Privacy Policy
1. Data controller
AGAPE INNOVATIONS GROUP INC.
18 King Street East, Suite 1400
Toronto, ON M5C 1C4
Canada
Email: kontakt@hazonlive.com
Corporation incorporated under the laws of the Province of Ontario, Canada. AGAPE INNOVATIONS GROUP INC. is the service provider and the controller within the meaning of Article 4(7) GDPR for the processing of personal data on hazonlive.com.
2. Collection and processing of personal data
We collect personal data when you register, use our services or get in touch with us. This includes:
- Name and email address (on registration)
- Usage data (chat histories, uploaded documents)
- Payment data (processed via the payment service provider Stripe, not stored by us)
- Technical data (IP address, browser, device)
3. Legal bases
Processing is carried out on the basis of:
- Article 6(1)(b) GDPR (performance of a contract)
- Article 6(1)(a) GDPR (consent)
- Article 6(1)(f) GDPR (legitimate interests)
4. Use of artificial intelligence
Hazonlive uses AI models for text generation, document analysis and image generation. The AI providers are listed in detail as processors in section 6. The following applies:
- Your inputs (prompts, conversation histories, image descriptions) are transmitted to the AI providers
- The AI providers (Anthropic, OpenAI) process the data in the USA; the transfer is based on Standard Contractual Clauses pursuant to Article 46(2)(c) GDPR
- In accordance with the providers’ API terms, inputs are not used to train the AI models
- All AI-generated content is labelled as such
- Further information: AI transparency notice
4a. AI-assisted processing of connected email mailboxes
When you connect an email account (e.g. Gmail) to Hazonlive, the platform regularly retrieves incoming messages and processes them with AI: detecting whether a reply is needed, sorting them into categories (e.g. customer enquiry, appointment, invoice, newsletter) and preparing draft replies. The following applies:
- Only the subject line and a shortened message text are transmitted to the AI providers (data minimisation); attachments are not transmitted
- To learn your writing style, selected messages you have sent yourself may be read; a shortened excerpt is passed to the AI providers as a style example within the prompt (not to train the models). We delete these examples as soon as you disconnect the mailbox.
- Nothing is ever sent, deleted or permanently altered automatically — every reply requires your explicit approval (human-in-the-loop), and automatic sorting can be undone at any time
- The legal basis vis-à-vis the senders of your emails is Article 6(1)(f) GDPR (legitimate interest in the efficient handling of incoming business communication); every AI categorisation is stored with a justification and is available for you to view
- Access tokens for your mailbox are stored in encrypted form (AES-256-GCM); content from Google services is used exclusively for the functions described here that are visible to you and is not analysed for advertising purposes (Google API Services User Data Policy, Limited Use)
- Incoming messages are automatically deleted from Hazonlive after 90 days (answered ones after 24 months); your mailbox itself remains unaffected
4b. Use of Google user data (Gmail and Google Calendar)
When you connect a Google account to Hazonlive, we access only the following Google user data and use it solely for the functions described below that are visible to you:
- Incoming Gmail messages (read): retrieved so that your AI assistant can detect whether a reply is needed, sort messages into categories and prepare suitable draft replies. Only the subject line and a shortened message text are transmitted to the AI providers, no attachments (data minimisation).
- Gmail drafts (create): draft replies are stored as drafts in your mailbox. Nothing is ever sent automatically — sending always requires your explicit approval.
- Gmail labels and message filing (manage): Hazonlive creates its own label namespace, applies labels to messages and archives them to organise your inbox. Messages are not permanently deleted without your action.
- Google Calendar events (read and create): when you confirm an appointment (e.g. via telephone reception), Hazonlive adds it to your Google Calendar; existing events are read to check for conflicts.
- Email address of your Google account: used solely to identify the connected account.
Storage, disclosure and retention: access and refresh tokens are stored in encrypted form (AES-256-GCM, see section 5a); processing takes place on servers in the European Union (Frankfurt). Google user data is disclosed only to the processors listed in section 6, to the extent necessary to provide the functions described, and is never used for advertising or to train AI models. This complies with the Google API Services User Data Policy, including the Limited Use requirements. Incoming messages are automatically deleted from Hazonlive after 90 days (answered ones after 24 months); your Google account itself remains unaffected. You can revoke the connection at any time in the settings.
5. Data storage
Master data and usage data are stored on servers in the European Union:
- Database: Supabase (AWS eu-central-1, Frankfurt)
- Hosting: Vercel, deployment region Frankfurt (fra1)
- Transactional emails (login, password reset): Resend (AWS eu-west-1, Ireland)
AI prompts and image descriptions are transmitted for processing to the AI providers in the USA named in section 6 (Standard Contractual Clauses pursuant to Article 46 GDPR). Payment data is processed by the payment service provider Stripe.
5a. Data security
We protect personal data — in particular sensitive content from connected Google services (Gmail, Google Calendar) — through technical and organisational measures pursuant to Article 32 GDPR:
- Encryption in transit: All connections to Hazonlive and between our services are exclusively TLS-encrypted (HTTPS).
- Encryption at rest: Data is stored encrypted in the database (encryption at rest, AWS eu-central-1, Frankfurt). Access and refresh tokens for connected mailboxes are additionally encrypted at the application level using AES-256-GCM.
- Access control and tenant isolation: Access to data is strictly separated by workspace and enforced at the database level through Row Level Security (RLS). Access to your data by our staff occurs only to the extent necessary for operation, support or legal obligations (principle of least privilege).
- Limited use of Google data:Content from Google services is used solely for the functions visible to you described in section 4a, is not disclosed to third parties (other than the processors listed in section 6 for the purpose of providing these functions) and is not used for advertising or to train AI models. This complies with the Google API Services User Data Policy, including the Limited Use requirements.
