Skip to content

Privacy Policy

How we handle your data

Last updated: February 20, 2026


Table of Contents

  1. Data Controller
  2. Services Use under Terms and Conditions
  3. Our Purposes and Lawful Basis of Data We Collect
  4. For How Long Do We Keep Your Data
  5. Personal Data Update
  6. Disclosure of Personal Data
  7. Rights of the User
  8. Data Security
  9. International Data Transfers
  10. Complaint Submission
  11. Additional Information for California Residents

In compliance with EU General Data Protection Regulation (GDPR, 679/2016/UE) and Italian Personal Data Protection and Digital Rights Guarantees Act (L. 196/2003), we provide you with the following information about the processing of your personal data.

This privacy policy describes how The Formula AI, S.R.L. ("Getbeel", "we", "us", "our") regulates the processing of your personal data collected through the use of the services offered on the websites and the mobile application (hereinafter, "Services").

If you are a California resident, please review the Notice at Collection and the "Additional Information for California Residents" section below for important information about how we process your personal information and your rights under California privacy laws.

The latest update of this Privacy Policy is indicated at the top of this text and it will become effective as of the date indicated in each version. Getbeel, thus, recommends reviewing this Privacy Policy from time to time.

In some cases, additional or supplemental privacy policies may be provided and will apply to certain personal data collected and processed by us. These additional policies will control to the extent there is a conflict with this privacy policy. Additionally, access and use of the Services are governed by the relevant Terms of Use.

PERSONAL DATA PROCESSING — The following sections address our collection and processing of your personal data through our Services, including any of their subdomains and sections.

1. Data Controller

The Formula AI S.R.L., as data controller, is responsible for the processing of users' personal data on the Services:

CompanyThe Formula AI S.R.L.
Registered InCommercial Registry of Milan
Tax Number13815270965
REAMI 2745629
Registered OfficeVia Marco Ulpio Traiano 37, 20149, Milan, Italy
Data Protection Officerinfo@theformulaai.com

2. Services Use under Terms and Conditions

You can only contract our Services and validly accept the relevant Terms of Use of each Service if you are of legal age.

Our products are directed to people of legal age. In specific cases, we may explicitly allow them to be hired for use by minors. They must be examined and accepted, on the minor's behalf, by the person of legal age who is the holder of the parental authority or in charge of their custody or education.

Notwithstanding the aforementioned, if you are a minor, in accordance with our terms and conditions, you cannot validly enter into any of the contracts we offer.

3. Our Purposes and Lawful Basis of Data We Collect

Your personal data is processed with different purposes. Each processing must be based on a lawful basis, among those set forth by the regulation. We use the following basis:

Legal BasisDescription
ConsentYou have given your informed, unequivocal and specific consent to the processing of your personal data aimed at a specific purpose.
Legal ObligationThe law requires us to process and disclose certain data on occasions to certain institutions (for example, to the Tax Authority).
Execution of a ContractThe data are strictly necessary to provide you with our services or to comply with what was agreed with you.
Legitimate InterestsOur legitimate interests, provided that your interests and rights do not prevail over them.

3.1. Browsing the Services

When you browse and use the Services, even if you do not register, data is automatically collected through technology or automated interactions, such as IP address, unique IDs and certain metadata (HTTP header, your browser, etc.). In addition, information may be collected on the number of downloads you perform. These data are recorded in order to, among other things, control the number of downloads made by each user, thus allowing us to detect a fraudulent or illegitimate use of the Services, and other violations of the relevant Terms of Use, that is, the management of the contractual relationship between you and Getbeel.

These technical data observed when the user browses the Services are processed for, among other things, the purpose of detecting and mitigating risks of attacks (bots, code injections, DDOS attacks), and, generally, to guarantee and maintain the Services security. Our lawful basis is our legitimate interest in protecting the security of our systems and preventing the violation of our terms and conditions.

Personal data processed: IP address, device ID and certain metadata such as the browser used or the HTTP/HTTPS header.

3.2. Contractual Relationship with Our Registered Users

When you register as a user (either free or paid), we request the personal data that we need for the management and fulfillment of our contractual relationship with you.

When you are requested to provide personal data that is deemed as necessary, due to legal obligation or in accordance with our contracting conditions, and you refuse to provide them, we may not be able to formalize said contract or provide the service, which will be communicated to you.

