NĀRO Privacy Statement
Version 2.0, last updated: 15 September 2026
This is a translation of the Dutch text. If the two differ, the Dutch text prevails.
1. Who we are
NĀRO is a sole proprietorship (eenmanszaak), registered in the trade register of the Dutch Chamber of Commerce (KvK) under the trade name NARO, KvK number 42062951, VAT identification number NL005466791B70. Contact: contact@gonaro.ai. The registered business address is on record in the trade register and is available on request. NĀRO has no data protection officer. Privacy questions: contact@gonaro.ai.
2. Our two roles
Controller. For website visitors, people who contact us, business contacts we approach and our clients' contact persons, we decide ourselves why and how we process data.
Processor. Our clients are installation and construction companies that use NĀRO to follow up quotes. We process data of their employees, customers and prospects on their behalf, under a data processing agreement. Did you receive a quote or follow-up email from such a company? Please direct questions about your data to that company. If you send your question to us, we forward it within five working days.
3. Which data we process as controller
| Who | Which data | Purpose | Legal basis | How long |
|---|---|---|---|---|
| Visitors to gonaro.ai | IP address, browser and time, via the website host | Serving and securing the website | Legitimate interest: a working, secure website | As briefly as the host keeps it; we store nothing |
| People who contact us | Name, company, email address, phone number and your message | Answering your question, preparing a collaboration | Legitimate interest, or steps at your request prior to a contract | Up to twelve months after the last contact, unless you become a client |
| Business contacts we approach | Name, job title, company, business email address and phone number, reply or unsubscribe | Approaching suitable businesses for business purposes | Legitimate interest: bringing our business to people's attention | Up to twelve months after the last contact. After you unsubscribe, only your email address on a suppression list |
| Contact persons and users at clients | Name, job title, contact details, billing data and communication with us | Performing the agreement, support, invoicing and client contact | Performance of the contract; legitimate interest for contact with employees | Up to two years after the end of the agreement. Financial records seven years (statutory retention) |
| Clients who give a testimonial or case | Name, job title, photo and quote | Showing how NĀRO works | Consent | Until you withdraw it. We update online publications within 14 days |
Source. If we approach you without you having contacted us first, your data comes from public sources such as your company website and from the business database Apollo.io. Our first email explains how to unsubscribe. You can object at any time.
Required? No, but without contact details we cannot answer your question or provide the service.
4. How the service works
- Connecting and detecting. An employee of the client connects their Microsoft mailbox via OAuth. NĀRO never receives their password; access can always be revoked at Microsoft. For detected quotes we store: the recipient's name and email address, subject, date, language, amount if known, technical properties and the follow-up status.
- Style profile and drafts. AI creates a style profile (tone, length, greeting, sign-off) from a selection of sent emails. Only that profile is kept, not the emails. AI then writes drafts of follow-up emails; we do not store email content in our database.
- Morning overview and sending. On a day with scheduled follow-up emails, the client's account holder receives an overview in the morning in which they can let each follow-up email go or hold it back. Without a response before the deadline, the follow-up email is sent as planned, from the employee's mailbox. If a recipient replies, the follow-up stops; AI classifies the reply.
- No training, access and end. We do not train AI models on this data, and under its terms our AI supplier Anthropic may not do so either. Only the owner of NĀRO has access to the systems and looks at email content only in the event of an outage or a question. Within 30 days after the end of the agreement we delete all of the client's data, including style profiles and access tokens; backups no later than 30 days after that.
5. Automated decision-making
NĀRO does not take decisions about people that produce legal effects or similarly significantly affect them (Article 22 GDPR). The AI only determines whether a follow-up email is sent, and the client's account holder can always intervene.
6. With whom we share data
We do not sell personal data and share it only with these service providers, with agreements on data protection.
| Service provider | Purpose | Location |
|---|---|---|
| Supabase | Database of the service | Singapore, storage in the EU (Ireland) |
| Trigger.dev (API Hero Ltd) | Scheduled tasks of the service | United Kingdom, with processing in the United States |
| Anthropic (Anthropic Ireland, Limited) | AI for style profiles, drafts and classifying replies | Ireland, with processing in the United States |
| Google (Google Workspace) | Our own business email | Ireland and United States |
| Moneybird | Bookkeeping and invoicing | Netherlands |
| Stripe | Payments | Ireland and United States |
| Calendly (Calendly LLC) | Scheduling an introduction or demo | United States |
| Typeform (Typeform S.L.) | Form for requesting a sample email | Spain, with processing in the United States |
| HubSpot (HubSpot Ireland Limited) | Managing contact details and requests | Ireland, with processing in the United States |
| GitHub (GitHub Pages) | Hosting of the website gonaro.ai | United States |
Microsoft is not our service provider: the mailbox belongs to the client. Otherwise we only disclose data if the law requires it.
7. Transfers outside the European Economic Area
For the United Kingdom, an adequacy decision of the European Commission applies. For the United States, we use the European Commission's standard contractual clauses, or the service provider's certification under the EU-U.S. Data Privacy Framework. Feel free to ask us which safeguard applies where.
8. Security
We take appropriate technical and organisational measures: access tokens are stored encrypted, the database is shielded, our accounts are protected with two-factor authentication and all traffic is encrypted in transit.
9. Cookies
gonaro.ai does not place tracking or advertising cookies and does not use analytics services. If that changes, we will update this statement in advance and ask for consent where required.
10. Your rights
You have the right to access, rectification, erasure, restriction and portability of your data, and to object to processing based on legitimate interest. You can always object to business outreach (direct marketing); we will then stop immediately. You can always withdraw your consent.
Send your request to contact@gonaro.ai. We respond within one month. You also always have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) via autoriteitpersoonsgegevens.nl.
11. Changes
The current version of this statement is on this page, with the date of the last change. We inform our clients by email of material changes.