Home
LaserGlobal.aiLegalPrivacy Policy
v1.0Updated 2026-02-25
Draft pending legal review. This document was prepared as a GDPR-aligned working draft by the Global AI Group LLC Privacy Office. It is not a substitute for advice from qualified counsel — please direct binding interpretation questions to legal@laserglobal.com.
Sections
Who we areData we collectHow we use your dataSharing & processorsInternational transfersData retentionYour rightsCookiesChildren’s dataChanges to this policyContact us & DPO

Privacy Policy

Global AI Group LLC (“LaserGlobal.ai”, “we”, “us”) is a global B2B SaaS platform for laser professionals. This Privacy Policy explains what personal data we process, why, on what legal basis, how long we keep it, and the rights you have under the EU/UK General Data Protection Regulation (“GDPR”) and equivalent regimes.

§ 1 · Who we are

The data controller for personal data processed about you on the platform is Global AI Group LLC, a Florida limited-liability company registered at 198 Tampa Ave E, Venice, FL 34285, USA, trading as LaserGlobal.ai.

You can reach our Privacy Office at privacy@laserglobal.com.

EU Representative pending appointment — interim privacy queries should be directed to privacy@laserglobal.com.

§ 2 · What personal data we collect

We process the categories of personal data set out below. The lawful basis for each category is identified by reference to Article 6 GDPR.

CategoryExamplesPurposeLegal basisTypical retention
Account & identityName, email, password hash, company, country, Portal IDCreate & operate your accountArt. 6(1)(b) — contractLifetime of account + 30 days
Profile & business dataLogo, address, machines registered, certifications, trust scoreDeliver the platform features you sign up forArt. 6(1)(b) — contractLifetime of account
Usage & telemetryPages viewed, feature usage, device & browser, IP address, error logsOperate, secure & improve the platformArt. 6(1)(f) — legitimate interest24 months from collection
Payment dataBilling name, address, card token (held by Stripe), invoices, plan historyBill subscriptions & comply with finance lawArt. 6(1)(b) — contract; Art. 6(1)(c) — legal obligation7 years (tax records)
Marketing communicationsEmail, opt-in status, campaign engagementSend commercial emails you asked forArt. 6(1)(a) — consentUntil you withdraw consent + 6 months
Support & correspondenceChat transcripts, support tickets, attachmentsHelp you, train support agents, dispute resolutionArt. 6(1)(f) — legitimate interest3 years from last contact
Insurance & compliance docsCertificates, carrier names, policy numbers, AI-extracted metadataVerify operator credentials & match to insurance providersArt. 6(1)(b) — contractLifetime of account; AI extracts purged at deletion
Community contentPosts, replies, photos, videoOperate the moderated communitiesArt. 6(1)(b) — contractLifetime of account; redacted on deletion

We do not knowingly process Article 9 special-category data (health, race, religion, biometrics, sexual orientation). If you believe such data has reached us, please email us so we can delete it.

§ 3 · How we use your data

  • Provide the service. Authenticate you, route requests to the right portal (Customer, Manufacturer, Insurance Provider, Admin, Onboarding Admin), display your data back to you.
  • Run the AI assistant (“The Guardian”). Send the prompt + minimum necessary context to our LLM processor (Anthropic) to answer your question. We do not use your prompts to train third-party models.
  • Improve the platform. Aggregated, de-identified telemetry is used to fix bugs, prioritise features and detect abuse.
  • Bill subscriptions. We send your billing details to Stripe to charge your card; Stripe is the data controller for the card token itself.
  • Marketing (consent-based). Send product updates and onboarding emails when you opt in. Every email contains a one-click unsubscribe.
  • Legal & safety. Comply with court orders, tax law, fraud prevention, and platform integrity.

§ 4 · Sharing & third-party processors

We do not sell personal data. We share it only with the processors below, each under a written Data Processing Agreement that meets Article 28 GDPR.

ProcessorRoleHosting regionTransfer mechanism
Anthropic, PBCAI inference (Guardian, triage, drafting)United StatesSCCs (EU 2021/914) — Module 2 (C → P)
Stripe, Inc.Subscription billing & invoice recordsUnited StatesSCCs + Stripe DPA
MongoDB AtlasPrimary application databaseUnited StatesSCCs + Atlas DPA
Amazon Web ServicesApplication & file hostingUnited StatesSCCs + AWS DPA
ResendTransactional & outreach email deliveryUnited States / EUSCCs + Resend DPA
Google LLC (OAuth)Optional sign-in via Google identityUnited StatesSCCs + Google Cloud DPA

When we add or replace a sub-processor with access to your personal data, we will update this list and notify enterprise customers in advance per their DPA.