You can open your account as a registered user on Getbeel with your own account on other platforms, such as Google, using the federated Login that you will find at the top of our websites, and access whenever you want through them, without having to create and remember a specific username and password to access Getbeel.

This option is possible due to the collaboration between Getbeel and Google as the joint controllers of the processing of your personal data, so that (i) you can identify yourself directly on these platforms, (ii) they confirm that you are who you say you are, and (iii) we provide you with your login as a registered user on Getbeel.

Getbeel obtains from this platform, with your previous consent, your username, image and email address in order to register you as a Getbeel user. Additionally, this platform collects online identifiers (IP address), technical identifiers (from your device, as well as their advertising identifiers such as your "Google ID") and record, each time you use their login, the date and time of your access to Getbeel. Further information can be found in Google Privacy & Terms.

You can exercise your privacy rights (e.g., access, rectification, erasure, limitation of processing, portability and revocation of consent, depending on your jurisdiction) in relation to the personal data obtained from these platforms (and other data that you may have provided to Getbeel in your relationship with us) by contacting Getbeel at the email address provided in this policy.

Please note that the rectification or deletion of your data in your Getbeel account does not automatically imply the rectification or deletion of your data and accounts on the platforms that authenticate your identity: you must also contact them to exercise your rights.

To exercise your personal data protection rights in relation to any other data arising from your relationship with these platforms, you should contact the relevant platform.

3.3. Personalized Advertising on Getbeel and Other Websites

We promote our products with social networks and other platform users, between profiles of potential Getbeel users, using audience segments by interests already offered by platforms such as Google and LinkedIn, and hired by Getbeel for this purpose. Likewise, we can only identify you if you register as a user. Our lawful basis is our legitimate interest in acquiring new clients through personalized advertising of our products through profiling offered by social media and other platforms.

Personal data processed: we select the groups of users to whom advertising will be displayed based on the segments offered by the platforms, such as age ranges, country, or professional role. These platforms provide us with aggregated information about the performance of each campaign, but we cannot identify the specific users who have become registered users as a result of it.

We may also use retargeting to reach visitors who have visited and left our Services without registering, when they have accepted the use of our cookies, allowing us to display advertising to them on third-party websites. In this case, our basis of legitimacy is your consent (given both on our Services and on third-party websites where the advertising is displayed). You can find more information about this treatment in our Cookies Policy.

3.4. Sending of Commercial Communications by Email

We will send you electronic commercial communications if (i) you have registered or contracted any of the Services, (ii) you request information about our products through any of the forms for this. In any case, we will do so as long as you have not expressed your objection to receiving such communications (you can do this conveniently via the specific slider in your user profile, as well as in each communication you receive, at the bottom, via the "Unsubscribe" button).

3.5. Surveys

Based on our legitimate interest to know your opinion in order to improve our products' performance and usability, we may contact you to request your opinion and preferences through satisfaction surveys. In addition, based on our legitimate interests (improving our products, increasing our sales) we offer you to participate in surveys in order to learn first-hand about your opinions and preferences about our products and, on that basis, to eliminate friction, facilitate their use and improve your interactions with them. Therefore, we will contact you to ask for your opinion through satisfaction surveys.

Personal data processed: contact information.

3.6. AI Assistant Customer Support

We use an artificial intelligence-based chat system to provide you with faster and more efficient support.

How it works: The AI assistant operates through the fully automated analysis of your queries, using natural language processing and predefined rules to identify the topic of your request and provide the most suitable response. To do so, it compares your query against a knowledge base composed of frequently asked questions, your account data, and predefined customer support rules.

Legal basis: Your explicit consent, provided by clicking the relevant acceptance button before initiating a conversation with the assistant. You may withdraw your consent at any time, in which case you will be redirected to our human support team. The withdrawal of consent shall not affect the lawfulness of any processing carried out prior to such withdrawal.

Personal data processed: username, email address registered with Getbeel, language preference, browser, time zone, operating system, and the content of your queries and conversations with the AI assistant.

Your right to challenge automated decisions: If you believe that the assistant's response is unsatisfactory, inaccurate, or prejudicial, or if it is unable to provide you with a satisfactory answer, you may challenge the decision or lodge a complaint at info@theformulaai.com. Our human supervisor team will review your case, taking into account any additional details and context you submit, before reaching a final decision.

