Privacy Policy
Last updated: January, 2026
Introduction
We are Tovie AI UK Limited, a United Kingdom company, located at 128 City Road, London, United Kingdom, ECLV 2NX ("the Company", "Tovie AI", "we", "us" or "our").
When you interact with our websites and/or use our services you provide us with your personal data. Personal data is information that relates to you and may be used to identify you as an individual.
Your personal data is valuable, and we are committed to protecting it in accordance with all applicable laws and regulations.
Please note: Tovie AI operates as both a Controller (for our own website and marketing data) and a Processor (for customer data processed through our AI agent platform). The role distinction is critical to understanding your data protection rights and our obligations.
Purposes
We developed this Privacy Policy to explain to you the following:
- What kind of personal data we collect
- How and why do we process it
- How we protect it
- What are your rights regarding your data
Scope and Limitations
We process personal data of data subjects in all markets of our presence and comply with all applicable privacy legislation including but not limited to the following:
- EU:
- The principles of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 "On the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) ("the EU GDPR")
- Spanish Data Protection Act 3/2018
- Other local regulations
- UK:
- UK General Data Protection Regulation (the UK GDPR)
- Brazil and Latin America:
- Lei Geral de Proteção de Dados (LGPD) and equivalent regional data protection laws
- Other jurisdictions: We comply with applicable data protection regulations in all regions where we operate.
The processes related to the processing of personal data of our Employees and Contractors are out of the scope of this Privacy Policy.
General Statements
Categories of Data Subjects
In general, we process the personal data of the following Data Subjects:
- Users of our products and services
- Employees and Contractors of our Clients, Customers and Partners
- Users of the products and services of our Clients, Customers and Partners, including the content of the Services (hereinafter referred to as "Content")
- End-users interacting with AI agents deployed by our Clients through our platform
Controller The Company as a Controller
We act as a Controller for:
As a Controller, we ensure compliance with the requirements defined and established by:
- This Privacy Policy
- Our Data Protection Impact Assessment (DPIA) for processing activities
- Other applicable local regulations
We process controller data on the following lawful bases: legitimate interest (service improvement, system operation), contract (service provision), and consent (where applicable).
Processor The Company as a Processor
We act as a Processor for the vast majority of our platform services. When our Clients, Customers, or Partners ("Controllers") use our AI agent platform to process personal data (whether through chatbots, voice agents, orchestrators, or action agents), we process that data solely on the Controller's instructions and for the Controller's legitimate business purposes.
Key processor principles:
- Default role: By default, the Company is a Processor and the Client is the Controller for all data flowing through agent scenarios, customer interactions, and client-specified workflows.
- No discretionary use: Company does not use customer data for any purpose other than executing the Client's instructions. We do not use customer data to train models, build internal analytics, test features, or develop new products without explicit written Client consent.
- Mandatory Data Protection Agreement: All processor relationships must be formalized through a Data Processing Agreement (DPA). Controllers must contact us at privacy@tovie.ai to execute or update the DPA before processing begins or changes in scope occur.
- Sub-processors: When Tovie AI engages sub-processors (e.g., LLM providers, cloud infrastructure, integrations), we notify Clients and obtain their approval per the DPA. Clients may object to sub-processor changes.
- Processor obligations: As a Processor, we:
- Process data only per written Controller instructions
- Assist Controllers in fulfilling data subject rights requests
- Ensure appropriate technical and organisational security measures
- Cooperate with supervisory authorities
- Provide assistance for Data Protection Impact Assessments (DPIAs)
- Delete or return data upon Client request.
Personal Data Processing
General Principles of Personal Data Processing
Lawfulness, Fairness and Transparency
We process all personal data lawfully, fairly and in a transparent manner. As a Processor, we follow the lawful basis determined by the Controller. As a Controller, we rely on explicit lawful bases documented in Annex I.