§ 5 · International data transfers

The platform is operated from the United States. When personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on:

  • Standard Contractual Clauses (EU Commission Implementing Decision 2021/914) and, for UK transfers, the UK International Data Transfer Addendum.
  • Additional technical and organisational measures — encryption in transit (TLS 1.2+) and at rest (AES-256), least-privilege access controls, audit logging, vendor risk reviews.
  • Adequacy decisions where available (e.g. EU – US Data Privacy Framework for participating processors).

A copy of the SCCs or applicable transfer mechanism for a specific processor is available on request to privacy@laserglobal.com.

§ 6 · Data retention

We hold each category of personal data only for as long as we have a lawful purpose. The defaults are:

CategoryRetentionDeletion trigger
Account record & profileLifetime of account + 30 daysAccount closure or admin-initiated deletion
Usage telemetry & error logsUp to 24 monthsTime-based purge
Stripe billing records7 yearsTax & finance law
Support tickets3 years from last contactTime-based purge
AI chat transcripts180 daysTime-based purge unless attached to an open support case
Marketing opt-in recordsUntil withdrawal + 6 monthsUnsubscribe / withdraw consent
Insurance documentsLifetime of accountDSR Erasure or account closure
Backups35 days rollingBackups age out — erasure requests are honoured in primary storage immediately and propagate to backups within 35 days

§ 7 · Your rights under GDPR

If you are in the EU/UK/Switzerland (or another jurisdiction with a comparable regime), you have the following rights regarding your personal data:

  • Right of access (Art. 15) — get a copy of the personal data we hold about you.
  • Right to rectification (Art. 16) — ask us to correct inaccurate data.
  • Right to erasure (Art. 17) — ask us to delete your data, subject to retention obligations.
  • Right to restriction (Art. 18) — pause processing while a dispute is resolved.
  • Right to portability (Art. 20) — receive your data in JSON / CSV and have it sent elsewhere.
  • Right to object (Art. 21) — object to legitimate-interest processing, including direct marketing.
  • Rights re automated decisions (Art. 22) — opt out of solely-automated decisions with legal effects.
  • Right to withdraw consent (Art. 7(3)) — at any time, without affecting prior lawful processing.

To exercise any of these rights, submit a request via our Data Subject Request portal (coming this quarter) or email privacy@laserglobal.com. We will respond within 30 days (extendable by 2 months for complex requests, with notice). You also have the right to complain to your local supervisory authority.

§ 8 · Cookies

We use a small number of cookies and similar technologies to keep you signed in, remember your preferences, and (with consent) measure how the platform is used. Full details are in our Cookie Policy.

You can review and change your choices at any time via the control in the footer.

§ 9 · Children's data

LaserGlobal.ai is a business-to-business platform intended for laser professionals aged 18 and over. We do not knowingly process the personal data of anyone under 16. If you believe a child has provided us with personal data, contact our Privacy Office and we will delete it.

§ 10 · Changes to this policy

We may update this policy from time to time. Material changes will be notified to logged-in users via in-app banner and, where required, by email. The change log below is non-exhaustive — the live document is always the authoritative version.

VersionDateSummary
1.02026-02-25Initial publication aligned with GDPR, UK GDPR and Florida UDTPA expectations.

§ 11 · Contact the Privacy Office / DPO

For privacy questions, DSR follow-up, or to escalate a concern:

  • Email: privacy@laserglobal.com
  • Postal: Global AI Group LLC, 198 Tampa Ave E, Venice, FL 34285, USA (mark envelope “Privacy Office”)
  • Reference: please include your Portal ID if you have one — it lets us authenticate faster.
Global AI Group LLC (trading as LaserGlobal.ai) · 198 Tampa Ave E, Venice, FL 34285, USA
Legal HubPrivacy
We respect your privacy

We use cookies to keep you signed in, run the platform, and (with your consent) measure how it's used. Cookie Policy · Privacy Policy