I. Who we are
Controller
GiovChat (“Giov Chat”, “Giov”, “we”, “us”) is a product of Fegig Technologies Limited. The product website is https://giovchat.app. The company’s website is https://codewithfegig.com. This policy covers giovchat.app, the operator dashboard, the visitor chat widget we host, the mobile SDK, connected channels, GiovBot, accounts, and support.
Privacy, data-protection, and legal requests: legal@giovchat.app. Product support: support@giovchat.app.
Laws we consider
We process personal data in line with applicable law, including:
- UK GDPR and the UK Data Protection Act 2018;
- EU GDPR (Regulation (EU) 2016/679) and the ePrivacy Directive as implemented in EU member states;
- the California Consumer Privacy Act as amended by the CPRA (“CCPA”), and similar US state laws;
- Brazil’s LGPD, Canada’s PIPEDA, and Australia’s Privacy Act, where those laws apply to our processing of your data;
- other mandatory local rules that cannot be contracted out of.
II. Whose data this covers, and our role
Giov handles several groups of people. The legal role is different for each.
- Operators and workspace admins: you create an account with us. We are the controller of that account, billing identity, and product-usage data.
- People who visit our marketing site or email us: we are the controller of that enquiry and website data.
- Your customers and website or app visitors (“End Users”): when they chat through a widget, SDK, or channel you connect, you are the controller. We process that data on your instructions as a processor.
- People on messaging networks (WhatsApp, Messenger, Instagram, Telegram, email): you are typically the controller; the network is a separate controller or processor under its own terms. We process messages that land in your Giov inbox as your processor.
III. The product surfaces this notice describes
Depending on your plan and configuration, Giov may process data in connection with:
- Marketing pages, pricing, checkout, and account creation.
- The operator dashboard: inbox, assignment, notes, search, filters, office hours, ratings, and team seats.
- The website widget and widget appearance, domains, and pre-chat fields (name, email, phone).
- The React Native / mobile SDK in apps you publish.
- Email, WhatsApp, Messenger, Instagram, and Telegram channels on eligible plans.
- Visitor profiles, contact hub, custom attributes, segmentation, page tracking, and timelines.
- Conversation history, file attachments, exports, and audit logs.
- Workspace analytics and diagnostics.
- GiovBot: knowledge, procedures, guardrails, tests, hosted model calls, and bring-your-own-key calls.
- Billing, trials, plan entitlements, and hosted AI credits.
IV. Categories of personal data
Account and Operators
Name, email, hashed password, workspace name, role, authentication logs, and device/browser used to sign in.
Billing
Plan, subscription status, renewal dates, and customer or transaction identifiers from checkout. We do not store full card numbers. Card data is collected by the payment reseller named at checkout.
End User and conversation data (processor)
Messages, files, timestamps, channel, page URL, referrer, approximate location from IP, device and browser type, identity fields you configure (name, email, phone), contact attributes, notes, ratings, and operator actions on the thread.
GiovBot
Knowledge sources you add, prompts, procedures, guardrails, retrieval traces, and AI replies. If you use a bring-your-own key, the model provider also receives the prompt content you send.
Technical and security data
IP address, logs, error reports, and anti-abuse signals. Cookie and similar storage is described in the Cookie Policy.
Special category and sensitive data
We do not require health, religion, biometric, or similar special-category data. If your conversations contain it, you must have a lawful basis to collect it from End Users. Do not use Giov as a medical, legal, or credit-decision system without your own compliance review.
V. Purposes and legal bases (UK / EU GDPR)
Where GDPR applies, we rely on the bases below. Similar concepts exist under other regimes (contract, legitimate interests, consent, legal obligation).
- Article 6(1)(b) contract: creating an account, providing the Services, applying plan limits and credits, sending verification and security email.
- Article 6(1)(c) legal obligation: tax, accounting, and responding to lawful requests.
- Article 6(1)(f) legitimate interests: securing the service, preventing abuse, understanding product usage in a limited way, improving reliability, and responding to enquiries. You may object; see Rights.
- Article 6(1)(a) consent: optional statistics or marketing cookies via Cloudflare Zaraz, and optional marketing email. You can withdraw consent without affecting the core service.
- For End User data in your widget or channels, you determine the basis (typically your contract with that person, legitimate interests in providing support, or consent for cookies / marketing messages).
VI. Payments
Paid plans are sold at checkout by our online reseller, Paddle.com, which acts as Merchant of Record for the purchase. Card details are collected by Paddle, not by Giov.
We receive the email used at checkout, subscription status, and identifiers needed to turn paid features on in your workspace. Paddle’s handling of buyer data is described in its privacy notice at https://www.paddle.com/legal/privacy.
VII. Recipients
We share data with vendors only as needed to run Giov. Typical recipients:
- Cloudflare, for hosting, DNS, content delivery, and Zaraz consent / tag management on our site.
- Our email delivery provider, for verification and service messages.
- Paddle.com, for paid checkout, invoices, and subscription state.
- AI model providers behind hosted GiovBot replies; and, if you connect your own key, the provider you choose.
