Privacy Policy
Global AI Group LLC (“LaserGlobal.ai”, “we”, “us”) is a global B2B SaaS platform for laser professionals. This Privacy Policy explains what personal data we process, why, on what legal basis, how long we keep it, and the rights you have under the EU/UK General Data Protection Regulation (“GDPR”) and equivalent regimes.
§ 1 · Who we are
The data controller for personal data processed about you on the platform is Global AI Group LLC, a Florida limited-liability company registered at 198 Tampa Ave E, Venice, FL 34285, USA, trading as LaserGlobal.ai.
You can reach our Privacy Office at privacy@laserglobal.com.
§ 2 · What personal data we collect
We process the categories of personal data set out below. The lawful basis for each category is identified by reference to Article 6 GDPR.
| Category | Examples | Purpose | Legal basis | Typical retention |
|---|---|---|---|---|
| Account & identity | Name, email, password hash, company, country, Portal ID | Create & operate your account | Art. 6(1)(b) — contract | Lifetime of account + 30 days |
| Profile & business data | Logo, address, machines registered, certifications, trust score | Deliver the platform features you sign up for | Art. 6(1)(b) — contract | Lifetime of account |
| Usage & telemetry | Pages viewed, feature usage, device & browser, IP address, error logs | Operate, secure & improve the platform | Art. 6(1)(f) — legitimate interest | 24 months from collection |
| Payment data | Billing name, address, card token (held by Stripe), invoices, plan history | Bill subscriptions & comply with finance law | Art. 6(1)(b) — contract; Art. 6(1)(c) — legal obligation | 7 years (tax records) |
| Marketing communications | Email, opt-in status, campaign engagement | Send commercial emails you asked for | Art. 6(1)(a) — consent | Until you withdraw consent + 6 months |
| Support & correspondence | Chat transcripts, support tickets, attachments | Help you, train support agents, dispute resolution | Art. 6(1)(f) — legitimate interest | 3 years from last contact |
| Insurance & compliance docs | Certificates, carrier names, policy numbers, AI-extracted metadata | Verify operator credentials & match to insurance providers | Art. 6(1)(b) — contract | Lifetime of account; AI extracts purged at deletion |
| Community content | Posts, replies, photos, video | Operate the moderated communities | Art. 6(1)(b) — contract | Lifetime of account; redacted on deletion |
We do not knowingly process Article 9 special-category data (health, race, religion, biometrics, sexual orientation). If you believe such data has reached us, please email us so we can delete it.
§ 3 · How we use your data
- Provide the service. Authenticate you, route requests to the right portal (Customer, Manufacturer, Insurance Provider, Admin, Onboarding Admin), display your data back to you.
- Run the AI assistant (“The Guardian”). Send the prompt + minimum necessary context to our LLM processor (Anthropic) to answer your question. We do not use your prompts to train third-party models.
- Improve the platform. Aggregated, de-identified telemetry is used to fix bugs, prioritise features and detect abuse.
- Bill subscriptions. We send your billing details to Stripe to charge your card; Stripe is the data controller for the card token itself.
- Marketing (consent-based). Send product updates and onboarding emails when you opt in. Every email contains a one-click unsubscribe.
- Legal & safety. Comply with court orders, tax law, fraud prevention, and platform integrity.
§ 5 · International data transfers
The platform is operated from the United States. When personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on:
- Standard Contractual Clauses (EU Commission Implementing Decision 2021/914) and, for UK transfers, the UK International Data Transfer Addendum.
- Additional technical and organisational measures — encryption in transit (TLS 1.2+) and at rest (AES-256), least-privilege access controls, audit logging, vendor risk reviews.
- Adequacy decisions where available (e.g. EU – US Data Privacy Framework for participating processors).
A copy of the SCCs or applicable transfer mechanism for a specific processor is available on request to privacy@laserglobal.com.
§ 6 · Data retention
We hold each category of personal data only for as long as we have a lawful purpose. The defaults are:
| Category | Retention | Deletion trigger |
|---|---|---|
| Account record & profile | Lifetime of account + 30 days | Account closure or admin-initiated deletion |
| Usage telemetry & error logs | Up to 24 months | Time-based purge |
| Stripe billing records | 7 years | Tax & finance law |
| Support tickets | 3 years from last contact | Time-based purge |
| AI chat transcripts | 180 days | Time-based purge unless attached to an open support case |
| Marketing opt-in records | Until withdrawal + 6 months | Unsubscribe / withdraw consent |
| Insurance documents | Lifetime of account | DSR Erasure or account closure |
| Backups | 35 days rolling | Backups age out — erasure requests are honoured in primary storage immediately and propagate to backups within 35 days |
§ 7 · Your rights under GDPR
If you are in the EU/UK/Switzerland (or another jurisdiction with a comparable regime), you have the following rights regarding your personal data:
- Right of access (Art. 15) — get a copy of the personal data we hold about you.
- Right to rectification (Art. 16) — ask us to correct inaccurate data.
- Right to erasure (Art. 17) — ask us to delete your data, subject to retention obligations.
- Right to restriction (Art. 18) — pause processing while a dispute is resolved.
- Right to portability (Art. 20) — receive your data in JSON / CSV and have it sent elsewhere.
- Right to object (Art. 21) — object to legitimate-interest processing, including direct marketing.
- Rights re automated decisions (Art. 22) — opt out of solely-automated decisions with legal effects.
- Right to withdraw consent (Art. 7(3)) — at any time, without affecting prior lawful processing.
To exercise any of these rights, submit a request via our Data Subject Request portal (coming this quarter) or email privacy@laserglobal.com. We will respond within 30 days (extendable by 2 months for complex requests, with notice). You also have the right to complain to your local supervisory authority.
§ 9 · Children's data
LaserGlobal.ai is a business-to-business platform intended for laser professionals aged 18 and over. We do not knowingly process the personal data of anyone under 16. If you believe a child has provided us with personal data, contact our Privacy Office and we will delete it.
§ 10 · Changes to this policy
We may update this policy from time to time. Material changes will be notified to logged-in users via in-app banner and, where required, by email. The change log below is non-exhaustive — the live document is always the authoritative version.
| Version | Date | Summary |
|---|---|---|
| 1.0 | 2026-02-25 | Initial publication aligned with GDPR, UK GDPR and Florida UDTPA expectations. |
§ 11 · Contact the Privacy Office / DPO
For privacy questions, DSR follow-up, or to escalate a concern:
- Email: privacy@laserglobal.com
- Postal: Global AI Group LLC, 198 Tampa Ave E, Venice, FL 34285, USA (mark envelope “Privacy Office”)
- Reference: please include
your Portal IDif you have one — it lets us authenticate faster.