Purpose Limitation
We collect and process personal data for the specified, explicit and legitimate purposes and do not further process it in a manner that is incompatible with those purposes.
Data Minimisation
We collect and process personal data in a limited way: we only process the personal data we need to achieve a specific purpose.
Accuracy
We are undertaking all necessary measures to:
- Keep the personal data up to date
- Ensure that personal data that is inaccurate is erased or rectified in a timely manner
Storage Limitation
We store personal data no longer than necessary for the purposes for which the personal data is processed. Default retention periods are specified in Annex I, and Clients using our platform may configure custom retention schedules within their deployment (particularly for on-premises deployments).
Integrity and Confidentiality
We ensure the security of the personal data by implementing appropriate measures to protect such data against accidental or unlawful destruction, loss, alteration, unauthorised access to, or disclosure.
Accountability
We as a Data Controller are responsible for and able to demonstrate compliance with the principles outlined in this Privacy Policy. As a Processor, we maintain documentation and assist Controllers in demonstrating compliance.
Data Subject Rights Guaranties
As a Controller we respect the data subject rights summarized below and ensure their fulfilment.
As a Processor we guarantee that we will follow the instructions of a Controller to provide guarantees regarding the data subject rights. Controllers remain responsible for responding to data subject requests; Toxie AI provides reasonable assistance upon request.
Right to Be Informed
The right to be informed encompasses the Company's obligations to provide 'fair processing information' through this Privacy Policy. Where Toxie AI processes data as a Processor, the Client (Controller) is responsible for providing privacy notices to data subjects. Toxie AI will assist in providing information about our processing role upon request.
Right to Access
As a Data Subject you have the right to access your personal data and supplementary information. The right to access allows you to be aware of and verify the lawfulness of the processing.
In accordance with the GDPR you have the right to obtain:
- Confirmation that your personal data is being processed
- Access to your personal data
- Other supplementary information
To request this information, contact us by email at privacy@tovie.ai with the subject line "Access Request". For data processed through our platform on behalf of our Clients, please contact the relevant Client (data Controller) directly, as they manage the primary data access mechanisms.
Right to Rectification
- If your personal data is incomplete, outdated, or incorrect, and processed in our products or services, you can change it on your own at any time. We provide our users with the functionality that allows them to view, manage and/or update their personal data in the Account settings.
- When you need to rectify your personal data which is not stored in our products or services and cannot be deleted by yourself, contact us by email at privacy@tovie.ai with the subject line "Rectification Request".
Right to Erasure ("Right to Be Forgotten")
The broad principle underpinning this right is to enable a data subject to request deletion or removal of his or her personal data where there is no compelling reason for its continued processing. The right to erasure does not provide an absolute "right to be forgotten". It means that you can ask us to delete your personal data by email at privacy@tovie.ai with the subject line "Erasure Request", and we will consider your request and inform you of the results.
We can refuse to delete your personal data when the processing of the personal data is necessary for the following:
- Exercising the right of freedom of expression and information
- Compliance with a legal obligation for the performance of a public interest task or exercise of official authority
- Reasons of public health purposes in the public interest
- Archiving purposes in the public interest, for scientific research, historical research or statistical purposes
- Establishment, the exercise or defence of legal claims
Otherwise, we will delete your personal data without undue delay in accordance with our local regulations. For data processed as a Processor, we will delete or assist in deletion upon the Controller's instruction.
Right to Restrict Processing
This right means that you have a right to "block" or suppress the processing of your personal data. If you restrict the processing of your personal data, we will store your personal data but will not further process it in another way.
If you would like to exercise your right to restrict the processing of your personal data, contact us by email at privacy@tovie.ai with the subject line "Processing Restriction Request".
Right to Data Portability
The right to data portability allows you to obtain and reuse your personal data for your own purposes across different services. It allows you to move, copy or transfer personal data easily from one IT environment to another in a safe and secure manner, without hindrance to usability.
