Company Information

BOTS4.me is operated by TreeLab OÜ, a company specializing in AI-powered automation solutions, ERP integrations, and intelligent business process automation.

Company Details:
TreeLab OÜ
Registry Code: 17063252
VAT Number: EE102796911
Ahtri 12, Tallinn, 10111, Estonia (European Union)
Data Controller: TreeLab OÜ acts as the data controller for all personal data collected through BOTS4.me services. We are committed to GDPR compliance and maintaining the highest standards of data protection for our AI automation platform.

Data We Collect

When you use our AI automation services or purchase our business solutions, we collect the following types of information:

Personal Information

  • Name, email address, phone number
  • Company name and job title
  • Billing address and payment details
  • Account credentials (encrypted)

Technical Information

  • IP address and browser type
  • Device information and OS
  • API usage and integration logs
  • Automation performance metrics

Usage Analytics

  • Feature usage and adoption patterns
  • Bot execution statistics
  • ERP integration performance
  • Service optimization data

Communication Data

  • Support tickets and chat logs
  • Email communications
  • Feedback and survey responses
  • Consultation notes

How We Use Your Data

Service Provision & AI Automation

  • Delivering our AI-powered automation solutions (Mail2ERP, AutoERP, etc.)
  • Processing transactions and managing service subscriptions
  • Providing technical support and automation consulting
  • Monitoring system performance and bot reliability
  • Facilitating ERP integrations and data processing workflows

Communication & Support

Official communications from us are sent only from our verified domains @bots4.me and @tirelessbots.com.

  • Sending service updates and important automation notifications
  • Responding to inquiries and technical support requests
  • Providing automation consulting and implementation guidance
  • System maintenance alerts and security notifications
  • Product updates, feature announcements, and upgrade opportunities for existing customers (including free-tier), based on our legitimate interest in informing users about similar services — with opt-out available in every communication
  • Broader marketing communications about business solutions, industry insights, and case studies (with explicit opt-in consent via subscription form)

Legal Basis for Processing

We process your data based on the following legal grounds:

  • Contract Performance: To deliver AI automation services you’ve purchased and maintain ERP integrations
  • Legal Obligation: For accounting, tax compliance, and regulatory requirements
  • Legitimate Interest: For system security, fraud prevention, service improvement, business analytics, and communicating with existing customers (including free-tier users) about similar BOTS4.me products and services in accordance with Article 13(2) of the ePrivacy Directive (2002/58/EC). We have conducted a Legitimate Interest Assessment confirming that our interest in informing existing customers about relevant product updates and upgrade opportunities does not override your rights and freedoms, particularly as every communication includes an easy opt-out mechanism.
  • Consent: For broader marketing communications (newsletter, case studies, partner content), optional features, and advanced analytics. Consent is collected separately via our subscription forms and may be withdrawn at any time without affecting the lawfulness of prior processing or your access to the Service.

AI Automation & Business Data

Important Data Responsibility: Our AI automation solutions process business data on your behalf. You remain the data controller for any personal data processed by our bots. We act as a data processor, ensuring compliance with your data protection requirements.

Data Processing Boundaries

When BOTS4.me processes data on your behalf (including emails, invoices, and other business documents submitted to our automation services), we act strictly as a data processor under GDPR Article 28. This means:

  • Data submitted for processing is used exclusively to deliver the requested automation services
  • We do not use processed data for marketing, lead generation, profiling, or any purpose unrelated to the service you requested
  • Third-party personal data contained within your processed documents (such as contact information of your customers, suppliers, or partners) is never used by BOTS4.me for our own purposes
  • We do not contact, profile, or market to any third parties whose data appears in your processed documents
  • These boundaries apply to all service tiers, including free-tier accounts
  • Processed data is retained only for the duration necessary to deliver the service and is deleted in accordance with our data retention policy

Automation Configuration Data

  • Email processing rules and filters for Mail2ERP
  • ERP integration mappings and field configurations
  • Business workflow automation rules and schedules
  • API endpoints and authentication credentials (encrypted)
  • Data transformation and validation rules

Processed Business Content

  • Email metadata and processing results (not email content)
  • Bot execution logs and performance metrics
  • Error reports and debugging information
  • Data import/export statistics and success rates
  • System integration health and monitoring data
Data Protection Guarantee: We never access, read, or store the actual business content processed by our AI bots. We only collect metadata about performance, system health, and processing statistics to ensure service reliability and improvements.
Your Responsibility: When our AI automation bots process personal data for your business, you are responsible for ensuring compliance with privacy laws (GDPR, CCPA, etc.) and obtaining necessary consents from your customers and stakeholders.

