This Privacy Policy explains what personal data Gmelius collects, how we use it, and the rights you have. It covers our website, our applications, and our AI assistants and agents, and explains how it works together with our Data Processing Addendum for business customers.
1. Who we are and what this Policy covers
Gmelius SA ("Gmelius", "we", "us") is a Swiss company (CHE-411.148.873) headquartered in Geneva, Switzerland. We provide a collaboration and AI platform for Google Workspace, including shared inboxes, workflow automation, and AI assistants and agents (collectively, the "Services").
Two roles. We process personal data in two capacities, and different rules apply to each:
- As a processor, on behalf of our customers. The content of your emails, drafts, attachments, calendar events, Google Drive files, data from connected third-party applications, and any other content that your organisation and its users make available through the Services ("Customer Content") is processed on the instructions of the organisation that subscribed to the Services (the "Customer"). The Customer is the controller of Customer Content. Our processing of Customer Content is governed by our Data Processing Addendum ("DPA") and, where signed, our HIPAA Business Associate Agreement. If you are a user of the Services within a Customer organisation, please direct questions about Customer Content to your organisation.
- As a controller, for our own purposes. We determine how we process the personal data described in Sections 2 and 3 below: account and identity data, billing data, usage data, support and marketing communications, and website data. This Policy governs that processing.
Where this Policy and the DPA both address Customer Content, the DPA prevails for Customers who have accepted it.
2. Personal data we collect
Account and identity data
- Name, email address, profile picture or Gravatar
- Timezone and language preferences
- Gmail signatures and aliases; list of Gmail labels and Google calendars
- Gmelius configuration (subscription details, templates, notes, boards, automation rules, agent configurations)
- Thread, draft and message identifiers linked to Gmelius features (shared labels, sequences, notes)
Customer Content accessed through Google Workspace APIs
- Gmail messages, drafts, labels and mail settings
- Google Calendar events and calendar lists
- Google Drive files and file metadata — optional, only where an agent has been created with access to Google Drive
- Basic Google account profile (name, email address, profile picture)
Our access to and use of this data is governed by Section 5 (Google Workspace APIs — Limited Use). We collect only what the features you enable require.
Customer Content from connected applications
Where your organisation connects a third-party application (for example a CRM, chat or automation tool), we process the data exchanged with that application as described in Section 6.
Feature-specific data
- Email tracking: subject and recipients of tracked emails, and open and click events.
- AI assistants and agents: see Section 4.
Usage, device and support data
- Log data, IP address, browser and device type, feature usage and diagnostic events
- Communications with our support and sales teams, including the content of your requests
Website and marketing data
- Cookies and similar technologies as described in our Cookie Policy
- Information you provide when requesting a demo, downloading a resource or subscribing to communications
3. How we use personal data and on what legal basis
- To provide the Services, create and secure your account, and deliver the features you enable — performance of a contract (GDPR Art. 6(1)(b)).
- To operate, secure and improve the Services, including preventing abuse and fraud, and producing aggregated, de-identified statistics — our legitimate interests (Art. 6(1)(f)).
- To provide customer support and respond to your requests — performance of a contract and legitimate interests.
- To communicate with you about the Services, including product updates and, where permitted, marketing communications from which you can opt out at any time — legitimate interests or your consent (Art. 6(1)(a)) where the law requires it.
- To bill and to comply with legal obligations, including accounting, tax and responding to lawful requests — legal obligation (Art. 6(1)(c)).
Customer Content is never used for marketing, advertising or profiling, and Google Workspace data is used only as set out in Section 5. Where Swiss law applies, we rely on the corresponding justifications under the Swiss Federal Act on Data Protection (FADP).
4. AI assistants and agents
Gmelius offers AI-powered features, including AI Sorting, Dispatching and Reply Assistants and configurable agents ("Meli") that can read, classify, draft and take actions on your behalf (together, "AI Features"). AI Features are enabled by the Customer's administrator or by individual users; they are not active unless enabled.
What data AI Features process
- AI Sorting and Dispatching Assistants process the subject and body of incoming emails in real time to classify or route them. This content is not stored by the AI Feature.
- AI Reply Assistants process the body of an email thread to generate a draft reply. Drafts and, where enabled, style preferences derived from your own account are stored encrypted to personalise future drafts. You can delete this data at any time.
- Agents retrieve data only from the sources the Customer selected when creating the agent (for example Gmail, Google Calendar, Google Drive or a connected application) and only in response to a task you initiated or a workflow you configured. Agents produce outputs (drafts, labels, routing decisions, actions) that are recorded in an audit trail so that you can review what an agent did and why.
