Effective: on publication
Last updated: 2026-05-18
Document key: privacy-policy
Plain-English summary
GAEZLA is an American company that runs on Cloudflare and uses Stripe for billing. We collect personal data about people who visit our marketing website and about the individuals whose information our business customers connect to the service. We do not sell personal data, do not use advertising or analytics trackers, and do not include any third-party AI provider (if you connect your own, that is between you and that provider). California residents have specific rights under the California Consumer Privacy Act, set out below. This Policy is governed by US law.
1. Who we are and how to contact us
Controller: T1P5M4RK, LLC, a Delaware limited liability company, 1111B S Governors Ave Ste 90229, Dover, DE 19904, USA.
Privacy contact: legal@t1p5m4rk.com. The privacy contact handles privacy questions, data-subject requests, and CCPA requests.
2. Scope
This Privacy Policy describes how we process personal data in connection with:
(a) Our marketing website — gaezla.com and subpages.
(b) The GAEZLA service — when business customers use our IT operations orchestration platform, we process personal data about their administrators, users, and (where configured) data the service ingests from systems in their IT estate.
It does not describe how our customers process their own end-users’ data. For that, see the Data Processing Addendum.
Governing law: This Privacy Policy is governed by the laws of the State of Delaware and the United States. GAEZLA is an American company; we do not commit to compliance with non-US privacy regimes in this document. Customers and individuals from outside the United States are welcome to use GAEZLA, but do so under US law as set out here.
3. Data we collect and why
3.1 Marketing website visitors
| Data | Purpose |
|---|---|
| IP address and request metadata (collected by Cloudflare as our CDN) | Delivering pages securely, bot management, basic network-level analytics by Cloudflare |
| Form submissions (e.g. contact form: name, email, message) | Responding to enquiries |
| No third-party analytics tags were installed on the site as of the last audit (2026-05-15). If analytics are added, this Policy and the Cookie Notice will be updated. |
3.2 Service customers (business customers and their administrators)
| Data | Purpose |
|---|---|
| Account data (company name, administrator email, billing address) | Account creation and management |
| Payment data (name, card details — handled by Stripe; we receive only a token) | Subscription billing |
| Usage and log data (API calls, agent actions, timestamps, IP addresses of authenticated requests) | Providing, securing, and improving the Service; debugging; audit trail |
| Support communications | Providing support |
3.3 Data the Service ingests from the Customer Estate
GAEZLA is an IT operations orchestration tool. When a business customer configures the Service to connect to systems in its IT estate, the Service ingests data from those systems and may execute actions on the customer’s authorisation. Data ingested may include personal data, for example:
- Directory and identity data: usernames, email addresses, group memberships, employee identifiers, last-login timestamps
- Device and asset data: hostnames, serial numbers, MAC and IP addresses, OS and software inventory
- Network telemetry: source/destination addresses, ports, protocols, connection timestamps
- System and application logs: entries that may incidentally contain identifiers, usernames, or activity data
- Configuration data extracted from systems in the customer’s estate
- Ticketing / work-item metadata where the Service integrates with a ticketing system
For all such data, the business customer is the controller and GAEZLA is the service provider acting on the customer’s instructions. The Data Processing Addendum governs that relationship. Individuals whose data appears in this data should direct rights requests to the relevant business customer; we will forward any such request we receive to the customer.
We do not require, and customers must not configure the Service to ingest, sensitive personal information (as defined under CCPA) — including health, biometric, geolocation precise to within 1,850 feet, or government-identifier data — without first agreeing additional written safeguards with us.
3.4 Bring-your-own AI integrations
GAEZLA does not send data to any AI or large-language-model provider by default. Where a customer configures a bring-your-own AI integration, all data sent to that AI provider travels directly from the customer under the customer’s own API key. We are not a party to that relationship. The customer should review the AI provider’s privacy policy independently.
4. Cookies and similar technologies
We do not use advertising cookies, cross-site tracking pixels, or third-party analytics cookies on gaezla.com. The only cookies currently active are:
| Cookie | Provider | Purpose | Type |
|---|---|---|---|
__cf_bm | Cloudflare | Bot management (essential for CDN security) | Strictly necessary |
__cflb | Cloudflare | Load balancing (session affinity) | Strictly necessary |
Because we set only strictly necessary cookies, we do not display a consent banner. If we introduce analytics or advertising cookies in future, we will update this Policy and the Cookie Notice and implement an appropriate consent mechanism.
5. How we share personal data
We share personal data only:
(a) with sub-processors listed in our sub-processor list at gaezla.com/legal/sub-processors (currently Cloudflare for infrastructure and Stripe for payments);
(b) with professional advisers (lawyers, accountants) under confidentiality;
(c) to comply with US legal obligations (court orders, subpoenas, regulatory requirements); or
(d) in connection with a corporate transaction (merger, acquisition, asset sale), subject to equivalent confidentiality protections.
We do not sell personal data. We do not share personal data for cross-context behavioural advertising.
6. Where we process data
Our infrastructure is operated by Cloudflare, Inc., a US company with a global edge network. Customer data may be processed at any of Cloudflare’s global points of presence and is stored in Cloudflare R2 object storage. We do not commit to specific regional storage; customers requiring a specific data-residency posture should not use the Service. We do not commit in this Policy to specific international-transfer mechanisms (e.g. EU Standard Contractual Clauses) — GAEZLA is an American company and does not undertake non-US legal regimes in this document.
7. Retention
We retain personal data only as long as necessary or as required by US law:
| Category | Retention |
|---|---|
| Account data | Duration of subscription + 2 years (limitation period reference) |
| Payment records | As required by US federal/state tax law (typically 7 years) |
| Service logs | 90 days rolling |
| Support communications | 3 years |
| Customer Data the Service holds as a processor | Per Data Processing Addendum — deleted within 30 days of contract end from production; within 90 days from backups |
8. Your rights
8.1 California residents (California Consumer Privacy Act / California Privacy Rights Act)
If you are a California resident, you have the right to:
- Know what personal information we collect, the purposes, and the categories of third parties we share with (this Policy provides that disclosure).
- Access specific pieces of personal information we hold about you.
- Delete personal information we have collected from you, subject to the exceptions in CCPA Section 1798.105(d).
- Correct inaccurate personal information.
- Opt out of sale or sharing — we do not sell personal information and do not share it for cross-context behavioural advertising.
- Limit use of sensitive personal information — we do not use sensitive personal information beyond the limited purposes set out in CCPA Section 1798.121(a).
- Non-discrimination — we will not deny you service, charge a different price, or provide a lower-quality service for exercising CCPA rights.
- Authorise an agent to exercise these rights on your behalf, on verified instructions.
To exercise CCPA rights, contact legal@t1p5m4rk.com. We will verify your identity using reasonable means (typically by confirming control of the email address associated with your account or by other verifiable identifiers) and respond within 45 days, extendable by a further 45 days with notice if needed.
Sensitive personal information: We do not collect sensitive personal information about California consumers other than as needed to provide the Service (e.g. account login credentials).
8.2 Other US state laws (Virginia, Colorado, Connecticut, Utah, and similar comprehensive state privacy laws)
To the extent any other US state privacy law applies to you, you have substantially equivalent rights of access, deletion, correction, and opt-out of sale/targeted advertising. Use the same contact channel above to exercise them; we will respond within the timeframes the applicable state law requires.
8.3 Other jurisdictions
This Policy is governed by US law. Individuals outside the United States may contact us with questions or requests using the address above; we will respond on a reasonable-best-efforts basis under US law. We do not undertake compliance with non-US privacy regimes in this document.
9. Security
We use Cloudflare’s global network with TLS 1.2+ in transit and AES-256 at rest. Access to production systems is restricted to the founder-engineer with hardware second-factor authentication. We patch known vulnerabilities on an expedited basis. See our Security & Trust Overview at gaezla.com/legal/security.
10. Children
The Service is intended for business customers and their adult employees. We do not knowingly collect personal information from individuals under the age of 13 (or 16 where applicable). If you believe we have done so, contact legal@t1p5m4rk.com and we will delete the data promptly.
11. Changes to this Policy
We will notify registered customers of material changes by email at least 30 days before they take effect. The “Last updated” date at the top of this page reflects the date of the last revision.
12. Contact
Privacy questions and rights requests: legal@t1p5m4rk.com.