Last Updated: 13 AUGUST 2026

PRIVACY POLICY

Pametne Tehnologije d.o.o. (“we”, “our”, “us”) provides AI Leads Antispam Agent, an application that integrates with Bitrix24 to analyze incoming emails and help identify potential spam and leads using artificial intelligence. 

This Privacy Policy explains how we handle personal data when you use AI Leads Antispam Agent. 

1. Who is responsible for your data

Your organization (the company or individual who uses our application for business purposes) is responsible for deciding how personal data contained in incoming emails is used.

Your organization acts as the Data Controller, and we process personal data on its behalf as a Data Processor, where applicable under the GDPR.
You are responsible for ensuring that you have a lawful basis and all necessary permissions to process and provide the personal data contained in incoming emails to our application. 

2. What data we process 

When AI Leads Antispam Agent processes an incoming email from Bitrix24, we may process:

  • The sender's email address and other information contained in the FROM field;
  • The email subject;
  • The full body of the email;
  • AI-generated analysis and classification results;
  • An embedding generated from the email content. 

The embedding is a mathematical representation of the email content used to compare incoming emails with previously processed email data for the purposes of spam and lead detection. 

The embedding is stored on servers operated for Pametne Tehnologije d.o.o. within the European Union. 

Depending on the content of an incoming email, the data processed by the application may contain personal or other sensitive information included by the sender or other individuals in the email. 

3. Why we process this data 

We process this data solely to provide the AI Leads Antispam Agent functionality, including: 

  • analyzing incoming emails;
  • identifying potential spam;
  • identifying potential leads;
  • comparing incoming emails with previously processed email data using embeddings;
  • generating AI-based classification and analysis results; and
  • providing the resulting functionality within Bitrix24. 

We do not use the content of incoming emails for advertising or for selling personal data. 

4. AI processing 

To analyze incoming emails, AI Leads Antispam Agent uses third-party Large Language Model (LLM) services. 

Depending on the user's location and selected settings, we use either: 

  • Mistral API; or
  • OpenAI API. 

For users located in the European Union, Mistral is selected automatically as the default LLM provider.

For users located outside the European Union, OpenAI is selected automatically as the default LLM provider. 

The data sent to an LLM provider may include the FROM field, subject, and full body of the incoming email, as necessary to perform the requested analysis. 

AI processing is performed automatically. The output generated by the LLM is used by our application to provide spam and lead analysis functionality. 

OpenAI states that data submitted through its API is not used to train its models by default. Mistral similarly states that data submitted through its API is not used for model training, subject to the applicable service, contractual terms, and configuration. 

5. Where the data is stored 

Embeddings, AI analysis results, and other data required to provide the application are stored on servers operated for Pametne Tehnologije d.o.o. within the European Union. 

The LLM provider used for processing depends on the user's default or manually selected model. 

Mistral provides EU-based API infrastructure and offers an EU regional endpoint for API requests. 

OpenAI processes API data through its infrastructure and may process data outside the European Economic Area depending on the applicable service configuration and processing arrangements. 

6. International data transfers 

For users in the European Union, Mistral is selected as the default LLM provider in order to support processing within the European region. 

A user may manually change the selected LLM provider. 

If a user located in the European Union manually selects a provider or model that involves processing or transfer of personal data outside the European Union/European Economic Area, the user acknowledges that such processing may constitute an international transfer of personal data. 

Before making such a change, the user is responsible for considering whether the selected configuration is appropriate for their organization and for ensuring that the processing and transfer are lawful under the data-protection laws applicable to their organization. 

The use of a manually selected LLM provider does not change the user's organization's responsibilities as Data Controller. 

Where required, international transfers are subject to appropriate safeguards under applicable data-protection law, such as Standard Contractual Clauses or other legally recognized transfer mechanisms. 

Mistral states that transfers involving providers outside the EU are subject to appropriate safeguards, including Standard Contractual Clauses where applicable. 

7. How long we keep the data 

We retain data processed by AI Leads Antispam Agent for the duration of the applicable license or until the integration is deleted, subject to the deletion rules described below. 

The following data may be retained: 

  • Incoming email data required for the operation of the integration;
  • AI analysis and classification results;
  • Embeddings generated from email content; and
  • Configuration and technical data required to operate the integration. 

8. Data deletion 

Data associated with the integration is deleted in the following circumstances: 

  • When the integration is uninstalled, the associated data is deleted;
  • When a license expires, the associated data is deleted no later than one month after the end of the license;
  • When the user changes the selected LLM model, embeddings associated with the previous model are deleted and may be regenerated using the newly selected model.

Data may be retained for a longer period where retention is required by applicable law.

Third-party LLM providers may have their own retention periods and deletion procedures applicable to data processed through their APIs. 

For example, OpenAI's current API documentation states that API inputs and outputs may be retained for up to 30 days for abuse monitoring purposes unless applicable controls or contractual arrangements provide otherwise.

9. Who we share data with 

We may share or transmit personal data with the following services where necessary to provide the integration: 

  • Bitrix24: Incoming email data is obtained from Bitrix24 and AI analysis results may be used within Bitrix24. Bitrix24 processes personal data under the responsibility of the relevant organization and according to its own privacy and data-processing terms.
  • Mistral AI: Depending on the selected model, email content may be transmitted to Mistral through the Mistral API for AI processing.
  • OpenAI: Depending on the selected model, email content may be transmitted to OpenAI through the OpenAI API for AI processing.
  • Our hosting providers: Data required to operate the integration, including embeddings and AI analysis results, may be stored on infrastructure provided by our hosting providers in the European Union. 

We do not sell personal data and do not share personal data with third parties for advertising purposes.

10. Your rights

Under the GDPR and other applicable data-protection laws, individuals may have rights including:

  • Access to their personal data;
  • Correction of inaccurate data;
  • Deletion of personal data (“right to be forgotten”);
  • Restriction of processing;
  • Data portability;
  • Objection to processing; and
  • The right to lodge a complaint with a competent data-protection supervisory authority.

Because your organization generally determines why and how personal data contained in incoming emails is processed, requests concerning such personal data should normally be directed to your organization as the Data Controller. 

We will provide reasonable assistance to the organization in responding to valid data-protection requests. 

11. Security 

We apply appropriate technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, loss, or destruction.
These measures include appropriate access controls, secure communication and storage, and confidentiality obligations for personnel who may have access to personal data. 

We take measures appropriate to the risks associated with processing personal data, in accordance with Article 32 GDPR where applicable. 

12. Data breaches 

If we become aware of a personal data breach affecting data processed on behalf of an organization, we will notify the relevant organization without undue delay and provide reasonable information and assistance necessary for the organization to assess and, where required, notify the competent supervisory authority and affected individuals. 

13. Changes to the selected AI model 

AI Leads Antispam Agent allows users to change the LLM provider or model used for email processing, where this functionality is available. 

Changing the model may change the geographic location where email data is processed and may therefore result in an international transfer of personal data. 

When changing the model, the user is responsible for reviewing the applicable data-processing implications and ensuring that the selected configuration is suitable for their organization. 

When the selected model changes, embeddings associated with the previous model are deleted and new embeddings may be generated using the newly selected model.\

14. Contact us

If you have questions about how personal data is processed by AI Leads Antispam Agent, please contact us:

gdpr@pamteh.si
Pametne Tehnologije d.o.o.
Dunajska cesta 113
1000 Ljubljana
Slovenia