ClientAI
Legal

Privacy Policy

Effective from 10 October 2026. Version 1.0. This is a translation; the Czech version prevails.

ClientAI is a service through which companies connect their business systems, such as NetHunt CRM or ABRA Flexi, to Claude. This policy explains what personal data we process in doing so, why, for how long and who receives it.

1Who processes the data

ClientAI s.r.o., company ID 04593189, registered office Pod Děkankou 1694/4, Nusle, 140 00 Prague 4, Czech Republic, entered in the Commercial Register kept by the Municipal Court in Prague, section C, file 250379.

Privacy contact: info@clientai.eu.

2When we are controller and when processor

We are the controller of data about the people who use ClientAI: their e-mail address, their membership in a company and records of what they did in ClientAI.

We are a processor of the data a company connects from its own systems. That data belongs to the company, which decides about it. ClientAI reads it only when a person from that company asks a question in Claude. The details are set out in a data processing agreement with the company. To exercise your rights over data held in a company's systems, please contact that company. We will gladly help it respond.

3What data we process

E-mail address from sign-in

Source
signing in with a Google account to the administration, or when connecting the connector in Claude
Purpose
verifying who you are and which company's data you may read
Legal basis
performance of the contract with the company you work for, and our legitimate interest in securing the service
Retention
for as long as you are a member of a company in ClientAI

Membership and role

What
e-mail, company, role (owner or member), who created the membership and when
Purpose
access control: who may access which company and what they may change
Legal basis
performance of the contract with the company
Retention
until the membership is removed or the contract with the company ends

Credentials for the company's systems

What
for NetHunt the account e-mail and API key, for ABRA Flexi a user name and password, and the system's address
Purpose
letting ClientAI read from the system on the company's instructions
How
encrypted with AES-256-GCM, decrypted only at the moment of a call and never displayed in the administration
Retention
until the company deletes the connection or the contract ends

Data from the company's systems

What
the records Claude asks for, such as companies and deals from a CRM or documents from accounting; these may contain personal data of the company's contacts
Purpose
answering the question a user asked in Claude
Retention
not stored. ClientAI passes the data to Claude as the answer and discards it. A list of records from a NetHunt folder is kept in memory for at most 60 seconds to avoid repeated requests to the system.

Call log

What
the user's e-mail or the API token's name, time, tool, which connection, whether the call succeeded, how long it took and any error text; the question itself and the returned data are not in the log
Purpose
usage overview for the company, troubleshooting and security
Legal basis
performance of the contract with the company and our legitimate interest in securing the service
Retention
for the term of the contract with the company, then deleted

Administration change log

What
who changed what and when, such as adding a member or a connection; password and key values are never in the log
Purpose
traceability and security
Legal basis
our legitimate interest in securing the service
Retention
for the term of the contract with the company

Sign-in tokens

What
tokens Claude uses to authenticate to ClientAI, and the company's API tokens; we store only a hash, never the token itself
Purpose
keeping the connector signed in without signing in for every question
Retention
access tokens expire after one hour, refresh tokens after 30 days; API tokens until revoked

Server logs

What
IP address, time, requested address and browser identification
Purpose
operation, troubleshooting and protection against attacks
Legal basis
our legitimate interest in operating and securing the service
Retention
for the ClientAI service, 30 days in Google Cloud Logging; for the website www.clientai.eu, according to Cloudflare's policies, typically a few days

ClientAI also has operational tasks, such as a morning summary. They are not in operation yet. Before we enable them, we will add the data they process to this policy.

We do not use data from the ClientAI service for advertising, we do not sell it and we do not train any artificial intelligence models on it. We do not carry out automated decision-making or profiling.

4Data from your Google account

When you sign in with Google, ClientAI requests only the openid and email scopes. The one thing it receives from your Google account is your verified e-mail address.

