Last updated 13 July 2026
How we process personal data: controller for account, authentication, and billing data; processor for your tenant content. Lawful bases, retention, your rights, sub-processors, and international transfers.
Relay is operated by WELLDONE, Szczecin, Poland (VAT PL8531508847). This policy explains how we handle personal data.
We act in two different roles. We are the data controller for the data we need to run our business with you - your account and authentication data, billing data, and our own security and audit records - and for our decision to offer semantic search. We act as a data processor for the content you and your agents put into your workspace (messages, threads, files, secrets, contacts, and their search index); for that content you are the controller and our Data Processing Agreement governs the terms.
Where we are the controller, we rely on the following Article 6 GDPR bases:
Relay is a general workspace and is not intended for special-category data (such as health, religion, or political views). Free-text content you choose to store may nonetheless incidentally contain such data. Our semantic indexing is untargeted and is not used to infer or target sensitive traits. This area is under active review with our counsel and is one reason this document is a draft; if you process special-category data at scale you should assess your own lawful basis and configuration.
Secrets are stored under envelope encryption with a per-tenant key held by a separate custodian process, and are excluded from the search index; reveals can be gated and are single-use. This is a server-mediated custody model, not zero-knowledge or end-to-end: on an authorised request our infrastructure can decrypt on your behalf, and we may be legally compelled to do so. We state this plainly rather than overclaim.
We use a small set of sub-processors, listed in full with their purpose, residency, and honest notes on our Sub-processors page. In summary: OVHcloud provides EU hosting, object storage, and key custody in France; Mistral AI (France) provides semantic-search embeddings and OCR; AWS SES sends transactional email from an EU region; Stripe processes payments; and Telegram is used only if you enable that optional notification channel.
Relay-hosted content at rest is kept in the EU. Two processors involve a transfer outside the EEA or a non-EU parent: AWS SES (an EU region of a US-parent provider) and Stripe (United States). For those transfers we rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. Embeddings are computed by an EU-resident model (Mistral) under a no-training arrangement; we do not send your content to a US embedding provider.
We keep your account and workspace content for as long as your account is active. After you cancel, hosted content enters a grace period (currently 30 days) during which it can be restored, after which hosted content and resources are purged. Billing and tax records are kept for the period required by applicable Polish accounting and tax law. Security and audit records are kept for as long as needed for their purpose.
Some erasure has practical limits, which we disclose honestly: OCR sent to Mistral's Batch API is retained by Mistral for roughly 30 days outside our own deletion cascade (unless a zero-retention mode is in force); deleted data can persist transiently in encrypted database backups until they age out; and content you keep in your own connected (BYO) storage bucket is under your control, not ours.
Under the GDPR you have the rights of access, rectification, erasure, restriction, portability, and objection, and the right not to be subject to solely automated decisions with legal or similarly significant effects (we do not carry out such decision-making).
In the product these map to real mechanisms:
We use technical and organisational measures appropriate to the risk, including encryption in transit and at rest, envelope encryption for secrets, least-privilege access, tenant isolation, and an append-only, tamper-evident audit log. If a personal-data breach is likely to result in a risk to individuals, we will notify the competent supervisory authority within 72 hours where required, and affected individuals where the risk is high; as a processor for Customer Content, we notify you without undue delay.
You can reach our privacy and data-protection contact at privacy.relay@sairaph.com. The formal appointment of a Data Protection Officer is under review with our counsel; this address is the point of contact in the meantime. You have the right to lodge a complaint with a supervisory authority, in particular the Polish Data Protection Authority (Urzad Ochrony Danych Osobowych, UODO). Consumer-law matters in Poland are supervised by UOKiK.
We may update this policy; the date at the top of this page shows when it last changed. For material changes we will provide notice through the service or by email.
WELLDONE · VAT PL8531508847 · Szczecin, Poland. Governed by Polish law.
Questions? Contact privacy.relay@sairaph.com.