Privacy Policy
This policy explains how Guidance Srl handles personal data through the cerase.ai website and the Cerase platform, and in particular how Cerase accesses, uses, stores and shares Google account data (Gmail and Google Drive) when a user authorises the connection.
1. Data controller
The controller of the data described in this policy is:
Guidance Srl — which publishes and operates Cerase.ai
Largo Ignazio Chiurlia, 25 — 70122 Bari (BA), Italy
VAT number IT02874960996 — Share capital €10,000 fully paid
Privacy contact: privacy@cerase.ai
For anything concerning personal data — exercising your rights, deletion requests, questions about this policy — write to privacy@cerase.ai. We reply within one month of receipt, as required by Article 12 GDPR.
2. Who this policy applies to
Cerase is a B2B platform: a company buys it and that company's people use it. This changes the role Guidance Srl takes on, and it is worth settling up front, because it determines who you should address your requests to.
- Visitors to cerase.ai. Guidance Srl is the controller. Section 3 applies.
- Users of the Cerase platform. The customer company decides what data the assistant processes and for what purposes, so the customer company is the controller, while Guidance Srl acts as a processor under Article 28 GDPR, on the basis of a Data Processing Agreement signed before activation. Sections 4 and 5 apply.
- Third parties whose data appears in the assistant's work — the customer's clients, suppliers and correspondents. Here too the controller is the customer company; Guidance Srl processes such data only on its instructions.
In practice: if you use Cerase because your employer assigned it to you and you want to know what data is processed about you or have it deleted, the request goes to your employer, which is the controller. We carry it out on their instructions, and we will help route it if you write to us.
3. Data collected by the cerase.ai website
3.1 Browsing data
The website is a static page. The systems serving it record, for technical operation and security, the data any web server receives: IP address, date and time of the request, page requested, browser user agent, outcome of the request. These logs are used to diagnose faults and prevent abuse, and are not used to profile visitors.
3.2 Contact requests
If you contact us — by email or by submitting a request form — we process the data you provide (name, company, email address, phone number if you give one, the content of your message) in order to reply and, if the conversation continues, to assess an activation together. We do not use these contacts for unsolicited marketing.
3.3 Cookies and third-party resources
The site uses no profiling cookies. It stores a single technical preference in your browser, the language chosen with the footer switch (cerase_lang), because otherwise the choice would have to be repeated on every visit. The site also loads fonts and icons from Google Fonts and Cloudflare: in doing so, your browser discloses its IP address to those providers. The full list of tools is in the Cookie Policy.
4. Data processed in the Cerase platform
When a company activates Cerase, the platform processes on its behalf:
- Data about enabled users — name, work email address, group, assigned assistants, permissions, identifier on the chat channel the company uses.
- Conversations with the assistants — text and voice messages exchanged with the assistant, and the replies produced.
- Content from connected systems — emails, documents, ERP or CRM records, attachments, which the assistant accesses through the connectors the administrator has enabled, with the permissions the administrator has granted.
- Action log (audit log) — which action was performed by which assistant, on behalf of which user, on which connector and with what outcome, together with model inputs and outputs.
- Technical and usage data — usage metrics, credits consumed, application logs needed to run and bill the service.
Before any text leaves the customer's perimeter to reach a language model, a per-tenant PII filter masks sensitive data according to rules the administrator chooses (names, tax codes, IBANs, phone numbers, email addresses, IP addresses, custom regular expressions). The administrator decides, per group, connector and agent, what to mask, what to block, and what merely to flag in the audit log.
5. Google data: Gmail and Google Drive
This section sets out in detail how Cerase accesses, uses, stores and shares your Google account data. The connection is optional: Cerase works without it, and no Google data is read until you explicitly grant access from the Google consent screen.