You can ask us to provide you with your personal data we process by email at privacy@tovie.ai with the subject line "Data Portability Request".
Right to Object
At any time, you have the right to object to the processing of your personal data, including profiling, processing for purposes of scientific/historical research and statistics, for direct marketing purposes and others.
The corresponding request must be submitted to us by email at privacy@tovie.ai with the subject line "Objection to Processing".
Categories of the Personal Data Processed
Categories of personal data we process are summarized in Annex I hereto.
Children and Special Categories of Personal Data
Children
Our products and services are not intended to be used by children under 16 years of age. If you are under the age of 16 you should not try to register an account or provide us with any personal data. We do not collect any personal data from such individuals.
Special Categories of Personal Data
Tovie AI does not proactively collect or process special categories of personal data (as defined in Article 9 of the GDPR), including: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation.
However, as a Processor for our Clients: If a Client's use case involves special categories of data (for example, health data in an insurance claims chatbot, financial data in a banking agent, or other sensitive information), Tovie AI will process such data only in accordance with the following conditions:
- Controller responsibility: The Client (data Controller) is solely responsible for establishing a lawful basis for processing special categories under Article 9 GDPR (e.g., explicit consent, contractual necessity, public task, vital interests, legitimate activities of certain organisations, or other Article 9(2) exceptions).
- Deployment model: For use cases involving special categories, Tovie AI defaults to on-premises deployment to ensure maximum data sovereignty and Client control. Cloud deployment may be available only after explicit risk assessment and Client written approval.
- Data minimisation: Tovie AI assists Clients in minimising special category data exposure through:
- Technical controls and encryption
- Data masking tools (e.g., Tovie Data Mask) to limit sensitive data visibility
- Purpose-limitation configurations within agent logic
- Audit logging of special category data access.
- DPIA requirement: For processing involving special categories, Clients must conduct a Data Protection Impact Assessment (DPIA) and share results with Toxie AI. Toxie AI will cooperate in DPIA documentation and assist in identifying and mitigating risks.
- Documentation: The DPA must explicitly reference the special categories being processed, lawful basis, technical measures, and retention schedules.
If Toxie AI becomes aware that special category data is being processed without proper contractual and legal safeguards, we reserve the right to restrict processing pending Client remediation.
If you have reason to believe that special category data has been collected improperly, please inform us immediately by email at privacy@tovie.ai.
Purposes and Lawful Basis for the Processing of Personal Data
We collect and process your personal data in accordance with the EU GDPR, the UK GDPR, LGPD, and other applicable laws. The purposes and lawful basis for the processing are pointed out in Annex I hereto.
Collection of Personal Data
All personal data we process is lawfully obtained. We collect personal data for specific purposes, and we will use it for these purposes only.
The list of the purposes for which we as a Controller collect and process your personal data is set out in Annex I hereto.
For Processor roles: Toxie AI collects personal data only as directed by the Controller and in accordance with the Data Processing Agreement.
Cookies and Other Automatic Tools
We use commonly used tools to automatically collect information that may contain personal data collected from your device when you visit our website and/or use our service. This information may include the IP address of your device, information about the operating system and browser you use, and other data related to your activities on our website and/or in our service.
More information about cookies we use you can find in our Cookies Policy.
Data We Receive From Third Parties
Personal Data Received from Identity Providers (Federated Access Management)
We may receive your personal data when you login into our services using your identity provider (for instance, Google or GitHub), which transfers your personal data to us.
We do not control and are not responsible for how these identity providers collect and process your personal data. However, when we receive your personal data, we act as a Controller and process it for our own purposes. Detailed information regarding such processing is provided in Annex I.
Use, Retention, and Disposal of the Personal Data
The usage, methods, storage limitations, and retention period of personal data must be:
- Defined in Annex I (for Controller-processed data)
- Consistent with the information contained in this Privacy Policy
- For Processor-managed data: defined in the Data Processing Agreement and configurable by the Client
We maintain the accuracy, integrity, confidentiality, and relevance of personal data based on the processing purposes.