3.7. Submitting Your Resume

When you apply to join the The Formula AI team or as a freelance designer or collaborator, we process your personal data on the basis of your consent, in order to assess your recruitment.

Personal data processed: contact information and information included in your CV and/or cover letter provided to support your application.

3.8. Third-Party Integrations, APIs, Plugins and Extensions

We may integrate or utilize various third-party extensions, add-ons, APIs, plugins, and other technologies (collectively, "Third-Party Integrations") within our platform or services. These Third-Party Integrations are operated and provided by independent companies that are not under our direct control.

This involves connecting and accessing some of your data in Google, always under strict adherence to Google's API Services User Data Policy, including its Limited Use requirements.

Regarding the processing of your personal data granted by Google, we inform you of the following: The data obtained from Google — email, name, language preference and image — and the same information is collected in order to give you access to our products and to ensure compliance with our terms and conditions, i.e. with our agreement with you using our extension. Also, such data is used for security purposes against any type of attack or fraudulent or illegitimate use of the same, based on our legitimate interest to maintain the security, integrity and resilience of our systems and ensure the regular provision of the service, and to comply with our agreements and protect our assets. You may deactivate or unsubscribe at any time and may exercise your privacy rights, in particular your right to object, by contacting us at the address given in the specific section of this policy.

Additionally, Getbeel integrates with the following types of third-party services to provide its accounts payable automation functionality:

  • Email providers (e.g., Gmail, Outlook): to scan and extract invoice-related emails in accordance with the semantic search parameters configured by the user.
  • Banking and financial data providers: to import bank statements for reconciliation with extracted invoices.
  • Electronic invoicing systems (e.g., SDI — Sistema di Interscambio): to issue and transmit electronic invoices as required by Italian law.

Each integration operates only upon user authorization and processes only the data strictly necessary to perform the requested function.

3.9. AI-Based Products — Getbeel Data Processing

Getbeel is a platform that uses artificial intelligence to automate the following processes:

  • Email inbox scanning, extraction of relevant emails, and storage within the platform.
  • Reconciliation of bank statements with extracted invoices.
  • Issuance of electronic invoices for entities subject to mandatory electronic invoicing in Italy.
  • Self-invoicing of foreign invoices for businesses with their registered office in Italy.

Email Access and Semantic Search

When you grant the software access to your email inbox to enable scanning and extraction, you are not granting access to all of your emails. Getbeel's proprietary algorithm performs a semantic search (which does not involve artificial intelligence systems) based on the information for which extraction has been authorized (provider name and the keyword "invoice" or "receipt", according to the semantic search preferences selected by the user). Emails that do not match the parameters of the semantic search performed by the algorithm are not read, opened, or processed in any way, and remain under the exclusive control of the user.

Only for emails that match the semantic search parameters, the invoice-related information contained in the email is extracted and transferred to the Getbeel platform. Once collected within the platform, artificial intelligence systems perform the reconciliation between invoices and bank statements. All data and information that do not match the semantic search parameters are inaccessible to Getbeel and to the artificial intelligence systems used by Getbeel.

The user may modify or restrict the semantic search parameters at any time. In the event that such parameters are modified, the client assumes responsibility for any failure to extract invoices corresponding to removed or modified parameters.

Purposes of Processing

The information and data collected as described above are processed for the following purposes:

  • To provide our Service in accordance with our terms and conditions and usage policy, based on the existing contract between the parties.
  • To maintain the security of our products and systems, based on our legitimate interests.

Additionally, in no case do these data processing activities aim to uniquely identify you.

Personal Data Subject to Processing

  • Registered user data (such as name, email, and login credentials).
  • Data contained in emails extracted in accordance with the semantic search parameters, including invoice-related information.
  • Inputs provided during the use of artificial intelligence-based products, as well as the outputs generated by such products.
  • Data contained in bank statements uploaded to or linked with the platform for reconciliation purposes.

3.10. Legally Binding Processing

In some cases we are legally bound by different regulations (regardless of whether or not you give your consent), to process and/or transfer certain personal data to different entities. For example, to the tax authority, or the law enforcement authorities, at their request.

Personal data processed: those set forth in the applicable regulations.

