Privacy Policy

Last updated: August 31, 2026

1. Introduction and Scope

In this Privacy Policy, “Sheetgo”, “we”, and “us” mean the entity that acts as controller or processor for the relevant processing activity, either Sheetgo Europe S.L. or Sheetgo, Inc., as set out in section 2.

This Privacy Policy explains how Sheetgo processes personal data in connection with:

  • visits to our website;
  • pre-contractual interactions and inquiries;
  • use of Sheetgo products and services;
  • participation in the Sheetgo Data Space;
  • related customer support and compliance activities.

This Privacy Policy applies globally, subject to applicable data protection laws, including Regulation (EU) 2016/679 (GDPR).

If you participate in the Sheetgo Data Space, the Data Space Privacy Addendum also applies and forms part of this Privacy framework.

2. Identity of the Sheetgo Entities

Sheetgo Europe S.L.
Muelle de la Aduana, s/n
Valencia, Valencia 46024
Spain
Email: [email protected]

Sheetgo, Inc.
131 Continental Drive, Suite 305
Newark, Delaware 19713
United States
Email: [email protected]

Sheetgo acts as a data controller or data processor depending on the specific processing activity, as described below.

Depending on how the customer purchases the services, the customer’s contract, and therefore the entity acting as controller or processor, is with either Sheetgo Europe S.L. in Spain or Sheetgo, Inc., a Delaware corporation in the United States. The contracting entity is identified at the time of purchase, either in the self checkout or in the Order Form signed with the sales team.

Regardless of which entity enters into the contract, Sheetgo Europe S.L. and its group operate the platform and engage subprocessors on behalf of that entity. Where the GDPR applies to personal data, its requirements apply regardless of which entity issues the invoice.

3. Pre-Contractual Processing

(Leads, Forms, Inquiries)

3.1 What data do we process

We may process:

  • identification and contact details (name, email, company, role);
  • corporate information provided in forms;
  • information necessary to evaluate service suitability;
  • documentation voluntarily shared for onboarding assessment.

3.2 Purpose

  • responding to inquiries;
  • preparing proposals;
  • assessing eligibility for products or the Data Space;
  • conducting compliance checks.

3.3 Legal basis

  • Article 6(1)(b) GDPR — pre-contractual measures at your request;
  • Article 6(1)(f) GDPR — legitimate interest in assessing service suitability.

3.4 Retention

If no contractual relationship is established, personal data is deleted or anonymised within a reasonable period unless legal obligations require otherwise.

3.5 Children’s Data

Sheetgo services are not directed to children under 16, and we do not knowingly collect personal data from children under 16.

4. Use of Sheetgo Products

When you use Sheetgo products:

4.1 Account and subscription data

The applicable Sheetgo entity identified in section 2 acts as data controller for:

  • account creation;
  • billing and invoicing;
  • security and authentication;
  • usage monitoring for service integrity.

Legal basis:

  • performance of a contract (Art. 6(1)(b));
  • legitimate interest in service security (Art. 6(1)(f)).

4.2 Customer Data (Content uploaded or processed)

For Customer Content:

Sheetgo acts as a data processor, processing Customer Content only on documented instructions.

The applicable Data Processing Agreement (DPA) governs these activities.

Sheetgo does not determine the purposes or means of processing Customer Content.

Sheetgo does not access or use Customer Content for its own purposes.

Except for limited technical metadata necessary to operate the service (such as file identifiers, structural headers, connection configuration data, and usage diagnostics), Sheetgo does not store full copies of Customer Content within its internal systems. Customer Content remains within the customer’s designated storage environment unless explicitly configured otherwise.

Some Sheetgo features and products use artificial intelligence (AI), for example to suggest workflow steps when you describe a workflow in natural language or to operate Virtual Employees that a customer deploys. AI processing is performed by the AI services of Sheetgo’s cloud infrastructure provider, acting as a subprocessor. The AI subprocessors are listed on our Subprocessors page. AI processes Customer Content only on the customer’s instructions to provide the requested functionality. Neither Sheetgo nor any of its AI providers uses Customer Content, personal data, or data obtained through integrations to train general AI models. Standard plans use a shared processing environment in the United States. Enterprise and Virtual Employee deployments can be provisioned in a chosen region and in a dedicated environment configured so that the provider does not retain Customer Content.

4.3 Third-Party Platform Integrations

When customers connect Sheetgo to third-party platforms (including Google Workspace, Microsoft 365, Dropbox, or similar services), Sheetgo may request specific account permissions strictly necessary to enable the requested functionality.

A detailed description of such permissions and data handling practices is available in the Third-Party Integrations & API Data Use Notice, incorporated by reference into this Privacy Policy.

5. Participation in the Sheetgo Data Space

Participation in the Sheetgo Data Space is optional and governed by specific contractual rules.

