Legal Documents

Effective Date: April 13, 2026
01

Terms of Service

These Terms of Service ("Terms") govern your access to and use of our services. By using our platform, you agree to be bound by these Terms. Please read them carefully.

1. Definitions

"Service"
The software, platform, and services provided by Gola AI, including all features, applications, and content.
"User"
Any individual or entity that accesses or uses the Service, whether registered or not.
"Account"
Your registered user account required to access certain features of the Service.
"Content"
Any data, text, images, or other materials uploaded, transmitted, or stored through the Service.

2. Account Registration & Security

To use certain features, you must register for an Account. You agree to:

  • Provide accurate, current, and complete information during registration
  • Maintain and promptly update your account information
  • Maintain the security of your password and accept all risks of unauthorized access
  • Notify us immediately of any actual or suspected security breaches
  • Accept responsibility for all activities that occur under your Account

3. Acceptable Use

You agree not to use the Service to:

  • Violate any applicable laws, regulations, or third-party rights
  • Upload, transmit, or distribute malware, viruses, or malicious code
  • Attempt to gain unauthorized access to any part of the Service
  • Interfere with or disrupt the integrity or performance of the Service
  • Engage in any activity that could damage, disable, or impair our infrastructure
  • Harvest, collect, or gather user data without consent
  • Use the Service for any illegal or unauthorized purpose

4. Payment & Billing

If you purchase a paid subscription:

  • You agree to pay all fees associated with your subscription plan
  • Fees are billed in advance on a recurring basis (monthly or annually)
  • All payments are non-refundable except as required by law
  • We reserve the right to change pricing with 30 days notice
  • Failed payments may result in immediate suspension of service

5. Intellectual Property

The Service and its original content, features, and functionality are owned by Gola AI and are protected by international copyright, trademark, patent, trade secret, and other intellectual property laws. You retain ownership of your Content, but grant us a license to host, store, and process it solely to provide the Service.

6. Termination

We may terminate or suspend your Account and access to the Service immediately, without prior notice or liability, for any reason, including breach of these Terms. Upon termination, your right to use the Service will immediately cease. All provisions of the Terms which by their nature should survive termination shall survive.

7. Limitation of Liability

To the maximum extent permitted by law, Gola AI shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including loss of profits, data, or goodwill, arising out of or relating to your use of or inability to use the Service.

8. Changes to Terms

We reserve the right to modify or replace these Terms at any time. Material changes will be notified at least 30 days in advance. Your continued use of the Service after changes constitutes acceptance of the new Terms.

02

Privacy Policy

This Privacy Policy describes how we collect, use, store, and protect your personal information when you use our Service. We are committed to protecting your privacy and handling your data transparently.

1. Information We Collect

Personal Information:

  • Name, email address, and contact information
  • Account credentials and authentication data
  • Billing information and payment details (processed securely by our payment processors)
  • Profile information and preferences

Usage Information:

  • IP address, browser type, and device information
  • Pages visited, features used, and interaction data
  • Log files and diagnostic information
  • Cookies and similar tracking technologies

2. How We Use Your Information

  • Provide, maintain, and improve our Service
  • Process transactions and send related information
  • Send technical notices, updates, and support messages
  • Respond to your comments and questions
  • Monitor and analyze trends, usage, and activities
  • Detect, prevent, and address fraud and security issues
  • Personalize your experience and deliver relevant content

3. Data Storage & Security

We implement appropriate technical and organizational measures to protect your personal data:

  • Encryption of data in transit (TLS 1.3) and at rest (AES-256)
  • Regular security assessments and penetration testing
  • Access controls and authentication mechanisms
  • Regular backups and disaster recovery procedures
  • Employee training on data protection practices

4. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. When you delete your account, we will delete or anonymize your personal information within 30 days, except where retention is necessary for legal obligations or legitimate business purposes.

5. Your Rights (GDPR & CCPA)

Depending on your location, you may have the following rights:

  • Access: Request a copy of your personal data
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion of your personal data
  • Portability: Request transfer of your data
  • Restriction: Request limitation of processing
  • Objection: Object to processing of your data
  • Withdraw Consent: Withdraw consent at any time

To exercise these rights, contact us at privacy@gola.work.

6. Cookies & Tracking

We use cookies and similar technologies to enhance your experience, analyze usage, and assist in marketing efforts. You can control cookies through your browser settings. Essential cookies necessary for the operation of the Service cannot be disabled.

7. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) and adequacy decisions where applicable.

8. Children's Privacy

Our Service is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe we have collected information from a child under 16, please contact us immediately.

03

Subprocessors

To provide our services, we engage third-party service providers ("Subprocessors") who process personal data on our behalf. This section identifies our current Subprocessors, their locations, and the services they provide.

Third-Party Service Providers

We maintain strict Data Processing Agreements (DPAs) with all Subprocessors to ensure your data is handled securely and in compliance with GDPR Article 28 and other applicable data protection laws.

Netcup
📍 Germany (EU)
Infrastructure
Primary hosting and compute infrastructure. Provides virtual private servers and dedicated resources for running application workloads and databases.
User Account Data Application Data System Logs Metadata
Cloudflare
📍 United States (Global CDN)
Security & CDN
Content delivery network (CDN), DDoS protection, web application firewall (WAF), and DNS management for performance and security optimization.
IP Addresses Request Headers Traffic Logs Cached Content
Backblaze
📍 EU
Storage
Object storage and backup services for file storage, media assets, and encrypted database backups. S3-compatible storage with high durability.
File Uploads Media Assets Encrypted Backups Log Archives
Amazon Web Services (SES)
📍 EU (Frankfurt)
Communications
Transactional and marketing email delivery services. Handles all outbound email communications including authentication emails and notifications.
Email Addresses Message Content Delivery Metadata Engagement Metrics

Security & Compliance Standards

All Subprocessors are required to maintain the following standards:

  • SOC 2 Type II certification where applicable
  • Encryption at rest (AES-256) and in transit (TLS 1.3 minimum)
  • Regular penetration testing and vulnerability assessments
  • Access limited to specific service requirements (least privilege)
  • Right to audit provisions in all Data Processing Agreements
  • Data breach notification within 24 hours

International Data Transfers

For Subprocessors located outside the European Economic Area (EEA), we implement appropriate safeguards including EU Standard Contractual Clauses (SCCs) and ensure adequate protection measures are in place for international data transfers in compliance with GDPR Chapter V.

Changes to Subprocessors

We will notify customers of any new Subprocessors at least 30 days prior to their engagement, or as soon as reasonably practicable. Customers may object to new Subprocessors by contacting us within this notice period. This page is updated whenever we engage new Subprocessors or change existing arrangements.

Questions About Our Legal Documents?

If you have any questions about our Terms, Privacy Policy, or Subprocessors, please contact our legal team.

legal@gola.work