Privacy Policy
Pursuant to EU Regulation 2016/679 (GDPR) and applicable Italian data protection law.
1. Data controller
The data controller is SWAVO S.R.L., with registered office at Via Olmo 20, 41030 San Prospero (MO), Italy, VAT no. IT04273800369. For any request please write to admin@swavo.ai or via certified email (PEC) to swavo@pec.it.
2. Categories of data
Registration data (name, email, phone, company), platform usage data (application logs, interaction events), conversational data (transcripts of Giulia calls and WhatsApp chats handled on behalf of the user's customers), billing data (company name, VAT, address, payment methods via Stripe).
3. Purposes of processing
Providing the Swavo service, contract and administrative management, customer support, product improvement via aggregated analytics, legal compliance (invoicing, retention), service communications. No advertising profiling.
4. Legal basis
Performance of contract (art. 6.1.b GDPR); consent (art. 6.1.a) for non-essential cookies and marketing; legal obligation (art. 6.1.c) for invoicing and retention.
5. Processing methods
Data is processed with electronic means on servers located in the European Union (Supabase database in Ireland, Vercel application servers in Frankfurt, Hetzner voice infrastructure in Germany). Appropriate technical and organisational measures are in place to prevent loss, unauthorised access, alteration or destruction.
6. Data retention
Account data is retained for the duration of the contract and up to 24 months thereafter. Application logs for 12 months. Billing data for 10 years (statutory). Call transcripts for up to 12 months unless configured otherwise.
7. Disclosure to third parties and sub-processors
Data may be shared with technical providers (Supabase, Vercel, Hetzner, OpenAI, Anthropic, Cartesia, ElevenLabs, Deepgram, Meta WhatsApp Business, Stripe), each bound by a data processing agreement under Article 28 GDPR. No data is sold to third parties.
8. Data subject rights
Access, rectification, erasure, restriction, portability, objection. To exercise these rights write to admin@swavo.ai. You may always lodge a complaint with the Italian Data Protection Authority (Garante Privacy).
9. Cookies
Swavo uses essential technical cookies (language preference, consent storage) and, only with your consent via the banner, anonymous analytics cookies (Vercel Analytics and Speed Insights) to measure site performance. No profiling or third-party marketing cookies. You can change your preferences anytime via the “Cookie” link in the footer.
10. Transfers outside the EU
Some providers (OpenAI, Anthropic, Cartesia, ElevenLabs, Deepgram, Stripe) are based in the USA. In particular, the audio of calls handled by the voice assistant is transmitted to the transcription provider (Deepgram), and the text of the assistant's replies to the speech synthesis provider (Cartesia); their processing also takes place outside the European Economic Area. Transfers are based on EU Commission Standard Contractual Clauses and, where applicable, the Data Privacy Framework.
11. Connected calendars (Google Calendar, Microsoft Outlook)
If you choose to connect your Google or Microsoft calendar, Swavo reads your calendar events (title, time, location, status) solely to display them in the portal Agenda next to your Swavo appointments and to avoid scheduling overlaps. The connection is optional, happens only with your explicit consent and can be revoked at any time from the portal (“Disconnect”) or from your Google/Microsoft account settings; on revocation the tokens are deleted and the mirrored events are erased. If you also enable write access (the optional “Enable write access” button, which requires a separate consent), the appointments you create, move or cancel in Swavo — by yourself or through the AI assistant — are also created and updated as events in the connected calendar. Swavo only creates and modifies events generated by Swavo: events created directly in your own calendar are never modified or deleted by us. Access tokens are stored encrypted on our servers in the European Union. Calendar data is not used for advertising, is never sold or transferred to third parties, is not used to train artificial-intelligence models, and is accessible to our staff only with your consent for support, for security purposes or to comply with the law. Swavo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
12. Artificial intelligence and Google user data (Limited Use)
Swavo includes an AI assistant (“Giulia”) that helps handle appointments and customer requests. Data received from Google APIs (the events of the connected calendar) is processed solely to provide the user-facing features the user asked for — showing those events in the Agenda and avoiding scheduling overlaps — and is not retained by any model. Swavo does NOT use, transfer or sell Google user data (raw, aggregated or derived) to create, train, improve or fine-tune foundational or generalized artificial intelligence or machine learning models, whether our own or third-party. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Swavo’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
13. How we protect Google user data (security measures)
In transit: all communication between your browser, our servers and the Google APIs travels over encrypted HTTPS/TLS channels. Access tokens: Google and Microsoft OAuth tokens are encrypted before being stored, using a dedicated key held in a secrets vault separate from the database; they live in a private schema that is not reachable through the public API and can only be decrypted by the server-side processes that run the synchronisation. Isolation: every record is bound to the owning company and protected by row-level security rules, so one customer can never read another customer’s data. Staff access: only a small number of authorised people can reach production systems, with individual authentication, and only with your consent for support, for security reasons or to comply with the law. Location: data resides on servers in the European Union — database in Ireland, application servers in Frankfurt, voice infrastructure in Germany. Retention and deletion: of the connected calendar we keep a mirror limited to a rolling window (30 days back, 90 days forward), refreshed at every sync; when you disconnect, we immediately revoke the tokens with Google/Microsoft, overwrite them, and delete the mirrored events straight away. On account closure, data is deleted within the periods stated in section 6. In the event of a personal data breach we act in accordance with articles 33 and 34 of the GDPR.