Legal
Privacy Policy
Last updated: 27 July 2026
1. Who we are
G4LM is operated by POETIC BEATS, UNIPESSOAL, LDA, Rua Zeca Afonso, 6 1ºF, 7800-522 Beja, Portugal (“G4LM”, “we”, “us”). We are the data controller for personal data processed through the G4LM website, and — acting on our customers’ instructions — a data processor for the business data our customers connect to the G4LM platform. For any privacy matter, contact help@galmgroup.com.
2. What we collect
- Account data — name, work email address, and password hash of invited users. Access to G4LM is by invitation only; we do not operate open registration.
- Customer business data — when a firm connects an accounting system (e.g. Xero), we retrieve, on a read-only basis, invoices and contact records to compute analytics. When email analytics ship, we will process message metadata only (sender/recipient domains, subjects, timestamps) — never message bodies.
- Usage & technical data — server logs (IP address, user agent, timestamps) kept for security and reliability, and an audit trail of privileged actions within the platform.
- Website enquiries — anything you send us when requesting access (typically firm name, team size and accounting system).
3. Why we process it (legal bases)
- To provide the service under our contract with your firm (Art. 6(1)(b) GDPR).
- To secure the platform, prevent abuse, and keep audit trails (Art. 6(1)(f) — legitimate interest).
- To answer enquiries you send us (Art. 6(1)(b)/(f)).
- To comply with legal obligations, including tax and accounting rules (Art. 6(1)(c)).
4. Where your data lives
The platform and its database are hosted in the European Union (Frankfurt, Germany), on Vercel (hosting) and Neon (managed PostgreSQL). These providers act as our sub-processors under data processing agreements. We do not sell personal data, and we do not use it for advertising.
5. Integrations are read-only and revocable
Accounting connections use OAuth with read-only scopes; G4LM never writes to your accounting system. Disconnecting an integration deletes the stored access tokens immediately. Data already synced remains in your workspace and is deleted on request or on termination of the contract.
6. Retention
Account and workspace data are retained for the life of the customer contract and deleted within 30 days of a verified deletion request or contract termination, except where law requires longer retention. Server logs are retained for up to 12 months.
7. Your rights
Under the GDPR you may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest. Write to help@galmgroup.com. You may also lodge a complaint with the Portuguese supervisory authority (CNPD — Comissão Nacional de Proteção de Dados).
8. Cookies
The platform uses strictly necessary session cookies to keep you signed in. This website sets no analytics or advertising cookies.
9. Changes
We will post any changes to this policy on this page and update the date above. Material changes will be notified to customers directly.