Privacy Policy
Effective date: 26 August 2026
This Privacy Policy explains how Performance Labs SL processes personal data when you visit the My AI Employee websites, create an account, use the My AI Employee accounting SaaS, submit documents through Captura links, contact us, or use our billing flows.
1. Roles And Privacy Contact
Performance Labs SL, VAT ID ESB56217169, Paseo de la Castellana 194, Planta baja, Puerta B, 28046 Madrid, Spain, is the controller for its own website, account, contracting, billing, fraud-prevention, legal-compliance, and service-security processing.
When an accounting firm or other organization uses My AI Employee for its own clients, documents, communications, and workflows, that organization determines the purposes and legal basis for that client/workflow data. Performance Labs SL processes that data on the organization's documented instructions to provide the service, except for the narrow separate-controller purposes described above.
Privacy contact: ruben@performancelabs.net.
2. What My AI Employee Does
My AI Employee is a supervised software service for accounting firms and similar professional teams. It helps collect client documents, organize review queues, identify document facts, track missing items, file approved originals, prepare supervised follow-ups, and provide document and factual-data downloads.
My AI Employee does not file taxes, submit official accounting records, give legal or tax advice, or replace professional review. Users remain responsible for checking all outputs before using them.
3. Data We Process
Depending on how the service is used, we may process:
- Account data: name, email, login credentials, authentication events, organization membership, roles, preferences, and support communications.
- Organization data: firm name, slug, workspace settings, team members, billing status, subscription plan, usage limits, and audit-relevant operational events.
- Client and contact data entered by users: client names, emails, internal references, folder labels, client checklists, and related workflow notes.
- Accounting documents and files: invoices, receipts, bank statements, uploaded documents, metadata, extracted text, review status, export data, and related processing results.
- Captura upload data: public upload tokens, uploaded files, upload status, client association, device/browser metadata, and optional notes submitted by the uploader.
- Email-source data where enabled: mailbox connection metadata, message headers, sender information, subjects, body snippets, attachments, synchronization status, and UID cursors needed to avoid duplicate processing.
- WhatsApp Business data where enabled: the customer-owned or customer-selected WhatsApp Business Account, business portfolio, and phone-number identifiers; encrypted authorization token and registration PIN where required; webhook, registration, template, payment-readiness, and connection status; sender and recipient phone numbers; sender profile-name snapshot; inbound message text, captions, images, documents, filenames, media metadata, checksums, and timestamps; outbound recipient, message body, Utility-template name/version/language/parameters, private-link reference, and send mode; delivery, read, failure, conversation, pricing, and error identifiers; client-matching and reply-correlation results; permission and revocation evidence;
STOPopt-out evidence; and review and audit status. - Telegram data where enabled by an organization: encrypted bot credentials; bot, chat, user, update, message, and file identifiers; Telegram username and display-name snapshots; message text, captions, images, documents, file metadata, timestamps, connection and delivery status, client association, and review status.
- AI processing data: prompts or structured inputs derived from uploaded documents, model outputs, confidence signals, extracted fields, and human review decisions.
- Billing data: Stripe customer identifiers, subscription status, plan, billing address, tax identifiers where provided, invoice metadata, payment status, and portal events.
- Website and analytics data: IP-derived technical data, pages visited, referrer, campaign parameters, consent status, and optional advertising/analytics identifiers when you accept optional cookies.
- Security and diagnostic data: IP address, user agent, device/browser information, request logs, error logs, and abuse-prevention signals.
- Operational support data: normalized authenticated page routes, important account and workspace actions, quota decisions, processing status and timing, AI model usage, internal correlation identifiers, and administrator access to investigation views. We do not intentionally place document contents, credentials, cookies, or authorization tokens in these operational events.
Captura mobile app submissions may include the QR or link token used to connect the app, scanned images or PDFs, optional notes, and upload metadata such as platform, source, document count, and user agent.
For Telegram, the organization connects a bot that it controls and gives each selected client a time-limited personal invitation. The bot shows the client a short notice when the connection starts, and the organization must confirm the client before messages or documents enter the service. We record the version, user, and time of the organization's channel acknowledgement. That acknowledgement records the organization's configuration decision; it is not presented as the client's consent or as the organization's legal basis under the GDPR.
