Privacy Policy
Last updated: August 24, 2026
1. Data privacy commitment
At CaviusConnect, we believe privacy is a fundamental human right. Our multi-tenant architecture ensures that your organization's data is strictly isolated and never shared. This Privacy Policy explains how we collect, use, protect, and handle your information.
2. Information we collect
Account information: name, email address, company name, phone number, and billing details when you register.
Message data: content and metadata of messages sent and received through our platform (WhatsApp, SMS, Email, Voice).
Contact data: customer contact lists you upload or store in our system.
Usage data: how you interact with our platform, including API calls, feature usage, and performance metrics.
Device and log data: IP addresses, browser type, device information, and access times.
Third-party integrations: data from connected services (Twilio, SendGrid, Meta WhatsApp) necessary to provide messaging services.
3. How we use your data
Service delivery: process and deliver outgoing messages, manage inbound communications, and maintain your unified inbox.
AI features: power AI auto-replies, sentiment analysis, and intelligent routing.
Analytics: provide delivery reports, engagement metrics, and platform usage insights.
Security: detect fraud, prevent abuse, and maintain audit logs for compliance and security purposes.
Improvement: enhance platform features, fix bugs, and optimize performance.
Communication: send service notifications, security alerts, and optional product updates (you can opt out).
4. Third-party services
We work with trusted partners to deliver our services:
- Google Cloud Platform: infrastructure hosting and AI services
- MongoDB Atlas: database storage
- Twilio: SMS and Voice services
- SendGrid: email delivery
- Meta: WhatsApp Business API
- Google Analytics: website analytics (anonymized)
All third parties are bound by data processing agreements and security requirements.
5. Your rights
Access: request a copy of your data via your account settings or by contacting support.
Correction: update inaccurate information through your account dashboard.
Deletion: request account and data deletion (subject to legal retention requirements).
Portability: export your data in machine-readable formats (JSON, CSV).
Objection: object to certain processing activities, particularly for marketing purposes.
Restriction: request limited processing of your data in certain circumstances.
To exercise these rights, visit your settings panel or email privacy@caviusconnect.com.
6. California privacy rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the CPRA, gives you additional rights over your personal information:
Right to know: request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, and the purposes for collection.
Right to delete: request deletion of personal information we have collected from you, subject to legal retention requirements.
Right to correct: request correction of inaccurate personal information.
Right to opt out of sale or sharing: we do not sell your personal information or share it for cross-context behavioural advertising.
Non-discrimination: we will not discriminate against you for exercising any of these rights.
To exercise these rights, email privacy@caviusconnect.com. We will verify your request and respond within the timeframes the CCPA requires.
7. Data retention
Active accounts: data retained while your account is active and for 90 days after cancellation.
Messages: stored for the duration specified in your plan (typically 12 months).
Audit logs: retained for 2 years for security and compliance purposes.
Legal requirements: some data may be retained longer if required by law.
8. International data transfers
Your data may be processed in the United States and other countries where our service providers operate. For EU customers, we use Standard Contractual Clauses approved by the European Commission. See our GDPR page for more information.
9. Security
We implement industry-standard security measures including TLS 1.3 encryption in transit, AES-256 encryption at rest, multi-factor authentication, role-based access controls, and regular security audits. See our Security page for full details.
10. Cookies and tracking
We use cookies for authentication, preferences, and analytics. See our Cookie Policy for details on managing cookies.
11. Children's privacy
Our services are not intended for individuals under 16 years of age. We do not knowingly collect personal information from children.
12. Changes to this policy
We may update this Privacy Policy periodically. Material changes will be notified via email or platform notification 30 days before taking effect.
13. Contact us
For privacy questions or concerns:
Email: privacy@caviusconnect.com
Data Protection Officer: dpo@caviusconnect.com
