Privacy
Zavyra Privacy Policy
Effective date: 13 July 2026
1. Data controller
The controller of account, website and billing data is ProWEB Agency, Parowa 18, 59-724 Osiecznica, Poland, NIP 612-174-56-24. Privacy contact: office@zavyra.com.
2. Customer data in connected stores
When a Zavyra customer imports personal data of buyers, employees or contractors, that customer normally remains the controller and ProWEB Agency acts as a processor under a data processing agreement.
3. Data categories
We may process account identity and contact data, company and invoice data, subscription status, IP address, session identifiers, security and audit logs, support correspondence, connected-store identifiers, tokens, product, offer and order data, and prompts or content sent to AI functions.
4. Purposes and legal bases
Data is processed to create and perform the contract, provide integrations and AI functions, process billing, meet tax and legal duties, protect security, prevent abuse, handle support and claims, improve the service and, where permitted, send product communication. The legal bases include contract performance, legal obligation, legitimate interests and consent where required.
5. Recipients and processors
Data may be shared with hosting, infrastructure, e-mail, monitoring, accounting, legal and security providers, payment operators including Stripe, AI providers including OpenAI, and platforms selected by the customer such as Shopify, Allegro, Etsy or Amazon. Public authorities may receive data where required by law.
6. International transfers
Some providers may process data outside the European Economic Area. Where required, transfers rely on adequacy decisions, Standard Contractual Clauses or another mechanism permitted by GDPR.
7. Retention
Account data is retained for the contract and afterwards for accounting, legal claims and statutory obligations. Security logs are retained for a period proportionate to risk. Customer-imported data is deleted or returned according to the contract, technical retention and backup cycles.
8. Rights
Depending on the legal basis, a person may request access, correction, deletion, restriction, portability, object to processing or withdraw consent. Requests can be sent to office@zavyra.com. A complaint may be lodged with the President of the Personal Data Protection Office in Poland.
9. Required and optional data
Data required for registration, security, invoicing and service delivery is necessary to perform the contract. Marketing data and optional profile fields are voluntary.
10. Automated functions and AI
Zavyra may generate classifications, recommendations, descriptions and alerts automatically. These functions normally do not make decisions producing legal or similarly significant effects about the account holder without human involvement.
11. Cookies
Necessary cookies and similar technologies support login, security, sessions and settings. Analytics or marketing cookies are used only where a valid legal basis, including consent when required, is available.
12. Security
We use organisational and technical safeguards appropriate to risk, including access controls, encrypted transport, logging, backups and software updates. Users should use strong credentials and report suspected incidents promptly.
13. Data processing agreement
Business customers processing buyer or employee data through Zavyra should enter into the Zavyra Data Processing Agreement. It defines instructions, confidentiality, subprocessors, security, assistance and deletion or return of data.
14. Policy changes
This Policy may be updated when law, providers, security measures or service functions change. Material updates will be communicated through the platform or by e-mail.