1. Data Controller
Boyraz Solutions BV
Registered in Belgium
Company number (KBO): 0802.940.264
VAT number: BE 0802.940.264
Registered address available via the Belgian Crossroads Bank for Enterprises (KBO Public Search).
Email: info@suavi.io
Website: https://suavi.io
2. About This Privacy Policy
This Privacy Policy describes how Boyraz Solutions BV ("Suavi", "we", "us") collects, uses and protects personal data in the context of:
- The website suavi.io
- The Suavi interoperability platform (workpanel) — a bridge between the customer's Gmail, calendar, contacts and other administrative tools (CRM, invoicing, accounting)
- All related services
This policy applies to:
- Customers: businesses (BVs, VOFs, sole proprietors) that use the Suavi platform
- Users: individuals who access the platform on behalf of a customer
- Contacts: individuals whose data is stored in the platform by customers (customers of our customers)
- Website visitors: people who visit suavi.io
3. What Data Do We Collect?
3.1 Data of Customers and Users
| Data | Purpose | Legal basis |
|---|---|---|
| Company name, KBO number, VAT number | Contract performance, invoicing | Contract performance (art. 6(1)(b) GDPR) |
| Contact name, email, phone | Account management, communication | Contract performance (art. 6(1)(b) GDPR) |
| Login credentials (email, password hash) | Authentication | Contract performance (art. 6(1)(b) GDPR) |
| Billing details, IBAN | Payment | Contract performance (art. 6(1)(b) GDPR) |
| Usage data (logins, actions, preferences) | Platform operation, improvement | Legitimate interest (art. 6(1)(f) GDPR) |
3.2 Data Processed on Behalf of Customers
As a processor, we process the following data on behalf of our customers (the customer is the data controller for this data):
| Data | Module |
|---|---|
| Contact details (name, email, phone, address) | CRM |
| Email content and metadata | |
| Invoice amounts, payment details | Invoicing |
| Calendar data (appointments, locations) | Calendar |
| Social media content | Content |
The processing of this data is governed by the Data Processing Agreement (DPA) we sign with each customer.
3.3 Data of Website Visitors
| Data | Purpose | Legal basis |
|---|---|---|
| IP address, browser type, operating system | Security, technical operation | Legitimate interest (art. 6(1)(f) GDPR) |
| Page visits, referring URL | Website analytics | Consent (art. 6(1)(a) GDPR) |
4. What We Use Your Data For
- Service delivery: providing the interoperability services you signed up for — bridging your Gmail, calendar, contacts and other administrative tools (CRM, invoicing, accounting) with AI-assisted automation.
- Account management: creating and maintaining your account, authentication and authorization.
- Billing: issuing and sending invoices for our services.
- Communication: informing you about service changes, updates, maintenance or security incidents.
- Platform improvement: analyzing (anonymized) usage patterns to improve our services.
- Security: detecting and preventing fraud, abuse and security incidents.
- Legal obligations: complying with tax, accounting and other statutory record-keeping requirements.
5. Use of Artificial Intelligence
The Suavi platform uses AI models from third parties to generate emails, invoices, content and other output on behalf of the customer.
No automated individual decision-making: During the initial period (Shadow Mode), all AI output is submitted to the customer for approval. The customer decides when the system transitions to autonomous operation.
Transparency: Customers can view which actions the system has performed at any time and can revert to manual approval.
The AI models are provided by:
- Anthropic (Claude) — based in the US
- Google (Gemini) — based in the US/EU
- OpenAI (GPT-4o) — based in the US
Data submitted to AI models is used solely to generate the requested output and is not used to train the models (in accordance with the business processing agreements with these providers).
6. Sub-Processors and Transfers Outside the EEA
To deliver our service, we use the following sub-processors. Some are located outside the European Economic Area (EEA), particularly in the United States. For these transfers, we apply Standard Contractual Clauses (SCCs) as approved by the European Commission, encryption in transit and at rest, and business processing agreements with each sub-processor.
| Sub-processor | Purpose | Location |
|---|---|---|
| Anthropic (Claude) | AI processing: email drafts, classification, strategy | United States |
| Google (Gemini, Gmail API, Calendar API, Contacts API) | AI processing; email, calendar and contacts integration | EU / United States |
| OpenAI (GPT) | AI fallback and image generation | United States |
| Microsoft (Outlook, Microsoft 365) | Email and calendar integration via OAuth | EU / United States |
| Meta Platforms (Instagram, Facebook) | Social media integration: posting content, managing comments/messages | United States / Ireland |
| Hetzner Online GmbH | Server hosting and primary data storage | European Union (Germany) |
| Cloudflare, Inc. | CDN, DDoS protection, encrypted backup storage (R2) | United States |
| Mollie B.V. | Payment processing for subscription fees | Netherlands (EU) |
We do not share personal data with third parties for commercial or marketing purposes. An up-to-date list of sub-processors is always available at suavi.io/privacy. Customers are notified of material changes at least 30 days in advance.
