Legal

Privacy policy

How Gapfy collects, uses, shares and protects personal data across our website, the Gapfy Maestro platform and our products, in line with the EU General Data Protection Regulation.

Last updated: 13 July 2026

1. Who we are

This privacy policy is issued by GAPFY UNIPESSOAL LDA ("Gapfy", "we", "us"), a company incorporated in Portugal under NIPC PT 518 008 029, with registered offices at Rua de Cedofeita 451, Loja 71, 4050-181 Porto, Portugal.

For all matters relating to personal data and this policy you can contact us at privacy@gapfy.io. We have not appointed a Data Protection Officer because our processing does not meet the thresholds in Article 37 GDPR; the address above is our point of contact for data-protection requests.

2. Controller or processor

Our role depends on the data in question:

  • We are the controller of personal data we decide the purposes for: visitors to this website, people who contact us, account and identity data of the users who sign in to our products, billing contacts, and the aggregated usage analytics described in section 6.
  • We are a processor for the content that a customer organisation and its authorised users store inside a Gapfy Maestro tenant or any of our products ("Customer Data"). For that data the customer organisation is the controller and our processing is governed by our Data Processing Agreement.
  • Job applicants: when you apply for a job through a career site hosted on gapfy.io (our Gapfy Audition recruitment module), the employer that published the job is the controller of your application data (CV, cover letter, answers and status), and Gapfy processes it as that employer's processor under our Data Processing Agreement. The employer's own privacy notice governs your application. You can exercise erasure, export and restriction of your application data yourself through the privacy page linked from each career site, or by contacting the employer - see our Your data rights page.

3. The personal data we collect

  • Contact data you provide voluntarily through the contact form or by email - name, email address, company, role and the content of your message.
  • Account and identity data - your name, email address and the identifier issued by our identity provider (Microsoft Entra External ID) when you create or sign in to an account, together with the roles, permissions and paid-seat assignments given to you. Your password and any multi-factor credentials are held by the identity provider, never by us.
  • Profile data you choose to add - such as a profile picture, a short biography, a personal website or handle, and, where you provide them, your date of birth and gender.
  • Contact and address data you choose to add - postal address and phone number (a one-time code is used temporarily to verify a phone number).
  • Financial and tax data where a feature you use requires it - bank account details (such as the account holder, IBAN, BIC or SWIFT), tax or VAT number and business name, and any identity, address or bank verification documents you upload. We hold these only to operate the features you choose to use.
  • Billing data for paid subscriptions - billing name, email, address and tax identifiers, and limited payment metadata (such as card brand and last four digits). Card numbers are handled directly by our payment processor; we never store full card details.
  • Product and usage data generated when you use our products ("Customer Data") - for example links, notes, saved tabs and browser sessions in Gapfy Harmony; API requests, environments and any credentials you choose to store in Gapfy Echo (secret values are encrypted at rest on your device and, when synced, encrypted at rest on our EU infrastructure with keys we manage - they are protected in transit and in storage, but our systems can technically access them to operate the service, so treat them accordingly); repository metadata, commit and branch templates and commit activity in Gapfy Riff; timesheets in Gapfy Timesheet; bookings in Gapfy Booking; documents you upload to Gapfy DocuVault; job application data submitted by candidates through career sites in Gapfy Audition (name, contact details, CV and cover letter files, answers to application questions, optional self-declared languages and gender, and talent-pool consent - processed for the employer as described in section 2); and activity and audit logs that record actions taken in your account.
  • Aggregated usage analytics - we operate our own cookieless analytics software (Umami) on our EU infrastructure. It briefly processes your IP address and browser information to compute a salted identifier that resets every day, stores no cookies and nothing on your device, does not record your IP address, and shares nothing with any third party. See our Cookies policy for details.
  • Technical and security data collected automatically - IP address, device and browser information (User-Agent), and the server and security logs needed to operate, secure and troubleshoot the services. Authentication, single sign-on and AI-governance events record the IP address and device against your account for security and audit purposes.
  • Enterprise single sign-on data - where your organisation connects its own identity provider, we process directory identifiers such as your organisation's tenant identifier, group identifiers and email domains to route sign-in and assign roles (SSO and SCIM provisioning).

