Legal
Privacy Policy
Effective date: 8 October 2026
0. Who does this notice apply to?
This notice applies to the use of the Service by individuals acting in a private capacity, for non-business and non-professional purposes.
If you use the Service as a sole trader, on behalf of a business or other organisation or as its employee or agent, or otherwise in the course of any economic or professional activity, this notice does not apply to you; instead, the documents available at the following location apply to you:
https://azta.eu.trust.site/resources → Resources → Documents
The reason for this is that the data protection roles differ in the two cases. If you use the Service as a private individual, Azta Kft. qualifies as a controller under the GDPR and is directly responsible to you for the processing. If you use it for business or professional purposes, then with respect to the content entered into the Service, you, or your employer or principal, are the controller, and Azta Kft. acts as a processor, on your instructions. This relationship is governed not by a privacy notice but by a data processing agreement.
The table below will help you decide which document applies to you:
| How do you use the Service? | Role of Azta Kft. | Document applicable to you |
|---|---|---|
| As a private individual, for your own non-business and non-professional purposes (e.g. a question relating to your own tax return) | Controller | This notice |
| As a sole trader, or on behalf of or as an employee of a business, accounting firm, tax adviser or other organisation, with a self-service (Pro) subscription | Processor with respect to content and user account data; controller with respect to contractual and billing data and security logs | azta Pro - Data Processing Agreement and Privacy Notice, available at: https://azta.eu.trust.site/resources |
| Under a bespoke, signed Enterprise agreement | Processor with respect to content and user account data; controller with respect to contractual and billing data and security logs | The data protection annex to the Enterprise agreement (Data Processing Agreement and Privacy Notice) |
The calendar integration and the meeting bot feature are available exclusively under a subscription for business and professional purposes, and are not available to private individual users. For the sake of transparency, we publish the data processing rules for these features - including the handling of Google and Microsoft calendar data - in Section 5, even where, as regards the allocation of roles, the user concerned is governed by the documents referred to in the table above.
The Word add-in is available under Pro and Enterprise subscriptions, to both private individual and business users. The Gmail and Microsoft Outlook mailbox integration is available exclusively under an Enterprise agreement, for company (organisational) mailboxes; it is not available to private individuals. If you use the Word add-in as a private individual, Azta Kft. qualifies as a controller for the processing operations described in Section 6.1, and you may exercise your rights directly against us. If you use it for business or professional purposes, the roles are governed by the documents referred to in the table above; however, the technical and security content of Section 6 applies in that case as well.
Exception. Section 10 (Cookies) of this notice, and the rows of the table in Section 2 relating to website visits, contacting us, complaint handling, the newsletter and appointment booking, apply to all visitors and enquirers, regardless of whether you visit our website as a private individual or for business purposes. In these processing operations, Azta Kft. qualifies as a controller in all cases.
1. Introduction
Azta Korlátolt Felelősségű Társaság (company registration number: 01-09-470071, tax number: 32861196-2-41, registered office: Balance Hall building, 4th floor, Váci út 99-105., 1139 Budapest, Hungary; hereinafter: "Data Controller", "we"), as controller, is committed to protecting your personal data (you being the "Data Subject", "you").
In this notice, we explain how we collect, process, share and protect your personal data when you use our website and services (collectively: "Service"). This notice is to be read together with the provisions of the General Terms and Conditions and Terms of Service (hereinafter: GTC), the Cookie Policy and, where the Word add-in is used, the End User License Agreement of the add-in.
The former company name of Azta Kft. was Phantic Kft. Contracts concluded and documents issued under the former name continue to apply to Azta Kft. unchanged.
2. The data we collect and our processing operations
In the course of your use of the Service, we process the following categories of data:
- Identification and account data: name, e-mail address, telephone number, password hash or SSO identifier.
- Billing data: name, billing address, tax number (if any), payment-related data.
- Content data: the questions you ask (prompts), the content of uploaded documents, the responses generated by the Service, information stored in memory, and transcribed text resulting from dictation.
- Document data from the azta for Word add-in: the text of the document opened in Microsoft Word or the part of it selected by you, the structural data of the document (headings, paragraph identifiers, tables), the questions asked of the add-in and the changes proposed by the add-in.
- Usage and technical data: IP address, session ID, device and browser information, operating system, pages visited, logging metadata of actions performed in the Service.
- Cookie and analytics data: as set out in Section 10, solely on the basis of your consent.
