1. Scope and roles
This document is a draft for founder and legal review. It is not legal advice and does not create a commitment until approved and published.
This draft covers Bavio account data and data relating to people who interact with a customer’s Agent. In many deployments, the customer decides why and how caller data is used while Bavio processes it to provide the service. The legal role can vary by deployment and jurisdiction.
2. Account and Workspace data
Bavio may process names, email addresses, business profile information, onboarding state, subscription state, users, Agent settings, Knowledge, Phone Numbers, provider connections, and authentication metadata.
3. Telephony and caller data
Configured telephony paths may expose caller numbers, provider call identifiers, call status, timestamps, duration, routing metadata, and audio or media references. Customers decide which calls they route and must provide required notices.
4. Audio, recordings, transcripts, and insights
Conversation paths may store transcript structures, summaries, extracted fields, recordings or recording references, and processing state. The repository shows targeted TTS cleanup paths, but not one complete retention window for every category.
5. Agent instructions, Knowledge, and AI output
Prompts, Agent instructions, Knowledge context, model inputs, generated speech or text, structured extraction, and conversation insights may be processed by configured provider paths. AI output is not automatically verified or professional advice.
6. Leads, Actions, Workflows, and webhooks
Bavio may process Lead fields, ActionExecution, ExecutionEvidence, WorkflowExecution, webhook configuration, delivery metadata, request status, and related audit information. A successful HTTP request does not prove the intended business result.
7. Billing and payment references
The audited code includes subscription, usage, processor event, and payment references. It does not establish that Bavio stores full payment-card numbers. Dodo is an observed billing path; final processor terms remain subject to confirmation.
8. Technical, security, and browser data
The runtime may generate request metadata, errors, operational logs, and security events. The frontend uses authentication/onboarding cookies, localStorage values for session and preferences, and sessionStorage for country context. No analytics or advertising vendor was established by this audit.
9. How data is used
Data may be used to authenticate users, provide voice and dashboard features, persist Conversations, produce transcripts or structured understanding, execute configured Actions and Workflows, deliver webhooks, bill usage, prevent abuse, troubleshoot, and provide support.
11. Retention
Retention periods vary by data type, provider, customer configuration, and legal requirement and are being finalized before production launch. Do not treat UI removal as database, object storage, backup, provider-copy, or log deletion.
12. Security
Observed controls include tenant checks, PostgreSQL RLS on selected tables, signed provider callbacks, encrypted webhook-secret storage, HTTPS validation, environment-based secrets, and idempotency in selected action/workflow paths. These statements are implementation observations, not certification claims.
13. Privacy requests
Depending on applicable law, a person may request access, correction, deletion, export, restriction, objection, or other rights. Contact [PRIVACY_EMAIL] and include enough information to verify identity. Customers may need to coordinate requests concerning their caller data.
14. Deletion and account closure
The repository does not establish a complete self-service deletion flow for every database and storage entity. Sign-out or clearing browser storage does not delete server-side data. Bavio will apply approved request procedures subject to legal, security, provider, backup, and fraud-prevention constraints.
15. Children and sensitive data
The service is intended for business use. Customers must not collect sensitive or regulated information unless their use is lawful, necessary, configured safely, and supported by an approved agreement. Age and sector rules require legal review.
16. International processing
Providers may process data in locations determined by their service configuration. Primary hosting region and transfer mechanism are [PRIMARY_HOSTING_REGION] and [TRANSFER_MECHANISM] until confirmed.
17. Changes
This notice may change as product behavior, providers, or legal requirements change. The approved update date and notice method remain [EFFECTIVE_DATE] and [NOTICE_METHOD].
18. Contact
Privacy contact: [PRIVACY_EMAIL]. Support: hello@bavio.in. Legal entity and address: [LEGAL_ENTITY_NAME], [REGISTERED_ADDRESS].
