Legal
Irelia Privacy Policy (Personal Data Processing Notice)
Automation Genius By KDL — Notice pursuant to Art. 13 of Regulation (EU) 2016/679 (GDPR)
Version 1.0 dated 16 September 2026
0. Controller and contacts
The controller is Automation Genius By KDL, a sole proprietorship of Kristian Di Lillo, VAT no. IT02789630692, with registered office at Contrada Santa Maria Maggiore 4, 66011 Bucchianico (CH), Italy, owner of the Irelia trademark and commercial brand (hereinafter “Irelia”).
For any request relating to personal data, including the exercise of the rights described in section 8, write to info@irelia.ai. For formal communications: certified email (PEC) nextwaveai@pec.it.
1. Who this notice is for
1.1 This notice describes the processing for which Irelia is the controller, i.e. decides the purposes and means. It concerns:
- Partners: the businesses and professionals that purchase access to the Irelia Platform, and their contact persons (section 2);
- Affiliates: those who join Irelia’s affiliate marketing programme (section 3);
- Platform Users: the natural persons holding access credentials to the Platform, as administrators or staff members of a Partner or of one of its Clients (section 4);
- those who send Irelia a contact request through the website or other channels (section 5).
The same person may fall within more than one category: in that case the relevant sections apply.
1.2 Workspace data. The data processed within the Platform’s Workspaces — contacts, conversations with End Users through the AI Agents, uploaded content, bookings — are not covered by this notice. For such data Irelia acts as a processor on behalf of the Partner or, through the Partner, of the Client for which the Workspace is configured, under the data processing agreement (DPA) published at https://irelia.ai/legal/dpa. The purposes and manner of such processing are determined by the Workspace controller and described in its own privacy notice.
The same applies to the account and subscription data of the Partners’ Clients registered on the Platform: Irelia processes them on behalf of the Partner, which is their controller, and requests concerning them must be addressed to the Partner.
1.3 End Users. Anyone who has conversed with an AI Agent on WhatsApp, Instagram, Facebook Messenger or webchat will not find here the notice that concerns them: the controller of their data is the business or professional they conversed with, which provided them with its own privacy notice. Requests received by Irelia in relation to such data are forwarded to the Partner concerned, with acknowledgement of receipt within five working days.
1.4 Cookies. The use of cookies and similar technologies on the irelia.ai website is described in the cookie policy, available on the website.
2. Partners
2.1 Data processed
Irelia processes the data that the Partner provides upon registration and during the relationship, and those generated by the use of the Platform:
(a) identifying and tax data of the Partner and of its contact person: company name or name, address, VAT number and tax code, SDI recipient code or PEC for electronic invoicing, name and role of the contact person; (b) contact data: Account email address, telephone number, contact details used for ordinary communications, including the dedicated WhatsApp group set up with the Partner; (c) payment data: the payment method is registered with Irelia’s payment service provider, indicated in section 7, which processes the full data; Irelia receives and retains only the outcome of the operations, the transaction identifiers and the elements needed to recognise the registered method; (d) contractual and billing data: Plan, Credits purchased and consumed, invoices, history of acceptances of the contractual documents with date, time and version; (e) Account usage data: access and operation logs, results of the automatic validation of the AI Agents’ configurations (Config-gate), suspension and restoration events, communications with support.
2.2 Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| (a) Management of registration, of the trial period and of the Account; delivery of the Platform; support; communications relating to the relationship, including changes to the contractual documents and to the Sub-processor list | Performance of the contract and of pre-contractual measures requested by the Partner — Art. 6(1)(b) GDPR |
| (b) Electronic invoicing, tax and accounting obligations | Legal obligation — Art. 6(1)(c) GDPR |
| (c) Security of the Platform, prevention of non-compliant uses, verification of compliance with the contractual documents, retention of Config-gate results and logs as evidence, incident management, protection of Irelia’s rights in the event of complaints or disputes | Irelia’s legitimate interest — Art. 6(1)(f) GDPR |
| (d) Sending to the Partner, from registration and including the trial period, at the Account email address, communications on news, features and offers relating to the Platform | Irelia’s legitimate interest — Art. 6(1)(f) GDPR and Art. 130(4) of Italian Legislative Decree no. 196/2003; the Partner may object at any time through the link in each communication or by writing to info@irelia.ai |
Providing the data for purposes (a) and (b) is necessary: without them the Account cannot be created and the Platform cannot be delivered. Purpose (d) does not condition the relationship.