The individual processing operations are set out item by item in the table below, by purpose, categories of data processed, legal basis and retention period.
| Purpose of processing | Data processed | Legal basis | Retention period |
|---|---|---|---|
| Registration and operation of the user account. Registration is required to access the Service. | E-mail address, password hash or SSO identifier | Article 6(1)(b) GDPR: performance of a contract. The legal basis for retention following termination of the account is Article 6(1)(f) GDPR: the Data Controller's legitimate interest in enforcing any civil law claims and in preventing abuse. | For the lifetime of the account and 2 years thereafter |
| Provision of the Service: questions and answers. Processing and display of the questions asked (prompts) and of the generated responses, and provision of the "Recent searches" tab. | Any personal data contained in the question and the response | Article 6(1)(b) GDPR: performance of a contract | None; upon termination of the account, the data are separated from the user and the data relating to the user are anonymised. |
| Document upload. The User may attach a document to their question, which the Service analyses. | Data contained in the uploaded documents | Article 6(1)(b) GDPR: performance of a contract. The feature is part of the intended use of the Service and is therefore not based on consent. | None; upon termination of the account, the data are separated from the user and the data relating to the user are anonymised. |
| Dictation feature. The User may ask their question orally; the Service converts the audio into text and processes only the transcribed text. | The transcribed text (prompt), which may contain personal data. Azta Kft. does not store the audio recording. | Article 6(1)(b) GDPR: performance of a contract. The browser's microphone permission is a technical access permission and does not in itself constitute consent under the GDPR. | None; upon termination of the account, the data are separated from the user and the data relating to the user are anonymised. |
| Memory feature. The Service is able to store information from conversations on a long-term basis. The feature is optional, may be switched off and on at any time, and stored items may be deleted individually. | Data stored in memory, as provided by the User | Article 6(1)(a) GDPR: consent. Consent may be withdrawn at any time by switching off the feature; withdrawal does not affect the lawfulness of prior processing. | Until consent is withdrawn or the account is terminated |
| Personalisation. The Service personalises responses according to the preferences specified by the User. | Data voluntarily provided by the User for this purpose | Article 6(1)(a) GDPR: consent, which may be withdrawn at any time | Until consent is withdrawn or the account is terminated |
| Subscription management and payment of fees. | Name, e-mail address, subscription and payment data | Article 6(1)(b) GDPR: performance of a contract | 5 years from termination of the subscription (Section 6:22 of the Civil Code) |
| Invoicing. The Data Controller has a statutory obligation to issue invoices for purchases and to retain them. | Name, e-mail address, billing data | Article 6(1)(c) GDPR: compliance with a legal obligation | 8 years, pursuant to Section 169 of Act C of 2000 on Accounting |
| Contact and customer support. | E-mail address and any other personal data communicated by the Data Subject | For existing subscribers, Article 6(1)(b) GDPR; otherwise Article 6(1)(f): the Data Controller's legitimate interest in responding to enquiries. | 5 years from the closure of the enquiry |
| Handling of consumer complaints. | Data contained in the complaint, the complainant's name and contact details | Article 6(1)(c) GDPR: legal obligation, pursuant to Section 17/A(7) of Act CLV of 1997 on Consumer Protection | 5 years from the closure of the complaint |
| Marketing. The Data Controller sends marketing communications if you have consented to this. | Name, e-mail address | Article 6(1)(a) GDPR: consent, in accordance with Section 6 of Act XLVIII of 2008 on the Essential Conditions of and Certain Limitations to Business Advertising Activity. Consent may be withdrawn at any time via the unsubscribe link or at info@azta.ai. | Until consent is withdrawn |
| Service messages. Information about outages of the Service and about changes to the terms or to this notice. Contains no marketing content. | E-mail address | Article 6(1)(f) GDPR: the Data Controller's legitimate interest in informing Users of material circumstances affecting the Service | Until termination of the account |
| Operational and security logging. Ensuring the availability of the Service, troubleshooting, and maintaining the security of the system. | IP address, session ID, device and browser information, logging metadata, prompts | Article 6(1)(f) GDPR: the Data Controller's legitimate interest in the secure and reliable operation of the Service | 12 months |
| Prevention of abuse and fraud, enforcement of the GTC. | Account data, technical and log data, content affected by the abuse | Article 6(1)(f) GDPR: the Data Controller's legitimate interest in ensuring the lawful use of the Service and preventing unauthorised access | 2 years from the closure of the investigation |
