Back to Zavyra

Privacy

Zavyra Privacy Policy

Effective date: 13 July 2026

1. Data controller

The controller of account, website and billing data is ProWEB Agency, Parowa 18, 59-724 Osiecznica, Poland, NIP 612-174-56-24. Privacy contact: office@zavyra.com.

2. Customer data in connected stores

When a Zavyra customer imports personal data of buyers, employees or contractors, that customer normally remains the controller and ProWEB Agency acts as a processor under a data processing agreement.

3. Data categories

We may process account identity and contact data, company and invoice data, subscription status, IP address, session identifiers, security and audit logs, support correspondence, connected-store identifiers, tokens, product, offer and order data, and prompts or content sent to AI functions.

4. Purposes and legal bases

Data is processed to create and perform the contract, provide integrations and AI functions, process billing, meet tax and legal duties, protect security, prevent abuse, handle support and claims, improve the service and, where permitted, send product communication. The legal bases include contract performance, legal obligation, legitimate interests and consent where required.

5. Recipients and processors

Data may be shared with hosting, infrastructure, e-mail, monitoring, accounting, legal and security providers, payment operators including Stripe, AI providers including OpenAI, and platforms selected by the customer such as Shopify, Allegro, Etsy or Amazon. Public authorities may receive data where required by law.

6. International transfers

Some providers may process data outside the European Economic Area. Where required, transfers rely on adequacy decisions, Standard Contractual Clauses or another mechanism permitted by GDPR.

7. Retention

Account data is retained for the contract and afterwards for accounting, legal claims and statutory obligations. Security logs are retained for a period proportionate to risk. Customer-imported data is deleted or returned according to the contract, technical retention and backup cycles.

8. Rights

Depending on the legal basis, a person may request access, correction, deletion, restriction, portability, object to processing or withdraw consent. Requests can be sent to office@zavyra.com. A complaint may be lodged with the President of the Personal Data Protection Office in Poland.

9. Required and optional data

Data required for registration, security, invoicing and service delivery is necessary to perform the contract. Marketing data and optional profile fields are voluntary.

10. Automated functions and AI

Zavyra may generate classifications, recommendations, descriptions and alerts automatically. These functions normally do not make decisions producing legal or similarly significant effects about the account holder without human involvement.

11. Cookies

Necessary cookies and similar technologies support login, security, sessions and settings. Analytics or marketing cookies are used only where a valid legal basis, including consent when required, is available.

12. Security

We use organisational and technical safeguards appropriate to risk, including access controls, encrypted transport, logging, backups and software updates. Users should use strong credentials and report suspected incidents promptly.

13. Data processing agreement

Business customers processing buyer or employee data through Zavyra should enter into the Zavyra Data Processing Agreement. It defines instructions, confidentiality, subprocessors, security, assistance and deletion or return of data.

14. Policy changes

This Policy may be updated when law, providers, security measures or service functions change. Material updates will be communicated through the platform or by e-mail.