration. IMAP synchronization may store the same categories of message metadata and content described for Gmail. Outbound delivery and sent-message records may include recipients, subject, message content, delivery status, timestamps, and provider identifiers. E-mail is also processed by the customer’s selected mail provider when it is retrieved or delivered.

13. Chatbot, Conversation, Lead and Booking Data

GEKALAB may process chatbot messages, session identifiers, contact details, support-handoff messages, lead source and qualification information, internal assignment/status data, booking requests and confirmed appointment details, service selections, consent or unsubscribe status, and customer communications. Workspaces may also upload documents for a knowledge base; GEKALAB stores the source files, extracted text and chunks, and vector representations used to retrieve relevant passages. Telegram chat identifiers, bot credentials, delivery status, and notification content are processed only when a workspace configures Telegram notifications.

14. How We Use Information

We use information to understand and respond to enquiries; assess requirements; prepare proposals; plan, design, develop, configure, integrate, test, deploy, maintain, and support customer solutions; provide, operate, secure, and improve GEKALAB-hosted services; authenticate users; manage workspaces and permissions; deliver connected integrations and communications; process subscriptions and record payments; monitor reliability and abuse; enforce terms; and meet legal obligations.

15. Service Providers / Data Processors

Data may be processed by providers that support normal GEKALAB operations, but only as needed for their services. These may include Google for Google account, Gmail, and Calendar connections; Microsoft for Microsoft 365 and Outlook connections; configured AI providers such as OpenAI or Google Gemini for requested AI functionality; Cloudflare for network, security, and backup-object storage services; Contabo and other hosting infrastructure used to run the service; the customer’s selected SMTP, IMAP, notification, or e-mail provider; and a configured payment processor for subscriptions or customer payment workflows. The provider involved depends on the feature and configuration selected by the customer or GEKALAB for the service.

16. Data Sharing and Disclosure

We may disclose information to authorized members of the relevant workspace; to service providers and connected platforms needed to perform the requested service; to professional advisers; when required by law, court order, or a valid governmental request; to investigate fraud, security, abuse, or threats to rights and safety; or in connection with a merger, financing, reorganization, or sale of assets, subject to appropriate notice and safeguards. Providers receive only the information reasonably necessary for their role. We do not disclose customer data to advertisers.

17. Sale of Personal Information

GEKALAB does not sell personal information. We do not sell Google user data or share it for cross-context behavioral advertising.

18. Data Security

GEKALAB uses reasonable technical and organizational safeguards appropriate to the service, including encrypted transport, encrypted OAuth tokens and stored integration credentials, access controls, workspace and tenant scoping, restricted administrative access, private service networks, monitoring, secure server infrastructure, and backups. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.

19. Data Storage

Core account, workspace, customer, booking, message, configuration, and operational records are stored in protected application databases. GEKALAB currently uses PostgreSQL for durable application records, Redis for limited queue, session, caching, and rate-control state, and Qdrant for workspace-scoped vector representations used by knowledge retrieval. Uploaded knowledge files and generated service data are stored in protected application storage. Encrypted backup archives may be stored in Cloudflare R2. These storage systems are not exposed as public customer databases.

20. Data Retention

We retain personal information only for as long as reasonably necessary to provide the service, maintain business and transaction records, meet legal obligations, resolve disputes, enforce agreements, preserve security and audit evidence, and support legitimate operations. Retention varies by data category and workspace configuration. For example, synchronized e-mail, conversation, lead, booking, delivery, and knowledge records generally remain while the relevant workspace or service record remains active unless they are deleted through an available workflow or a valid deletion request is completed. We do not claim a fixed deletion period where the product does not enforce one.

21. Backups

GEKALAB maintains encrypted, access-controlled backups for resilience and recovery. The current application backup process uses a short rolling retention configuration, generally limited to seven days and seven versions. Actual aging may vary because of backup success, restoration testing, legal holds, or operational recovery requirements. Data removed from active systems may remain in an existing backup until that backup is overwritten or expires and is not restored except for disaster recovery, security, or legal needs.

22. Account Disconnection and OAuth Revocation

An authorized workspace user can disconnect a Google or Microsoft connection in GEKALAB. A full disconnect stops future API use through GEKALAB, attempts provider revocation where supported, clears the locally stored access and refresh tokens, and marks the connection disconnected. GEKALAB also supports capability-level disconnects, such as disabling e-mail send, e-mail read, or calendar use while preserving other capabilities on the same provider connection. Disabling a capability stops GEKALAB from using that capability, but does not necessarily reduce the permissions already granted at the provider while other capabilities remain connected.

Google users can also revoke GEKALAB through the third-party access controls in their Google Account. Revocation or disconnection stops future access but does not automatically erase records already synchronized into GEKALAB, booking records, sent-message records, logs, or backups. Those records are handled under the retention and deletion terms in this policy.

23. Data Deletion Requests

To request access to, correction of, or deletion of personal information associated with GEKALAB, contact support@gekalab.com. Please identify the relevant account, workspace, or e-mail address and provide enough information for us to verify authority and locate the data. Workspace and user deletion can also be completed by authorized GEKALAB platform administrators after ownership, legal, billing, and security requirements are addressed. Deletion removes applicable active records and associated workspace data, subject to information we must keep for legal, security, fraud-prevention, dispute, transaction, or backup purposes.

24. User Rights

Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent, and to complain to a data-protection authority. These rights may be limited by law and by GEKALAB’s role as a processor for a customer. If your information was submitted to a customer’s workspace, we may direct the request to that customer. We will not discriminate against you for exercising an applicable privacy right.

25. International Processing

GEKALAB and its service providers may process information in countries other than the country where you live. Privacy laws may differ in those locations. Where required, we use appropriate contractual, organizational, or other safeguards for international transfers.

26. Children’s Privacy

GEKALAB’s business services are not directed to children under 13, or a higher minimum age where required by local law. We do not knowingly collect a child’s personal information through our own account-registration or marketing activities. If you believe a child has provided personal information improperly, contact us so we can investigate and take appropriate action.

27. Changes to This Privacy Policy

We may update this policy as GEKALAB’s services, integrations, or legal obligations change. We will post the revised policy at this URL and update the date above. We may provide additional notice when a change is material and applicable law requires it.

28. Contact Us

For privacy questions or requests, contact:

GEKALAB Privacy Support
44 Watson St
Toronto, Ontario M1C 1E3
Canada
E-mail: support@gekalab.com
Phone: +1 332 263 1078