| Development of the Service. The Data Controller develops the Service on the basis of aggregated, pseudonymised usage statistics. The Data Controller uses the content of prompts and uploaded documents neither to train nor to fine-tune any artificial intelligence model. | Aggregated, pseudonymised usage and product analytics events. No document content is passed to any analytics provider. | Article 6(1)(f) GDPR: the Data Controller's legitimate interest in improving the quality and security of the Service. No individual-level profiling takes place. | Aggregated statistics do not constitute personal data; the retention period for pseudonymised events is 24 months |
| Word add-in (azta for Word). An add-in that can be installed from the Microsoft Marketplace store (formerly: Microsoft AppSource) and allows azta to be invoked directly from Microsoft Word. The add-in accesses the document currently open in Word (ReadWriteDocument permission): it reads its text or the part of it selected by you and its structural data, and, after your express approval, may modify it using tracked changes. It does not access the file system or other documents. Availability: Pro and Enterprise subscriptions. See Section 6.1 for details. | The text of the open document or the part of it selected by you, the structural data of the document (headings, paragraph identifiers, tables), the questions asked of the add-in, the proposed changes, technical metadata relating to use of the add-in | Article 6(1)(b) GDPR: performance of a contract. | Content read from the document: 30 days. The questions, responses and proposed changes (the conversation): until the conversation is deleted, but no longer than until termination of the account. Technical data saved in the settings part of the document remain in your file (Section 6.1). |
| Appointment booking. The User may use the Calendly service to book an appointment for a consultation with the azta team. | Name, telephone number, e-mail address, booking details | Article 6(1)(b) GDPR: taking steps at the request of the Data Subject prior to entering into a contract | 12 months from the booking |
| Cookies and analytics. | Data specified in the Cookie Policy | Article 6(1)(a) GDPR: consent, via the cookie banner | As set out in the Cookie Policy |
Automated decision-making. The Data Controller does not carry out any decision-making or profiling based solely on automated processing which produces legal effects concerning you or similarly significantly affects you (Article 22 GDPR).
Mandatory or voluntary nature of providing data. Providing the e-mail address required for registration is a contractual prerequisite for using the Service; without it, the Service cannot be used. In the case of further processing operations based on the performance of a contract (document upload, dictation), the provision of data is necessary in order to use the feature concerned. In the case of processing operations based on consent (memory, personalisation, marketing, cookies), the provision of data is voluntary; in its absence, the feature concerned is not available, but the core functions of the Service can be used.
3. If you provide the data of another person
The question you ask or the document you upload may contain personal data of another natural person (for example, a family member, business partner or employee). In such cases, the Data Controller processes personal data that it has not obtained from the data subject.
The source of such data is in every case you; the categories of data processed and the retention periods are the same as in the corresponding rows of the table in Section 2, and the purpose of the processing is the provision of the Service. The Data Controller uses such data solely to answer your question.
The Data Controller is unable to inform these data subjects directly, since it does not have their contact details, and providing such information would involve a disproportionate effort within the meaning of Article 14(5)(b) GDPR. The Data Controller fulfils this obligation by publishing this section. We ask you, as a user, to share with us only as much data as is strictly necessary to answer the question and, where possible, to remove any unnecessary personal data.
We further ask you not to share with us any special categories of data within the meaning of Article 9 GDPR (for example, data concerning health, religious beliefs, political opinions or trade union membership), or data relating to criminal matters within the meaning of Article 10. The Service is not intended for the processing of such data, and the Data Controller neither requests nor collects consent for the processing of such data.
The Service is intended for persons who have reached the age of 18; to our knowledge, we do not collect personal data from minors.
4. Processors and data transfers
We do not sell, trade or rent your personal data to third parties. However, to operate the Service we engage processors, who process the data solely on our instructions, under a contract concluded with us that complies with Article 28 GDPR.
We may also share your data where this is required by law, ordered by a binding decision of a court or authority, or necessary to protect our rights or for the safety of you or others.