5.1 Scopes requested, and why
We request only the scopes needed for the features your company's administrator has enabled. If a feature is not enabled, its scope is not requested.
| Google scope | What it is used for in Cerase |
|---|---|
gmail.readonly |
Lets the assistant read messages and attachments in the mailbox, so it can summarise a thread, extract the figures from an incoming invoice, spot requests left unanswered, and prepare the work the user asked for. |
gmail.send |
Lets the assistant send an email on the user's behalf when the user authorises it — for example the reply to a customer who has just approved. |
gmail.modify |
Lets the assistant create drafts in the user's mailbox, apply or remove labels, and archive messages it has finished working on. This is the scope behind the “I'll prepare it, you send it” flow: the reply appears in the drafts folder and goes out only if the user sends it. |
drive |
Lets the assistant read the documents it needs and save the files it produces in the folders the company has designated — a quote in the client folder, a report in the management folder, a meeting transcript alongside the rest of the documents. |
drive.readonly |
Requested instead of drive when the administrator configures the connector as read-only: the assistant may consult documents but neither modify nor create them. |
The Gmail and Drive scopes listed above are classified by Google as restricted scopes. We treat them accordingly: access is limited to what the requested feature needs, is subject to the controls described in this section, and is verifiable in the audit log.
5.2 How we access the data
Access happens solely through OAuth 2.0: you grant it from the Google consent screen, after seeing which scopes are being requested. Cerase never asks for, receives or stores your Google account password.
Access and refresh tokens are held by the connector Gateway, a service isolated from the environment the assistant runs in. Tokens are encrypted at rest and never enter the prompt sent to the model: the assistant can ask the Gateway to perform an authorised action, but it cannot read or reveal the credentials that make the action possible.
Every call goes through the Gateway, which checks the permissions set by the administrator and the human-approval level configured for that connector — read-only, draft-only, requires user confirmation, autonomous — and records it in the audit log.
5.3 How we use the data
Gmail and Drive data is used solely to carry out the user's requests and the procedures the company has configured: reading what is needed to complete a task, producing the requested reply or document, and recording the action in the audit log.
We do not use it for advertising, we do not sell it, we do not pass it to data brokers, we do not use it to profile users or build audiences, and we do not use it for purposes other than those the access was granted for.
5.4 How we store the data
- Content read from Gmail and Drive. It is processed for as long as the requested task requires. It is retained in the customer's environment only where the work itself requires it — for instance the transcription of an attachment indexed in a knowledge notebook — and always according to the retention rules the customer company has configured.
- Output produced. The documents, drafts and records the assistant creates stay where they were created: in your Drive, in your mailbox, or in your tenant environment.
- Audit log. The action log keeps 24 months of history, including actions performed on Google connectors, together with model inputs and outputs. The customer company can export it as JSON/CSV.
- OAuth tokens. They remain valid until you revoke authorisation or the company disables the connector. On revocation they are deleted immediately.
- Where. Each customer's environment and its backups reside in data centres within the European Union. Backups are encrypted with AES-256 at rest.
5.5 Who we share the data with
We do not share Google data with anyone, with three exceptions only, all of them necessary to run the service or required by law:
- Language model providers (sub-processors). To generate a reply, the text relevant to the task is sent to the model configured for that plan — after passing through the PII filter described in section 4. Providers are contractually bound to process the data only to deliver the service and not to use it to train their models. The current sub-processor list — which model, which provider, in which region, for which purpose — is given to every customer alongside the DPA and updated whenever it changes; it is available on request at privacy@cerase.ai. A customer on the BYOK option uses its own provider, in which case the data does not leave its own contractual perimeter.
- Infrastructure providers. Hosting, storage and backup within the EU, bound by processor agreements.
- Authorities. Where we are required to do so by law, or to establish, exercise or defend a legal claim.
Human access. Our staff does not read customers' Gmail and Drive content. Human access is permitted in four cases only: where the user or customer expressly authorises it, for documented security reasons (for example investigating an incident), where the law requires it, or on aggregated and anonymised data for internal operations. Every access is logged.
5.6 AI models and training
We do not train models on your Google data
Guidance Srl does not use data obtained through Google Workspace APIs — including Gmail and Google Drive content — to develop, improve or train generalized or non-personalized artificial intelligence or machine learning models, whether our own or third parties'. The model providers we use as sub-processors are contractually bound by the same prohibition.
5.7 Limited Use disclosure
Limited Use disclosure
Cerase.ai's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5.8 How to revoke access and delete data
You can withdraw your authorisation at any time, in either of two equivalent ways:
- from the Google Account › Third-party apps with account access page, by removing Cerase;
- from the Cerase admin console, by disabling the Google connector for your user or for the whole organisation.