For WhatsApp Business, the organization connects a WABA and business number that it owns or is authorized to manage. The organization contracts with Meta for the messaging transport and configures Meta billing directly. Incoming messages and supported media can enter Captura. Every outbound message uses recorded permission for the exact number and purpose and an approved Utility template. The organization may send reviewed operational document requests or enable configured automatic follow-ups. Sensitive documents should be uploaded through the private, expiring portal link rather than attached to an outbound WhatsApp message.
The organization must inform affected clients, choose and document an appropriate legal basis, record the permission or other messaging authorization required for the exact number and purpose, honor objections and STOP, and keep a reasonable alternative channel available. A permission record in My AI Employee documents the organization's operational evidence; it does not by itself decide whether GDPR consent is the correct legal basis.
Do not upload special-category data unless it is strictly necessary for the accounting workflow and your organization has a lawful basis to process it.
Connected Google Workspace Mailboxes
When a user chooses Continue with Google, My AI Employee requests the Google account's email address, read-only access to Gmail messages, and permission to send email from that Gmail account. We use that access only to provide the connected-mailbox features that the user and organization select: identifying the connected mailbox, collecting relevant client emails and attachments into visible document workflows, preventing duplicate collection, and sending reviewed or configured operational document requests and reminders from the connected address. My AI Employee cannot use this access to delete, move, alter, or mark existing Gmail messages as read.
We store encrypted OAuth connection credentials, synchronization cursors, relevant message metadata and body content, attachments, and the document or communication records created from them. Google Workspace data may be processed by the infrastructure, storage, security, and AI-processing providers described in this Policy only when necessary to provide or secure these visible user-facing features and on the organization's instructions. We do not sell Google Workspace data, use it for advertising, use it to determine creditworthiness, or use it to train or improve a general-purpose or shared AI model.
Human access to Google Workspace data is prohibited except with the user's specific consent for support, when necessary for security or abuse investigation, when required by law, or when the data has been aggregated and de-identified for permitted internal operations. The use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Users can stop future Google access at any time by removing My AI Employee from their Google Account third-party connections. Stopping provider access does not automatically delete documents or communication records already collected into the organization's workspace. The organization or user can request deletion of the connection credentials and related stored data by following our Data Deletion Instructions. Existing records are then handled under the retention and deletion rules below, including any legal, security, dispute, or protected-backup limitations that apply.
4. Purposes And Legal Bases
We process personal data for these purposes:
- To provide the service, authenticate users, manage organizations, process uploads, generate review outputs, and support document and factual-data downloads. Legal basis: performance of a contract or pre-contractual steps.
- To manage billing, subscriptions, invoices, tax collection, and payment-related support. Legal basis: performance of a contract and legal obligations.
- To protect the service, prevent abuse, maintain security, debug incidents, and keep audit-relevant logs. Legal basis: legitimate interests and, where applicable, legal obligations.
- To respond to contact, support, and sales requests. Legal basis: consent, pre-contractual steps, or legitimate interests depending on the request.
- To send service notifications, onboarding messages, and important account or billing communications. Legal basis: performance of a contract and legitimate interests.
- To receive inbound WhatsApp messages and media, route them into the organization's Captura workflow, prepare or send operational document requests through approved Utility templates to numbers and purposes with recorded permission, maintain private request links, and record delivery, reply, permission, and opt-out evidence. For client/workflow data, Performance Labs acts on the organization's instructions; the organization determines the applicable legal basis.
- To improve the product, measure feature usage, and understand conversion funnels. Legal basis: legitimate interests for aggregated operational analysis, and consent for optional analytics or advertising cookies where required.
- To comply with legal, tax, accounting, consumer, and regulatory duties. Legal basis: legal obligations.
5. Data Uploaded By Organizations
When an organization uploads or receives documents from its own clients, the organization is responsible for ensuring it has the necessary authority and legal basis to collect and process those documents. Performance Labs SL processes that data to provide My AI Employee, following the configuration and instructions of the organization, except where we must process data for our own legal, security, or billing obligations.