| Recipient | Activity | Role | Data residency and transfer safeguard |
|---|---|---|---|
| Amazon Web Services EMEA SARL (Luxembourg) | Cloud infrastructure, operation of the web application, hosting, logging | Processor | EU - AWS Frankfurt (eu-central-1). No transfer outside the EEA takes place. |
| Amazon Web Services EMEA SARL - Bedrock | AI model access (inference) - being phased out, replaced by OpenRouter | Processor | EU - eu-central-1. Zero Data Retention configuration. |
| Supabase Pte. Ltd (incorporated in Singapore, EU data centre) | Database and file storage, including the storage of document content read from the Word add-in (30 days) and of messages mirrored from mailboxes (30 days) | Processor | EU - Frankfurt. Data at rest remains in the EEA. The contracting party is a Singapore company, therefore EU Commission SCCs 2021/914/EU. |
| OpenRouter, Inc. (USA) | Primary AI inference gateway (access to large language models) | Processor | EU/EEA - processes the content of requests exclusively within the EU/EEA (EU-only configuration) and does not store it (Zero Data Retention). On the basis of EU Commission SCCs 2021/914/EU. |
| Mistral AI (France) | Document processing and analysis | Processor | EU - EU regional endpoint; no transfer outside the EEA takes place. Does not train models on the data (model training disabled). |
| Hyperdoc Inc. ("Recall.ai", USA) - solely for the calendar integration and the meeting bot feature | Storage of calendar access tokens, retrieval of calendar events, operation of the meeting bot and audio recording | Processor | Account configured in the EU region (eu-central-1, Frankfurt); the provider is a US company, therefore the safeguard is: EU Commission SCCs 2021/914/EU. The audio recording is deleted after transcription. |
| Soniox, Inc. (USA) - solely for the dictation and meeting bot features | Speech recognition: conversion of dictated questions and meeting audio into text | Processor | EU region and EU endpoint, with no fallback to a US endpoint; the provider is a US company, therefore the safeguard is: EU Commission SCCs 2021/914/EU. Processes the audio in memory; does not store it or train on it. |
| Exa Labs, Inc. (USA) | AI-powered web search - | Processor | Transit to the USA. EU Commission SCCs 2021/914/EU. |
| Stripe Payments Europe, Limited (Ireland) | Card payment processing | Processor and, with respect to payment data, independent controller | EEA - Ireland; data importer Stripe, LLC (USA): EU Commission SCCs 2021/914/EU or, as applicable, EU-US Data Privacy Framework. PCI DSS Level 1. |
| KBOSS.hu Kft. (Szamlazz.hu), Budapest | Electronic invoicing and archiving | Processor | Hungary. |
| Emergence Engineering Kft. (SzamlaBridge), Budapest | Invoicing integration middleware | Processor | Hungary; the provider's sub-processors use EU data centres, with transfers to their US entities on the basis of EU Commission SCCs 2021/914/EU or, as applicable, the EU-US Data Privacy Framework. |
| Plus Five Five, Inc. ("Resend", USA) | Transactional e-mail delivery | Processor | USA - data are stored in the USA. EU Commission SCCs 2021/914/EU or, as applicable, EU-US Data Privacy Framework. |
| Calendly, LLC (USA) | Appointment booking | Processor | EU Commission SCCs 2021/914/EU or, as applicable, EU-US Data Privacy Framework. |
| PostHog, Inc. (USA) | Product analytics | Processor | EU data residency (Frankfurt). EU Commission SCCs 2021/914/EU. Only anonymised or pseudonymised usage data; no document content is transferred. |
| Google Ireland Limited (Google Analytics) | Analytics | Processor or, with respect to certain purposes, independent controller | Google Ireland Limited (Ireland); data may also be transferred to the USA (Google LLC: EU-US Data Privacy Framework or, as applicable, SCCs). Only with your cookie consent. |
| Google Ireland Limited (Google Ads) | Advertising, ad measurement | Joint controller at the data collection and transmission stage (Article 26 GDPR) | Google Ireland Limited (Ireland); data may also be transferred to the USA (Google LLC: EU-US Data Privacy Framework or, as applicable, SCCs). Only with your cookie consent. |
| Meta Platforms Ireland Limited | Ad measurement, analytics | Joint controller at the data collection and transmission stage (Article 26 GDPR) | EEA - Ireland; Meta may transfer the data to the USA on the basis of the EU-US DPF or SCCs. Only with your cookie consent. |
Analytics and advertising providers. We transfer data to the recipients whose activity is "Analytics" or "Advertising" only if you have consented to this via the cookie banner. An agreement pursuant to Article 26 GDPR is in place with the providers designated as joint controllers; the essence of the agreement will be made available to you on request.
Transfers outside the EEA. Wherever possible, we use data centres located within the EEA. Where this is not possible, data are transferred on the basis of the standard contractual clauses (SCCs) set out in European Commission Implementing Decision (EU) 2021/914, or by engaging a provider that is duly certified under the EU-US Data Privacy Framework. A copy of the appropriate safeguards will be made available to you on request at info@azta.ai. We have carried out a transfer impact assessment (TIA) for transfers to third countries, which we review annually.
Exclusion of model training. Neither Azta Kft. nor the processors it engages use your questions, uploaded documents or the generated responses to train or fine-tune any artificial intelligence model. A Zero Data Retention configuration is in place with OpenRouter (and, until it is phased out, with AWS Bedrock), which means that neither the input nor the output is stored after the response has been generated. Model training is disabled at Mistral AI.
An up-to-date list of the processors we engage is available in our Trust Center: https://azta.eu.trust.site/resources. Registered Users will be notified in advance of any material change to the list.
5. Calendar integration and meeting bot: handling of Google and Microsoft calendar data
This section applies to the calendar integration and meeting bot feature. As regards the allocation of roles, a user who uses the feature is governed by the azta Pro Data Processing Agreement or by the data protection annex to the Enterprise agreement; in such cases, Azta Kft. acts as a processor with respect to calendar and meeting data, and the controller is the user, or the user's employer or principal.
