Privacy

Privacy Policy

Last updated: September 14, 2026

This policy explains what data GECAS.AI processes when you visit this website, chat with the website AI assistant or contact us, why we use that data and what rights you may have.

In short: we do not sell personal data or use advertising cookies. Your chat messages are processed by OpenAI to generate a response. They may also be logged temporarily to operate and protect the service and forwarded to Justinas's private Telegram chat for human oversight and any follow-up you request. Do not send passwords, payment card details, health information or other sensitive data through the chat.

1.Who we are

Data controller: Justinas Gecas, operating as GECAS.AI, Lithuania. GECAS.AI builds and maintains website AI assistants and business process automation solutions. For privacy questions or requests, email justin@gecas.ai.

2.Data we collect

We do not ask for special-category or highly sensitive personal data. Do not send the website AI assistant passwords, payment details, identity documents, health information or confidential information about other people.

3.Cookies and browser storage

We do not use advertising or cross-site tracking cookies. The chat widget stores an anonymous conversation identifier temporarily in your browser's sessionStorage so the conversation can continue in the same tab; it is removed when you close that tab. Cloudflare may use strictly necessary security technologies to detect malicious traffic and protect the service.

4.Why we use data and our legal bases

We do not send marketing messages unless you specifically request them or clearly agree to receive them. Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect processing that was lawful before consent was withdrawn.

5.AI processing and human oversight

Chat messages are sent through the OpenAI API to generate the assistant's response. Our Responses API requests disable application-state storage. OpenAI may still retain limited abuse-monitoring logs for up to 30 days by default, or longer where required by law or reasonably necessary to protect its services or third parties. API data is not used to train OpenAI models unless the account owner explicitly opts in to share it.

A copy of each website chat question and AI response is also sent to Justinas's private Telegram chat. This supports human oversight, error alerts and any follow-up response you request. If the assistant does not have a reliable answer, it may offer once to collect your contact details so Justinas can reply personally. Providing contact details is optional.

The website AI assistant does not make decisions that produce legal or similarly significant effects for you. We do not use chat data for profiling or targeted advertising.

6.Who receives the data

We use service providers to operate the website and AI assistant. They receive only the information needed to perform their function. We do not sell or rent personal data.

OpenAIProcesses chat content to generate the website AI assistant's response.
TelegramDelivers private copies of chats to Justinas for oversight, error monitoring and follow-up.
RailwayHosts the website AI assistant application and its temporary operational files.
CloudflareProvides website hosting, protection and aggregated traffic statistics.
Web3FormsForwards contact-form data to our email inbox.
Email providerReceives, stores and sends emails relating to enquiries.

We may also disclose data to professional advisers or public authorities where required by law. Some service providers may process data outside the European Economic Area. Where required, those transfers rely on an adequacy decision, standard contractual clauses or another lawful safeguard.

7.How long we keep data

We keep personal data only for as long as reasonably necessary to answer an enquiry, provide the follow-up you requested, protect the service, resolve an error or handle a legal claim. The application may keep temporary operational chat logs on Railway; these are not intended as a permanent customer record and may be cleared during redeployments or maintenance. Telegram and email copies may remain as operational correspondence until they are no longer needed or you ask us to delete them, unless a legal obligation requires longer retention. Service providers retain security and technical logs under their own terms. OpenAI's default abuse-monitoring period is up to 30 days, subject to the exceptions described above.

8.Your rights

Depending on the applicable law and circumstances, you may have the right to access, correct or delete your personal data; restrict or object to its processing; receive data you provided in a portable format; and withdraw consent. You may also object to processing based on legitimate interests.

To exercise a right, email justin@gecas.ai. We may need to verify your identity before acting on your request. You may lodge a complaint with Lithuania's State Data Protection Inspectorate or the supervisory authority in your country.

9.Security and children

We use reasonable technical and organisational safeguards, including restricted system access, traffic controls and private operational alerts. However, no online service can guarantee absolute security.

GECAS.AI is a business service and is not intended for children. If you believe a child has provided personal data, please contact us so we can review and remove it.

10.Changes and contact

We may update this policy when the service or legal requirements change. The date at the top of the page identifies the current version. For privacy questions or requests, email justin@gecas.ai.