7. Retention Periods
| Data | Retention period |
|---|---|
| Account data | Duration of the agreement + 30 days after termination |
| Billing data | 7 years (statutory retention) |
| Data processed on behalf of customer | Duration of the agreement; deletion within 30 days of a request upon termination |
| Backups | Maximum 90 days after deletion from production |
| Website logs | 6 months |
8. Security
We take appropriate technical and organizational measures to protect personal data against unauthorized access, loss or destruction, including:
- Encrypted connections (TLS)
- Per-customer database isolation (tenant isolation)
- Encrypted backups (AES-256)
- Access control and authentication
- Automated security monitoring (Guard module)
- Continuous backups to European data centers
- Audit logging of all system actions
9. Your Rights
Under the GDPR, you have the following rights:
- Right of access (art. 15 GDPR): you can request a copy of the personal data we process about you.
- Right to rectification (art. 16 GDPR): you can request correction of inaccurate or incomplete data.
- Right to erasure (art. 17 GDPR): you can request deletion of your personal data, unless we are subject to a statutory retention obligation.
- Right to restriction (art. 18 GDPR): you can request that we restrict the processing of your data.
- Right to data portability (art. 20 GDPR): you can request your data in a machine-readable format.
- Right to object (art. 21 GDPR): you can object to processing based on legitimate interest.
- Right to withdraw consent: if processing is based on consent, you can withdraw it at any time.
To exercise your rights: send an email to info@suavi.io with a copy of your ID. We respond within 30 days.
Note: if you are a contact of one of our customers (a customer of our customer), please direct your request to the relevant customer, who is the data controller for your data.
10. Cookies
Suavi.io uses the following cookies:
| Cookie | Type | Purpose | Retention |
|---|---|---|---|
| session | Strictly necessary | Session management, authentication | Session |
| csrf_token | Strictly necessary | CSRF attack protection | Session |
Strictly necessary cookies do not require consent. If we add analytics or marketing cookies in the future, we will ask for your consent beforehand via a cookie banner.
11. Changes
We may update this Privacy Policy from time to time. Material changes are communicated at least 30 days in advance by email to our customers. The most recent version is always available at suavi.io.
12. Google API Services — User Data Policy
Suavi's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
12.1 Google APIs We Access
When a Customer connects their Google Workspace or personal Google account to Suavi, we access the following Google APIs exclusively to deliver the services the Customer has subscribed to:
| Google API | Scope | Why Suavi needs it |
|---|---|---|
| Gmail API | gmail.modify | Mark processed emails as read; apply labels (e.g. "suavi-processed", "suavi-lead"); move emails to folders based on Customer-defined rules; delete spam/junk flagged via the Suavi interface. |
| Gmail API | gmail.send | Send AI-drafted email replies from the Customer's own Gmail account, after the Customer approves the draft (Shadow Mode) or for categories the Customer has explicitly marked as autonomous. |
| People API | contacts.readonly | Read-only sync of Google Contacts into the Suavi CRM, so the AI can recognize known contacts and personalize drafts. Suavi never modifies Google Contacts. |
| People API | contacts.other.readonly | Read "Other contacts" that Gmail auto-creates from email threads, for CRM completeness. |
| Calendar API | calendar.readonly | Detect scheduling conflicts when drafting meeting proposals; display availability in the Suavi dashboard; provide context to AI drafts. |
| Calendar API | calendar.events | Create calendar events on behalf of the Customer after Customer approval (e.g. when a client confirms a proposed meeting time via email). Every event creation is logged in the Suavi audit trail. |
12.2 Limited Use Commitment
Data received from Google APIs is subject to the following Limited Use restrictions, in strict compliance with Google's User Data Policy:
- User-facing features only: Google user data is only used to provide or improve the user-facing features of the Suavi platform (email automation, CRM, calendar, scheduling). It is not used for any other purpose.
- No advertising: Suavi does not use Google user data for advertising, including retargeting, personalized advertising, or interest-based advertising.
