1. Overview & scope
Claivi Technologies Inc. ("Claivi", "we", "our", "us") provides an AI-assisted customer-support platform for small and medium businesses. This Privacy Policy explains what personal data we collect, why we collect it, how we protect it, and what rights you have over it.
This policy applies to all users of the Claivi platform — including workspace owners, operators (agents), and the end customers whose messages are processed through the service. If you are a customer messaging a business that uses Claivi, that business is the "Controller" of your data under applicable law, and you should direct your privacy requests to them first.
Governing frameworks: Personal Information Protection and Electronic Documents Act (PIPEDA, Canada), General Data Protection Regulation (GDPR, EU/UK — where applicable), California Consumer Privacy Act as amended (CCPA/CPRA), Ontario's private-sector privacy laws, and Quebec Law 25.
Where any provision of this policy conflicts with applicable law, the stricter requirement prevails.
2. Legal entity & regulator
Data Controller (for workspace data):
Claivi Technologies Inc.
200 Bay Street, Toronto, ON M5J 2J2, Canada
Email: privacy@claivi.com
Privacy Officer: dpo@claivi.com
Primary regulator: Office of the Privacy Commissioner of Canada (OPC). For Quebec users: Commission d'accès à l'information du Québec (CAI). For users in the European Union/UK, our representative is appointed as required by Article 27 GDPR — contact dpo@claivi.com for referral.
3. Data we collect
We collect the following categories of personal data:
3.1 Account & billing data
- Full name, business email, job title.
- Hashed password (we never store plaintext passwords).
- Workspace name, business address, phone number (optional).
- Billing details: billing address, tax IDs, payment method token (Stripe token — we never store full payment card numbers).
- Verification status, account creation IP, account age.
3.2 Conversation data
- Messages sent and received through channels you explicitly connect (Instagram, Telegram, WhatsApp, web chat, email).
- Attachments and media: file names, sizes, metadata. Message timestamps.
- Channel-specific identifiers: Instagram DM ID, Telegram chat ID, WhatsApp phone number, email address of the end customer.
- AI-generated draft replies, confidence scores, embedding vectors of messages.
- We do not read messages from channels you have not enabled.
3.3 Knowledge base content
- FAQs, articles, documents, and Q&A pairs you upload.
- Embedding vectors derived from your documents for RAG retrieval.
- Upload metadata: author, timestamp, version history.
3.4 Technical & usage data
- IP address, browser user-agent, device type, operating system.
- Dashboard interaction patterns (page views, feature usage).
- Aggregated performance counters: response time, resolution rate, message volume.
- Audit logs: all state-changing actions with timestamp, actor, target, IP.
- Third-party authentication identifiers (Google ID, GitHub ID) if OAuth is used.
3.5 Data we do NOT collect
- We do not collect precise geolocation (beyond IP-based country).
- We do not collect special categories of data (health, religion, biometrics, political opinions, trade union membership).
- We do not knowingly collect payment card numbers, government IDs, passwords, or financial account credentials.
- We do not run advertising trackers, social-media pixels, or session-replay tools.
4. How we collect it
We collect personal data from these sources:
- Directly from you: account registration, dashboard inputs, KB upload, settings.
- From connected channels: messages flow through APIs from Meta (Instagram), Telegram, WhatsApp, and your website's widget or email.
- From authentication providers: Google and GitHub OAuth provide name, email, and avatar URL.
- Automatically: IP address, user-agent, and usage patterns are captured by our servers and CDN (Cloudflare).
5. How we use it
We use personal data exclusively for the following purposes:
- Service operation: store conversations, generate AI-assisted draft replies, route conversations to human operators, maintain your private RAG index.
- Your private AI index only: Your messages and documents train only your workspace's private embedding index. They never improve a global model, are never shared with other tenants, and are never used for third-party training.
- Billing: count resolved conversations, generate invoices, process payments via Stripe, send receipts.
- Security & abuse prevention: detect unauthorized access, enforce rate limits, block abusive behavior, maintain audit trails.
- Communications: send transactional emails (invites, password resets, security alerts, billing notices), product updates with opt-out, and critical security advisories (no opt-out for these).
- Product improvement: aggregated, anonymized analytics to improve routing accuracy, UI, and performance. Individual message contents are never used for product improvement.
- Legal compliance: respond to lawful requests, enforce our Terms of Service, protect our rights and the rights of others.
We do not sell personal data. We do not rent, trade, or share personal data for monetary or other valuable consideration. We do not profile you for cross-context behavioral advertising. We do not share data with data brokers.
6. Legal basis (GDPR)
For individuals in the EEA, UK, and Switzerland:
- Contract performance (Art. 6(1)(b)): processing necessary to deliver the service — account management, routing, billing.
- Legitimate interests (Art. 6(1)(f)): security monitoring, fraud prevention, aggregated analytics, direct marketing with opt-out.
- Consent (Art. 6(1)(a)): for non-essential cookies and certain marketing. Withdrawable at any time.
- Legal obligation (Art. 6(1)(c)): compliance with laws, court orders, or regulatory requests.
For conversation data, the workspace owner is Controller.