How AI models are used
- AI Features are powered by third-party foundation models operated by the AI model providers listed in our sub-processor list. We only use providers that contractually commit to zero data retention: data is processed to return a result and is not stored or logged by the provider beyond immediate processing.
- Your data is never used to develop, improve or train generalised AI or machine-learning models, whether ours or a provider's. Any personalisation is specific to your account.
- Human review of AI inputs or outputs by Gmelius staff occurs only in the circumstances described under "Limited human access" in Section 5.
Human oversight and automated decisions
AI Features assist people; they do not make decisions that produce legal or similarly significant effects on individuals. Customers control the level of autonomy of each agent, including whether a human must approve an action before it is taken (for example, before an email is sent). AI-generated content may contain errors and should be reviewed before it is relied upon.
Retention and control
Personalisation data and agent audit trails are retained for the duration of your subscription and deleted when the associated agent, user or account is deleted, subject to Section 9. You can change an agent's access, delete an agent, disable AI Features, revoke Google permissions or delete your account at any time.
5. Google Workspace APIs — Limited Use
Gmelius connects to Google Workspace APIs (Gmail, Google Calendar and, optionally, Google Drive) and to your Google account profile in order to provide the features you enable. Permissions are requested incrementally: we ask only for the access required by the features you actually use, at the point you enable them. Our access to and use of this data is governed by the Google API Services User Data Policy, including its Limited Use requirements.
Gmelius' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
What this means in practice
- User-facing features only. We use Google user data solely to provide and improve features that are visible and prominent in the Gmelius user interface.
- No advertising. We do not use Google user data for serving advertisements, including retargeting, personalised or interest-based advertising.
- No sale of data. We do not sell Google user data, and we do not transfer it to third parties except as required to provide or secure the Services, to a connected application at your explicit direction (Section 6), or where required by law.
- No generalised AI or ML training. We do not use, and we do not permit our AI service providers to use, raw or derived Google Workspace data to develop, improve or train generalised artificial intelligence or machine-learning models. Where Gmelius features are powered by AI models (Section 4), data is processed solely to return a result to the user who requested it, under a zero data retention arrangement with the model provider.
- Limited human access. Humans do not read Google user data unless (i) we have your explicit consent to access specific messages or files, (ii) it is necessary for security purposes such as investigating abuse, (iii) it is required to comply with applicable law, or (iv) the data has been aggregated and de-identified for internal operations.
Scopes we request and why
- Gmail (read, compose, send and manage messages) — to power shared inboxes, shared labels, email notes, templates, sequences and campaigns, open and click tracking, and AI Features.
- Gmail settings — to replicate your existing preferences, including email aliases and signatures.
- Google Calendar — to synchronise Gmelius boards with your calendars and link cards or tasks to calendar events.
- Google Drive (optional) — requested only if and when you create a Gmelius agent that you give access to Google Drive. Where granted, it allows that agent to locate, read, reference and, where you ask it to, create or update files in your Drive in order to complete the tasks you assign to it. If you do not create an agent with Drive access, this permission is never requested and Gmelius does not access your Drive.
- Basic profile and email address — to create and identify your Gmelius account.
AI agents and the Model Context Protocol (MCP)
Gmelius exposes an interface based on the Model Context Protocol (MCP) that allows AI agents to act on your behalf within Gmelius. This interface is available exclusively to agents built and operated by Gmelius. We do not make your Google Workspace data available through MCP to third-party AI clients or agents that we do not operate.
Agent access is subject to the same rules set out above. You decide which data sources each agent may use when you create it, and any additional Google permissions required are requested from you at that point. An agent retrieves Google user data only in response to a task you have initiated or a workflow you have configured. Data retrieved in this way is used to produce the result you asked for, is not retained beyond what is required to deliver that result and to maintain an audit trail of the actions taken, and is never used to develop, improve or train generalised artificial intelligence or machine-learning models.
You may revoke Gmelius' access to your Google account at any time from your Google account permissions page, and delete your Gmelius account and associated data from your Gmelius Account page.
6. Third-party integrations and connectors
The Services can be connected to third-party applications such as CRM, chat, project-management and automation tools ("Connected Applications"). A connection is established only when a Customer administrator or user explicitly enables it and authorises the relevant access.
- Data flows to and from a Connected Application only as configured by the Customer, for example to attach an email to a CRM record or to post a notification in a chat channel. Where an agent is given access to a Connected Application, it uses that access only to perform the tasks assigned to it.
- Google Workspace data is transferred to a Connected Application only where you have explicitly configured that flow, consistent with the Limited Use requirements in Section 5.