- No sale or transfer: Suavi does not sell Google user data to third parties, nor transfer it to third parties for advertising, credit-worthiness, or other commercial purposes.
- No human access except in narrow circumstances: Suavi does not allow humans to read Google user data, except (a) with the Customer's explicit consent for specific messages, (b) for security investigations, (c) to comply with applicable law, or (d) when data is aggregated and used for internal operations in compliance with applicable privacy laws.
- No use for AI model training: Google user data is not used to develop, improve, or train generalized or non-personalized AI or machine-learning models. AI processing occurs via API calls to Anthropic, Google and OpenAI under business-processing agreements that contractually exclude training on customer data.
12.3 Revoking Google Access and Deleting Google Data
Customers can revoke Suavi's access to their Google account at any time:
- In Suavi: go to Settings → Integrations → Gmail / Google Calendar. Two distinct actions are available:
- Refresh tokens — signs you in to Google again without removing any data. Used during Google's verification cycle for OAuth apps awaiting approval. Tokens are replaced; emails, calendar events, contacts and embeddings remain.
- Erase integration — with a typed-word confirmation step and an automatic backup taken beforehand, this immediately deletes all stored OAuth tokens for that platform and all cached data that originated from that Google service: email messages, calendar events, message embeddings, and contacts imported via the Google Contacts API.
- In Google: go to myaccount.google.com/permissions and remove Suavi's access. Tokens immediately become invalid on Suavi's side.
- Full data deletion request: send an email to info@suavi.io with "Google data deletion" in the subject, including the email address, name and (optional) phone number you wish to have erased. We process deletion requests manually within 30 days. The procedure consists of an identifier-based search and deletion across the data categories listed in §7, with anonymization rather than deletion of statutory invoicing data (kept for the periods set out in §7).
12.4 Retention of Google Data
Google OAuth tokens and associated metadata are retained only while the integration is active. Fetched email content, calendar events and contacts imported from Google Contacts are stored encrypted. They are deleted immediately when the Customer uses the in-product "Erase integration" action described in §12.3. The "Refresh tokens" action does not delete data; it only replaces the OAuth tokens. Upon termination of the Agreement, all remaining Customer data is deleted manually within 30 days following a written request to info@suavi.io, subject to statutory retention for invoicing data (see §7).
12.5 Scope of "Google data"
The "Erase integration" action removes data that originated from the Google service connected through that integration: email messages (Gmail), calendar events (Google Calendar), message embeddings derived from Gmail content, and contacts imported via the Google Contacts API at OAuth grant time. It does not delete contacts that were imported from other sources, including but not limited to: the Customer's own address book or contact files (e.g. vCard/CSV upload), manual entries made through the Suavi interface, contacts auto-extracted by Suavi from non-Google email content, or contacts synchronized from non-Google billing platforms. These are not "Google data" within the meaning of Google's API Services User Data Policy and require a separate full data deletion request as described in §12.3.
13. Other Third-Party Platform Integrations
13.1 Microsoft (Outlook, Microsoft 365)
When a Customer connects their Microsoft 365 / Outlook account, Suavi accesses the following scopes through the Microsoft Graph API, exclusively to deliver the subscribed services: Mail.ReadWrite, Mail.Send, Calendars.ReadWrite, and offline_access. The same Limited Use principles described in §12.2 apply to Microsoft data: no advertising use, no sale or transfer, no use for AI model training, and no human access except with explicit Customer consent.
13.2 Meta Platforms (Instagram Business, Facebook Pages)
When a Customer connects an Instagram Business or Facebook Page account to Suavi, we access profile data, published content, engagement data (comments and direct messages on Suavi-managed content), and webhook notifications from Meta via the Meta Graph API. Meta platform data is only used to provide the functionality the Customer actively requested (connecting the account, publishing content, receiving events); it is never sold, rented, shared with advertisers, or used to train AI models. Suavi's use of Meta API information complies with the Meta Platform Terms and Developer Policies. Customers can revoke access via Suavi → Settings → Disconnect, or via their Instagram/Facebook app settings; Meta's deauthorize callback is handled at https://suavi.io/workpanel/api/meta/data-deletion.
14. Complaints
If you believe we are not processing your personal data correctly, you can:
- Contact us at info@suavi.io
- File a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit):
Belgian Data Protection Authority
Drukpersstraat 35, 1000 Brussels, Belgium
Tel: +32 (0)2 274 48 00
Email: contact@apd-gba.be
Website: gegevensbeschermingsautoriteit.be
15. Contact
For questions about this Privacy Policy or about the processing of your personal data: