Privacy Policy
We built Chalvas with privacy at its core. This policy explains what data we collect, how we use it, and your rights as a user and enterprise customer.
Overview
Chalvas, Inc. ("Chalvas", "we", "us", or "our") provides an enterprise AI platform including the Chalvas web application, desktop application, mobile companion, CLI, APIs, and related services (collectively, the "Services"). This Privacy Policy describes how we collect, use, disclose, and protect information about you when you use our Services or interact with us.
For enterprise customers deploying Chalvas under a separate Data Processing Agreement ("DPA"), the DPA governs the processing of your organization's data to the extent it conflicts with this policy. Please contact your account manager to obtain a copy of our standard DPA.
Key Principle: Your enterprise data is never used to train shared AI models. Data belonging to your organization remains yours.
Data We Collect
Account & Identity Information
When you create an account or your organization provisions access, we collect:
- Full name, work email address, and profile photo
- Organization name, domain, and industry
- Job title and role within your organization
- Authentication credentials (passwords stored as cryptographic hashes; SSO tokens via your IdP)
- Billing contact information and payment method details (processed by Stripe; card numbers never stored by Chalvas)
Usage & Interaction Data
We automatically collect information when you use our Services:
- Feature usage patterns, session duration, and navigation events
- Device type, operating system, browser version, and IP address
- API request logs, latency metrics, and error reports
- Workspace configurations, agent templates created, and workflow definitions
Content & AI Interaction Data
Depending on your use of the Services:
- Conversation messages, prompts, and AI-generated responses
- Documents, files, and knowledge base content you upload
- Agent configurations, workflow logic, and automation rules
- Integration credentials and third-party API connections (encrypted at rest)
Communications
- Support tickets, chat logs, and email correspondence with our team
- Survey responses, feedback submissions, and NPS scores
- Content shared in community forums or public channels
How We Use Your Data
| Purpose | Legal Basis (GDPR) | Examples |
|---|---|---|
| Provide and operate the Services | Contract performance | User authentication, feature delivery, workspace management |
| Billing and account management | Contract performance | Invoice generation, subscription changes, seat management |
| Security and fraud prevention | Legitimate interest | Anomaly detection, abuse prevention, audit logging |
| Product improvement | Legitimate interest | Aggregated feature analytics, error diagnosis (no PII in model training) |
| Customer support | Contract performance | Responding to tickets, reproducing bugs, onboarding assistance |
| Marketing communications | Consent / legitimate interest | Product updates, newsletters (opt-out available at any time) |
| Legal compliance | Legal obligation | Regulatory reporting, responding to lawful requests |
We use aggregated, de-identified usage metrics to understand how our products are used and to improve them. This data cannot be used to identify individual users or organizations.
Data Sharing & Disclosure
We do not sell your personal information. We share data only in the following circumstances:
Service Providers (Sub-processors)
We engage trusted third parties to help operate our Services. All sub-processors are bound by data processing agreements consistent with this policy. Current sub-processors include:
| Sub-processor | Category | Location |
|---|---|---|
| Amazon Web Services | Cloud infrastructure | US, EU, AP |
| Anthropic, OpenAI, Google (configurable) | AI model inference | US (data processing agreements in place) |
| Stripe | Payment processing | US, EU |
| Datadog | Observability & logging | US, EU |
| Intercom | Customer support | US |
| Postmark | Transactional email | US |
Business Transfers
If Chalvas undergoes a merger, acquisition, or asset sale, your data may be transferred. We will provide notice before your data is subject to a different privacy policy.
Legal Requirements
We may disclose information where required by law, court order, or government authority, or where necessary to protect the rights, property, or safety of Chalvas, our customers, or the public. Where legally permitted, we will notify you of such requests.
AI & Model Data Policy
Enterprise data isolation guarantee: Conversations, documents, and workflows belonging to your organization are isolated within your tenant and are never used to train or fine-tune shared models.
When you interact with AI models through Chalvas, your prompts and responses may be processed by third-party model providers (e.g., Anthropic, OpenAI) subject to our agreements with those providers. Enterprise customers can configure private model deployments where all inference occurs within their own cloud or on-premise environment with no third-party model access.
We may use anonymized, aggregated interaction patterns (with no connection to individual users, organizations, or content) to improve routing, caching, and platform performance.
Model Context Protocol (MCP)
When you connect external tools via MCP servers, data flows between your configured tools and the AI model. Chalvas acts as the orchestration layer. Review the privacy policies of any external MCP server you connect to your workspace.
Data Retention & Deletion
| Data Category | Retention Period |
|---|---|
| Account & identity data | Duration of account + 30 days post-deletion |
| Conversation history | Per workspace settings (default: 12 months, configurable) |
| Uploaded documents | Until deleted by user or organization admin |
| Audit logs | 24 months (Enterprise/Government plans: configurable up to 7 years) |
| Billing records | 7 years (legal requirement) |
| Security incident records | 5 years |
| Support correspondence | 3 years from ticket closure |
| Anonymized usage analytics | Indefinitely (no PII) |
Organization admins can delete workspaces, users, and data through the admin console. Account deletion requests are processed within 30 days. Backups are purged on a 30-day rolling cycle.
Security
We implement industry-leading security measures including:
- Encryption at rest: AES-256 for all stored data
- Encryption in transit: TLS 1.3 for all network communications
- Key management: Customer-managed encryption keys (CMEK) available on Enterprise plans
- Access control: Role-based access control (RBAC), least-privilege principles
- Authentication: MFA, SSO via SAML 2.0 / OIDC, hardware key support
- Audit logging: Immutable audit trail for all admin and agent actions
- Certifications: SOC 2 Type II, ISO 27001 (in progress), GDPR compliant, HIPAA BAA available
- Penetration testing: Annual third-party pen tests; bug bounty program active
In the event of a data breach affecting your organization, we will notify you within 72 hours of discovery, consistent with GDPR and applicable breach notification laws.
Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal data:
Rights for all users
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data (subject to legal retention requirements)
- Portability: Receive your data in a structured, machine-readable format
- Opt-out of marketing: Unsubscribe from marketing emails at any time via the unsubscribe link or account settings
Additional rights (EU/UK — GDPR/UK GDPR)
- Restriction: Request restriction of processing in certain circumstances
- Objection: Object to processing based on legitimate interests
- Automated decision-making: Not be subject to solely automated decisions that significantly affect you
- Lodge a complaint: File a complaint with your local supervisory authority (e.g., ICO in the UK, relevant DPA in EU)
California (CCPA/CPRA)
- Right to know what personal information is collected and how it is used
- Right to opt out of the "sale" or "sharing" of personal information (we do not sell data)
- Right to non-discrimination for exercising your privacy rights
- Right to correct inaccurate personal information
- Right to limit use of sensitive personal information
To exercise any of these rights, contact us at privacy@chalvas.ai. Enterprise customers may also submit requests through their account admin console. We respond to verified requests within 30 days.
Children's Privacy
Our Services are designed for business and enterprise use and are not directed at individuals under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a minor, please contact us at privacy@chalvas.ai and we will delete it promptly.
International Data Transfers
Chalvas is headquartered in the United States. If you access our Services from the European Economic Area (EEA), United Kingdom, or other regions with data transfer restrictions, your data may be transferred to and processed in the US and other countries where our infrastructure operates.
We ensure appropriate safeguards are in place for such transfers, including:
- EU Standard Contractual Clauses (SCCs) with all sub-processors
- UK International Data Transfer Agreements (IDTAs)
- Adequacy decisions where applicable
- Data Processing Agreements with enterprise customers
Enterprise customers can request EU-only or specific regional data residency. Contact your account manager for regional data residency options.
Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page
- Send an email notification to account administrators
- Display a notice within the Chalvas application for 30 days
Your continued use of the Services after the effective date of an updated policy constitutes your acceptance of the changes. If you disagree with material changes, you may close your account.
Contact Us
For privacy-related questions, requests, or concerns, please contact us through one of the following channels:
| Channel | Contact |
|---|---|
| Privacy inquiries & rights requests | privacy@chalvas.ai |
| Legal & DPA requests | legal@chalvas.ai |
| Security vulnerabilities | security@chalvas.ai |
| Mailing address | Chalvas, Inc. · 340 Pine Street, Suite 800 · San Francisco, CA 94104 · USA |
EU Representative: For GDPR-related inquiries, our EU representative can be reached at eu-rep@chalvas.ai.