Regardless of the foregoing, in accordance with the requirements of the Google API Services User Data Policy, we disclose below how we access, use, store and share Google and Microsoft calendar data.
5.1 What data we access and why
The purpose of the feature is to enable the user to connect their Google Calendar or Microsoft Outlook calendar to the Service and to invite the azta bot to their meetings, which produces a text transcript and a summary of the meeting. For this, we need only the following:
- Calendar read permission. We request read-only access; we do not create, modify or delete calendar events.
- We process only those events that contain a video conferencing link. We use the event's time, title and video conferencing link, and the names and e-mail addresses of the invitees, solely in order to assign the bot to the correct meeting.
- We do not store the descriptions or attachments of calendar events, or events without video conferencing.
5.2 How we use the data
We use data obtained through the Google and Microsoft APIs solely to provide and improve the user-facing features described above. The Service does not learn from this data, and we do not use it for any other purpose.
5.3 With whom we share it
Calendar data and access tokens are stored and processed on our behalf by Hyperdoc Inc. ("Recall.ai"), as processor, in an account configured in the European Union region (eu-central-1, Frankfurt); the provider is a US company, and we therefore apply the safeguards (SCCs) set out in Section 4 with it. Meeting audio is converted into text by Soniox, Inc., likewise as processor, in a European Union region. Beyond this, we do not share calendar data with any third party, unless required by law or by a binding decision of an authority.
5.4 How long we store it, and how it can be terminated
- We store calendar data until the calendar connection is terminated, and we do not archive it.
- The user may terminate the calendar connection within the Service at any time. Upon termination, we revoke and delete the stored access tokens and delete the stored calendar data.
- Access may also be revoked at any time in the security settings of the Google account or the Microsoft account.
- The audio recording of the meeting is permanently deleted immediately after transcription; we do not store audio on a long-term basis. No video or screen recording is made.
5.5 Compliance with the Google API Services User Data Policy. azta.ai's use and transfer of information obtained through Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. In English: “azta.ai's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.” Accordingly, we expressly declare that user data obtained through Google APIs:
- is used solely to provide and improve the user-facing features described in this section;
- is not used or transferred for advertising purposes, including personalised, behavioural and retargeted advertising;
- is not sold or rented;
- is not used to develop, train or fine-tune any general-purpose artificial intelligence or machine learning model, and we extend this prohibition to the processors we engage;
- is not made available for human reading, except where the user has given their express consent, where this is necessary for security reasons or to investigate abuse, where required by law, or where the data serve internal operational purposes in aggregated, anonymised form;
- is transferred to third parties only to our processors referred to in Section 5.3, to the extent necessary to provide the feature.
5.6 Microsoft calendar data. Sections 5.1-5.4 apply mutatis mutandis to connection with the Microsoft Outlook calendar. The user may also revoke access to the Microsoft account at any time in the settings of the Microsoft account.
5.7 The role of Google and Microsoft. We access calendar data through the user's own Google or Microsoft account, on the basis of the permission granted by the user. In this relationship, Google and Microsoft are not our processors but the user's own service providers; the legal relationship with them is governed by their own data processing terms.
5.8 Meeting participants. The bot joins the meeting visibly to participants, under a name that clearly indicates that a recording is being made, and on joining it sends a message informing participants that a recording is being made. Any participant may request the removal of the bot. The subscriber organising the meeting, as controller, has control over the content of the recording and the transcript, and participants should therefore primarily exercise their data subject rights with that subscriber; we forward requests received by us to the subscriber without delay. You may also send your request to info@azta.ai. The Service may not be used for covert recording without the participants' knowledge.
6. Mailbox integration and Word add-in
This section applies to the Word add-in and to the Gmail and Microsoft Outlook mailbox integration. These features are available to different groups: the Word add-in under Pro and Enterprise subscriptions, to both private individual and business users; the mailbox integration exclusively under an Enterprise agreement, for company (organisational) mailboxes, and not to private individuals. With respect to the Word add-in, in the case of a private individual user, Azta Kft. acts as controller; in the case of a business user, the roles are governed by the azta Pro Data Processing Agreement or by the data protection annex to the Enterprise agreement. With respect to the mailbox integration, the controller is in all cases the Enterprise Customer, and Azta Kft. acts as processor, in accordance with the data protection annex to the Enterprise agreement.
Regardless of the foregoing, in accordance with the requirements of the Google API Services User Data Policy and of Microsoft Partner Center and Microsoft Entra ID, we disclose below how we access, use, store and share Google and Microsoft user data.