- Messaging networks you connect (Meta, WhatsApp, Instagram, Telegram, and your email host) so messages can be delivered.
- Professional advisers (legal, accounting) under confidentiality.
- Authorities when required by law, or parties to a genuine business transfer with equivalent protections.
VIII. International transfers
Giov is hosted on Cloudflare and may be accessed from more than one country. Vendors may process data in the United Kingdom, the European Economic Area, the United States, or other regions. We sell to customers globally, so your Operators and End Users may be anywhere you allow.
Where a transfer from the UK or EEA needs a safeguard, we use tools such as the UK International Data Transfer Addendum, EU Standard Contractual Clauses, and vendor security reviews. Ask legal@giovchat.app if you need a summary of subprocessors for a vendor review.
IX. Retention
- Account and workspace records: for the life of the workspace, then a short wind-down so you can export.
- Conversation history: according to your plan’s retention window (for example 90 days on Starter, longer on paid plans), then deleted or anonymised.
- Billing identifiers and invoices: as required for tax and dispute periods (often up to six years in the UK).
- Support and legal correspondence: as long as needed to resolve the matter and keep a limited record.
- Zaraz consent records: according to Cloudflare’s consent cookie lifetime so we can show that a choice was recorded.
- You can ask for export or deletion at legal@giovchat.app. Deleting a workspace removes Customer Content we hold as processor, except copies we must keep for law, security, or billing.
X. Security
We use TLS in transit, hashed passwords, access controls on production systems, and scoped API credentials. No method of transmission or storage is perfectly secure. You must keep operator accounts, widget domains, channel tokens, and AI keys under your control.
XI. GiovBot and automated processing
GiovBot uses machine learning to draft replies from your knowledge and conversation context. That is not intended as a solely automated decision that produces legal or similarly significant effects about a person (for example credit, employment, or essential public services). You remain responsible for review, handoff, and how End Users are told they may be speaking with an assistant.
If you believe an automated output about you as an Operator (for example entitlement or abuse flags) is wrong, email legal@giovchat.app and we will look at it with human review.
XII. Your rights (UK / EU and similar)
Depending on where you live, you may have the right to access, correct, delete, or export your personal data; to restrict or object to certain processing; to withdraw consent; and to lodge a complaint with a supervisory authority (in the UK, the ICO; in the EU, your local DPA).
Email legal@giovchat.app. We may need to verify you are the account owner. We aim to respond within one month. Workspace admins control operator seats and End User data in the dashboard. End Users should contact the business whose widget they used; we will help that business with a valid request.
For payment records held by the reseller, you can also use the contact details on your receipt or https://paddle.net.
XIII. California (CCPA / CPRA)
If you are a California resident, this section applies to personal information we collect as a business. In the prior twelve months we collected the categories described above (identifiers, commercial information, internet activity, geolocation derived from IP, and customer-content you submit). We use them for the business purposes in this policy.
We do not sell your personal information for money. We do not share it for cross-context behavioural advertising as a core practice of Giov. If that changes, we will offer a “Do Not Sell or Share” control. We do not use or disclose sensitive personal information to infer characteristics, and we ask you not to send us sensitive data we do not need.
You may request to know, access, correct, or delete personal information, and to not be discriminated against for exercising CCPA rights. Submit requests to legal@giovchat.app with the subject “CCPA Request”. We will verify you (for example by matching the email on the account). An authorised agent may submit a request with proof of authority.
We do not currently respond to browser Do Not Track signals because there is no consistent industry standard; Cookie settings / Zaraz consent is the control for optional cookies on our site.
XIV. Other US states, Brazil, Canada, Australia
Nevada: we do not sell “covered information” as defined in Nevada law. Email legal@giovchat.app if you want notice if that practice changes.
Other US state privacy laws (for example Virginia, Colorado, Connecticut, Texas) may give you rights to access, delete, opt out of targeted advertising or profiling, and appeal a refusal. Use the same email. If your state requires an appeal process, we will describe the next step in our response.
Brazil (LGPD): you may request confirmation of processing, access, correction, anonymisation, portability, information about sharing, and revocation of consent, and complain to the ANPD.
Canada (PIPEDA) and Australia (Privacy Act / APPs): you may request access and correction, and complain to the OPC or the OAIC if we cannot resolve the matter. We process Operator data to provide the contract and to operate a secure global SaaS service.
XV. Children
Giov is built for business use. We do not knowingly collect personal data from children under 16 (or under 13 where US COPPA is the relevant test). If you believe we have, contact legal@giovchat.app and we will delete it. You must not target the widget at children or use Giov to collect children’s data unless you have a lawful basis and parental consent where required.
XVI. Cookies
Cookie and similar storage on Giov’s own site is described at https://giovchat.app/cookies. Consent for non-essential tools on our site is collected with Cloudflare Zaraz. Storage the widget or SDK sets on your properties is your responsibility.
XVII. Changes
We may update this policy as Giov changes. We will revise the date above and, for material changes, notify account owners by email or in the dashboard.
