Privacy Policy
Last updated: 3 September 2026 · Version 1.1
This is a convenience translation. The Portuguese version is the governing text. Questions in English are welcome at [email protected].
This Privacy Policy describes how Gavvio collects, uses, stores and shares personal data when you use our platform. It was written in compliance with Brazil's General Data Protection Law (LGPD — Law 13,709/2018) and with the requirements of the integration platforms we connect to (Meta Platforms, Google, TikTok, Stripe, among others).
1. Who we are (Data Controller)
Gavvio is a product of Oyio, operated by ALOYSIO CEDENO GALVAO 85778881509(a Brazilian sole proprietorship, "MEI"), a private legal entity registered under CNPJ 26.943.862/0001-41, headquartered in Salvador, Bahia, Brazil, hereinafter "Gavvio", "we" or "our".
For privacy questions, to exercise your rights or for any request about your data, contact our data protection officer (DPO) at[email protected]. That mailbox is actively monitored and answered within 5 business days.
2. Data we collect
2.1 Directly from you (Gavvio user)
- Identification: full name, e-mail, password (stored as a bcrypt hash — never in plain text).
- Organization: organization name, workspaces, role (owner, admin, analyst, viewer, chat agent, comment moderator).
- Authentication: JWT session tokens, TOTP secret (encrypted with AES-256-GCM) for 2FA.
- Payment: subscription data (plan, charges) processed by Stripe — we do not store card data.
- Platform usage: access logs, actions performed, resources consumed (AI token quota, SEO credits).
2.2 From integrations you connect
When you connect an integration (via OAuth or webhook), Gavvio receives and processes data originating on those platforms. That data belongs to the customer organization; Gavvio acts as a processor in that flow. Summary of what may be collected:
| Provider | Data categories |
|---|---|
| Google Calendar / Meet / YouTube | Calendar events, meeting metadata, Meet transcripts (text), participants, duration; comments on the connected YouTube channel's videos and the replies you publish. |
| Meta (Facebook Pages, Instagram, WhatsApp Business, Ads) | Messages, comments, WhatsApp conversations and calls (and recordings, when enabled), contacts' public profile, campaign metrics, page/account/number IDs. |
| TikTok (TikTok for Business) | Comments on your videos and the replies published, the business account's direct messages, public profile data, profile and video insights, account IDs. |
| Stripe | Subscription events, payments, receipts, transactional tax data. |
| WooCommerce / Hotmart / Mercado Pago | Orders, payment status, product data, basic customer data. |
| Mautic / Chatwoot | E-mail events (open, click, bounce), support conversations, contact metadata. |
| Cal.com / Typebot | Meeting bookings, form/bot answers, calendar events. |
| Your website (tracking script and forms) | Navigation and conversion events, ad click identifiers, form answers and the contact data provided in them. |
2.3 Data obtained from Google APIs
Gavvio's use and transfer to any other app of information received from Google APIs will adhere to theGoogle API Services User Data Policy, including the Limited Use requirements. Concretely: Google data (calendar, meetings, transcripts, YouTube comments) is used only to provide the features you see in your workspace; it is not sold, not used for advertising, not used to train generalized AI models, and only read by humans with your consent, for security or legal reasons, or in aggregated and anonymized form.
2.4 Data obtained from the Meta and TikTok APIs
Data received from the Meta and TikTok platforms is used exclusively to provide, inside the workspace that connected the account, the inbox, comment reply, automation, contact profile and insights features. It is stored while the channel stays connected, deleted when the channel is disconnected or the account is deleted, and handled in accordance with theMeta Platform Termsand theTikTok for Business terms. We do not use that data to build profiles outside the workspace, for our own advertising, or to train generalized AI models.
2.5 Cookies and similar technologies on gavvio.com
On the public domain gavvio.com we use no marketing, remarketing or ad-profiling cookies. The site is static and sets no cookies of its own; visit statistics come from Cloudflare Web Analytics, which is aggregated and uses no cookies and no visitor identifiers. The application at app.gavvio.com uses only strictly necessary cookies (session and preferences).
