Effective: 2026-08-08
Plain-English summary
GAEZLA is an American company running on Cloudflare, with Stripe for billing. We collect the minimum needed to run the site and the service, set no cookies on gaezla.com, use no analytics or advertising trackers, and sell nothing about you. Data our business customers connect to the service belongs to them; we process it on their instructions under the Data Processing Addendum. This Policy is governed by US law.
1. Who we are
Controller: T1P5M4RK, LLC, a Delaware limited liability company, 1111B S Governors Ave Ste 90229, Dover, DE 19904, USA. Privacy contact (questions and rights requests): info@gaezla.com.
Governing law: this Policy is governed by the laws of Delaware and the United States. We do not undertake compliance with non-US privacy regimes in this document; customers subject to such regimes are responsible for their own assessment and may negotiate separate written terms.
2. Data we collect and why
Website visitors (gaezla.com): IP address and request metadata, processed by Cloudflare as our CDN to deliver pages securely and manage bots; and whatever you submit through the contact form (name, email, message), used to respond.
Service customers: account data (company name, contact name and email, billing address) for account management; payment data handled by Stripe — we receive only a token, never card numbers; usage and log data (API calls, agent actions, timestamps, IPs of authenticated requests) to provide, secure, and debug the Service; and support communications.
Data the Service ingests from a customer’s IT estate: GAEZLA is an IT operations tool. When a business customer connects its systems, the Service ingests data that may include personal data — usernames, email addresses, group memberships, device and network identifiers, log entries, configuration, and ticketing metadata. The business customer is the controller of that data; we process it only on their instructions under the DPA. If your data appears there, direct rights requests to that business; we forward any we receive. Customers must not configure the Service to ingest sensitive personal information (as defined by the CCPA) without agreeing additional written safeguards with us.
Bring-your-own AI integrations: we send nothing to any AI provider by default. Where a customer connects their own AI provider under their own key, that transfer is between the customer and that provider.
3. Cookies
gaezla.com sets no cookies and runs no analytics, advertising, or tracking scripts, so no consent banner is shown. Your theme preference is kept in your browser’s localStorage and never leaves your device. During payment you are on Stripe’s checkout pages (checkout.stripe.com), where Stripe sets its own cookies under Stripe’s privacy policy. If we ever introduce non-essential cookies, we will update this Policy and add a consent mechanism first.
4. Sharing
We share personal data only with the sub-processors listed at /legal/sub-processors (currently Cloudflare for infrastructure, Stripe for payments); with professional advisers under confidentiality; to comply with US legal obligations; or in a corporate transaction under equivalent protections. We do not sell personal data and do not share it for cross-context behavioural advertising.
5. Where data is processed
Our infrastructure is Cloudflare’s global network; data may be processed at any of its points of presence and is stored in Cloudflare R2. We do not commit to regional storage or to specific international-transfer mechanisms; customers requiring a data-residency posture should not use the Service.
6. Retention
| Category | Retention |
|---|---|
| Account data | Subscription + 2 years |
| Payment records | As US tax law requires (typically 7 years) |
| Service logs | 90 days rolling |
| Support communications | 3 years |
| Customer Data held as a processor | Per the DPA: deleted within 30 days of contract end (production), 90 days (backups) |
7. Your rights (US residents)
California residents have the CCPA/CPRA rights to know, access, correct, and delete personal information, to opt out of sale or sharing (we do neither), to limit use of sensitive personal information (we collect none beyond login credentials), to non-discrimination for exercising rights, and to use an authorised agent. Residents of other states with comprehensive privacy laws have substantially equivalent rights. To exercise them, email info@gaezla.com; we verify identity by reasonable means (typically control of the account email) and respond within 45 days, extendable once by 45 days with notice. Individuals outside the US may use the same address; we respond on a reasonable-efforts basis under US law.
8. Security
TLS 1.2+ in transit, AES-256 at rest, production access restricted with hardware-key MFA, expedited patching. Details: /legal/security.
9. Children
The Service is for businesses and their adult users. We do not knowingly collect personal information from children under 13; if you believe we have, contact info@gaezla.com and we will delete it promptly.
10. Changes
We notify registered customers of material changes by email at least 30 days before they take effect; the effective date above reflects the latest revision.