7. AI & automated decision-making
Claivi uses AI to assist customer support:
- Three-tier pipeline: (1) deterministic FAQ match, (2) embedding search, (3) LLM fallback. Tenants are isolated.
- No fully automated decisions: AI drafts are subject to optional human review. Claivi does not make automated decisions with legal effects.
- PII redaction: emails, phones, cards, passports, IBANs, SNILS, INN are auto-redacted before AI processing.
- Output guardrails: every AI reply is scanned for prompt leakage, system-prompt fragments, off-topic code, and KB exfiltration.
- No training on your data: zero-retention API configurations are used with AI providers.
- Right to human review: request human review via privacy@claivi.com.
8. Data retention
- Conversation messages
Default: 90 days. Configurable 30-365 days in settings. Permanently deleted on expiry. - Account data
Lifetime + 30 days post-deletion. Billing records: 7 years (tax law). - Knowledge base
Deleted within 30 days of removal or account termination. - Audit logs
Immutable for 1 year, archived for 2 more. Access limited. - Analytics
Aggregated counters: indefinite (anonymized). Raw logs: 90 days. - Backups
30-day encrypted retention. Purged per policy on restore.
9. Cross-border data transfers
Claivi may transfer data globally with appropriate safeguards:
| From | To | Safeguard |
|---|---|---|
| Canada | United States | SCCs + DPA + zero-retention |
| Canada | European Union | EU Adequacy Decision + SCCs |
| EEA/UK | Canada | EU Adequacy Decision (Art. 45) |
| EEA/UK | United States | EU-US Data Privacy Framework + SCCs |
To request SCCs: dpo@claivi.com.
10. Sub-processors
| Sub-processor | Processing | Location | Certification |
|---|---|---|---|
| AWS | Compute, RDS PostgreSQL, S3 | Montreal, Canada | SOC 2, ISO 27001, PCI DSS |
| OpenAI | LLM inference (zero-retention) | United States | SOC 2 Type II |
| Stripe | Payments, billing | United States | SOC 2, PCI DSS Level 1 |
| Cloudflare | CDN, DDoS, WAF | Global edge | SOC 2, ISO 27001 |
| Resend | Transactional email | EU (Frankfurt) | SOC 2, GDPR-compliant |
30-day notice before engaging new sub-processors. 14-day objection right.
11. Security measures
Encryption at rest
AES-256 for PostgreSQL, S3, backups. AWS KMS with auto-rotation.
Encryption in transit
TLS 1.2+ required. HSTS, mTLS for inter-service communication.
Access control
RBAC (admin/agent/viewer). 2FA required for owners. 24h session timeout.
Audit logging
Immutable trail of all state-changing operations. 1-year retention.
Penetration testing
Annual third-party pen test. Quarterly internal reviews.
Vulnerability management
Daily dependency scanning. SAST in CI/CD. 30-day patch SLA.
Network security
VPC isolation. WAF. DDoS protection. No public DB access.
Personnel security
Background checks. NDAs. Quarterly access reviews. Least privilege.
12. Data breach protocol
- Detection: automated monitoring, intrusion detection, 24/7 security on-call.
- Containment: isolate affected systems, revoke credentials, forensic snapshot.
- Assessment: scope, data categories, root cause within 24 hours.
- Notification to workspace owners within 48 hours of confirmed breach.
- Regulatory notification: OPC within 72 hours (PIPEDA), CAI (Quebec Law 25), supervisory authority (GDPR).
- Remediation: prevent recurrence, update controls, post-mortem.
Workspace owners must notify their end customers.
13. Your rights
- Access (PIPEDA, GDPR Art. 15, CCPA): portable copy in JSON or CSV.
- Rectification (PIPEDA, GDPR Art. 16): correct inaccurate data.
- Erasure (PIPEDA, GDPR Art. 17, CCPA): delete within 30 days.
- Restrict (GDPR Art. 18): pause processing during dispute.
- Portability (GDPR Art. 20): structured, machine-readable format.
- Object (GDPR Art. 21): to legitimate interest processing, including marketing.
- Withdraw consent (GDPR Art. 7): any time, does not affect prior processing.
- Non-discrimination (CCPA): no discrimination for exercising rights.
- Know / opt out (CCPA): we do not sell personal information.
- Human review of AI decisions: request via privacy@claivi.com.
Request via dashboard or privacy@claivi.com. Identity verification required. No fee unless manifestly unfounded.
14. Complaints & regulator
- Canada (PIPEDA): priv.gc.ca, 1-800-282-1376.
- Quebec (Law 25): cai.gouv.qc.ca.
- EU (GDPR): local DPA — edpb.europa.eu.
- UK: ICO — ico.org.uk.
- California (CCPA): CPPA — cppa.ca.gov.
Contact us first. Response within 15 business days.
15. Changes to this policy
- Email notice to workspace owners 30 days before material changes.
- Dashboard banner for 14 days.
- Continued use after effective date constitutes acceptance.
16. Contact
Claivi Technologies Inc.
200 Bay Street, Toronto, ON M5J 2J2, Canada
Privacy: privacy@claivi.com
DPO: dpo@claivi.com