Privacy Policy – Gaiasuite
Last Updated: 17 August 2026
Gaiasuite commits to safeguarding personal data with transparency aligned to global SaaS standards. This policy explains how data is collected, used, stored, protected, shared, and deleted under international privacy regulations. Where we process data obtained through connected platforms, we also comply with the data protection and acceptable-use requirements of those platforms.
1. Who We Are
Gaiasuite serves as the data controller for personal information processing, with local representatives or subprocessors appointed based on jurisdiction.
2. Personal Data We Collect
We limit collection to the data that is the minimum necessary to perform the functions you authorize.
2.1 Data You Provide
- Name and contact details
- Company information and role
- Account registration information
- Communication preferences
- Information submitted via forms
2.2 Data Collected Automatically
- IP address and approximate location
- Device and browser information
- Usage logs and interaction data
- Cookies and tracking technologies
2.3 Third-Party Integration Data
When connecting Gaiasuite to external platforms, data necessary for integration operation is processed. For order fulfillment, this includes end-customer personally identifiable information (PII) — such as the buyer’s name, shipping address, and contact details — retrieved from connected sales channels.
The connected seller acts as data controller; Gaiasuite functions solely as processor under data processing agreements. Processing enables seller operations exclusively—never for advertising, resale, or any purpose beyond the authorized function. We do not use PII to locate, track, or contact end customers for our own purposes. End customers should contact the seller directly regarding privacy rights.
3. How We Use Your Data
Processing supports:
- Platform provision, maintenance, and improvement
- Account authentication and access management
- Technical and customer support delivery
- Platform reliability, monitoring, and security
- Analytics and performance insights
- Legal, regulatory, and contractual compliance
Personal data is never sold. Automated decision-making requires human involvement. We access and use data only to the extent necessary to provide the requested service.
4. Legal Bases for Processing
Processing relies on:
- Contractual necessity
- Legitimate interest
- Consent
- Legal obligation
5. Sharing and Disclosure
Data is shared only with:
- Trusted subprocessors providing hosting, analytics, security, or infrastructure
- Third-party platforms chosen for integration
- Regulatory or governmental authorities when legally required
All partners maintain strict contractual data protection obligations. Connected sales channel data is used exclusively for requested services, never shared beyond listed parties, and protected per channel requirements. We do not sell, rent, or disclose end-customer data to unauthorized third parties, and we do not share it for advertising purposes.
6. International Data Transfers
Global operations may process data outside your region, ensuring compliance through:
- Standard Contractual Clauses
- Adequacy decisions
- Technical and organizational safeguards
- Data Transfer Impact Assessments
7. Data Storage and Security
Personal data is stored on secure, access-controlled infrastructure hosted by vetted providers. Our safeguards include:
- Encryption at rest using AES-128 (meeting or exceeding the minimum of AES-128 or RSA with a 2048-bit key size) and encryption in transit using TLS 1.2 or higher
- Multi-factor authentication, role-based access, and least-privilege controls that restrict data access to authorized personnel only
- Logical separation of integration and end-customer data, with clear attribution of data origin
- Continuous infrastructure monitoring, logging, and intrusion detection
- Regular audits, vulnerability assessments, and secure software development practices
- Confidentiality obligations imposed on all employees and subprocessors handling personal data
- An incident response process to detect, investigate, and notify affected parties of security incidents in accordance with applicable law and platform requirements
8. Data Retention and Deletion
Data retention follows necessity principles with subsequent secure deletion or anonymization:
- Account and user data: Retained during the customer relationship; deleted post-closure except where legally required
- End-customer order data (PII): Anonymized or deleted within 30 days of order fulfillment, except the minimum data required by law, tax, or accounting rules, which is held encrypted and access-restricted before permanent deletion
- Deletion on request or revocation: Upon request from a connected platform (including Amazon), upon revocation of authorization, or upon termination of the integration, we permanently and securely delete all associated Information within 30 days, using industry-standard sanitization processes, except where retention is required by law
Secure deletion means the data is rendered permanently unrecoverable across primary and backup systems within the applicable timeframe.
9. Your Rights
Depending on jurisdiction, rights may include:
- Data access
- Information correction
- Data deletion
- Processing restriction or objection
- Data portability
- Consent withdrawal
- Marketing opt-out
- Supervisory authority complaint filing
Exercise rights by contacting: dpo@gaiasuite.com
10. Cookies
Gaiasuite uses cookies for essential functions, performance improvement, and analytics. A separate Cookie Policy is available.
11. Changes to This Policy
Updates appear here with modified “Last Updated” dates.
12. Contact
For privacy policy or data processing questions: dpo@gaiasuite.com