On revocation, tokens are deleted immediately and the assistant loses all access to your Google data. To request deletion of derived data still held in the environment — indexed content, transcripts, working copies — write to privacy@cerase.ai stating the organisation and the account concerned: the request is carried out within 30 days, save for the audit log retention the controller requires for traceability and for encrypted backups, which are overwritten on their own rotation cycle.
6. Legal bases
- Performance of a contract or pre-contractual steps (Art. 6(1)(b) GDPR) — delivering the service, managing the account, replying to contact requests.
- Legitimate interests (Art. 6(1)(f) GDPR) — infrastructure security, abuse prevention, technical logs, defending a legal claim.
- Consent (Art. 6(1)(a) GDPR) — connecting the Google account and other optional systems, non-technical cookies. Consent can be withdrawn at any time, without affecting the lawfulness of processing already carried out.
- Legal obligation (Art. 6(1)(c) GDPR) — tax and accounting duties, and requests from authorities.
- For processing where Guidance Srl acts as processor, the legal basis is determined by the customer company as controller.
7. Recipients and processors
Data may be processed on our behalf and on our instructions by: cloud infrastructure and backup providers within the European Union; language model providers, within the limits described in section 5.5; email and support tools used to communicate with customers; legal, tax and accounting advisers. All act as processors under Article 28 GDPR, or as independent controllers where the law requires. We do not sell personal data and do not disclose it for third-party marketing.
8. Transfers outside the European Economic Area
Cerase's infrastructure is in the EU and data stays there. Where a model provider entails a transfer to a third country, that transfer takes place only on the basis of a European Commission adequacy decision or of Standard Contractual Clauses, together with any supplementary measures required. The country and region of each provider are stated in the sub-processor list. A customer that requires no data to leave the EU can configure Cerase with EU-hosted models only, or in BYOK mode on its own infrastructure.
9. Retention periods
| Data | Retention |
|---|---|
| Website browsing logs | Up to 12 months, then deleted or anonymised |
| Contact requests | 24 months from the last exchange, unless a contract follows |
| Account and configuration data | For the duration of the contract |
| Conversations with the assistants | As configured by the customer as controller |
| Audit log | 24 months |
| Google OAuth tokens | Until revoked; then deleted immediately |
| Encrypted EU backups | Per the configured rotation cycle, up to 24 months |
| Tax and accounting records | 10 years, as required by law |
On termination of the contract, the data in the customer's environment is deleted within 30 days, unless otherwise agreed in writing and subject to statutory obligations.
10. Security
We apply technical and organisational measures appropriate to the risk: encryption in transit and at rest (AES-256 for backups), isolation of each customer's environment, connector credentials held in a separate service never exposed to the model, role-based access control with mandatory MFA for administrators, an immutable action log, automated EU backups with verified restore, and automated analysis of procedures (skills) before they can be enabled. In the event of a personal data breach we act under Articles 33 and 34 GDPR and notify affected customers promptly.
11. Your rights
Under Articles 15-22 GDPR you have the right to obtain access to your data, its rectification, its erasure, restriction of processing, portability in a structured format, and to object to processing based on legitimate interests. Where processing rests on consent, you may withdraw it at any time.
To exercise them, write to privacy@cerase.ai. Where the processing concerns your company's use of the platform, we forward the request to the controller — your company — and carry it out on their instructions, telling you where it was routed.
You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome — garanteprivacy.it) or with the supervisory authority of the country where you live.
12. Children
Cerase is a service for businesses and is not intended for anyone under 18. We do not knowingly collect children's data. If we find that we have, we delete it.
13. Changes to this policy
We may update this policy when the service, our providers or legal obligations change. The date at the top of the page always states the latest update. Where a change is material — for instance a new purpose or a new Google data access scope — we inform active customers before it takes effect.
14. Contact
Guidance Srl — Largo Ignazio Chiurlia, 25 — 70122 Bari (BA), Italy
Privacy: privacy@cerase.ai
Terms of Service: cerase.ai/en/terms