  • We use the e-mail address only to verify who you are and to find which company in ClientAI you belong to.
  • We have no access to Gmail, Drive, Calendar, contacts or any other data in your Google account.
  • We do not store Google access tokens. We discard them once the e-mail address is verified.
  • We do not share data from your Google account with third parties, use it for advertising, or train artificial intelligence models on it.

ClientAI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How Google user data is stored, kept and deleted

  • Stored: your e-mail address only, in ClientAI's database in the EU (Google Cloud, Belgium), as part of your membership in a company.
  • Kept: for as long as you are a member of a company in ClientAI.
  • Deleted: when your company's owner removes you, your membership and sign-in tokens are deleted immediately and your access ends. Your address then remains only in the call log and the administration change log, which we delete when the contract with your company ends. On request we delete it within 30 days, unless a record is needed to protect the service or by law.
  • How to ask for deletion: write to info@clientai.eu from the address you sign in with. You can also revoke ClientAI's access at any time in your Google account under Security, Third-party apps with account access.

5Who receives the data

  • Google Cloud (Google Cloud EMEA Limited, Ireland) runs ClientAI's servers, database and backups as our processor. Sign-in with Google is provided by Google Ireland Limited.
  • Cloudflare (Cloudflare, Inc., USA) hosts the website www.clientai.eu and, when you visit it, processes your IP address and technical request data to deliver the page and protect it against attacks. ClientAI service data does not pass through Cloudflare.
  • Google (Google Ireland Limited) measures visits to the website www.clientai.eu through Google Tag Manager, only if you consent. ClientAI service data never enters this measurement.
  • Anthropic, the provider of Claude: data from a company's systems that a user asks for in Claude is passed by ClientAI to Claude as the answer. This transfer happens on the user's instruction and is governed by the user's company's agreement with Anthropic, not by an agreement with us.
  • Public authorities, where the law requires it.

We do not share data with anyone else.

6Where the data is stored

ClientAI's database, backups and servers are in the European Union, in the Google Cloud region europe-west1 in Belgium. Where Google as the cloud provider processes some data outside the EU, for example for support, it does so under the European Commission's standard contractual clauses.

The website www.clientai.eu is delivered by Cloudflare's global network, so technical data about website visits may also be processed outside the EU, likewise under standard contractual clauses.

7Security

  • All communication is encrypted with TLS.
  • Each company's data is separated. The database enforces the separation on every row, so even an application bug cannot expose another company's data.
  • Credentials for companies' systems are encrypted with AES-256-GCM and never displayed in the administration.
  • The tools available to Claude can only read. They never write to a company's systems.
  • The administration is accessible only through a Google account with explicitly granted access.

8This website and cookies

The website www.clientai.eu is hosted by Cloudflare. We measure website visits with Google tools managed through Google Tag Manager, such as Google Analytics.

  • Consent: measurement and marketing cookies are set only if you click Accept in the banner on the website. Without consent, measurement is off and Google may receive only an anonymous, cookieless signal that a page was visited (Google Consent Mode).
  • What is measured: pages visited, where you came from, device and browser type, approximate location derived from the IP address, and time of the visit.
  • Retention: Google Analytics cookies last at most 2 years; data in Google Analytics is kept for at most 14 months.
  • Changing your choice: you can withdraw or give consent at any time with the Cookie settings link in the footer of every page.
  • Legal basis: your consent. Technical data strictly needed to deliver the page is processed by Cloudflare based on our legitimate interest.

If Cloudflare considers a visit suspicious, it may set a strictly necessary security cookie. The ClientAI administration uses strictly necessary cookies from Google Identity-Aware Proxy to keep you signed in.

9Your rights

You have the right to access your data, to have it corrected or erased, to restrict its processing and to data portability. You may object to processing based on legitimate interest. Write to info@clientai.eu and we will respond within one month.

If you disagree with how we handle your data, you may lodge a complaint with the Czech Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, uoou.gov.cz.

10Changes to this policy

When we change this policy, we publish the new version on this page with its effective date. We notify the companies using ClientAI of material changes by e-mail in advance.