6.1 Word add-in (azta for Word)
The add-in can be installed from the Microsoft Marketplace store and allows you to invoke the azta service directly from Microsoft Word. We publish the add-in under the publisher name "Azta Korlátolt Felelősségű Társaság", through Microsoft Partner Center; our publisher account has been verified by Microsoft in Partner Center. In addition to the GTC, use of the add-in software is governed by the End User License Agreement of the add-in (azta.ai/legal/word-add-in-eula).
Access to the open document. If you use the azta for Word add-in, the Service accesses the document that you currently have open in Word. For this, the add-in requests the permission defined by Microsoft as "ReadWriteDocument", which allows the open document to be read and, as described below and with your approval, modified. This differs from the handling of uploaded documents: you do not upload the document; instead, the add-in reads it from the open file. The add-in does not access your file system, your other documents, your mailbox or your calendar.
Data processed:
- the text of the open document or the part of it selected by you;
- the structural data of the document (headings, paragraph identifiers, tables);
- the questions asked of the add-in and the changes proposed by the add-in;
- technical data relating to use of the add-in (session ID, settings, the acceptance status of suggestions).
Purpose and legal basis of the processing. The purpose of the processing is to answer the question asked or to prepare the requested text change. Its legal basis is the performance of the service contract (Article 6(1)(b) GDPR). In the case of a private individual user, Azta Kft. acts as controller; in the case of a business user, as processor (see Section 0).
Writing to the document. The add-in modifies the document only after your express approval, and every change is inserted through the Word tracked changes (Track Changes) feature, so that it can be reverted. The add-in saves technical data (session ID, settings, the acceptance status of suggestions) in the settings part of the document; these remain in your file even after you have finished using the Service, and travel with the file if you share the document.
Where we process it. The content of the open document is processed by large language models, which we access through OpenRouter, Inc., in an EU-only configuration: the content is processed exclusively by model providers operating within the EU/EEA, and it does not leave for a third country. Until the transition is complete, processing may also take place on the Amazon Web Services (AWS) Bedrock service, in the eu-central-1 (Frankfurt, EU) region. In neither case does the model provider store the content (Zero Data Retention) or use it for model training.
Storage and retention. For the purpose of responding, we store the content read from the document (text and structural data) in our own database operated by Supabase, in the eu-central-1 (Frankfurt, EU) region, and delete it after 30 days. We retain the questions, responses and proposed changes (the conversation) in the same way as prompts, until the conversation is deleted, but no longer than until termination of the account. We do not store the technical data saved in the settings part of the document: they remain in your file.
The role of Microsoft. In this relationship, Microsoft is not our processor: Word and Microsoft 365 are your own services. With respect to data relating to distribution through the Microsoft Marketplace store (downloads, licence status), Microsoft acts as an independent controller, under its own data processing terms.
6.2 Mailbox integration: what we access and why
The sole purpose of the mailbox integration is to automatically identify invoices and financial documents arriving in the User's mailbox and to organise them into the workspace of the User's organisation. We do not carry out any processing beyond this purpose.
- We request read-only permission. The Service does not send, forward, modify or delete messages, and does not access the mailbox settings.
- We encrypt data in transit (TLS) and at rest; in addition, we store access tokens (OAuth refresh tokens) encrypted with a separate application key.
- The Service creates a mirrored copy of the messages received in the mailbox in the last 30 days (subject, sender, recipients, date, message body, attachments, message ID), and examines them solely by automated means in order to determine whether a given message or attachment qualifies as an invoice or a financial document.
- We store the mirrored messages and attachments in our own database operated by Supabase, in the eu-central-1 (Frankfurt, EU) region, for 30 days, after which they are automatically and permanently deleted. The mirrored copy is not an archive: we keep only a short, rolling time window for the purpose of identification. The 30-day period is aligned with the typically monthly invoicing and accounting period, so that the invoices and letters of a given month can be processed throughout that period; longer retention (for example, quarterly) is not needed. We organise the identified invoices and financial documents, and the data extracted from them, into the workspace of your organisation, and retain them for the period specified in the data protection annex to the Enterprise agreement.
- You may switch off the feature at any time and terminate the mailbox connection at any time (Settings → Integrations → Disconnect). Upon termination, we revoke and delete the stored access tokens and immediately delete all mirrored messages and attachments. Invoices already organised into the workspace are retained thereafter as well, in accordance with the Enterprise agreement.
- Access may also be revoked at any time in the security settings of the Google account or the Microsoft account.