3. Purposes of processing (legal basis — LGPD)
| Category | Purpose | Legal basis |
|---|---|---|
| Identification + authentication | Provision the account, keep the session secure, authorize multi-tenant access. | Performance of a contract (art. 7, V) |
| Payment | Process subscriptions, issue receipts, dunning. | Performance of a contract (art. 7, V) + legal/tax obligation (art. 7, II) |
| Integration data | Unify the timeline, generate dashboards, run automations, answer messages and comments, ground RAG answers inside the workspace. | Performance of a contract (art. 7, V) + legitimate interest of the end controller (art. 7, IX) |
| Access logs | Audit, security, fraud prevention, debugging. | Regulatory obligation (art. 7, II) + legitimate interest (art. 7, IX) |
4. Sharing with third parties (sub-processors)
To operate the platform we share minimal amounts of data with the following sub-processors. Each is bound by contracts with data protection clauses (DPA) and technical measures equivalent to ours:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Server hosting, database and object storage. | Germany (EU) |
| Backblaze, Inc. | Backup storage. | United States |
| BunnyWay d.o.o. (bunny.net) | Hosting and delivery (CDN) of videos you upload. | Slovenia (EU), with global points of presence |
| Amazon Web Services, Inc. (SES) | E-mail sending from your domain. | United States / Brazil |
| Resend, Inc. | Transactional e-mail (invites, recovery, notifications). | United States |
| Anthropic PBC | LLM models (Claude) for chat, briefing, the chat builder and content generation. | United States |
| OpenAI, L.L.C. | LLM models (GPT), embeddings and audio transcription (Whisper). | United States |
| Cohere Inc. | Semantic search reranking. | Canada |
| DataForSEO LLC | SEO research data (volumes, SERPs, keywords). | United States / EU |
| Stripe Payments Europe Ltd. | Payment processing and subscription management. | Ireland (EU) |
| Cloudflare, Inc. | Reverse proxy, CDN, DDoS mitigation, DNS, hosting of this site. | Global (with points of presence in Brazil) |
| Sentry / Functional Software, Inc. | Error telemetry and performance monitoring. | United States |
| Meta Platforms, Inc., Google LLC and TikTok Pte. Ltd. | Integration APIs (messages, comments, calendar events, Meet transcripts, insights) — only when you connect those services. | United States / Singapore |
5. International data transfers
Several sub-processors above are located outside Brazil (EU, USA, Canada, Singapore). International transfers rely on Standard Contractual Clauses and the other safeguards accepted by the ANPD under article 33 of the LGPD. We keep an internal inventory of those transfers and the corresponding contracts, available to data subjects on request.
6. Data retention
| Category | Retention period |
|---|---|
| Active user account | While the account is active. |
| Closed account (deletion requested) | Recoverable for 30 days; then irreversibly deleted. Backups are purged within 90 days. |
| Access and audit logs | 12 months (evidence in security incidents and disputes). |
| Financial data (receipts, invoices) | 5 years, per Brazilian tax law. |
| Integration events on the timeline | While the organization is active, or per the retention policy configured by the workspace. |
| Integration OAuth tokens | Deleted immediately when the integration is disconnected, with revocation at the provider where the API allows. |
| Call recordings | Per the period configured by the workspace; deleted with the contact when it is erased. |
7. Your rights as a data subject (LGPD art. 18)
You have the right to:
- Confirmation that your data is processed.
- Access to the data we hold about you.
- Correction of incomplete, inaccurate or outdated data.
- Anonymization, blocking or deletion of unnecessary data.
- Portability of your data to another provider.
- Deletion of data processed on the basis of your consent.
- Information about the public and private entities we share data with.
- Information about the option of not giving consent and its consequences.
- Withdrawal of consent, under article 8, § 5.
- Objection to processing that violates the LGPD.
To exercise any of these rights, e-mail [email protected]or follow the simplified procedure in Data Deletion. We answer within 15 days.
If you are the end customer of an organization that uses Gavvio (for example, you messaged a business on WhatsApp or answered one of its forms), that organization is the controller of your data. You may exercise your rights directly with it or write to us, and we will forward the request.
8. Security
- Passwords are stored with bcrypt; never in plain text.
- 2FA (TOTP) secrets are encrypted with AES-256-GCM at rest.
- Integration OAuth tokens are encrypted with AES-256-GCM at rest.
- Client-server communication always over TLS (1.2 minimum).
- Multi-tenant isolation on every query through a mandatory middleware (
organization_id+workspace_id), with automated isolation tests on every release. - Audit logs for sensitive mutations (billing, white-label, member management, OAuth connections, contact merges, deletions).
- Provider webhooks are validated with an HMAC-SHA256 signature before processing.
- 2FA required for Organization Owners and Admins.
More detail in Security and privacy.
9. Children
Gavvio is not intended for people under 18. We do not knowingly collect data from children or teenagers. If we identify such a case, we delete the data immediately.
10. Changes to this policy
We may update this Policy periodically. Material changes are communicated by e-mail to the Organization Owner at least 30 days in advance. The current version is always available at gavvio.com/privacy.
- Version 1.1 (3 September 2026): added TikTok and YouTube among the integrations, the Google API Limited Use disclosure, the video and e-mail sub-processors, and the 30-day recovery window.
- Version 1.0 (29 April 2026): initial publication.
11. Supervisory authority
If you are not satisfied with our response, you may file a complaint with Brazil'sNational Data Protection Authority (ANPD) atgov.br/anpd.