2.3 Retention
| Data | Period |
|---|---|
| Identifying, contact, contractual and payment data (2.1 a-d) | Invoices, tax data and payment history: 10 years from the issue date of each tax document (Art. 2220 of the Italian Civil Code); the others, 24 months from the termination of the Agreement, the period during which the Partner retains access to the export and erasure functionalities for Workspace data (DPA, Art. 10.4) |
| Access and operation logs | Up to 12 months from the generation of each record; beyond that, only if necessary for an ongoing incident, dispute or audit, until its closure |
| Config-gate results, suspension events and communications with support | Duration of the relationship and the following 24 months; beyond that, only if necessary for an ongoing dispute or audit |
| Data used for purpose (d) | Duration of the relationship and the following 12 months, unless an earlier objection is made |
After these periods, the data are erased or anonymised.
3. Affiliates
3.1 Data processed
Irelia processes the data of those who join the affiliate marketing programme:
(a) identifying and tax data: name or company name, address, VAT number and tax code, SDI recipient code or PEC for electronic invoicing; (b) contact data: account email address, contact details provided; (c) programme data: affiliate link, attributed conversions and their status, fees accrued, withdrawal requests, invoices issued to Irelia; (d) bank details indicated in the invoice issued to Irelia, used for the payment of fees by bank transfer.
3.2 Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| (a) Management of programme membership, attribution of conversions, calculation and payment of fees, communications relating to the relationship | Performance of the contract — Art. 6(1)(b) GDPR |
| (b) Receipt and recording of invoices, tax and accounting obligations | Legal obligation — Art. 6(1)(c) GDPR |
| (c) Prevention of programme abuse (self-referrals, artificial conversions), security, protection of Irelia’s rights | Irelia’s legitimate interest — Art. 6(1)(f) GDPR |
Providing the data for purposes (a) and (b) is necessary: without them it is not possible to join the programme or receive the fees.
3.3 Retention
| Data | Period |
|---|---|
| Tax data, invoices, fees and bank details (3.1 a, c, d) | 10 years from the issue date of each tax document (Art. 2220 of the Italian Civil Code) |
| Contact data and programme data not relevant for tax purposes | Duration of the relationship and the following 12 months |
| Access and operation logs | Up to 12 months from the generation of each record |
The attribution of conversions is based on an identifier stored in the browser of visitors who reach the website through the affiliate link, for three months; this technology is described in the website’s cookie policy.
4. Platform Users
4.1 Who they are
The natural persons to whom a Partner, or one of its Clients for its own Workspace, has assigned access credentials to the Platform: administrators, staff members, operational personnel. The User is not a party to the contract between Irelia and the Partner. This section is made available at first access.
4.2 Data processed
(a) identifying and access data: name, email address, credentials (stored in protected form) or identifier received from the third-party authentication service chosen by the User; (b) role and permissions assigned by the Partner or by the Client, including the permission to view End Users’ identifying data; (c) access and operation logs of the actions performed in the Platform, with date, time and IP address.
The data of the Workspaces the User accesses and operates in are not covered by this section: they are processed by Irelia on behalf of the Workspace controller (section 1.2).
4.3 Purposes and legal basis
Irelia processes Users’ data to manage and protect the access to the Platform requested by the Partner or by the Client: creation and verification of credentials, application of permissions, security, traceability of operations, service communications relating to access. The legal basis is the legitimate interest of Irelia and of the Partner in secure and traceable access (Art. 6(1)(f) GDPR). The User cannot object to the processing without giving up access, because the processing is inseparable from access itself.
The Partner, or the Client inviting the User, is obliged to inform the User of this processing; Irelia in any event makes this notice available at first access.