6.3 Human access
Our staff access data originating from the mailbox only in the following four cases: (i) where the Customer (or you on its behalf) expressly requests customer support, in a documented manner, and access is necessary for that purpose; (ii) for the purpose of investigating a security incident or abuse; (iii) in order to comply with a legal obligation or a binding obligation imposed by an authority; or (iv) in aggregated, anonymised form, for internal operational purposes. In all other cases, the processing is carried out exclusively by automated means.
6.4 Compliance with the Google API Services User Data Policy. The Gmail integration uses a so-called restricted scope permission of Google (https://www.googleapis.com/auth/gmail.readonly, read-only access). azta.ai's use and transfer of information obtained through Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements applicable to restricted scope permissions. In English: “azta.ai's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.” Accordingly, we expressly declare that user data obtained through the Gmail API:
- is used solely to provide and improve the user-facing feature described in Section 6.2;
- is not used or transferred for advertising purposes, including personalised, behavioural and retargeted advertising;
- is not sold or rented;
- is not used to develop, train or fine-tune any general-purpose artificial intelligence or machine learning model, and we extend this prohibition to the processors we engage;
- is not made available for human reading, except in the four cases listed in Section 6.3;
- is transferred to third parties only to our processors referred to in Section 6.6, to the extent necessary to provide the feature.
For the use of restricted scope permissions, Google requires an independent security assessment (CASA - Cloud Application Security Assessment), which we will have carried out before the feature goes live and renew annually thereafter. A summary of the results of the assessment will be made available on request.
6.5 Microsoft mailbox integration. We access the Microsoft Outlook mailbox through Microsoft Entra ID (formerly Azure AD) authentication, exclusively with delegated permissions: Mail.Read (reading the signed-in user's own mail, read-only access), User.Read (reading the user's name and e-mail address) and offline_access (maintaining synchronisation without repeated sign-in). We do not request application permissions: the Service accesses only the signed-in user's own mailbox, on that user's behalf; it does not access other employees' mail, shared mailboxes or organisation-wide data. The provisions of Sections 6.2 and 6.3 also apply to this integration. In the case of an organisational (Microsoft 365) mailbox, the organisation's administrator may approve access in advance on behalf of the organisation; this does not connect any mailbox - each user must do that themselves, and may decline. The administrator may revoke access at any time in the Microsoft Entra admin center (Enterprise applications). In this relationship, Microsoft is not our processor but your own service provider or that of your organisation.
6.6 With whom we share it
The mirrored messages and attachments are processed, for identification and for the extraction of invoice data (optical character recognition and AI-based processing), by our processors listed in Section 4, subject to the data residency and safeguards set out in Section 4. Neither we nor our processors train models on data originating from the mailbox (Section 4). Beyond this, we do not share data originating from the mailbox with any third party, unless required by law or by a binding decision of an authority. We do not transfer data originating from the mailbox to analytics providers.
6.7 Information for senders and other data subjects. The mailbox integration necessarily also affects the data of persons who are not our users: the senders and further recipients of messages, and the persons named in invoices and financial documents. With respect to this feature, the controller is the organisation (Enterprise Customer) whose company mailbox has been connected; we act on its instructions, as processor. The legal basis of the processing is determined by the Customer (typically legitimate interest under Article 6(1)(f) GDPR), and informing the data subjects is likewise the obligation of the Customer; this section is supplementary information provided for transparency. We examine the mirrored copy of non-relevant messages solely by automated means and store it for no longer than 30 days, and human access to the data is possible only in the narrow circumstances set out in Section 6.3. The data subjects may object to the processing on grounds relating to their particular situation, and may request the erasure of data relating to them from the controller organisation; we forward requests received at info@azta.ai to the Customer concerned without delay.
6.8 Your responsibility. You may connect to the Service only a company mailbox issued by your organisation (the Enterprise Customer), with the permission of your organisation and in accordance with its rules; a private mailbox may not be connected. Please do not connect a mailbox that contains secrets protected by law - in particular attorney-client, medical or other professional secrets - if you do not have an appropriate legal basis for their processing.
6.9 Special categories of data. By its nature, a mailbox may also contain special categories of data within the meaning of Article 9 GDPR. The Service is not directed at the processing of such data: the sole purpose of the automated examination is to identify financial documents, and the mirrored copy of messages that do not meet the identification criteria is retained for no longer than 30 days and then automatically deleted. Should any such data nevertheless end up in an identified document, we will delete it within the retention period set out in the Enterprise agreement; immediate erasure may be requested by the Customer (your organisation).
7. Artificial intelligence
You are interacting with an artificial intelligence system. The azta.ai service is based on artificial intelligence: the answers to your questions are generated by an AI system. We provide this information pursuant to Article 50(1) of Regulation (EU) 2024/1689 on artificial intelligence (AI Act).
