Effective date: June 1st 2026
1. Who is responsible
sAi is provided by IntSec.NET — Interactive Systems & Security di Alessio Bravi, Via Luigi Pirandello 15, 06012 Città di Castello (PG), Italy, VAT IT02517950545.
For a customer organisation's contact, territory and sales information, that organisation normally decides why and how the information is used and acts as data controller; IntSec.NET acts as its service provider or processor under the applicable agreement. IntSec.NET is responsible for information used to operate accounts, deliver support, secure the service and answer website or commercial enquiries.
2. Information sAi processes
- Account information: name, work email, organisation, role, authentication and security information.
- Business information: professional contacts, workplaces, contact methods, interests, availability, territories, appointments, notes and activity history entered or imported by authorised users.
- Public-directory information: professional identities, workplaces and business contact details gathered from publicly accessible web sources so users can discover a contact and choose whether to import an editable copy into their own address book.
- Location and planning information: a position or chosen map point when a user asks to find nearby opportunities or plan a route.
- Assistant information: questions, replies and, when the user enables storage, voice recordings. Audio remains in the sAi environment and follows the service's automatic retention controls.
- Service and support information: security events, diagnostic records, device/browser details and communications with support.
3. Google information
sAi provides two separate Google features, each started by the user:
- Google sign-in receives the Google account's basic identity information, including name and email, to sign an existing invited sAi user into the correct account. Google sign-in does not create an sAi account automatically.
- Google Calendar connection reads the user's calendar list so the user can choose a calendar; creates and manages the dedicated “sAi Visits” calendar when requested; and reads, creates, updates or removes calendar events as needed to keep field visits and the selected calendar in step.
Calendar information may include calendar names and identifiers, event identifiers, titles, start and end times, change status and synchronization information. sAi stores an encrypted authorization credential so synchronization can continue while the user is not actively using the app. If the user selects a personal calendar instead of a dedicated sAi calendar, existing event information from that calendar can be mirrored into sAi to show busy time and avoid planning conflicts. sAi recommends a dedicated calendar to keep work visits separate.
Google information is used only to provide the sign-in and calendar features the user requests, maintain security, and resolve service problems. It is not sold, used for advertising, used to build advertising profiles or made available to other sAi organisations.
sAi's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
4. Why information is used
Information is processed to:
- provide maps, availability, contact management, routes, visits, calendars and team coordination;
- provide the public professional directory and user-controlled import into a personal or organisational address book;
- answer user questions and perform user-confirmed assistant actions;
- authenticate users, apply roles and protect each organisation's information;
- provide support, maintain reliability, prevent abuse and investigate security events;
- meet legal, accounting and contractual obligations.
The legal basis depends on the relationship and purpose: performance of the service contract, the customer organisation's instructions, legitimate interests in providing and securing the service, compliance with law, and the user's authorization where a connected service is optional.
5. Sharing and service providers
Information is disclosed only when needed to provide or protect sAi, comply with law, or follow the customer organisation's valid instructions. This may include hosting and infrastructure suppliers, Google for the user-requested Google features, and the provider used to answer assistant text requests. Voice audio is processed within the sAi environment and is not sent to the external assistant provider.
Providers are limited to the information needed for their task and are subject to contractual and security safeguards. IntSec.NET does not sell sAi customer information. Private data added and managed by an individual account or customer organisation remains confidential to that same entity and is not shared with another customer organisation. Public-directory records originate from publicly accessible sources and remain distinct from those private records.
6. Retention and deletion
- Customer business information is kept while the account or service relationship requires it, subject to user deletion, organisational policy, contractual retention and legally required records.
- Assistant conversations and stored voice messages follow the service's short automatic retention period; stored voice is also removed when the user switches audio storage off.
- Security and audit records may be retained for accountability, recovery and legal obligations.
- Google credentials and mirrored busy-time information are kept while Calendar remains connected.
Disconnecting Google Calendar asks Google to revoke the grant and removes the stored credential and mirrored busy-time information from sAi. Existing sAi appointments remain in sAi, and visit events already written to Google Calendar remain there so the user does not unexpectedly lose their calendar history; the user can delete those events in Google. Deleting an sAi visit while connected also removes its linked Google event when the service can reach Google.
7. Security
sAi uses organisational separation, role-based access, protected sessions, encrypted Google credentials, activity records and controlled service access. No online service can promise absolute security, so users should protect their credentials and report suspected access promptly.
8. User choices and rights
Depending on applicable law, individuals may request access, correction, deletion, restriction, portability or objection, and may complain to a data-protection authority. Some requests concerning business records must be handled by the customer organisation that controls them.
- Google Calendar can be disconnected from sAi Account settings.
- Google access can also be reviewed or revoked from the user's Google Account permissions.
- Users can delete supported records in the product or ask their organisation or sAi support for assistance.
9. Public website
This public website is static. It does not use analytics, advertising pixels or marketing cookies. Opening an email link uses the visitor's chosen email application. The separate sAi application uses strictly necessary security and session cookies after a user interacts with sign-in.
10. Contact and updates
Privacy and deletion requests: info@intsec.net
Product support: support@intsec.net
This policy may be updated when the service or legal requirements change. The effective date above identifies the current version.