- Data minimisation: Only the data required for the respective function is transmitted to AI providers (e.g. subject line and shortened message text, no attachments).
- Operations and monitoring: We use access logging and error/stability monitoring to detect security incidents. You can revoke mailbox connections at any time in the settings; revoked tokens become invalid and the associated connection is removed.
6. Processors and disclosure to third parties
We use the following service providers as processors (Article 28 GDPR) or as independent controllers:
Anthropic PBC (Claude)
- Purpose: text AI, AI agents, document analysis, conversation processing
- Data transferred: user prompts, conversation histories
- Server location: USA (SCCs pursuant to Article 46 GDPR)
- Privacy: https://www.anthropic.com/privacy
OpenAI OpCo LLC (GPT-5.5)
- Purpose: text AI, request routing, complex analyses
- Data transferred: user prompts, contextual conversation data
- Server location: USA (SCCs pursuant to Article 46 GDPR)
- Privacy: https://openai.com/policies/privacy-policy
OpenAI OpCo LLC (gpt-image-2)
- Purpose: AI image generation on user request
- Data transferred: image prompts (text descriptions)
- Server location: USA (SCCs pursuant to Article 46 GDPR)
- Privacy: https://openai.com/policies/privacy-policy
- Note: No user images are transmitted to OpenAI, only text prompts for image generation.
Supabase Inc.
- Purpose: database and authentication
- Server location: AWS eu-central-1, Frankfurt am Main
- Privacy: https://supabase.com/privacy
Vercel Inc.
- Purpose: hosting and delivery of the application
- Server location: deployment region Frankfurt (fra1)
- Privacy: https://vercel.com/legal/privacy-policy
Resend (Drip.com, Inc.)
- Purpose: sending transactional emails (sign-up confirmation, password reset, system notifications)
- Data transferred: email address, user name, mail content
- Server location: AWS eu-west-1, Ireland (EU)
- Privacy: https://resend.com/legal/privacy-policy
Functional Software, Inc. (Sentry)
- Purpose: error diagnostics and stability monitoring of the application. With your consent (cookie banner: „Alle akzeptieren“ / “Accept all”) additionally session replay for error analysis — text inputs are masked and media blocked in the process.
- Data transferred: technical error data (browser, device, error message); with consent additionally IP address and masked session recordings
- Server location: USA (SCCs pursuant to Article 46 GDPR)
- Privacy: https://sentry.io/privacy/
Twilio Inc.
- Purpose: telephone reception (incoming calls, call notes) — only relevant if the telephone feature is activated in your workspace
- Data transferred: caller’s phone number, call metadata, where applicable call content/transcripts
- Server location: USA (SCCs pursuant to Article 46 GDPR)
- Privacy: https://www.twilio.com/legal/privacy
Tavily Inc. / Brave Software Inc. (web research)
- Purpose: internet research by the assistants (e.g. lead search, trend research) when a task requires a web search
- Data transferred: search queries derived from your task — in individual cases these may contain personal information (e.g. the name or company of a contact person)
- Server location: USA (SCCs pursuant to Article 46 GDPR)
- Privacy: https://tavily.com/privacy and https://brave.com/privacy/ respectively
Stripe (payment service provider)
- Purpose: technical payment processing (card payment, SEPA direct debit and others) on behalf of the provider
- Data transferred: name, email address, billing address, payment data (PCI-DSS-compliant via Stripe)
- Provider: Stripe, Inc. or the regionally responsible Stripe entity (e.g. Stripe Payments Europe, Ltd.)
- Server location: among others the USA (SCCs pursuant to Article 46 GDPR)
- Privacy: https://stripe.com/privacy
- Note: The purchase contract for paid plans is concluded with the provider (AGAPE INNOVATIONS GROUP INC.); Stripe handles the payment technically. For details, see Terms and Legal notice (Imprint).
7. Your rights
You have the right to:
- Access to your stored data (Article 15 GDPR)
- Rectification of inaccurate data (Article 16 GDPR)
- Erasure of your data (Article 17 GDPR)
- Restriction of processing (Article 18 GDPR)
- Data portability (Article 20 GDPR)
- Objection to processing (Article 21 GDPR)
- Withdrawal of consent given (Article 7(3) GDPR)
To exercise your rights, please contact us at: kontakt@hazonlive.com
8. Cookies and consent
We use technically necessary cookies for authentication. With your consent (“Accept all” in the cookie banner) we additionally enable error diagnostics via Sentry including session replay (see section 6; content is masked). We do not use marketing or advertising cookies. You can change your choice at any time via “Cookie settings” in the footer.
9. Retention period
Personal data is deleted as soon as the purpose of storage no longer applies. On account deletion, all data is deleted within 30 days.
Results of the legal assistant (contract traffic light, GDPR check, DPA draft, legal question) are stored as a history so you can review them again. Only the structured results and metadata are kept, never the full contract or input text. They are deleted automatically after 90 days, and every entry can also be deleted manually at any time.
10. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority.
11. Transfer of data to third countries
Personal data is transferred to the USA in the context of AI processing (Anthropic, OpenAI), error diagnostics (Sentry), web research (Tavily/Brave), telephone reception (Twilio) and payment processing (Stripe). The transfer is based on the Standard Contractual Clauses of the European Commission pursuant to Article 46(2)(c) GDPR, together with supplementary technical and organisational measures of the respective providers.
In addition, the operator AGAPE INNOVATIONS GROUP INC., based in Toronto, Canada, has access to personal data as the controller. This transfer is based on the adequacy decision of the European Commission for Canada (Article 45 GDPR), which applies to commercial organisations subject to the Canadian data protection act PIPEDA.
As of: 13 July 2026.