Data Sharing & Third Parties

We work with trusted partners to deliver our AI automation services. Your data may be shared only with the following categories of recipients:

Essential Service Providers (Sub-processors)

  • Cloud Infrastructure: A tier-1 European Union data-center operator (Czech Republic) hosts both the public bots4.me website (WordPress) and the dynamically-provisioned per-client production processing servers. All customer personal data is stored and processed within the European Union. The specific hosting provider’s identity is available to customers on request under a signed Data Processing Agreement (DPA).
  • Identity Providers: Microsoft Corporation (Microsoft Entra ID / Microsoft Graph) and Google LLC (Google Identity Services) when you use Secure Quick Connect (OAuth) to link a Microsoft 365 or Google account. We never receive your password — these providers issue us a revocable access token scoped to the permissions you approve.
  • Cloud Storage Providers: Microsoft OneDrive and Google Drive when you use Mail2CLOUD to back up email attachments. We hold a narrow OAuth token (App Folder / drive.file scope) that can only see files our application created.
  • Payment Processors: Stripe Payments Europe Ltd. (Ireland) and other secure payment gateways (payment data only — we never see your card number)
  • Email Services: Transactional email providers for system notifications
  • Analytics Providers: Google Analytics for service improvement (anonymized data only)
  • Security Services: CloudFlare Inc. for DDoS protection and CDN services in front of the public website
  • Encryption Architecture: Sensitive customer data stored on the public bots4.me website is encrypted with an RSA-2048 public key. The matching private key is held on a separate isolated server we control and never resides on the same host as the encrypted data. Production processing servers operate on decrypted data only in volatile memory; no decrypted client data is written to disk.
  • Email Delivery Services: For sending transactional notifications and product communications to existing customers. Email addresses are shared with our email delivery provider solely for message transmission and are not used for any other purpose.

A current sub-processor list is maintained at bots4.me/privacy-policy. We will notify customers of any material change at least 30 days before a new sub-processor begins processing personal data.

Third-Party Authentication Scopes (OAuth)

When you use Secure Quick Connect to link a Microsoft 365, Google, Microsoft OneDrive or Google Drive account, we request only the minimum OAuth permissions needed for the product features you activate. Below is the complete list of scopes we may request, with the exact reason each one is needed and what we never do with it.

Microsoft (Microsoft Entra ID / Microsoft Graph)

Scope What it lets us do Used by
openid, profile, emailVerify your identity and your account email address. Standard OpenID Connect sign-in.All apps (sign-in)
offline_accessRefresh access tokens automatically so you don’t have to re-authenticate every hour. Without this, the apps would stop working overnight.All apps
https://outlook.office.com/IMAP.AccessAsUser.AllConnect to your Outlook/Office 365 mailbox via IMAP (using OAuth, not your password) to read incoming messages for processing.Mail2ERP, AutoSPAM, Mail2CLOUD
Mail.ReadWriteRead and move messages between folders (e.g. move spam to a Quarantine folder, mark processed messages as read). We never delete mail.AutoSPAM, Mail2ERP
MailboxSettings.ReadWriteCreate the dedicated folders our apps move messages into (Quarantine, Archive, Processed). Without this we cannot file mail anywhere.AutoSPAM, Mail2ERP
Files.ReadWrite.AppFolderCreate and write into a single dedicated app folder on your OneDrive — we cannot see or touch any other file or folder in your OneDrive.Mail2CLOUD (OneDrive only)

Google (Google Identity / Gmail / Drive)