4.4 Retention
| Data | Period |
|---|---|
| Identifying data, credentials, role and permissions | Until the credentials are removed by the Partner or by the Client; after the termination of the Agreement with the Partner, for the 24 months during which the export and erasure functionalities for Workspace data remain accessible (DPA, Art. 10.4) |
| Access and operation logs | Up to 12 months from the generation of each record; beyond that, only if necessary for an ongoing incident, dispute or audit |
5. Contact requests
5.1 Data processed
Those who contact Irelia through the website form, by email or through other channels provide their name, business, email address, telephone number where applicable, and the content of the request.
5.2 Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| (a) Responding to the request and managing the contact | Pre-contractual measures taken at the request of the data subject — Art. 6(1)(b) GDPR |
| (b) Forwarding the request, at Irelia’s discretion, to a Partner delivering AI Agent-based services, when the request concerns such services | Legitimate interest of Irelia and of the data subject in directing the request to whoever can fulfil it — Art. 6(1)(f) GDPR |
| (c) Sending promotional communications about Irelia and the Platform, where the data subject has requested this in the contact form or otherwise | Consent — Art. 6(1)(a) GDPR and Art. 130 of Italian Legislative Decree no. 196/2003; revocable at any time through the link in each communication or by writing to info@irelia.ai |
After the forwarding referred to in letter (b), the Partner processes the data received as an independent controller, in accordance with its own privacy notice; Irelia keeps a record of the forwarding. The forwarding imposes no obligation on the data subject towards the Partner. Anyone who does not wish their request to be forwarded may indicate this in the request or by writing to info@irelia.ai.
Without the consent referred to in letter (c), Irelia does not send promotional communications to those who have submitted a contact request.
5.3 Retention
| Data | Period |
|---|---|
| Request and contact data (purposes a and b) | 12 months from the last contact or from the forwarding to the Partner |
| Data processed for purpose (c) | Until consent is withdrawn and in any event 24 months from the last interaction |
6. Google Calendar integration
6.1 Why this section. The AI Agents’ appointment booking feature can connect a Google calendar. The connection is made by the Workspace controller with its own Google account: the calendar data are Workspace data, which Irelia processes on its behalf in accordance with the DPA (section 1.2). This section is published because Google requires that the use of data received from its APIs be described in a privacy notice at a public address.
6.2 Compliance with the Google policy. Irelia’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
6.3 Authorisation. The Workspace controller authorises the connection through Google’s OAuth 2.0 flow and may revoke it at any time from the Platform or from the permissions page of its own Google account (myaccount.google.com/permissions).
6.4 Data accessed. Email address and basic profile information of the Google account; list of calendars and related metadata (names, time zones); calendar events, including titles, dates, times, durations, attendees, descriptions and status.
6.5 Use. The data are used exclusively for booking and managing appointments through the AI Agents, on behalf of the Workspace controller: (a) reading events to determine availability; (b) creating, updating and deleting events to reflect bookings made in chat; (c) detecting changes made directly on the calendar to keep the booking records aligned; (d) sending pre-appointment reminders. The data are retrieved on demand at each interaction and are neither bulk-downloaded nor replicated beyond what is necessary for the booking.
6.6 Sharing. Calendar data are processed by Irelia’s Sub-processors indicated in the section dedicated to Workspace data of the Sub-processor List published at https://irelia.ai/legal/subprocessors, bound by data processing agreements, and by no other party: (a) cloud infrastructure providers for the serverless processing of calendar operations; (b) database and application platform providers, where the booking records and, in encrypted form, the OAuth tokens are stored; (c) language model providers — currently OpenAI, Anthropic, Google Cloud (Vertex AI) and Amazon Web Services for the DeepSeek models run on AWS Bedrock; the up-to-date list is in the List — which receive, for each individual interaction, exclusively the availability in summary form (free and bookable time slots) and only the elements of the event needed to process the booking request or the reminder. Before sending to the model providers, the identifying data known to the Platform — name, telephone number, email address — are replaced with placeholders and reconstituted only in Irelia’s systems; such providers retain the data received only for the limited time provided for in their respective API terms, indicated in the List, and contractually guarantee that the data received through their APIs are not used to train, improve or develop artificial intelligence models or for any other purpose unrelated to the request. Calendar data are not sold, assigned or shared with third parties for advertising purposes or for purposes unrelated to appointment booking.