The system does not qualify as a high-risk system under the AI Act. The generated responses may be inaccurate or incomplete, and it is therefore not recommended to use them without human review. The responses do not constitute tax advice or legal advice. Detailed information on the characteristics and limitations of the system and on the possibility of human oversight is provided in the GTC.
The system does not learn from your data: the exclusion of model training set out in Section 4 extends to all AI features of the Service.
8. Data security and retention
We apply appropriate technical and organisational measures to protect your personal data against unauthorised access, use, alteration or destruction. Data are protected with AES-256 encryption at rest and TLS encryption in transit; access is role-based, following the principle of least privilege; and the operation of the system is accompanied by centralised logging and automated anomaly detection.
Our company holds a valid ISO/IEC 27001:2022 information security certification. It is important to note, however, that no method of transmission over the internet or of electronic storage provides complete security.
Personal data breach. In the event of a personal data breach, we begin remediation without delay. Where the breach is likely to result in a risk to the rights and freedoms of natural persons, we notify it to the Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) within 72 hours of becoming aware of it (Article 33 GDPR). Where the breach is likely to result in a high risk, we also inform the affected Users (Article 34 GDPR).
Retention. The retention periods for each processing operation are set out in the table in Section 2. Upon expiry of the retention period, your data will be deleted or irreversibly anonymised without separate notice. Data are removed from backups in accordance with the backup cycle, no later than 60 days after deletion.
Risk assessment. We have carried out a data protection impact assessment under Article 35 GDPR with respect to the processing of content data with the help of artificial intelligence (questions, uploaded documents, memory, dictation, Word add-in), and with respect to the meeting bot and mailbox integration features; we will finalise the latter before the features go live. We review the impact assessments at least annually and whenever there is a material change in the processing. With the measures set out in the impact assessment, the processing does not involve a high residual risk.
9. Your rights
You have the following rights:
- access to the personal data processed about you (Article 15 GDPR);
- rectification (Article 16 GDPR);
- erasure ("right to be forgotten") (Article 17 GDPR);
- restriction of processing (Article 18 GDPR);
- data portability, in a structured, commonly used and machine-readable format (Article 20 GDPR);
- objection to processing where its legal basis is legitimate interest (Article 21 GDPR);
- withdrawal of consent at any time where the legal basis of the processing is consent (Article 7(3) GDPR).
Right to object. We draw your attention to the fact that you may object at any time, on grounds relating to your particular situation, to processing based on legitimate interest - in particular to service messages, service development and abuse prevention. In that case, we will no longer process the data, unless the processing is justified by compelling legitimate grounds which override your interests, rights and freedoms.
To exercise your rights, please contact us at info@azta.ai, indicating as the subject of your request the right you wish to exercise. We will respond to your request without undue delay and in any event within 1 month; where necessary, this period may be extended by a further 2 months, of which we will inform you (Article 12(3) GDPR).
Where we have reasonable doubts concerning the identity of the person making the request, we may request additional information necessary to confirm their identity (Article 12(6) GDPR). In such a case, we will primarily ask for confirmation from the e-mail address associated with your account; we will not ask you to send sensitive identity documents.
You may request the deletion of your account at info@azta.ai.
Complaints and remedies. If you consider that the processing of your personal data infringes the GDPR, you may lodge a complaint with the supervisory authority or seek a judicial remedy. In Hungary, the competent supervisory authority is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) (website: https://naih.hu; address: Falk Miksa utca 9-11., 1055 Budapest; postal address: P.O. Box 9, 1363 Budapest; telephone: +36-30-683-5969; e-mail: ugyfelszolgalat@naih.hu). You may also lodge a complaint with the supervisory authority of the Member State of your habitual residence, your place of work or the place of the alleged infringement (Article 77 GDPR).
11. Changes to this notice
We update this notice from time to time. We publish the new version on this page and update the effective date. In the event of a material change - in particular with respect to the purposes of processing, the legal bases, sharing with third parties or data subject rights - we will notify registered Users by e-mail at least 15 days before the change takes effect.
12. Data protection contact
Azta Kft. is not required to designate a data protection officer (DPO) under Article 37 GDPR, since its core activities consist neither of large-scale, regular and systematic monitoring of data subjects nor of large-scale processing of the data referred to in Articles 9 and 10 GDPR. Data protection tasks are performed by the GRC Manager.
You may address your data protection questions to: andras.nagy@azta.ai.
13. Contact
If you have any questions regarding this notice, please contact us:
- Azta Korlátolt Felelősségű Társaság
- Company registration number: 01-09-470071
- Tax number: 32861196-2-41
- Registered office: Balance Hall building, 4th floor, Váci út 99-105., 1139 Budapest, Hungary
- Managing Director: Máté Márk
- E-mail: info@azta.ai