Organizations should inform their own clients that they use My AI Employee or similar processors when required by applicable data protection law.
An organization that enables WhatsApp Business must also tell affected clients that Meta/WhatsApp provides the external messaging network, that messages and media pass through that provider before entering the organization's My AI Employee workspace, that every outbound message uses an approved Utility template and permission for the exact number and purpose, how to opt out, and how to use a non-WhatsApp alternative. Removing or disconnecting the channel does not automatically erase messages, documents, or audit evidence already received into the workspace.
An organization that enables Telegram must inform clients that Telegram will independently process and may cloud-store content sent through that channel under Telegram's own terms and privacy information. The organization must decide when Telegram is appropriate, establish the necessary legal basis, and keep an alternative submission channel available. A client can stop the product connection through the bot, but should contact the organization if the client also wants the organization to erase or restrict copies already received into its workspace.
6. AI Processing
My AI Employee may use AI models and related providers to extract, classify, summarize, or suggest structured accounting information from documents and workflow context. AI outputs can be incomplete or incorrect and must be reviewed by a qualified person before use.
We design the service so AI processing supports supervised workflows. We do not intentionally use customer documents to train public foundation models unless a provider agreement or product configuration explicitly allows it and the customer has been informed.
7. Recipients And Processors
We may share personal data with service providers that help operate My AI Employee, including hosting, database, file storage, email delivery, authentication, analytics, AI processing, payment processing, tax calculation, logging, and customer support providers.
The main categories include EU-region application and database hosting, Cloudflare R2 for document storage, Google Cloud Vertex AI for configured AI inference, Backblaze B2 for encrypted backups, Stripe for billing and tax-aware payment flows, and email, authentication, analytics, security, logging, or operational providers where enabled. The applicable data processing agreement and subprocessor register identify the providers used for customer-data processing and their functions.
When an organization connects WhatsApp Business, Meta/WhatsApp is the customer-selected external messaging provider and recipient of the account, message, media, template, delivery, and related technical data needed to provide that channel. The customer owns or controls the connected WABA, accepts the applicable Meta terms, and pays Meta's transport charges directly. The exact Meta legal entity, role, processing locations, transfer mechanism, and contractual chain depend on the customer's account and the Meta product terms accepted for that connection. We therefore do not categorically describe Meta as Performance Labs' Article 28 subprocessor or as an independent controller without that customer-specific mapping.
When an organization enables Telegram, Telegram independently operates the messaging network and receives, transmits, and may cloud-store the bot, account, message, and file data required for that channel. Telegram applies its own terms and privacy information to that processing. We do not describe Telegram as our Article 28 subprocessor in this Policy because the applicable role and contractual chain for this optional channel have not been established as such.
Cloudflare R2 buckets used to store production accounting documents are configured with the European Union jurisdictional restriction. Cloudflare states that this restriction ensures objects in those buckets are stored and processed within the European Union. The restriction applies to the R2 objects in those buckets; other processing by the providers described in this Policy may occur in other locations as explained below.
AI requests for the configured accounting-document workflows are sent directly to Google Cloud Vertex AI through its European Union multi-region endpoint. This constrains the machine-learning processing location for that route. It does not mean that all provider metadata, security logging, support access, subprocessors, or retention are necessarily limited to the EU or subject to zero retention.
Backup files in the Backblaze design are encrypted by pgBackRest before upload and stored in the B2 EU Central account region, which Backblaze currently documents as Amsterdam. Backblaze is headquartered in the United States. The EU Central statement concerns stored customer files; it does not mean that account metadata, billing, support, security operations, personnel access, or onward subprocessors are exclusively EU-based.
We may also disclose data when required by law, to protect rights and security, in connection with a corporate transaction, or with your instructions.
8. International Transfers
Some providers may process data outside the European Economic Area. Where this occurs, we rely on appropriate safeguards such as European Commission adequacy decisions, Standard Contractual Clauses, data processing agreements, provider security commitments, or other lawful transfer mechanisms.
The transfer mechanism used for each relevant provider is recorded in the applicable contractual and subprocessor documentation. A storage-region configuration does not by itself mean that all account, support, security, personnel, or onward-provider processing is limited to that region.
