Last updated: [[1 September 2026]]
Effective date: [[1 September 2026]]
This Privacy Policy explains how Automight LLC (“Automight”, “we”, “us”) collects, uses, stores, shares and protects personal data when you visit automight.io, contact us, or use the automation systems and applications we operate (together, the “Services”).
1. Who we are
Data controller
Automight LLC
30 N Gould Street, Sheridan, WY 82801, United States
Email: [[privacy@automight.io]]
Phone: +1 331-373-4112
For the personal data we process on behalf of our clients while building and running their automation systems, our client is the data controller and Automight acts as a data processor under a separate data processing agreement. This policy describes our own processing as a controller, and explains our practices generally so that end users understand how their data is handled.
2. What data we collect
2.1 Data you give us
- Contact and booking data: name, email address, phone number, company name, website, and anything you write in a form or in a strategy-session booking.
- Client and project data: billing details, contract information, technical documentation, credentials and access you grant us to build or maintain your systems.
- Correspondence: emails, messages and call recordings or notes, where you have been informed and, where required, have consented.
2.2 Data we collect automatically
- Technical data: IP address, browser type and version, device type, operating system, language, referring URL.
- Usage data: pages visited, time on page, clicks, and similar analytics events.
- Cookies and similar technologies: see our Cookie Policy for the full list and for how to change your choices.
2.3 Data we receive from third parties
We may receive data from advertising and analytics platforms, from tools our clients connect to their systems, and from Google APIs where you have explicitly authorised access (see section 3).
3. Google user data
Where our applications connect to Google services, they do so only after you have signed in with Google and granted permission on Google’s own consent screen. You control that permission and can withdraw it at any time.
3.1 Scopes we request and why
| Scope | What it allows | Why we need it |
|---|---|---|
userinfo.email / userinfo.profile / openid | Read your basic profile: name, email address, profile picture. | To identify your account, create your session and contact you about the service. |
[[gmail.readonly / gmail.send / gmail.modify]] | [[Read, send or organise messages in your Gmail mailbox.]] | [[To run the email automations you configure — for example reading incoming leads and sending the replies you have set up.]] |
[[calendar.events]] | [[Read and create events in your Google Calendar.]] | [[To book, reschedule and sync appointments generated by your funnel.]] |
[[spreadsheets / drive.file]] | [[Read and write the specific Google Sheets and Drive files you select.]] | [[To read and write the data your automations and reports depend on.]] |
We request the narrowest scopes that make the features you asked for work. We do not request scopes for features you have not enabled.
3.2 How we use, store and share Google user data
- We use Google user data only to provide and improve the user-facing features you have explicitly enabled.
- Data is transmitted over TLS and stored encrypted at rest on [[our servers hosted at provider / region]]. OAuth tokens are stored encrypted and are accessible only to the processes that need them.
- We do not sell Google user data, and we do not use it for advertising, profiling, credit assessment or any purpose unrelated to the feature you enabled.
- We do not transfer Google user data to third parties except: (a) sub-processors strictly necessary to operate the service, bound by equivalent obligations; (b) where you have given explicit consent; (c) where required by law.
- We do not allow humans to read your Google user data, except: with your explicit consent for specific messages or files; where necessary for security purposes such as investigating abuse; to comply with applicable law; or where the data is aggregated and anonymised for internal operations.
- We do not use Google user data to develop, improve or train generalised artificial intelligence or machine learning models. Where a feature you enabled sends content to an AI provider to produce your requested output, that content is processed only for that request and is not used by us or by the provider to train models.
3.3 Limited Use disclosure
Automight’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3.4 Revoking access and deleting your data
You can revoke our access at any time from your Google Account at myaccount.google.com/permissions. Revoking access stops all further data retrieval immediately.
To have the Google user data we hold deleted, write to [[privacy@automight.io]]. We delete it within 30 days of the request, and in any case within 30 days of your account being closed, except where retention is required by law.
4. Why we process your data, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Replying to enquiries and preparing proposals | Steps taken at your request prior to entering a contract |
| Delivering the Services and supporting your systems | Performance of a contract |
| Invoicing, accounting, tax and legal records | Legal obligation |
| Security, fraud prevention and service improvement | Legitimate interests |
| Non-essential cookies, analytics and marketing communications | Consent |
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
5. Who we share data with
We do not sell personal data. We share it only with service providers that help us run the business, each bound by contract to process it solely on our instructions:
- Hosting and infrastructure providers [[e.g. Hetzner, Cloudflare]]
- Automation and workflow platforms [[n8n (self-hosted), Make.com, Zapier]]
- CRM and communication tools [[GoHighLevel, Google Workspace]]
- Analytics and advertising platforms [[GetInsights, Google Analytics, Meta]]
- Payment and invoicing providers [[Stripe, …]]
- Professional advisers, and public authorities where the law requires it
6. International transfers
Automight is established in the United States and operates from [[Malta]]. Personal data originating in the European Economic Area may therefore be transferred outside it. Where that happens, we rely on the European Commission’s Standard Contractual Clauses or another valid transfer mechanism, together with appropriate technical and organisational safeguards.
7. How long we keep data
- Enquiries that do not become projects: 24 months from the last contact.
- Client and contract data: for the duration of the relationship plus 10 years, for accounting and legal purposes.
- Google user data and OAuth tokens: for as long as your integration is active; deleted within 30 days of revocation, account closure or a deletion request.
- Analytics data: [[14 months]].
8. How we protect data
We use TLS in transit, encryption at rest, role-based access control, least-privilege credentials, multi-factor authentication on administrative accounts, logging, and regular backups. No system is perfectly secure, but we keep these measures under review and will notify you and the competent supervisory authority of a personal data breach where the law requires it.
9. Your rights
Depending on where you live, you may have the right to: access your data; correct it; delete it; restrict or object to processing; receive it in a portable format; withdraw consent; and opt out of the sale or sharing of personal data (we do not sell it). To exercise any of these, write to [[privacy@automight.io]]. We reply within 30 days.
If you are in the EEA and believe we have handled your data unlawfully, you may lodge a complaint with your national data protection authority.
10. Children
The Services are for businesses and are not directed at anyone under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Cookies
We use technical cookies and, with your consent, analytics and marketing cookies. Full details and controls are in our Cookie Policy.
12. Changes to this policy
We may update this policy. The current version is always at automight.io/privacy-policy, with the revision date at the top. Where changes are significant, we will notify you by email or a notice on the site before they take effect.
13. Contact
Automight LLC — 30 N Gould Street, Sheridan, WY 82801, United States
[[corporate@automight.io]]
2 risposte