Riservatezza
Privacy Policy
Uffici AI, LDA (“Uffici”, “we”) makes AI agents for small offices and teams, and operates the uffici.ai website. This policy explains what personal data we collect, what we do with it, who we share it with, and the rights you have over it.
It covers the uffici.ai website and the Uffici platform — the services we operate under the Uffici name, including early-access versions (together, the “Services”).
01Who we are and what we are responsible for
Uffici AI, LDA is a company incorporated in Portugal, based in Porto. For the website and for your account, we are the data controller.
Inside an organization’s workspace — conversations with agents, files, tables, and other working material — the organization controls the data. We process it on that organization’s behalf and on its instructions.
For anything in this policy, write to privacy@uffici.ai.
02Data we collect
What we collect depends on how you use the Services.
- Website visits — technical logs kept when a page is served: your IP address, browser type, and the pages requested. The website’s typefaces are loaded from Google Fonts, so your browser sends your IP address to Google when it fetches them.
- Measurement — the website uses Google Tag Manager to load measurement tags that help us understand how the site is used, such as pages visited and approximate region.
- Your account — your name, email address, password (held by our authentication provider as a hash; we never see or store it in plain text), date of birth where we ask for it, language, and email preferences.
- Your sessions — sign-in records, including IP address, device information, and last activity, kept to secure your account.
- Your organization’s content — what you and your team put into the workspace: the instructions and briefings you write for agents, conversations with agents, files you upload, tables and boards, and the credentials of services you choose to connect (stored encrypted).
- Email records — a log of the transactional email we send you, and a hashed record of addresses that have bounced or complained, so that we do not contact them again.
- Usage records — metered counts of what the Services consume on your behalf, such as model calls and storage. These are counts and costs, never the content itself.
03How and why we use data
- To provide the Services — operate your account and workspace, run your agents, deliver the email the Services send you. Legal basis: performance of a contract.
- To keep the Services secure — authenticate sign-ins, prevent abuse, keep each organization’s data isolated, honour email suppression. Legal basis: our legitimate interest in running a secure service.
- To understand how the website is used — aggregate measurement of visits. Legal basis: consent where required, otherwise legitimate interest.
- To meet legal obligations — respond to lawful requests and keep the records the law requires. Legal basis: legal obligation.
We do not sell personal data, we do not use your content for advertising, and we do not use your content to train our own models.
04How AI processing works
When you converse with an agent, the content needed to produce a response — the agent’s instructions, the conversation, your name as it appears in the workspace, and the material the agent reads on your behalf — is sent to AI model providers. We route these calls through OpenRouter, Inc., which forwards them to the provider of the model your agent uses. Providers process this content to generate the response.
Agents keep memory. The Services may record short factual notes drawn from conversations — a stated preference, a project, a decision — so agents stay useful across sessions. Organization administrators can review, correct, and erase these notes at any time.
The Services also generate conversation titles and running summaries using the same model infrastructure.
05Who we share data with
We share personal data with the providers we need to run the Services, each processing it only to provide their service to us:
- Google Cloud (Google Ireland Limited / Google LLC) — the cloud infrastructure where the Services and their data are hosted, and the identity service that stores and verifies sign-in credentials.
- OpenRouter, Inc. — AI model routing, as described above.
- Resend, Inc. — transactional email delivery, from EU infrastructure.
- Cloudflare, Inc. — networking, DNS, and TLS in front of the Services, and hosting of the uffici.ai website.
- Google LLC — website measurement (Google Tag Manager) and font delivery (Google Fonts).
Integrations are different. When your organization connects its own services — email, documents, project tools — those providers act under your agreement with them, on your credentials and your instructions, not as our subprocessors.
Beyond that, we disclose personal data only if the law requires it, to protect the Services and their users, or, in the event of a corporate transaction, to a successor bound by this policy.
06International transfers
We are established in the European Union, and some of our providers process data in the United States. Where personal data leaves the European Economic Area, we rely on the safeguards the GDPR provides — European Commission adequacy decisions, including the EU–US Data Privacy Framework where the provider is certified, or Standard Contractual Clauses.
07How long we keep data
- Account data — for as long as your account exists. When an account is deleted, personal identifiers are removed or anonymized.
- Sign-in sessions — until they expire; expired sessions are removed on a regular sweep.
- Organization invitations — invitations expire after a few days, and the record, including the invited address, is deleted within about thirty days.
- Email records — delivery logs are kept for about thirty days. The hashed record of bounced or complaining addresses is kept indefinitely, so we do not email people who should not be emailed; it survives account deletion for that reason.
- Your organization’s content — for as long as your organization keeps it. Content is deleted when you delete it, when an agent is deleted or reset, or when the organization’s account closes.
08Security
Traffic to the Services is encrypted in transit, and data is encrypted at rest. Credentials for connected services are additionally encrypted at the application layer before they reach the database. Each organization’s data is isolated, and that isolation is enforced in the database layer, not only in application code.
No system is perfectly secure. If you find a vulnerability, tell us at security@uffici.ai — see our security.txt.
09Cookies
The Services use cookies sparingly:
- Signing in — session cookies that keep you signed in. Strictly necessary.
- Preferences — cookies that remember your language and display choices.
- Measurement — on the website, Google’s tags may set cookies when measurement is active. Where consent is required for these, we ask before they are set.
There are no advertising cookies anywhere in the Services.
10Your rights
Under the GDPR you can ask us for access to your personal data, correction, deletion, restriction of processing, and a portable copy; you can object to processing based on legitimate interest; and you can withdraw consent at any time. Write to privacy@uffici.ai and we will respond within the timelines the GDPR sets.
If your data lives in an organization’s workspace, we may refer your request to that organization, since it controls that data — and we will help it respond.
You can also complain to a supervisory authority. Ours is the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados (cnpd.pt).
11Children
The Services are built for organizations and are not directed to children. You must be at least 18 to create an account, and we do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.
12Changes to this policy
When the Services change, this policy changes with them. We will post the new version here with an updated date, and for material changes we will tell account holders by email or in the product before they take effect.
13Contact
Uffici AI, LDA — Porto, Portugal.
Privacy: privacy@uffici.ai · Support: support@uffici.ai · Security: security@uffici.ai