Default retention periods for Processor-managed data:
- Platform logs and agent interactions: 1 to 6 months (configurable)
- Customer transactional data: Until the end of service contract + 6 years (or applicable statute of limitations in the relevant jurisdiction for legal claims, tax or compliance)
- Backup copies: In accordance with backup and disaster recovery procedures.
For on-premises deployments, Clients have full control over retention and deletion mechanisms.
Disclosure to Third Parties
The use of our services often involves the transfer of personal data to recipients and third parties (e.g., Suppliers, Sub-processors, or Partners).
As a Controller:
Whenever we use a third-party Supplier or a Partner to process personal data on our behalf, we ensure that this processor (or sub-processor) provides security measures that are appropriate to:
- The risks associated with the processing of your personal data
- Applicable laws, industry best practices and our local personal data protection and information security regulations.
For these reasons, we oblige our processors to process personal data only to fulfil their contractual obligations towards us and in accordance with our instructions and not for any other purposes. When we process personal data jointly with an independent third party, we explicitly specify our responsibilities and those of the third party in the relevant contract or any other legal binding document.
As a Processor:
When Client data flows through our platform, it may be disclosed to:
- LLM providers and AI services: Depending on the Client's configuration, data may be transmitted to external Large Language Model providers (e.g., OpenAI) for agent reasoning and generation. The volume and nature of data transmitted depends on:
- The Client's model selection and configuration
- Whether data masking (e.g., Toxic Data Mask) is enabled
- The specific agent workflow design.
- Note: By default, Tovie AI recommends and supports data masking tools to limit sensitive data exposure to external LLM providers.
- Cloud infrastructure providers: If deployed on cloud services (AWS, Google Cloud, IBM Cloud), data resides on those providers' infrastructure. Clients may select their preferred cloud region or provider as available.
- Client-specified integrations: Data may flow to external systems as configured by the Client:
- CRM systems (Salesforce, HubSpot, etc.)
- ERP systems
- Service desk and ticketing systems
- Email providers
- Messaging platforms and social networks
- Document repositories (Jira, Confluence, SharePoint)
- Custom APIs and webhooks
- Database systems.
- Sub-processors: Tovie AI may engage additional sub-processors for:
- Hosting and infrastructure
- Backup and disaster recovery
- Monitoring and logging
- Security and compliance services.
- Clients are notified of sub-processor changes and may object per the DPA.
Sub-processor Approval: Clients must approve Tovie's list of sub-processors and can request removal or alternative arrangements. Tovie AI maintains current sub-processor documentation available at privacy@tovie.ai.
Disclosure as a Result of Legal Obligations
We can disclose your personal data if it is necessary to comply with a legal obligation and/or judicial or regulatory proceedings, a court order or other regulatory process, or to protect us, our Customers, Clients and/or Partners against loss or damage. This may include, but is not limited to, exchanging information with the police, courts, law enforcement organisations, or regulatory authorities (including Data Protection Authorities, financial regulators, and telecom authorities).
In such cases, we will attempt to notify the affected party unless legally prohibited.
Deployment and Data Location
Deployment Options
Tovie AI platform deployment varies by use case and Client preference:
- On-Premises Deployment:
- Tovie AI provides the platform for installation on Client infrastructure
- Client maintains full control over data location, access, and management
- Client is responsible for infrastructure security, backup, and disaster recovery
- Suitable for highly sensitive data, special categories, and data localization requirements
- Self-service tools available for log retention configuration, data export, and deletion.
- Cloud Deployment:
- Hosted on AWS, Google Cloud, or IBM Cloud (Client selects provider)
- Clients can choose geographic region
- Tovie AI manages infrastructure; Client retains control over data configuration and access
- Automatic backups and disaster recovery included
- Self-service controls for retention and deletion.