Scope What it lets us do Used by
openid, profile, emailVerify your identity and your Google account email. Standard OpenID Connect sign-in.All apps (sign-in)
https://mail.google.com/Connect to your Gmail mailbox via IMAP and SMTP over OAuth (XOAUTH2). Google requires this scope for any IMAP/SMTP access — the narrower Gmail REST scopes do not work for IMAP/SMTP. We use it strictly for reading inbound mail, moving processed messages between folders, and sending reply mail from your own address. We never permanently delete mail.Mail2ERP, AutoSPAM, Mail2CLOUD, AutoCASH, Supplier2ERP
https://www.googleapis.com/auth/gmail.settings.basicCreate filters that route inbound mail to the dedicated folders the apps process (e.g. a “Processed” label). Strictly additive — we never disable or remove your existing filters.AutoSPAM, Mail2ERP
https://www.googleapis.com/auth/gmail.labelsCreate the dedicated Gmail labels (Quarantine, Processed, Archive) we file messages under.AutoSPAM, Mail2ERP
https://www.googleapis.com/auth/drive.fileCreate and write only the files our application uploads to Google Drive. We cannot see any other file or folder in your Drive — this is the narrowest Drive scope Google offers.Mail2CLOUD (Google Drive only)

What we never do with OAuth-granted access

  • We never use your email content, contacts, attachments or any Google/Microsoft user data to build, train or improve generalised or third-party AI/ML models. Models are tuned on your account’s own data only, in your account’s own isolated processing context.
  • We never sell your data, share it with advertising networks, or use it to serve targeted ads.
  • We never read mail or open attachments for human review except where strictly required to deliver a feature you activated, or where you explicitly request support troubleshooting on a specific message.
  • We never permanently delete mail, files or folders that we did not create.
  • We never transfer OAuth tokens to any party outside our infrastructure, except to the issuing provider (Microsoft or Google) when we exchange or refresh them.

Google API Services User Data Policy — Limited Use Disclosure

BOTS4.me’s use of information received from Google APIs adheres to the Google API Services User Data Policy , including the Limited Use requirements.

Specifically, BOTS4.me only uses access to read, write or send Gmail messages and Google Drive files to provide or improve user-facing features that are prominent in the requesting application’s user interface. We do not transfer Google user data to a third party except as necessary to provide or improve user-facing features, to comply with applicable law, or as part of a merger, acquisition or sale of assets with the user’s explicit consent. We do not use Google user data for serving advertisements, including retargeted, personalised or interest-based advertising. We do not allow humans to read Google user data unless we have your affirmative agreement for specific messages, doing so is necessary for security purposes such as investigating abuse, to comply with applicable law, or for internal operations and only with data that has been aggregated and anonymized.

Business Integration Partners

  • ERP Vendors: When you authorize integrations with Odoo, SAP, QuickBooks, etc.
  • API Services: Third-party APIs you configure for your automation workflows
  • Translation Services: For multi-language support in our AI processing

Legal Requirements

We may disclose data when required by law, such as:

  • Court orders or legal proceedings
  • Law enforcement requests (with valid legal basis)
  • Tax and regulatory compliance obligations
  • Protection of our rights, safety, and intellectual property
EU Data Protection: All personal data processing occurs within the European Union. We do not transfer personal data outside the EU without appropriate safeguards (adequacy decisions or Standard Contractual Clauses).

Data Security & Protection

We implement enterprise-grade security measures to protect your data and ensure the integrity of our AI automation platform:

Technical Safeguards

  • End-to-End Encryption: All data encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Multi-Factor Authentication: Required for all administrative access
  • Access Controls: Role-based permissions and principle of least privilege
  • Network Security: Firewalls, intrusion detection, and DDoS protection
  • API Security: OAuth 2.0, rate limiting, and request validation
  • Monitoring: 24/7 security monitoring and threat detection

Organizational Measures

  • Regular security training for all team members
  • Background checks for personnel with data access
  • Incident response procedures and breach notification protocols
  • Regular security assessments and penetration testing
  • Data minimization practices and privacy by design principles
  • Secure development lifecycle (SDLC) practices

Data Retention Periods

  • Account Data: Retained while your account is active, plus 30 days
  • Transaction Records: 10 years for accounting and tax purposes
  • Communication Logs: 3 years from last interaction
  • Technical Logs: 12 months for security and performance analysis
  • Automation Configurations: Retained until account deletion + 90 days
  • Support Tickets: 5 years for service improvement and legal compliance
Compliance Certifications: Our infrastructure partners maintain SOC 2 Type II, ISO 27001, and other industry certifications. We undergo regular security audits and maintain detailed security documentation for enterprise clients.

