PRIVACY POLICY
This Privacy Policy describes how personal data is collected, used, processed, stored and protected in connection with the use of the TRAVERF platform, website, software application, APIs, integrations and related services available through https://traverf.com (the "Services").
This Privacy Policy applies to website visitors, business clients, authorized users, prospective customers, contractors, business partners and other individuals whose personal data may be processed by the Provider.
- DATA CONTROLLER
The controller of personal data is:
For privacy-related requests please contact: eryk.bebynek@traverf.com
- CATEGORIES OF PERSONAL DATA
Depending on your interaction with the Services, Provider may collect and process:
-
Account Data: full name, business email, phone number, company name, job title, login credentials.
-
Billing Data: billing address, VAT number, payment details, transaction history.
-
Platform Usage Data: login logs, IP addresses, browser data, device identifiers, API usage logs, feature usage, activity history.
-
Client Uploaded Data: files, prompts, documents, customer records, communications, operational data.
-
Marketing Data: newsletter subscriptions, demo requests, marketing preferences and information submitted through forms integrated with Brevo.
-
Support Data: customer service communications, support tickets, troubleshooting logs.
-
SOURCES OF DATA
-
Personal data may be collected directly from: users, clients, website forms, integrations, API connections, cookies, sales processes, support communications.
-
Personal data may also be received from third-party service providers where legally permitted.
-
-
PURPOSES OF PROCESSING
Provider may process personal data for the following purposes:
-
Account Creation and Administration
-
Service Delivery
-
Billing and Commercial Operations
-
Security and Abuse Prevention
-
Customer Support
-
Product Development and Analytics
-
Legal and Regulatory Compliance
-
Marketing Activities
- LEGAL BASIS FOR PROCESSING (GDPR)
Where GDPR applies, Provider processes personal data based on: contract performance, legal obligations, legitimate interests, consent, defense of legal claims.
-
AI PROCESSING
-
Certain platform features may involve automated processing, AI-supported functionalities or integrations with third-party AI providers.
-
Users remain responsible for reviewing outputs.
-
Provider does not guarantee accuracy of AI-generated outputs.
-
Users should avoid uploading unnecessary sensitive personal data.
-
Certain AI-powered functionalities are provided through Google Gemini API services.
-
Where paid Google Gemini API services are used, prompts, uploaded files and generated outputs are processed in accordance with Google's applicable enterprise and paid-service terms.
-
Based on information provided by Google for applicable paid Gemini API services, prompts, uploaded content and generated outputs are not used by Google to train its foundation models, except as otherwise stated in Google's applicable documentation or legal requirements.
-
-
COOKIES AND TRACKING TECHNOLOGIES
-
The Provider may use cookies, pixels, SDKs, tags, local storage technologies and similar tracking technologies in connection with the website, platform and Services.
-
These technologies may be used to: enable core website functionality, maintain user sessions, authenticate users, remember user preferences, improve website performance, analyze traffic, measure platform usage, detect fraud, improve security, personalize user experience, support marketing activities where legally permitted.
-
Strictly Necessary Cookies: These cookies are required for proper functioning of the Services and may include: login authentication cookies, session cookies, security cookies, load balancing cookies, fraud prevention tools, platform functionality cookies. These cookies may be used without consent where permitted under applicable law.
-
Analytics Cookies: Provider may use analytics technologies to understand how users interact with the Services, including: page visits, feature usage, traffic sources, session duration, conversion tracking, product analytics. This may include services provided by entities such as Google, Mixpanel, Amplitude or similar analytics providers where implemented.
-
Performance Cookies: These technologies may be used to improve speed, stability and performance of the Services, including: caching tools, performance monitoring tools, error tracking systems, uptime monitoring tools.
-
Marketing and Advertising Technologies: Where applicable and legally permitted, Provider may use marketing technologies for: remarketing campaigns, advertising measurement, lead generation campaigns, campaign optimization, audience analytics. This may include services provided by entities such as Meta Platforms, LinkedIn, Google or similar advertising providers. Such cookies may be subject to user consent where required by law.
-
Certain third-party integrations embedded in the Services may independently place cookies or collect technical identifiers. The Provider is not responsible for independent cookie practices of third-party services that operate under their own privacy policies.
-
Cookies may remain stored for different periods depending on their purpose: session cookies may expire when browser sessions end, persistent cookies may remain for longer periods, retention periods may vary depending on third-party providers.
-
Users may manage cookie preferences through: browser settings, cookie banners, consent management tools, third-party opt-out tools where available. Disabling certain cookies may negatively affect functionality of the Services.
-
The Services may not respond to browser "Do Not Track" signals unless required under applicable law.
-
Provider may introduce new tracking technologies, analytics tools or advertising tools as the Services evolve, subject to applicable legal requirements.
-
-
DATA SHARING AND DISCLOSURES
Provider may disclose personal data where necessary to:
-
Infrastructure Providers
-
Payment Providers
-
Technology Providers, including Google LLC (Google Gemini API), marketing automation providers including Brevo, analytics providers and communication service providers
-
Professional Advisors
-
Corporate Transactions
-
Legal Requirements
- INTERNATIONAL TRANSFERS
Personal data may be transferred outside the EEA/UK where legally permitted. Appropriate safeguards may include: SCCs, adequacy decisions, other lawful mechanisms.
-
DATA RETENTION
-
Provider retains personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy.
-
Retention periods may vary depending on: account activity, legal obligations, tax obligations, contractual obligations, dispute resolution needs, fraud prevention requirements.
-
Following account termination: certain account data may be deleted, certain billing records may be retained, certain technical logs may be retained, backup retention periods may apply.
-
Provider may anonymize certain datasets for analytics, product development and operational improvement.
-
Once retention periods expire, personal data may be permanently deleted or anonymized.
-
-
DATA SUBJECT RIGHTS
-
Depending on applicable law, individuals may have the right to: access personal data, correct inaccurate personal data, request deletion, request restriction of processing, object to processing, request portability, withdraw consent, lodge complaints with supervisory authorities.
-
Provider may request identity verification before fulfilling requests.
-
Certain rights may be limited where processing is required by law, contract performance or legitimate legal interests.
-
Requests may be submitted to: eryk.bebynek@traverf.com
-
Provider will respond within legally required deadlines.
-
-
THIRD-PARTY LINKS
Provider is not responsible for third-party websites.
-
COMPLAINTS
-
If an individual believes that the Provider processes personal data in violation of applicable data protection laws, such individual may contact the Provider first in order to seek clarification or resolution of the matter. Privacy-related complaints may be submitted to: eryk.bebynek@traverf.com or through other contact channels made available by the Provider via Traverf.
-
The Provider may request additional information necessary to verify the identity of the individual submitting the complaint and to properly investigate the request.
-
The Provider will review complaints and privacy-related concerns within commercially reasonable timeframes and may request additional information where necessary.
-
If an individual believes that their rights under applicable data protection laws have been violated, they may also file a complaint with a competent supervisory authority in their country of residence, place of work or place of the alleged infringement.
-
For individuals located in Poland, complaints may be submitted to: President of the Personal Data Protection Office (Poland).
-
Nothing in this Privacy Policy limits any statutory rights available to individuals under applicable data protection laws.
-
-
CHANGES TO POLICY
Provider may update this Privacy Policy. Updated versions may be published on https://traverf.com.