Privacy policy
Draft of 8 October 2026
Draft for legal review, not yet in force.
Points still to be completed by counsel before launch:
- GATE A1’s registered name, company number and address.
- An EU representative under Article 27 GDPR, if counsel confirms one is needed.
- Retention of logs once the hosting setup is final (backups: 35 days, below).
- Review of the legal bases and of transfers outside the EU.
Who we are
Gatwyn is a customer-support service run by GATE A1, a company registered in Hong Kong. You can reach us at [email protected].
Two roles
- For your account and our website, GATE A1 is the controller: we decide how that data is used.
- For what a business keeps in its workspace (its customers’ messages, contact details and files), the business is the controller and GATE A1 processes the data only on its instructions, under a data processing agreement. If you wrote to a business that uses Gatwyn, contact that business first about your data.
What we process
- Account data: your name, email address and a hash of your password (never the password itself).
- Workspace content: conversations, customers’ names, email addresses and phone numbers, the ids Messenger and Instagram give them, attachments, notes, articles and settings.
- Security records: sign-ins and security events with the time and technical details needed to protect accounts.
- Website chat, for workspaces that switch it on: what visitors write and the photos or PDFs they send, the name they choose to give, a token kept in their own browser so the conversation continues when they come back (we store only a hash of it), a keyed hash of their network address used to limit abuse, and the email address they may leave to receive replies they miss, used for nothing else. The chat sets no cookies.
- Early access requests from our website: the name, email address, shop website and message you give us, the language of the page and the date of the wording you agreed to. We use them only to contact you about early access to Gatwyn, and they reach only GATE A1.
- Billing: plan, seats and Paddle’s identifiers. Card details are held by Paddle, never by us.
Why, and on what basis
- To provide the service you signed up for (performance of a contract).
- To contact you about early access, when you ask for it on our website (consent).
- To keep accounts and workspaces secure and to prevent abuse (legitimate interests).
- To meet legal duties such as accounting (legal obligation).
We do not sell personal data, and we do not use workspace content for advertising.
AI features
Pilot is off until a workspace switches it on. When it is on, the public messages of a conversation and the workspace’s published articles are sent to our AI provider to write drafts, answers or summaries. Internal notes and notes about customers are never sent. Answers sent to customers automatically are marked as coming from an AI assistant.
If a workspace with a connected Shopify store also allows it, a customer’s three most recent orders are read from the store when Pilot answers, and their name, date, status, items and tracking details are sent to the AI provider with the conversation. Addresses, payments and prices are not sent, and the orders are not stored by Gatwyn.
Where the data is
The service runs in the United Kingdom (London), and stored files and backups are kept in the United States (New York), both with DigitalOcean. Other providers operate elsewhere; the subprocessors page lists who they are, what they receive and when.
How long we keep it
Account data is kept while the account exists. Workspace content is kept while the workspace exists. An owner can export it at any time from the workspace settings, and can delete the workspace there: it is deleted seven days later, with every file in it. Encrypted backups expire 35 days after they are taken, so deleted content is gone from them within 35 days; they are never used to restore a single deleted workspace. Sign-in records keep their network address and browser for 12 months; after that only the type and time of each event remain. Sessions are deleted a day after they expire. Early access requests are deleted 24 months after they are made, or sooner if you ask us at [email protected]. The original file of each email a workspace receives, with all its headers, is deleted 30 days after it arrives; its text and attachments stay in the conversation.
Security
Every workspace’s data is separated at the database level, connections are encrypted, and secrets such as access tokens are encrypted before they are stored.
Your rights
You can ask to access, correct, delete or receive a copy of your personal data, object to some processing, or complain to a data protection authority. Write to [email protected].
You can download a copy of the personal data kept about your account yourself, as a file other services can read, from Your account in the account menu.
You can also delete your account yourself, from the same page. Your name, email address, password and sign-in history are erased at once. Conversations you took part in stay with the workspaces they belong to, shown as written by a former member.
Cookies
Gatwyn uses only the cookies it needs to work: one that keeps you signed in and one that remembers the light or dark theme you chose. There are no advertising or analytics cookies, so there is no cookie banner.
Children
Gatwyn is a tool for businesses and is not meant for anyone under 16.