Where your organisation invites you or provisions your account (invitations, single sign-on or SCIM), we receive your name, email address and directory identifiers from your organisation and its identity provider rather than from you.

4. Why we process it and on what legal basis

We process personal data only where the GDPR gives us a legal basis to do so:

  • Performance of a contract (Art. 6(1)(b)) - to create and manage your account, provide the services you or your organisation subscribe to, and handle billing.
  • Legitimate interests (Art. 6(1)(f)) - to keep our services secure, prevent fraud and abuse, maintain and improve our products, measure audience and usage of our websites and apps with privacy-preserving, first-party analytics, and respond to your enquiries. We balance these interests against your rights.
  • Legal obligation (Art. 6(1)(c)) - to meet our accounting, tax and other statutory duties.
  • Consent (Art. 6(1)(a)) - for any optional marketing communications and for any future technology that requires it. You can withdraw consent at any time without affecting prior processing.

You are never legally obliged to provide us personal data, but some of it is needed to contract with us: without a name, email address and identity-provider account we cannot create your account, and without billing and tax details we cannot process a paid subscription (tax law also requires them on invoices). Optional data (profile details, the contact form) only enables the related feature; not providing it simply means that feature is unavailable.

5. AI features and AI processing

Some of our products offer optional, AI-assisted features - for example semantic search and organisation in Gapfy Harmony, request and test generation in Gapfy Echo, commit and diff assistance in Gapfy Riff, natural-language entry in Gapfy Timesheet, document summarisation and question answering in Gapfy DocuVault, and natural-language commands in Gapfy Maestro. These features are available only on paid AI plans, are switched on at the choice of you or your organisation, and can be turned off by a tenant administrator.

When you use an AI feature, the content needed for that feature is sent through Gapfy's own AI gateway to our AI sub-processor, Microsoft Azure OpenAI Service (Azure AI Foundry), using an EU Data Zone deployment that keeps model processing within the European Union (the service resource and data at rest are in the West Europe region). Before any content leaves our gateway it passes an automated screening step that detects and blocks common personal-data patterns and prompt-injection attempts. The content sent is limited to what the feature needs - for example a link's title and your note, an API request definition, a code diff, or your own search query - and you remain responsible for not placing third parties' personal data, secrets or credentials into AI inputs beyond what the feature requires.

We do not use, and our AI provider does not use, your content or prompts to train AI models. AI output is advisory only: it is presented to you to review and accept, and no AI feature takes an action, makes a decision with legal or similarly significant effect, or profiles you automatically. To return results quickly and avoid charging twice for the same request, AI responses may be cached for up to 24 hours, and search embeddings for up to 30 days, within the EU. For semantic search, a numerical representation (embedding) of the indexed content, together with the underlying text, is stored in an EU-based search index that is isolated per organisation and removed when the underlying item is deleted. Records we keep for AI billing and abuse prevention contain usage counts and metadata only, never the content of your prompts.

6. Cookies, analytics and similar technologies

This website uses only strictly necessary cookies and preference cookies that are set when you choose a language or theme, and it loads an anti-abuse widget from Cloudflare on pages with a form. Our web analytics (Umami, described in section 3) is self-hosted on our own EU infrastructure and sets no cookies. Full detail is in our Cookies policy.

7. Who we share personal data with

We do not sell personal data. We share it with service providers who process it on our behalf under contract, and with our payment provider Stripe, which also processes payment data as an independent controller for payment execution, fraud prevention and its own legal obligations (see Stripe's privacy policy). Our current sub-processors - including Microsoft (Azure hosting and identity, Azure OpenAI for AI features and Azure AI Search for AI semantic search), Stripe (payments), Twilio (SMS) and Cloudflare (security) - are listed in our Sub-processors page. We may also disclose data where required by law or to protect our rights, users and the public.