Meta/WhatsApp's messaging infrastructure, support, security, and onward-provider processing may involve access or processing outside the EEA. Before enabling WhatsApp, the organization and Performance Labs must record the applicable Meta entity, terms, role, locations, and transfer safeguards for the connected customer account. Meta's public Technology Provider Terms, Data Processing Terms, and Global Data Transfer Addendum were accessed on 2 August 2026; the applicable in-account terms control if they differ.
Telegram's infrastructure and support processing may involve countries outside the EEA. Its locations, transfer mechanisms, and retention are governed by Telegram's own applicable terms and privacy information. Organizations should take that separate processing into account before enabling the channel and should offer clients a non-Telegram alternative.
9. Retention
We keep personal data only for as long as needed for the purposes above:
- Account and organization data: while the account or organization is active, and for a reasonable period afterward for support, audit, and legal purposes.
- Accounting documents and workflow data: while the organization keeps them in the service. An expired no-card trial is retained in read-only mode for 90 days, with deletion warnings around days 60 and 83, then its workspace documents and extracted data are permanently deleted. Account, organization membership, billing/consent records, and minimal audit history may be retained for their separate purposes.
- WhatsApp connection data held by My AI Employee: while the connection remains active or for the limited period needed to complete disconnection, security checks, and deletion. Disconnecting removes the saved authorization token and registration PIN and stops future product access after the provider-side revocation or unsubscription completes. Archiving or pausing a source is not deletion.
- WhatsApp messages, media, outbound bodies, delivery records, and workflow evidence held by My AI Employee: under the same retention and deletion rules as the related accounting documents and workflow. Permission, revocation,
STOP, provider-acceptance, and minimum delivery evidence may be retained separately for the period needed to honor opt-outs, demonstrate authorized use, resolve disputes, and meet applicable contractual or legal recordkeeping duties. - Private document-request links: until their configured expiry, earlier revocation, closure of the related review, or deletion of the related client/workflow data. The current default expiry is up to 30 days.
- Telegram channel data held by My AI Employee: bot credentials are removed when the organization disconnects the bot, and unused invitations and active client connections are revoked. Messages, files, delivery records, and audit evidence already received into the workspace remain under the same retention and deletion rules as the related accounting documents and workflow data. Disconnecting the integration does not delete copies that Telegram may retain under its own rules.
- Billing, invoice, and tax records: for the legally required retention period.
- Security logs: for a limited period appropriate to detect abuse, investigate incidents, and protect the service.
- Operational support and detailed AI-usage events: up to 13 months. Full IP addresses and raw user agents in this event history are removed after 30 days, while coarse network or country information may be retained for the remainder of that period.
- Marketing and cookie data: until consent is withdrawn, the cookie expires, or the data is no longer needed.
Deletion may be delayed where retention is required for legal claims, tax/accounting obligations, security investigations, backup integrity, or compliance duties. Deleted customer data may remain temporarily in encrypted, access-restricted backup copies. Those copies are used only for security and disaster recovery, expire under the documented backup-retention schedule, and have applicable deletion records reapplied if restored before ordinary use. The contractual retention and deletion schedule states the period applicable to the service version accepted by the organization.
10. Your Rights
Under applicable data protection law, you may have the right to access, rectify, erase, restrict, object to processing, request portability, withdraw consent, and object to automated decision-making where applicable.
To exercise your rights, contact ruben@performancelabs.net. We may need to verify your identity and, for organization-controlled data, coordinate with the organization that controls the workspace.
Step-by-step instructions are available on our Data Deletion Instructions page.
You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) or another competent supervisory authority.
11. Cookies
We use cookies and similar technologies for authentication, locale selection, consent management, security, attribution, analytics, and advertising where enabled. See our Cookie Policy for more information.
12. Security
We use technical and organizational measures intended to protect personal data, including access controls, tenant scoping, secure authentication, encrypted transport, restricted operational access, and audit-oriented processing patterns. No system is completely secure, and users are responsible for managing their own credentials and team access.
13. Changes
We may update this Privacy Policy to reflect product, provider, legal, or operational changes. The updated version will be published on this page with a new effective date when appropriate.