Skip to content
lavenity

Features

ReportingVen AIVen AI AgentOmnichannel InboxAI Assistant
Pricing
Sign inStart for free
← Back home

Data Processing Agreement

Last updated 5 August 2026

This Agreement governs how we process personal data on your behalf when you use Lavenity. It forms part of the Terms of Service you accept when creating a workspace, and is concluded in electronic form as Article 28(9) GDPR permits — no separate signature is needed.

1. Roles and scope

When visitors to your website write to you through the widget, or when conversations arrive from a connected channel, the personal data in them is yours: you decide why and how it is processed. Under the GDPR you are the controller and we are the processor.

This Agreement covers only that processing. Data about your own account and your teammates, which we process for our own purposes, is covered by our Privacy Policy, where we act as controller instead.

2. Subject matter, duration, nature and purpose

Nature and subject matter: hosting, storage, transmission and display of conversations and contact records, delivery of notifications, and — only where you switch them on — AI reply suggestions, autonomous replies and knowledge-base indexing.

Purpose: providing the Lavenity service to you under the Terms of Service, and nothing else. We do not sell personal data, and we do not use the content of your conversations to train models of our own.

Duration: for as long as your workspace exists, plus the period described in section 9.

3. Categories of data and data subjects

Data subjects are the visitors and customers who contact you, and the teammates who use your workspace. The personal data covers:

  • identifiers and contact details — name, email address, phone number where given, and identifiers from connected channels;
  • conversation content — messages, attachments and internal notes, including whatever a data subject chooses to write;
  • technical data — IP address, browser and device information, page URL and timestamps;
  • any other personal data you choose to send us through the widget, the API or a connected channel.

4. Our obligations

As your processor we undertake that:

  • we process personal data only on your documented instructions — the Terms of Service, this Agreement and the settings you choose in the product together constitute those instructions. If a law requires us to process otherwise, we will tell you before doing so unless that law forbids it;
  • everyone we allow to access the data is bound by an obligation of confidentiality;
  • we maintain the technical and organisational measures required by Article 32 GDPR — encryption in transit, access control, isolation of the widget, signed tokens and rate limiting;
  • we will tell you if, in our opinion, an instruction from you infringes data protection law.

5. Sub-processors

You give general authorisation for us to engage the sub-processors listed below. Each is bound by data protection obligations no less protective than those in this Agreement, and we remain fully liable to you for their performance.

We will give you notice before adding or replacing a sub-processor. You may object on reasonable data-protection grounds, and if we cannot resolve the objection you may stop using the affected part of the service and terminate it.

  • Hetzner Online GmbH (Germany) — hosting, databases and file storage.
  • Supabase — authentication of your teammates' accounts.
  • OpenAI — AI reply suggestions, autonomous replies and knowledge-base indexing. Engaged only for workspaces that switch AI features on; content sent through its API is not used to train its models.
  • Purelymail — delivery of notification and invitation emails.
  • Paddle — payment, invoicing and refunds for your subscription. Paddle receives billing data only, never conversation content.

6. International transfers

Hosting, databases and file storage are located in the European Union.

We are established in Ukraine, for which the European Commission has not adopted an adequacy decision, and some sub-processors operate outside the EEA. Those transfers are covered by the European Commission's Standard Contractual Clauses together with encryption in transit and at rest.

7. Assisting you with data subject rights

If a data subject asks you for access, rectification, erasure, restriction, objection or portability, we will assist you in answering, taking into account the nature of the processing and the information available to us. Write to privacy{'@'}lavenity.com and we will act without undue delay and in any case in time for your own one-month deadline.

The product does not currently expose self-service export or erasure of conversations and contacts, so these requests are carried out by us on your written instruction.

If a data subject approaches us directly about data we hold on your behalf, we will not answer for you — we will tell them to contact you and let you know.

8. Personal data breaches

If we become aware of a personal data breach affecting personal data we process for you, we will notify you without undue delay and in any event within 48 hours of becoming aware. The notice will describe what happened, the categories and approximate number of records concerned, the likely consequences and the measures taken, so that you can meet your own duties under Articles 33 and 34 GDPR.

9. Deletion and return of data

You may instruct us at any time to delete or return the personal data we process for you, and we will do so within 30 days of the request.

When your workspace is closed we delete that personal data within 30 days, except where a law requires us to keep it — billing and tax records being the usual case. Before deletion, and on request, we will return the data in a structured, commonly used, machine-readable format.

Deleted data may persist in encrypted backups until those backups are rotated out of use. We do not restore deleted data from a backup except to recover from an incident.

10. Audits, precedence and changes

On reasonable written request — no more than once a year, unless a supervisory authority requires otherwise or a breach has occurred — we will provide the information needed to demonstrate compliance with Article 28 GDPR, and where that is insufficient we will allow an audit by you or an independent auditor bound by confidentiality, arranged so as not to disrupt the service.

Where this Agreement and the Terms of Service conflict on the processing of personal data on your behalf, this Agreement prevails. We may update it and will give advance notice of material changes; the current version is always on this page.

Contact

Privacy questions: privacy@lavenity.com

Billing and support: support@lavenity.com

Other documentsPrivacy policyTerms of serviceRefundsCookies
lavenity

AI-powered support that keepscustomers moving forward.

Product

  • Reporting
  • Ven AI
  • Ven AI Agent
  • Omnichannel Inbox
  • AI Assistant
  • Pricing
  • Dashboard

Company

  • About us
  • Blog
  • Careers

Resources

  • Help Center
  • Documentation
  • Service status
  • Security

Alternative to

  • Intercom
  • Zendesk
  • Freshdesk
  • Help Scout
  • Crisp
  • Tidio
  • LiveChat
  • HelpCrunch
  • Tawk.to
  • Chatwoot
  • All alternatives

Legal

  • Privacy policy
  • Terms of service
  • Refunds
ENUKNONN