8. Where your data is stored and international transfers

Our infrastructure runs on Microsoft Azure in data centres located in the European Union (West Europe region), and AI processing in our default configuration also stays within the EU. Where a sub-processor processes data outside the European Economic Area, that transfer is covered by an adequacy decision or by the European Commission's Standard Contractual Clauses together with additional safeguards. The applicable mechanism for each provider is shown on the Sub-processors page. You can request a copy of the relevant Standard Contractual Clauses by writing to privacy@gapfy.io; the Commission's standard text is also published on the European Commission's website.

9. How long we keep it

We keep personal data only for as long as necessary for the purposes above:

  • Account and identity data - for as long as your account is active and, after you delete it, for the duration of the reversible grace window of our deletion lifecycle (currently 30 days), after which it is permanently deleted.
  • Contact-form data - submissions and the related notification records are deleted after 90 days; any resulting email correspondence is kept only as long as needed to handle your enquiry.
  • Verification documents (identity, address or bank documents you upload) - kept while the feature that requires them remains in use and deleted with your account.
  • Customer Data - for the duration of the customer's subscription and the return or deletion window set out in the Data Processing Agreement. Candidate application data is retained for the period configured by the employer on its career site, after which it is automatically deleted.
  • Billing and accounting records - for the period required by Portuguese tax law.
  • Security and audit logs - including authentication, single sign-on and AI-governance events that record IP address and device - for the period needed to operate, secure and evidence the services; for enterprise single sign-on this retention is configurable by the customer organisation. When an account or workspace is deleted, these records are anonymised (all personal identifiers removed); the anonymised records are kept for up to two years, or up to ten years where they support billing and usage accounting.
  • AI caches - AI responses expire within 24 hours and search embeddings within 30 days; AI usage records (counts and metadata, not content) are kept for billing and abuse prevention.

10. Abuse and fraud prevention

To protect the platform and its users, we maintain a list of email addresses that are barred from registering on Gapfy products, for example after serious abuse, fraud, or repeated violations of our terms. This list contains the email address, the reason for the block, its dates (including an optional expiry) and which administrator created the entry, and is processed under our legitimate interest in preventing abuse and fraud (Article 6(1)(f) GDPR). Entries are reviewed periodically and removed when no longer necessary.

If you believe an address was blocked in error, or wish to object to this processing, contact us using the contact details in this policy; we will review every objection individually.

11. Your rights

Subject to the conditions in the GDPR, you have the right to access your data, to have it rectified or erased, to restrict its processing, to data portability, and to withdraw consent.

Right to object: where we process your data based on legitimate interests (section 4), you may object at any time on grounds relating to your particular situation, and we will stop unless we have compelling legitimate grounds that override your rights. You may always object to direct marketing, with immediate effect.

A practical guide to exercising these rights, including the self-service options in our products, the candidate privacy page for job applicants, and how requests are routed when the controller is your employer, is on our Your data rights page. To make a request, write to privacy@gapfy.io; we respond within one month. You also have the right to lodge a complaint with the Portuguese supervisory authority, the Comissão Nacional de Proteção de Dados (CNPD, www.cnpd.pt), or with the authority in your country of residence.

12. Automated decisions

For the personal data we control, we do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. Our AI features are assistive only - they make suggestions that a person reviews and confirms - and we do not use them to profile you.

Exception - job applications: employers using our Gapfy Audition recruitment module can configure knockout questions that automatically decline applications that do not meet a stated requirement, without human review at that step. For those applications the employer is the controller: its privacy notice governs any automated screening, and you have the right to ask the employer for human intervention, to express your point of view and to contest the decision (Art. 22(3) GDPR). Gapfy provides the feature as the employer's processor.

13. Children

Our services are intended for businesses and professionals. They are not directed to children, and we do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us data, contact us and we will delete it.

14. How we protect your data

We apply appropriate technical and organisational measures, including encryption of data in transit and at rest, role-based access controls, network isolation, audit logging and least-privilege access to production systems. If a personal data breach occurs, we notify the competent supervisory authority and, where required, affected individuals, in line with Articles 33 and 34 GDPR.

15. Changes to this policy

We update this page whenever our processing changes. The date at the top reflects the most recent update. Material changes will be communicated through the services where appropriate.

16. Contact

Questions about this policy or your personal data can be sent to privacy@gapfy.io or through our contact page.