Raydo

Privacy & data protection

Privacy Policy

Last updated: 20 July 2026 · Effective date: 20 July 2026 · Version 1.0

Raydo is the chief of work for European SMBs. To do that work, Raydo processes personal data — your own contact details and, if you connect Raydo to your business tools, data from those tools. This policy explains exactly what data we process, which Google and Microsoft permissions (scopes) we request, how we handle that data and what rights you have. Everything runs on European infrastructure.

Deze pagina is ook in het Nederlands beschikbaar.

1.Who we are

Raydo is offered by Raydo AI B.V., established in the Netherlands (Chamber of Commerce / KvK: 42107027). For this privacy policy, Raydo is the data controller for the data collected via the website, and — depending on your agreement — controller or processor for data you have processed through connected tools.

2.Who this policy applies to

This policy applies to:

  • Website visitors of raydo.eu and its subdomains.
  • People who sign up for the waitlist or the beta programme.
  • Users of the Raydo product, including those who connect Raydo to a Google or Microsoft account or to other business tools.

Raydo is not yet generally available; launch is planned for autumn 2026. Until then a closed beta is running. Where this policy refers to "connected accounts", it concerns that beta and product environment.

3.What data we process

3.1 · Data you give us directly

  • Sign-up and contact data: email address, and (via the beta form) name, company name, role and your message.
  • Correspondence: the content of emails and messages you send us.

3.2 · Data from connected tools (with your consent)

If you connect Raydo to a Google or Microsoft account or to another business tool, Raydo processes — within the scopes you allow (see §4) — among other things:

  • Email: messages, metadata (sender, recipient, subject, timestamp) and, if you allow it, draft replies that Raydo prepares.
  • Calendar: appointments, participants and descriptions, to prepare meetings.
  • Contacts: name, email, phone, company and role of your relations.
  • CRM and company data: customer, deal and quote data from your CRM, enriched with public sources such as the Chamber of Commerce (KvK) register and company websites.

Raydo retrieves only what is needed for the feature you use, and shows the source for every result. Nothing goes to a customer without your approval.

3.3 · Data that is generated automatically

  • Technical logs: a limited server log (IP address, timestamp, requested page, user agent) for security and troubleshooting.
  • Cookies: the website uses no tracking or advertising cookies and no external analytics. There are no US trackers on the page.

4.Google and Microsoft scopes we use

When you connect Raydo to a Google or Microsoft account, Raydo requests only the permissions (scopes) needed for the features you enable. You see these scopes on the consent screen and can revoke access at any time (see §12). The tables below describe, per scope, what Raydo uses it for.

4.1 · Google

ScopeWhat Raydo uses it for
openid, userinfo.email, userinfo.profileSign you in securely and recognise your account (name, email).
.../auth/gmail.readonlyRead email to prepare and follow up on appointments; never to send.
.../auth/gmail.composePrepare draft replies and follow-up emails as drafts. Sending only happens after your approval.
.../auth/calendar.readonlyRead the calendar to recognise and brief meetings.
.../auth/contacts.readonlyRead contacts to build a complete customer picture.

4.2 · Microsoft (Microsoft Graph)

ScopeWhat Raydo uses it for
openid, profile, email, offline_access, User.ReadSign you in securely, recognise your profile and keep the connection active.
Mail.ReadRead Outlook email to prepare and follow up on appointments.
Mail.ReadWritePrepare draft replies and follow-up emails as drafts. Sending only after your approval.
Calendars.ReadRead the calendar to recognise and brief meetings.
Contacts.ReadRead contacts to build a complete customer picture.
Chat.ReadRead Teams messages in the conversations you invite Raydo to.

Raydo does not request broader access than the enabled features require. If you do not enable a feature, the associated scope is not requested.

5.Limited Use statement (Google & Microsoft)

Raydo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely, this means that Raydo, with data from Google Workspace APIs (such as Gmail, Calendar and Contacts):

  • uses it only to provide and improve the user-facing features you visibly use;
  • does not use or transfer it for advertising;
  • does not sell it to third parties;
  • does not use it to train generalised or personalised AI models; and
  • allows humans to read it only when you give consent, when needed for security, when we are legally required to, or when the data is aggregated and anonymised.

The same restrictions apply to data from Microsoft Graph; Raydo complies with the Microsoft APIs Terms of Use.

6.Purposes and legal bases (GDPR Art. 6)

PurposeLegal basis
Processing your waitlist/beta sign-up and communicating with you about launch and beta.Consent (Art. 6(1)(a)) and/or legitimate interest (Art. 6(1)(f)).
Providing the product: briefing meetings, updating the CRM, preparing follow-ups based on connected tools.Performance of the contract (Art. 6(1)(b)); for end users within a customer organisation, Raydo acts as processor on instruction.
Security, abuse prevention and troubleshooting.Legitimate interest (Art. 6(1)(f)).
Complying with legal obligations.Legal obligation (Art. 6(1)(c)).

7.AI models and your data

Raydo uses language models to prepare work. These models run on European infrastructure (Mistral AI, Paris). Your data is not used to train generalised AI models, and does not leave the EU for model processing. Every result Raydo produces is traceable to a source, and sensitive actions (such as emailing a customer) always wait for your approval.

8.Where your data lives & subprocessors

Raydo is deliberately built on a European chain. We engage the following subprocessors:

SubprocessorRoleLocation
ScalewayHosting, storage and compute (website, product)Amsterdam, NL
Mistral AILanguage models (AI processing)Paris, FR
TransIPEmail (sending/receiving)Netherlands

Google and Microsoft are not subprocessors of Raydo but the source from which you grant Raydo access to your own data. For the current list of subprocessors, contact support@raydo.eu.

9.Sharing with third parties

Raydo does not sell your data and does not share it for advertising. We only share data:

  • with the subprocessors above, solely to provide the service, under a data processing agreement;
  • when you instruct us to (for example, a draft you have sent);
  • when we are legally required to.

10.Retention periods

  • Sign-up data: until you unsubscribe or ask us to delete it; at the latest until the service is no longer relevant to you.
  • Connected-tool data: as long as the connection is active. If you revoke the connection or delete your account, we delete the associated data within a reasonable period, unless we are legally required to retain it.
  • Technical logs: short-lived, typically a few weeks to months, for security and troubleshooting.

11.Security

We take appropriate technical and organisational measures: encryption in transit (TLS) and at rest, access on a need-to-know basis, separated environments and a European infrastructure chain. Found a vulnerability? Report it responsibly to security@raydo.eu. Please give us a reasonable period to respond before you disclose anything publicly.

12.Your rights

Under the GDPR you have the right to access, rectification, erasure, restriction, objection and data portability, and the right to withdraw consent you have given.

13.International transfers

Raydo processes your data within the European Economic Area. The processing chain (hosting, AI, email) is located in the Netherlands and France. There is no US cloud in the data processing. If you connect a service from outside the EEA yourself (such as a Google or Microsoft account), that provider's own terms and transfer mechanisms apply to that service.

14.Children

Raydo is a business service and is not directed at children. We do not knowingly collect data from people under the age of 16.

15.Changes to this policy

We may update this policy. For material changes we update the date at the top and, where appropriate, actively inform you. The current version is always at raydo.eu/en/privacy.

16.Contact & complaints

Privacy & requests
support@raydo.eu

Or via the portal: dsr.raydo.eu

Security
security@raydo.eu

Report vulnerabilities responsibly.

Supervisory authority
Dutch Data Protection Authority

You have the right to lodge a complaint with the AP.

← Back to raydo.eu