4. For How Long Do We Keep Your Data

We process your personal data only for the necessary period of time, depending on each case. Once our processing has terminated, we keep your personal data blocked for different periods of time. The relevant deadlines in each case are listed below:

Processing ActivityRetention Period
Services security and anti-fraud measuresThirteen months
Contractual relationship dataDuration of the contractual relationship, then blocked for five years (contractual liability / IP claims) and six years (accounting information)
External designer contractual dataDuration of the intellectual property rights license, then blocked for five years (contractual liabilities)
Commercial communications by emailThree years from the last interaction, or until you object, whichever is earliest
Advertising cookiesSee Cookies Policy for detailed persistence information
SurveysDuration of the contractual relationship, unless you have objected
Non-commercial inquiriesDeleted once answered
Employment applicationsOne year from receipt
AI-based features (invoices, bank statements, reconciliation outputs)Duration of the contractual relationship and the legally required retention period thereafter. Extracted email content not related to invoices is not stored.
AI assistant customer supportTime necessary to manage and resolve your request, then blocked for five years (contractual liabilities). Data deleted once the conversation or support ticket is closed, or until you withdraw consent, whichever occurs first.
Fraud prevention (suspended users)Personal identifiers retained in restricted, pseudonymized form for the period strictly necessary to prevent recurrence
Legal obligationsDuring the limitation periods of possible responsibilities derived from our processing, and specifically during the periods imposed by regulation, law or contract

5. Personal Data Update

We ask that you immediately notify us of any changes to your personal data so that the information contained in our systems is up-to-date at all times and does not contain errors. In this sense, you represent and guarantee that the information and data that you have provided us is accurate, current and truthful.

6. Disclosure of Personal Data

Access by Third Parties Providing Services to Us

We may disclose personal data of our Users to third parties only in cases when it is strictly necessary for Getbeel to perform their functions and to comply with the relevant Terms of Use of each Service. We may also share personal information with other third parties to ensure compliance with applicable laws, including:

Sub-Processor CategoryPurpose
Service providersTo manage systems and information technology such as hosting, broadband, IT security or web analytics providers
Payment platforms, banks and transaction companiesTo ensure the fulfilment of necessary transactions
Advertising platforms, CRM and marketing toolsMarketing and advertising purposes
Recruitment management platformsManaging recruitment processes
User support management platformsCustomer support operations
Lawyers, auditors, legal and accounting consultancy servicesLegal, audit and financial compliance

These services provided by third parties are necessary for the development of Getbeel's business activity. The processing of personal data is at all times subject to a contract which establishes the duties of the data processor towards the data controller (us). Under no circumstances will personal information be used for other purposes and it will be managed in compliance with Getbeel policy guidelines, their privacy policy and the applicable data protection regulation.

In accordance with our commitment to your privacy and your data protection right, we exclusively choose only top-tier service providers, leaders in their respective sectors. You can request the list of providers that have access to your personal data, as well as the services provided by each one, through the email address provided in the exercise of rights section.

Data Flows within The Formula AI Group of Companies

The Formula AI, in order to centralise administrative and business infrastructure functions and to benefit from the functional specialisation and compartmentalisation inherent in these corporate structures, will process personal data within the group of suppliers, users and employees based on our legitimate corporate interests. Depending on the case, this processing is mainly carried out as a processor and, exceptionally, as a joint controller (for the execution of strategic decisions of the Group).

Data origin: each of the Group's subsidiaries collects the relevant data directly from the data subject in each case.

Personal data processed: basic identification and contact data, data required to log in (single login), economic and professional data, image, audio and video data (contractual management of suppliers — creators and models), data and metadata specific to web browsing (IT processing and web security).

Processing with an impact on the user's web experience: The single login or centralised management of user data from Getbeel allows us to facilitate access to services, improve user knowledge and offer products or services from other companies in the group; manage incident support and rights, as well as improving the security and transversal management of our Services.

Data subjects have the right to object to any of these processing operations based on our legitimate interests through the channels described in the following section.

7. Rights of the User

We guarantee the exercise of rights established in the General Data Protection Regulation.

You can exercise the rights described below by contacting Getbeel at info@theformulaai.com. Please note that Getbeel may require you to verify your identity before taking action on the request for the exercise of rights.

