Privacy Policy
Last updated: August 14, 2026
1. Data Controller
The data controller responsible for personal data processed through this website and services operated under the SaviaIA brand is:
- Entity / Provider: SaviaIA
- Contact Email: soporte@saviaplatform.com
- Privacy Email: admin@saviaplatform.com
- Data Protection Officer (DPO): not applicable. Processing does not meet any of the mandatory conditions set out in Article 37(1) of the GDPR.
2. Data We Process
We process different categories of data depending on your relationship with SaviaIA:
- Account and contact data: name, email address, encrypted password, company name, website URL, and business sector.
- Service usage data: access logs, IP address, assistant-generated conversations, and usage metrics.
- Billing data: corporate details, tax identifiers, and payment information managed securely through our payment service provider.
- Browsing data: technical information collected via strictly necessary local storage (see Cookie Policy).
In addition, when a person converses with an assistant published by a SaviaIA customer, we process the following data on behalf of that customer, who acts as the data controller:
- The full content of the conversation with the assistant, including messages sent and received.
- Contact details voluntarily provided during the conversation: name, email address, and phone number.
- A cryptographic hash of the IP address and browser user agent. The raw IP address is never stored in plain text.
- Consent to receive commercial communications, together with its date, only when the individual explicitly checks the box.
No registration or login is required to chat with an assistant.
3. Purposes and Legal Grounds
We process your personal data for the following purposes and under the following legal bases:
- Providing and managing the subscribed service — legal basis: contract performance.
- Creating and administering your account — legal basis: contract performance.
- Handling information requests and demo inquiries — legal basis: consent or pre-contractual measures.
- Billing and compliance with statutory tax obligations — legal basis: legal obligation.
- Improving and ensuring the security of the service — legal basis: legitimate interest.
- Sending service-related operational notices — legal basis: contract performance or legitimate interest.
4. Data Retention Period
We retain your data for the duration of the contractual relationship and, following its termination, for the statutory retention periods required to address any legal liabilities.
- Contractual and billing records: six years following contract termination pursuant to the Spanish Commercial Code, and four years for tax purposes under applicable tax legislation.
- Technical messaging channel logs: 180 days (operational technical benchmark).
- Assistant conversations and messages: retained as long as the customer maintains their assistant active on the platform.
- Documents uploaded by the customer: retained until the customer deletes them directly from their dashboard.
- Upon requesting the permanent deletion of an assistant, all associated data is permanently and irreversibly purged from active servers.
Any data subject may request access to or erasure of their personal data at any time, independently of these retention periods.
5. Recipients and Data Processors
To deliver our services, we engage technology providers who act as data processors under the guarantees of Article 28 of the GDPR:
- Anthropic (United States) — language model provider for generating responses strictly bounded by the customer verified corpus.
- Google (United States) — federated authentication, assisted extraction, and calendar integration when enabled by the customer.
- Stripe (United States and Ireland) — secure payment processing and subscription billing.
- Meta Platforms (United States and Ireland) — WhatsApp Business channel, when enabled by the customer.
- Telnyx (United States) — telephony and voice infrastructure, when enabled by the customer.
- Cloud hosting and database infrastructure: secure cloud data centers located within the European Union / EEA with encryption at rest and in transit.
The models used for generating semantic representations (embeddings) and transcribing voice notes run directly on the service’s own infrastructure.
We do not transfer your personal data to third parties, except where required by law.
6. International Data Transfers
Some of the service providers identified in the preceding section are established outside the European Economic Area, primarily in the United States. In particular, the language model that generates assistant responses executes on infrastructure operated by a US provider.
These transfers are governed by the safeguards established under Chapter V of the GDPR: Standard Contractual Clauses approved by the European Commission or, where applicable, the EU–US Data Privacy Framework adequacy decision. You may request a copy of these safeguards at the address provided below.
7. Your Rights
You may at any time exercise your rights of access, rectification, erasure, restriction of processing, objection, and data portability by writing to admin@saviaplatform.com, specifying the right you wish to exercise and proving your identity.
If you have interacted with an assistant deployed by a customer organization and wish to exercise your rights regarding that dialogue, you may contact that organization or us directly: we possess the technical capabilities to locate and delete your data based on the email address or phone number you supplied.
Where you have provided consent to receive commercial communications, you may withdraw it at any time, without affecting the lawfulness of processing carried out prior to withdrawal.
If you consider that the processing of your personal data infringes applicable regulations, you have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos – AEPD, www.aepd.es), C/ Jorge Juan 6, 28001 Madrid, Spain.