Cookies & Tracking Technologies

We use cookies and similar technologies to enhance your automation experience. For detailed information, please see our Cookie Policy.

Essential Cookies

Required for core automation platform functionality:

  • User authentication and session management
  • Security protection and fraud prevention
  • API access and integration maintenance
  • Dashboard preferences and automation settings

Analytics Cookies (Optional)

Help us understand and improve our AI automation services:

  • Feature usage and adoption analytics
  • Bot performance and efficiency metrics
  • User journey optimization data
  • Service reliability and error tracking
Cookie Management: You can control your cookie preferences through our cookie consent banner or by visiting our Cookie Policy page.

Your Privacy Rights

Under GDPR and applicable privacy laws, you have comprehensive rights regarding your personal data:

Right to Access

Request a copy of your personal data and information about how we process it.

Right to Rectification

Correct inaccurate or incomplete personal data in your account.

Right to Erasure

Request deletion of your personal data (subject to legal retention requirements).

Data Portability

Receive your data in a machine-readable format for transfer to another service.

Right to Restriction

Limit how we process your data in certain circumstances.

Right to Object

Object to processing based on legitimate interests or direct marketing.

Right to Opt Out of Marketing

Unsubscribe from product communications at any time via the link in any email, your account settings, or by contacting [email protected]. Opting out does not affect transactional communications necessary for service delivery, nor does it affect your access to any BOTS4.me services.

How to Exercise Your Rights

To exercise any of these rights:

  • Email us: [email protected] with your request
  • Account Dashboard: Manage preferences directly in your automation dashboard
  • Support Portal: Submit a ticket through our support system
  • Written Request: Send a letter to our registered office address
Response Time: We will respond to your request within 30 days. For complex requests, we may extend this by 60 days and will inform you of the extension and reasons for it.

Right to Lodge a Complaint

If you believe we have not handled your personal data properly, you have the right to lodge a complaint with:

  • Estonian Data Protection Authority: Our lead supervisory authority
  • Your Local DPA: The data protection authority in your EU country
  • European Data Protection Board: For cross-border data protection issues

International Data Transfers

As an EU-based company providing global AI automation solutions, we handle international data transfers with strict safeguards:

EU Data Processing

  • Primary data processing occurs within the European Union
  • EU-based servers and infrastructure for customer data
  • GDPR compliance for all European customers
  • Estonian data protection law compliance

International Customers

  • Adequacy Decisions: For countries with adequate data protection (UK, Switzerland, etc.)
  • Standard Contractual Clauses: For transfers to countries without adequacy decisions
  • Customer Data Residency: Available for enterprise clients with specific requirements
  • Regional Processing: Where required by local data protection laws
Transfer Safeguards: All international data transfers include appropriate safeguards such as encryption, access controls, and contractual protections to ensure the security and privacy of your data.

Contact & Data Protection Officer

For any privacy-related questions, data protection requests, or concerns about how we handle your personal data:

Privacy & Data Protection Contacts

Our privacy team is dedicated to protecting your data and ensuring compliance with all applicable privacy laws.

Postal Address

TreeLab OÜ – Privacy Team
Ahtri 12, Tallinn, 10111, Estonia (European Union)

Business Hours

  • Privacy Requests: Processed within 72 hours of receipt
  • Technical Support: Monday-Friday, 9:00-17:00 EET
  • Emergency Contact: Available 24/7 for data breach notifications
Policy Updates: We may update this privacy policy to reflect changes in our AI automation services, business practices, or applicable laws. Significant changes will be communicated via email and posted on our website with an updated effective date. Continued use of our services after policy updates constitutes acceptance of the changes.