6.7 Prohibited uses. The data received from Google APIs are used exclusively to provide and improve the user-facing appointment booking and management features, including pre-appointment reminders sent on behalf of the Workspace controller. Under no circumstances are they used for advertising, marketing, profiling, training of artificial intelligence models, creditworthiness assessment, data brokering or any other purpose unrelated to such features.
6.8 Security and human access. OAuth tokens are stored in encrypted form; transmissions with Google APIs take place over encrypted connections (TLS); access to calendar data is limited to the automated systems that perform the booking operations. No member of Irelia’s staff accesses calendar data in ordinary operations; human access takes place only upon the Workspace controller’s request for support, for security reasons or to manage an incident, or when required by law. The measures are described in the DPA, Art. 14.
6.9 Retention and erasure. OAuth tokens are retained exclusively for the duration of the connection and erased when the Workspace controller revokes it or upon termination of the Agreement with the Partner. Booking records follow the retention periods for Workspace data set out in the DPA, Art. 10, and may be erased by the Workspace controller at any time through the Platform. Erasure requests may also be sent to info@irelia.ai.
7. Recipients and transfers
7.1 Processors. The data covered by this notice are processed, on behalf of Irelia and on its instructions, by the processors indicated in the section “Recipients of data for which Irelia is the controller” of the Sub-processor List, published at https://irelia.ai/legal/subprocessors, which sets out for each of them the entity, service, data processed, country and transfer mechanism: cloud infrastructure and database, email sending, electronic invoicing.
7.2 Independent controllers. The following process the data for their own purposes and in accordance with their own privacy notices: (a) the payment service provider, indicated in the List, for the execution of Partners’ payments, fraud prevention and its own legal obligations; (b) Meta, for the data of the communications exchanged through the WhatsApp groups set up with Partners; (c) the Partners to which contact requests are forwarded (section 5); (d) Irelia’s tax and legal advisers, bound by professional secrecy; (e) public authorities, where required by law.
7.3 Transfers outside the EU. Some providers process data in the United States, as indicated in the List. Transfers take place on the basis of the standard contractual clauses adopted by the European Commission (Decision (EU) 2021/914, Art. 46(2)(c) GDPR) incorporated in the contracts with the providers; where the provider is certified under the EU-US Data Privacy Framework, the List indicates this as an additional safeguard. A copy of the clauses may be requested from info@irelia.ai.
7.4 No sale. Irelia does not sell or assign data to third parties for the latter’s own advertising purposes.
8. Data subject rights
8.1 Anyone affected by the processing described may exercise, by writing to info@irelia.ai, the rights provided for in Arts. 15-22 GDPR: access to the data, rectification, erasure, restriction of processing, portability of the data provided and processed on the basis of the contract, objection to processing based on legitimate interest — in particular to promotional communications, at any time and without giving reasons — and withdrawal of consent, without affecting the processing already carried out. Irelia replies within thirty days, extendable in the cases provided for in Art. 12(3) GDPR, and may request information to verify the identity of the requester.
8.2 Complaint. The data subject may lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it) or with the supervisory authority of the Member State in which they reside or work.
8.3 Automated decisions. Irelia does not take, on the data covered by this notice, decisions based solely on automated processing that produce legal effects or similarly significantly affect the data subject (Art. 22 GDPR). The automatic validation of the AI Agents’ configurations operates on the configuration, not on the person, and can be repeated after correction.
8.4 Requests relating to Workspace data. Requests from those who have conversed with an AI Agent are handled as indicated in section 1.3.
9. Updates
9.1 This notice is published at https://irelia.ai/legal/privacy with a version number and date, and may be updated as the processing, the providers or the legislation change. Previous versions remain available on request. This notice is published in Italian and in English; in the event of discrepancy, the Italian version prevails.
9.2 Updates that introduce new purposes or new recipients are communicated to Partners and Affiliates at the Account email address before the processing begins; for other updates, publication is authoritative.