Legal · v0.1

Privacy Policy

Pursuant to EU Regulation 2016/679 (GDPR) and applicable Italian data protection law.

v0.1 — Preliminary policy. To be reviewed by legal counsel before payment collection.

1. Data controller

The data controller is Swavo, registered in Italy. For any request please write to admin@swavo.ai.

2. Categories of data

Registration data (name, email, phone, company), platform usage data (application logs, interaction events), conversational data (transcripts of Giulia calls and WhatsApp chats handled on behalf of the user's customers), billing data (company name, VAT, address, payment methods via Stripe).

3. Purposes of processing

Providing the Swavo service, contract and administrative management, customer support, product improvement via aggregated analytics, legal compliance (invoicing, retention), service communications. No advertising profiling.

4. Legal basis

Performance of contract (art. 6.1.b GDPR); consent (art. 6.1.a) for non-essential cookies and marketing; legal obligation (art. 6.1.c) for invoicing and retention.

5. Processing methods

Data is processed with electronic means on servers located in the European Union (Supabase EU, Vercel EU, Hetzner Germany). Appropriate technical and organisational measures are in place to prevent loss, unauthorised access, alteration or destruction.

6. Data retention

Account data is retained for the duration of the contract and up to 24 months thereafter. Application logs for 12 months. Billing data for 10 years (statutory). Call transcripts for up to 12 months unless configured otherwise.

7. Disclosure to third parties and sub-processors

Data may be shared with technical providers (Supabase, Vercel, Hetzner, OpenAI, Anthropic, ElevenLabs, Deepgram, Twilio, Meta WhatsApp Business, Stripe, Fatture in Cloud), all bound by GDPR-compliant DPAs. No data is sold to third parties.

8. Data subject rights

Access, rectification, erasure, restriction, portability, objection. To exercise these rights write to admin@swavo.ai. You may always lodge a complaint with the Italian Data Protection Authority (Garante Privacy).

9. Cookies

Swavo uses essential technical cookies (language preference, consent storage) and, only with your consent via the banner, anonymous analytics cookies (Vercel Analytics and Speed Insights) to measure site performance. No profiling or third-party marketing cookies. You can change your preferences anytime via the “Cookie” link in the footer.

10. Transfers outside the EU

Some providers (OpenAI, Anthropic, ElevenLabs, Deepgram, Stripe) are based in the USA. Transfers are based on EU Commission Standard Contractual Clauses and, where applicable, the Data Privacy Framework.