Privacy Policy
Last updated: September 15, 2026
This Privacy Policy explains how Orygo AI Srl ("OrygoAI", "we", "us", "our"), via Roma 94B, 20024 Garbagnate Milanese (MI), Italy, VAT IT13679710965, processes personal data in connection with Listmap at https://listmap.ai.
Contact: davide@listmap.ai. PEC: orygo@legalmail.it. We have not appointed a Data Protection Officer.
Two different roles apply. They are not interchangeable.
1. Who is responsible for what
1.1 Data we process as controller
OrygoAI is the controller (titolare del trattamento) of personal data about the people who create accounts, pay, or visit the public site: account profile, authentication, billing, support emails, and cookies on the marketing homepage. For that data, this policy is the Article 13 notice.
1.2 List and enrichment data we process as processor
When you build lists, import rows, chat with the agent, or enrich emails and phone numbers, that content is the Customer's data. The Customer is the controller. OrygoAI is the processor (responsabile del trattamento) under the Data Processing Agreement. We host the rows, run the jobs you request, and call enrichment and model providers on your instructions. We do not decide who is on the list, why you built it, or how you use it after export.
Calling a vendor API does not move the processor role onto that vendor alone. The data still sits in our database; we choose the providers, send identifiers with our credentials, and write the results back into your workspace. Those vendors are our sub-processors, listed on the Sub-processors page. Some enrichment providers also keep independent B2B directories of their own; that catalog is their processing, not yours or ours. What we send them for a job, and what we store afterwards, is processing we do for you.
Questions from people on a list (erasure, access, objection) must go to the Customer. We will help the Customer as required by the DPA. We do not answer those requests as if we were the controller of the list.
2. Account and site data (OrygoAI as controller)
2.1 What we collect
- Account: name, email, password or Google sign-in identifiers, optional profile fields, organization membership and role.
- Authentication: session tokens issued by SuperTokens. Sessions travel in the Authorization header, not as login cookies.
- Billing: Stripe customer and payment references, credit purchases, invoices and fiscal records. We do not store full card numbers.
- Product usage needed to run the service: job status, credit consumption, support correspondence.
- Public homepage: cookies and similar identifiers managed through the Iubenda banner, as described in section 6.
We do not require special-category data (health, politics, religion, biometrics) to use Listmap. Please do not put that data in lists or chat.
2.2 Why we process it and legal bases (GDPR Art. 6)
- Contract (Art. 6(1)(b)): create and secure the account, provide the workspace, process credit purchases, send service email (verification, invites, billing alerts).
- Legal obligation (Art. 6(1)(c)): Italian and EU tax and accounting retention of invoices and payment records.
- Legitimate interests (Art. 6(1)(f)): keep the service secure, prevent abuse, debug outages, and understand aggregate product use. You may object as described in section 8.
- Consent (Art. 6(1)(a)): non-essential cookies on the public homepage, where the banner asks for it. Consent can be withdrawn at any time through the banner or by writing to us.
We do not sell personal data. We do not use account data to train public AI models. Chat and list content used as processor is handled under the DPA, not for OrygoAI's independent marketing.
2.3 How long we keep it
- Account and organization data: for as long as the organization exists. The owner can delete the organization from Account. That wipes workspace data and closes the account.
- Authentication records: until the account is deleted, then removed with the SuperTokens user.
- Billing transactions: kept as required by Italian tax law (typically ten years), even after the organization is deleted. Organization identifiers on those rows are detached.
- Support email: for as long as needed to resolve the request, then ordinary email retention.
3. List, chat and enrichment data (OrygoAI as processor)
This includes company and people rows, emails, phone numbers, LinkedIn URLs, chat messages, agent traces, uploaded files, and job outputs. The Customer determines the purpose. Our instructions are the product actions the Customer (or their agent) takes, plus the DPA.
- Storage: PostgreSQL on our hosting provider, scoped to the Customer's organization.
- Enrichment: we send the identifiers needed for the requested job (for example a LinkedIn URL or name/company) to Prospeo, Serper or StoreLeads and write the response into the list.
- Models: OpenAI and xAI receive the prompt and row context required for chat or a column job.
- Deletion: row delete and import-undo remove records from the database. Soft-deleted leftovers are purged after 30 days. Deleting the organization removes lists, chats, agents and members, subject to the billing retention above.
Listmap does not send outreach (email or phone) to people on a list. Using exported contacts for marketing or calling is the Customer's activity and the Customer's compliance (including ePrivacy / Codice delle comunicazioni elettroniche and, where applicable, the Registro Pubblico delle Opposizioni).
4. Recipients
We share personal data only with:
- Sub-processors needed to run Listmap, listed at Sub-processors.
- Professional advisors under confidentiality (legal, accounting) if required.
- Public authorities when the law requires it.
We do not share lists with other customers. There is no public list-sharing feature.
5. Transfers outside the EEA
Some providers are in the United States or other third countries (including SuperTokens, Stripe, Resend, Serper, StoreLeads, OpenAI, xAI, and hosting regions). Transfers rely on the provider's GDPR transfer tools — typically the EU Standard Contractual Clauses and, where applicable, a Data Privacy Framework self-certification. Details are on each provider's DPA. You can ask us for the current mechanism for a named provider at davide@listmap.ai.
6. Cookies
Signed-in Listmap does not use cookies for authentication. Session tokens are sent in headers. Details, including the invite cookie and the homepage Iubenda banner, are in the Cookie Policy.
7. Security
Access to workspace data is organization-scoped. Transport is HTTPS. Payments go through Stripe. We apply access control, backups on the hosting provider, and least-privilege credentials for vendor APIs. No method is perfectly secure; please use a unique password and protect your login.
8. Your rights (account and site data)
For data where OrygoAI is controller, you may request access, rectification, erasure, restriction, portability, and objection, and you may withdraw cookie consent. Write to davide@listmap.ai. You can also delete your organization from Account if you are the owner.
You may lodge a complaint with the Garante per la protezione dei dati personali (piazza Venezia 11, 00187 Roma, garanteprivacy.it) or the authority of your EU member state.
For list and enrichment data, exercise rights with the Customer who operates the workspace. We will assist that Customer under the DPA.
9. Children
Listmap is a B2B product. You must be at least 18. We do not knowingly collect data from children.
10. Changes
We may update this policy. The "Last updated" date at the top is the effective date. Material changes to sub-processors are also reflected on the Sub-processors page.