La Garzona ยท by Prime Nodes

Privacy Policy

Last update: May 18, 2026

๐Ÿ‡ฎ๐Ÿ‡น Versione italiana
Notice. The legally binding version of this Privacy Policy is the Italian version published at lagarzona.primenodes.app/privacy. This English translation is provided for the convenience of non-Italian readers and Google API Services verification reviewers. In case of any discrepancy between the two versions, the Italian version prevails.

This Privacy Policy describes how Prime Nodes (hereinafter "we", "the Controller") collects, uses, and processes personal data in connection with the La Garzona service (hereinafter "the Service"), an AI-powered conversational assistant offered to hair salons via WhatsApp and integrated with the salon's Google services.

1. Data Controller

The data controller is Prime Nodes, contactable at alan.magno@gmail.com.

2. Types of data processed

2.1 Salon data (the Service customer)

2.2 End-user data of the salon's clients (WhatsApp users)

3. Access to the salon's Google data

Transparency on the use of Google data. The Service requires the salon's authorization to access Google Calendar and Google Contacts on its Google Workspace or Gmail account. Such access is granted exclusively through Google OAuth 2.0 with explicit consent.

3.1 Google scopes requested and purpose

3.2 Compliance with Google API Services User Data Policy

La Garzona's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

4. Use of artificial intelligence and third-party AI providers

AI Transparency. The Service employs AI models (LLM and ASR) to understand user messages and generate appropriate responses. The following sections disclose which AI providers are used, what data they receive, and under which safeguards.

4.1 AI providers used

La Garzona uses the following third-party AI services to process user messages and data sourced from Google Workspace APIs (Calendar, Contacts):

4.2 Data sent to AI providers

Only the following data may be transmitted to the AI providers listed above, exclusively for the time strictly necessary to generate the response:

4.3 Contractual and non-training safeguards

Data transmitted to AI providers is not used to train the providers' AI models, pursuant to the commercial agreements (paid tier) Prime Nodes has with both providers:

Data sourced from Google Workspace APIs (Calendar, Contacts) is never used to train generalist AI models, neither by Google nor by OpenAI nor by any other provider, in compliance with the Google API Services User Data Policy ("Limited Use of User Data" section).

4.4 Retention by AI providers

Data transmitted to AI providers is subject to the retention and processing policies published by the respective providers (Google and OpenAI), which may include limited retention periods for abuse monitoring and technical debugging. Prime Nodes has selected providers that publish transparent and GDPR-compliant retention policies, but does not have direct control over their internal infrastructure.

5. Purposes of processing

6. Legal basis for processing

The processing is based on:

7. Data retention

8. Parties that can access the data

9. Extra-EU data transfers

Some providers (Google, Meta, OpenAI) process data also outside the European Union. Such transfers are carried out in compliance with the Standard Contractual Clauses approved by the European Commission and/or on the basis of applicable adequacy decisions.

10. Data subjects' rights

Salons and end users may at any time exercise the rights granted by GDPR (Articles 15โ€“22): access, rectification, erasure, restriction, portability, and objection. Requests must be sent to alan.magno@gmail.com.

In addition, salons may revoke La Garzona's access to their Google data at any time, directly from their Google account settings: https://myaccount.google.com/permissions.

11. Data deletion upon request

To request the complete deletion of data associated with your account, write to alan.magno@gmail.com with the subject "La Garzona data deletion request". We will proceed within 30 days from receipt of the verified request.

12. Data protection mechanisms

Technical and organizational measures adopted by Prime Nodes pursuant to GDPR Article 32 to protect personal data processed in the context of the La Garzona Service.

12.1 Data encryption

12.2 Access control

12.3 Logging and audit

12.4 Data breach notification

In the event of a personal data breach that poses a risk to the rights and freedoms of natural persons, Prime Nodes will notify the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) within 72 hours of becoming aware of the incident (GDPR Article 33) and, where required, will directly inform the affected data subjects (GDPR Article 34).

13. Changes to this Privacy Policy

This Privacy Policy may be updated periodically. The date of the most recent update is shown at the top. Material changes will be communicated to client salons via email.