- Connected Applications are operated by third parties under their own terms and privacy policies. Once data has been transferred to a Connected Application at your direction, its further processing is governed by that provider and by your organisation, not by Gmelius. Connected Applications are not Gmelius sub-processors.
- You can disconnect a Connected Application at any time from your Gmelius settings.
7. How we share personal data
We do not sell or rent personal data. We share personal data only:
- With sub-processors that host, secure or help us deliver the Services (cloud infrastructure, AI model providers, content delivery, email delivery, payment processing, support and CRM tooling). Each is bound by a data processing agreement, and the current list is published in our DPA.
- With Connected Applications at your direction (Section 6).
- Within your organisation, where your administrator manages users, shared inboxes and agents.
- For legal reasons, where required by law, court order or a competent authority, or to protect our rights, users or the public. Where permitted, we will notify the affected Customer so that it can seek a protective order.
- In a corporate transaction, such as a merger or acquisition, subject to confidentiality and this Policy.
8. International transfers
Gmelius is established in Switzerland, and our infrastructure is hosted on Google Cloud. Some of our sub-processors are located in the United States. Where personal data from Switzerland, the EEA or the United Kingdom is transferred to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (with the Swiss and UK addenda) and, where the recipient is certified, the EU-U.S., Swiss-U.S. and UK Data Privacy Frameworks. Switzerland is recognised as providing adequate protection by the European Commission and the United Kingdom.
9. Data retention
We retain personal data for as long as your account is active and as necessary to provide the Services, comply with legal obligations, resolve disputes and enforce our agreements. When you delete an individual account, we delete the associated data within 30 days. When a Customer terminates its subscription, Customer Content is returned or deleted within the periods set out in our DPA. In each case, some data may remain in encrypted backups for up to 90 days, and we may retain billing records for the period required by Swiss law. AI personalisation data and agent audit trails follow the same rules (Section 4).
10. Data security
- Encryption: all data in transit is encrypted using TLS; data at rest is encrypted.
- Access controls: access to personal data is restricted to authorised personnel on a need-to-know basis, logged and reviewed.
- Agent safeguards: agents operate within permission boundaries set by the Customer, with configurable human approval steps and a full audit trail.
- Assurance: our infrastructure and practices are monitored continuously. We are SOC 2 Type II certified. Our security overview is at gmelius.com/legal/security and our Trust Center.
11. Your rights
Depending on where you are located, you have the right to access, rectify, erase or receive a copy of your personal data, to restrict or object to its processing, to withdraw consent, and not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. California residents have equivalent rights under the CCPA/CPRA, including the right to know, delete and correct; we do not sell or share personal information for cross-context behavioural advertising.
To exercise your rights, contact privacy@gmelius.com. You can also delete your account and associated data from your Gmelius Account page. If your request concerns Customer Content, we will refer you to your organisation and assist it as required by our DPA. You have the right to lodge a complaint with a supervisory authority, including the Swiss Federal Data Protection and Information Commissioner (FDPIC), the authority of your EEA member state, or the UK Information Commissioner's Office.
Our Data Protection Officer can be reached at dpo@gmelius.com.
12. Analytics and cookies
On our website we use analytics services, including Google Analytics and Microsoft Clarity, configured to anonymise IP addresses, and HubSpot to understand how visitors use our website and to manage our sales relationships. These services do not receive any data obtained through Google Workspace APIs or any Customer Content. See our Cookie Policy for details and choices.
13. Payment processing
Payments are processed by Stripe, Inc. (PCI DSS Level 1). We do not store full payment card details. See Stripe's Privacy Policy.
14. Links to other websites
Our Services may contain links to websites not operated by Gmelius. We are not responsible for their privacy practices.
15. Children
The Services are intended for business use and are not directed to children under 16. We do not knowingly collect personal data from children under 16.
16. Changes to this Policy
We may update this Policy to reflect changes in our practices or for legal, regulatory or operational reasons. We will give at least thirty (30) days' notice of material changes by email to account administrators and by posting a notice on our website before the change takes effect, except where a shorter period is required by law. The "Effective" date at the top indicates when the current version applies.
17. Applicable law, language and contact
This Policy is governed by the substantive laws of Switzerland. Any dispute arising out of or relating to this Policy is subject to the jurisdiction of the competent courts of the Canton of Geneva, the jurisdiction of the Swiss Federal Court being expressly reserved.
This Policy is drafted in English. Translations are provided for convenience only; in the event of any discrepancy, the English version prevails.
Gmelius SA, Route de Pré-Bois 14, 1216 Cointrin / Meyrin, Geneva, Switzerland — privacy@gmelius.com