RightDescription
Right to Be InformedTransparency and information on how we process your personal data. Right that we satisfy, for example, through this Privacy Policy.
Right of AccessRight to request a copy of the personal data we hold, which will be provided to you within a month.
Right of RectificationRight to update or modify the personal data we have if it is incorrect or inaccurate.
Right to Limit ProcessingRight to request us to stop processing your personal data while a complaint is being resolved, among other cases.
Right Not to Be Subject to Automated DecisionsRight not to be subject to a fully automated decision based solely on the processing of your personal data, which produces legal effects concerning you or significantly affects you.

Additionally, when we process your personal data based on your consent or on our contractual relationship with you:

  • Right to Erasure ("Right to Be Forgotten"): Right to request that we delete personal data from our records. You can carry out this request at any time by closing your account, through your profile section.
  • Right to Data Portability: Right to obtain and reuse personal data for your own purposes.
  • Right to Withdraw Consent: Right to revoke at any time the consent previously given to any of our processing of your personal data.

Or, when we process your personal data based on our legitimate corporate interests:

  • Right to Object: Right to object to the processing of personal data based on our legitimate interests claiming circumstances based on your personal situation. You can oppose these treatments related to the sending of advertising both in the registration form, as well as through your own profile, by unchecking the box enabled in the "Notifications" section and through any of the commercial communications we send to you.

8. Data Security

We have implemented appropriate technical and organizational security measures, in accordance with Article 32 of the GDPR, to protect Users' personal data against loss, misuse, unauthorized access, disclosure, or alteration including access control, encryption, monitoring systems, and internal security procedures.

Given the sensitive financial nature of the data processed through Getbeel (invoices, bank statements, accounting records), we apply additional safeguards including encryption of data at rest and in transit, strict access controls, and regular security audits.

However, security risks are inherent in Internet and information technologies, and it is not possible to guarantee the absolute security of personal information.

There are also certain steps you can take to better protect against unauthorized access to your personal information. For example, you should choose a strong password that is unique and do not reuse passwords across multiple sites and services or share your password with others.

9. International Data Transfers

We carry out international data transfers with certain data processors: subcontractors and content delivery networks to help us to deliver our Services.

As mentioned, a data processor may be an external service provider engaged by us, which may have access to, process or store personal data about customers or partners in the context of the service it provides to us.

Some of these external service providers are located outside of the European Economic Area (EEA), so the processing of your personal data involves an international data transfer to jurisdictions with different standards than the EEA. Your data may be transferred outside the European Union in accordance with the terms set out in this Privacy Policy, but will not be disclosed to third parties, except in the cases expressly provided for in the applicable regulations or when necessary for the provision of the contracted services.

Our international data transfers can occur to countries with a level of protection of personal data potentially lower than that imposed by the GDPR. Said international data transfers are covered by standard contractual clauses (Art. 46.2.c GDPR).

10. Complaint Submission

If you have any questions regarding the way Getbeel processes your personal data, you can contact us by sending an email to info@theformulaai.com or by contacting directly:

Italian AuthorityGarante della Privacy — www.garanteprivacy.it
Spanish AuthorityAgencia Española de Protección de Datos (AEPD) — www.aepd.es

11. Additional Information for California Residents

This section of the privacy policy provides additional information for California residents and describes our information practices pursuant to applicable privacy laws, including the California Consumer Privacy Act and the regulations issued thereto, each as amended ("CCPA"). To the extent you are a California resident, and we collect "personal information" subject to the CCPA, the following applies.

This section does not address or apply to our handling of personal information that is exempt under the CCPA, such as publicly available information or de-identified or aggregated information. The information provided in this section is intended to provide an overall description of how we process California consumer's personal information. This section does not address or apply to information or practices that are not subject to the CCPA or to the personal information we collect from our contractors, job applicants, employees, Ambassadors, or professional designers, or to personal information we process related to events we may host or sponsor, which are subject to different notices.

