Privacy Policy
1. Who we are
Triscale GTM AI Agents is operated by Triscale, registered with the Dutch Chamber of Commerce (Kamer van Koophandel) under number 95199101, with its registered office at Jacob van Lennepstraat 263 B, 1053 JE Amsterdam, the Netherlands. We act as the data controller for account data, and as a data processor for the business content our customers bring into the service through the tools they connect. Questions about this policy: thibault@triscale.co.
2. What this policy covers
This policy covers the web application at gtmaiagents.triscale.co, the agent runs it performs, and the data read from the third party tools a customer connects. It does not cover those third party tools themselves, which have their own policies.
3. Data we process
Account data
Name, email address, hashed password, role, the company details a customer fills in (name, sector, website, contact emails, logo, social profiles), plus language, currency and interface preferences.
Data read from connected tools
Only the tools a customer explicitly connects, and only within the scopes granted:
- Fathom (scope public_api): meeting recording metadata, transcripts, summaries, action items, and the names, email addresses and domains of attendees.
- Cal.com (scope BOOKING_READ): upcoming bookings, their titles, description, times, attendees and the video call link, so the brief can offer a button to join.
- Google Calendar (scope calendar.events.readonly): the title, description, times, attendees and video call link of your upcoming events, read only. We never create, modify or delete an event. This data is used to prepare the meeting brief and to offer a button to join the call, is stored on our own server in Paris, France, is never sold, never shared for advertising, and never used to train a model.
- Notion (no scope: you choose the pages you share): the text of those pages, read only, to build the GTM context the agents read before writing.
- Google Drive (scope drive.readonly): read only. You designate the folders we may read, in the application; until you do, we look for a folder whose name contains Triscale or GTM context. We copy the text of the documents in those folders and their subfolders into your GTM context, at most 300 files per import, and ignore the rest of your Drive. We never create, modify or delete a file. This text is stored on our own server in Paris, France, is never sold, never shared for advertising, and never used to train a model.
- HubSpot (scopes oauth, crm.objects.contacts.read, crm.objects.companies.read, crm.objects.deals.read): contacts, companies, deals, amounts, stages and last activity dates. Read only. We never write to a customer CRM.
- Gmail (scopes gmail.send, gmail.readonly, openid, email). gmail.send sends a draft that a human read and approved in the application, from your own address so that replies come back to you. gmail.readonly searches threads with a known prospect (a meeting attendee or a deal contact): we read subject, date, direction and a short excerpt, pass that excerpt to the agent for that run, and do not copy messages into your GTM context or list your mailbox as a whole. Excerpts may appear in the run trace you can audit. The openid and email scopes serve only to know which address is authorised, so we can show it to you before you send. Nothing read through this connector is sold, shared for advertising, or used to train a model.
- Slack (scope incoming-webhook): posting only, into the single channel you choose on Slack's own authorization screen. This connector reads nothing: no message, no channel list, no member list, no file. We post notifications about your own activity, such as how many drafts are waiting, that a connector stopped responding, and the Monday recap. We never post the content of a draft, only counts and a link back to the application.
- Brevo (scopes account:read, contacts:read, transactional.email:write): account information, contacts and lists. The write scope is used for one thing only, sending a draft that a human read and approved in the application.
Content generated in the service
Drafts produced by agents and the edits made to them, run traces (tool calls, their inputs and outputs, errors, token counts), meeting notes, and the context documents a customer uploads or writes: positioning, ICP, scripts, pricing, customer stories, and samples of real emails used to capture the founder's voice.
Technical data
Server logs needed to operate and secure the service. We run no analytics, no advertising and no third party tracking on this site.
4. Why we process it
To provide the service the customer signed up for: reading the sources an agent needs, generating drafts, letting a human review them, and sending the ones a human approved. To operate, secure and debug the platform. To send service emails such as run failure alerts and the weekly digest, when they are enabled. The legal basis is the performance of our contract with the customer, and our legitimate interest in keeping the service secure and working.
5. AI processing
Generating a draft means sending content to a large language model. We use the Anthropic Claude API as a processor. What is sent: the excerpts an agent needs for the task at hand (call transcripts and summaries, CRM records, calendar entries, Gmail thread excerpts with a known prospect, context documents) together with the agent instructions. To our knowledge, content sent through the Anthropic commercial API is not used to train models. We train no model on customer data, and one customer data never serves another.
6. Where data is stored, and how it is protected
The application and its PostgreSQL database run on a dedicated server hosted by Hostinger in their Paris, France datacenter. All customer data therefore stays within the European Union. Protections in place: TLS in transit; connection tokens encrypted at rest with AES-256-GCM under a key held only on the server; passwords hashed with bcrypt; access tokens never returned to the browser and never written to logs; a single use anti-CSRF token on every OAuth flow; and account level isolation on every database query.
7. How long we keep it
Account data, connector data, drafts, run traces and context documents are kept for as long as the account is active, because the agents need that history to avoid writing the same follow-up twice. Deleting an account deletes its users, connections, drafts, runs, notes and context in cascade. Disconnecting a tool deletes the tokens stored for that tool. A customer can request deletion at any time at thibault@triscale.co.
9. Your rights
Under the GDPR you can request access, rectification, erasure, restriction and portability, and you can object to processing. Write to thibault@triscale.co and we will answer within one month. If a customer connected a tool that holds your personal data and you are not that customer, contact that customer first: they control the data, and we will help them act on your request. You can also lodge a complaint with a supervisory authority: the Autoriteit Persoonsgegevens in the Netherlands, where we are established, or the authority of the country where you live.
11. Changes
We will update this page when the service changes, and we will change the date at the top. Material changes to how we process personal data will be announced to account owners by email.
12. Contact
Triscale, Jacob van Lennepstraat 263 B, 1053 JE Amsterdam, the Netherlands. Email: thibault@triscale.co.