A separate Data Space Privacy Addendum applies.

5.1 Role differentiation

Depending on the processing activity:

Sheetgo acts as:

Data Controller for:

  • onboarding;
  • participation management;
  • logging, traceability, and governance metadata;
  • security monitoring.

Limited Data Processor when facilitating technical data exchange between participants and, where a deployment is configured with a Sheetgo-hosted shared dataset, when hosting that dataset on the participants’ behalf on Sheetgo’s cloud infrastructure.

Participants remain independent data controllers for datasets they designate.

6. Security Measures

Sheetgo implements appropriate technical and organisational measures under Article 32 GDPR, including:

  • encryption in transit and at rest;
  • access control and role-based permissions;
  • logging and traceability;
  • segregation of environments;
  • security monitoring;
  • incident response procedures.

Security practices are periodically reviewed and aligned with recognised industry standards.

Additional information regarding our security, compliance, and audit controls, including independently assessed standards (such as SOC 2 Type II), may be accessed through our Trust Center at https://trust.sheetgo.com/.

7. Service Providers and Subprocessors

Sheetgo may rely on carefully selected service providers for infrastructure, hosting, security, and support.

All subprocessors are subject to:

  • contractual safeguards;
  • confidentiality obligations;
  • GDPR-compliant transfer mechanisms where applicable.

An up-to-date list of subprocessors is available on our Subprocessors page.

8. Processing Locations – International Locations

Sheetgo’s processing infrastructure runs in the United States with a leading cloud infrastructure provider listed on our Subprocessors page. When workflows or AI features run, Customer Content passes through and is processed in transit on this infrastructure, but it is not stored there. Sheetgo stores only identification data on this infrastructure, such as names, email addresses, file names and identifiers, and logs.

Customer Content remains in the storage environment chosen by the customer’s organization, for example Google, Microsoft, or Dropbox, and in the region set by the customer’s own policies.

For Enterprise and Virtual Employee deployments, the region for the AI processing environment, any Data Space dataset hosted by Sheetgo for the deployment, and the AI model provided through that environment is agreed with the customer in the Order Form. For a deployment purchased through a cloud marketplace, which has no Order Form, the region for those items is agreed in a separate written agreement. If the applicable Order Form or separate written agreement does not specify a region, the United States is the default region.

Because Sheetgo Europe S.L. is established in the European Union while processing infrastructure runs in the United States, identification data is transferred from the European Union to the United States. Sheetgo relies on appropriate safeguards under Chapter V GDPR for these transfers, including the Standard Contractual Clauses incorporated into the provider’s data processing terms and the provider’s certification under the EU-U.S. Data Privacy Framework, together with supplementary measures where appropriate.

9. Retention Principles

Personal data is retained:

  • for the duration of the contractual relationship;
  • for applicable statutory limitation periods;
  • for security and audit purposes, where necessary.

Retention periods vary depending on the processing context.

10. Your Rights

Data subjects may request:

  • access;
  • rectification;
  • erasure;
  • restriction;
  • objection;
  • portability.

Requests may be submitted to: [email protected]

Where Sheetgo acts as a processor, requests may be redirected to the relevant controller.

Sheetgo does not perform automated decision-making or profiling within the meaning of Article 22 GDPR in connection with its core services or the Sheetgo Data Space.

Some features use AI to assist users, for example by suggesting workflow steps. These features support the user’s decisions and do not make decisions that produce legal or similarly significant effects without human involvement. AI output can be inaccurate, and users remain responsible for reviewing it. Neither Sheetgo nor its AI providers use personal data, Customer Content, or data obtained through integrations to train general AI models.

If you live in the US, depending on your U.S. state of residence, you may have additional privacy rights under applicable state laws (including, where applicable, California, Colorado, Virginia, Connecticut, and Utah privacy legislation). These rights may include:

  • the right to know what personal information is collected;
  • the right to request deletion;
  • the right to request correction;
  • the right to opt out of targeted advertising;
  • the right to non-discrimination for exercising privacy rights.

Sheetgo does not sell personal data within the meaning of U.S. state privacy laws.

11. Cookies and Tracking Technologies

Sheetgo uses cookies and similar technologies as described in the separate Cookie Policy.

Where required by law, consent is obtained before placing non-essential cookies.

12. Supervisory Authority

Data subjects may lodge a complaint with a supervisory authority, in particular in the EU Member State of their habitual residence, place of work, or place of the alleged infringement. Sheetgo Europe S.L.’s lead supervisory authority is the Spanish data protection authority, the Agencia Española de Protección de Datos (AEPD), at www.aepd.es.

13. Updates to this Privacy Policy

This Privacy Policy may be updated to reflect operational or legal changes.

The latest version will always be available on our website.