11.1 — Categories of Personal Information Collected and Disclosed

Categories of personal information collected: Generally, we collect the following categories of personal information:

  • Identifiers such as name, alias, address, unique personal identifier, online identifier, Internet Protocol (IP) address, email address, or similar information.
  • Customer records such as your account and profile information and customer records that contain personal information, such as name and contact information.
  • Characteristics of protected classifications such as characteristics of protected classifications under California and federal laws such as date of birth, gender, national origin, and citizenship.
  • Commercial information such as products or Services purchased, obtained, or considered, or other purchasing or use histories or tendencies.
  • Internet or other electronic network activity information such as information regarding your use of our Website such as browsing history, clickstream data, search history, and information regarding your interactions with our Websites and advertisements, including access logs and other activity information related to the use of our Services.
  • Geolocation data such as general location information about a particular individual or device.
  • Professional information such as current and former employer(s) and position(s), business contact information, and professional memberships.
  • Audio, Electronic, Visual, or Similar Information such as audio, electronic, visual, or similar information including photographs and images (e.g., that you provide us).
  • Inferences such as inferences drawn from other personal information that we collect to create a profile reflecting an individual's preferences.
  • Sensitive personal information such as driver's license number, and state identification card number.

11.2 — Sources of Personal Information

We collect personal information from the following sources: directly from individuals, through our Websites, service providers, business partners, advertising networks, internet service providers, operating systems and platforms, social media platforms, public and third-party databases, or other third parties.

11.3 — Retention

We retain the personal information we collect only as reasonably necessary for the purposes described above or as otherwise disclosed to you. For example, we will retain information as necessary to comply with our tax, accounting, and recordkeeping obligations, to provide you with the Services, and an additional period of time as necessary to protect, defend, or establish our rights, defend against potential claims, and comply with our legal obligations. In some cases, rather than delete your personal information, we may deidentify or aggregate it and use it in compliance with the CCPA.

11.4 — Purposes for Processing Personal Information

As more fully described in the "Our purposes and lawful basis for data we collect" section above, we collect, use, and otherwise process the above categories of personal information to operate and improve our Websites and Services, to manage your account, to contract with you, to promote our Websites and Services including across other websites and third-party services, to communicate with you, display personalized advertisements, conduct surveys, for research and analytics purposes, to develop new features, for safety and security, to prevent fraud, to respond to inquiries and complaints, for other customer service purposes, to comply with legal obligations, for general business operations, and for other business administration purposes including to investigate, prevent, or take action regarding illegal activities, suspected fraud, and situations involving potential threats to the safety of any person or violations of this privacy policy.

11.5 — Sensitive Personal Information

We do not use or disclose sensitive personal information beyond the purposes authorized by the CCPA. Accordingly, we use and disclose sensitive personal information as reasonably necessary:

  • To perform our services requested by you;
  • To help ensure security and integrity, including to prevent, detect, and investigate security incidents;
  • To detect, prevent and respond to malicious, fraudulent, deceptive, or illegal conduct;
  • To verify or maintain the quality and safety of our services;
  • For compliance with our legal obligations;
  • To our service providers who perform services on our behalf; and
  • For purposes other than inferring characteristics about you.

11.7 — California Resident Rights

The CCPA provides California residents with certain rights regarding their personal information. This section describes those rights and how to exercise them. Please note that these rights are subject to certain conditions and exceptions.

  • Right to know / request access: The right to know:
    • The categories of personal information we have collected about you;
    • The categories of sources from which we have collected your personal information;
    • The business or commercial purposes for collecting, selling, or sharing your personal information;
    • The categories of third parties to whom we have disclosed your personal information; and
    • The specific pieces of your personal information we have collected.
  • Right to delete: Subject to certain conditions and exceptions, you have the right to request we delete your personal information.
  • Right to correct: Subject to certain conditions and exceptions, you have the right to request that we correct inaccuracies in your personal information.
  • Right to opt-out of sales and sharing: You have the right to opt-out of "sales" and "sharing" of your personal information, as those terms are defined under the CCPA. While we do not "sell" personal information in the traditional sense (i.e., for money), our use of third-party analytics and advertising cookies may be considered "selling" and "sharing" under the CCPA.
  • Right to non-discrimination: We will not discriminate against you for exercising any of the rights described in this section.

To exercise your rights, email us at info@theformulaai.com.

11.8 — Verification

When you submit a request, we will take steps to verify your identity and request by matching the information provided by you with the information we have in our records. In some cases, we may request additional information in order to verify your identity, or where necessary to process your request. If we are unable to verify your identity after a good faith attempt, we may deny the request and, if so, will explain the basis for denial. You may also designate someone as an authorized agent to submit requests and act on your behalf. Authorized agents will be required to provide proof of their authorization, and we may also require the relevant consumer to verify the identity and the authority of the authorized agent.