Privacy Policy
How we collect, use, share and protect personal data when you use SVARA.
Last updated: [placeholder — date]
1. Who we are
[placeholder — legal entity, registered address and, where required, EU representative and Data Protection Officer contact].
2. Data we process
Account data (name, work email, company, billing details), service data (the content and metadata of the customer conversations you route through SVARA) and usage data (logs, device and diagnostic information).
3. Why we process it
To provide the service (contract), to keep it secure and reliable (legitimate interests), to bill you (contract and legal obligation), and — only where you have consented — for non-essential analytics.
4. AI processing
Message content is sent to our model providers solely to generate a draft reply. Your content is not used to train shared or third-party foundation models.
5. Sharing
We share data with the sub-processors listed on our Security page, and with authorities where legally required. We do not sell personal data.
6. Retention
Conversation content is retained for the audit window applicable to your plan and then deleted. Account and billing records are retained as required by law. [placeholder — insert exact retention periods].
7. International transfers
Where data leaves the EEA we rely on adequacy decisions or Standard Contractual Clauses. [placeholder — confirm transfer mechanisms].
8. Your rights
Access, rectification, erasure, restriction, portability and objection, plus the right to lodge a complaint with your supervisory authority. Contact us to exercise them.
9. Security
Encryption in transit and at rest, least-privilege access, MFA on internal systems and logged production access. See the Security page for detail.
10. Changes
We will notify customers of material changes to this policy before they take effect.