Data Location and Cross-Border Transfers
Primary Data Hosting: Tovie AI hosts and processes all platform data on servers physically located within the European Union or United Kingdom, ensuring EU/UK GDPR compliance and data sovereignty.
On-Premises Deployments: For Clients using on-premises deployment, data remains under Client control on their chosen infrastructure.
Third-Party Integrations: When Clients configure integrations with external services (including US-based LLM providers, CRMs, or SaaS platforms), data flows to those services are:
- Initiated and controlled by the Client (Controller)
- Subject to Client evaluation of transfer mechanisms (SCCs, BCRs, adequacy decisions)
- Client responsibility for lawful basis, DPIA, and jurisdictional compliance
Tovie AI Role: We assist Clients by:
- Documenting our sub-processors and their locations
- Providing transfer impact assessments for our services
- Implementing technical safeguards (encryption, pseudonymisation).
Cross-Border Transfer of Personal Data
Your personal data, when processed through our platform, may be transferred internationally depending on your deployment and integration choices:
- Platform infrastructure: As a Processor, we may use:
- Cloud services (AWS, Google Cloud, IBM Cloud) in selected regions
- Sub-processors and partners as listed in our sub-processor register.
- Third-party services: Client configurations may involve:
- Payment processor Stripe: Processes payment card and payment information for billing purposes. For more information, refer to Stripe's Privacy Policy.
- Web analytics providers: Monitor and analyze use of our services. Details in our Cookies Policy.
- Email marketing provider Mailchimp (Rocket Science Group LLC, USA): Used for newsletters and statistics. Details in Mailchimp's Privacy Policy.
- CRM platform Salesforce Inc. (USA): Tracks sales activities. Details in Salesforce's Privacy Policy.
- Lead enrichment service Apollo (ZenLeads Inc., USA): Enriches prospect information. Details in Apollo's Privacy Policy.
- Helpdesk service Zendesk: Provides customer support. Details in Zendesk's Privacy Policy.
- Safeguards for international transfers:
- We rely on Standard Contractual Clauses (SCCs) where applicable
- We perform Data Protection Impact Assessments (DPIAs) for transfers to countries with inadequate protection levels
- We implement supplementary technical and organisational measures to mitigate transfer risks
- Clients may restrict transfers to specific jurisdictions per their DPA.
For Processor-managed data in Client scenarios, Clients determine international transfer policies and are responsible for ensuring lawful bases (e.g., adequacy decisions, SCCs, Binding Corporate Rules). Towle AI assists by providing necessary transfer documentation and contractual terms.
Data Channels and Integration Points
Channels Through Which Data Enters the Platform
Client data enters Towle's platform through multiple channels as configured by the Client:
- Web and Chat Interfaces:
- Web widgets embedded on Client websites
- Web-based chat interfaces
- Custom web frontends.
- Messaging and Social Media:
- Messaging platform integrations
- Social media integrations as configured by Client.
- Voice and Telephony:
- Voice agent integrations (IVR systems, telephony platforms)
- Voice assistant deployments
- Automatic speech recognition (ASR) inputs.
- Email and Communication:
- Email integrations
- Email forwarding and processing.
- API and System Integrations:
- Direct API calls from Client applications
- Custom webhook integrations
- System-to-system integrations.
- External Data Sources:
- Document repositories (Jira, Confluence, SharePoint)
- Knowledge bases and RAG repositories
- Client databases and file systems
- CRM and ERP systems.
Data Logged by the Platform
For operational, debugging, and analytics purposes, Tovie AI logs the following in connection with platform usage:
Logged Data:
- User messages (text and transcribed voice)
- Agent execution events and state changes
- Function/action invocations and results
- API calls and responses
- Error traces and exceptions
- Performance metrics (response time, token usage, status codes)
- Session metadata (session ID, timestamps, user ID)
- Technical logs for system operations.
Retention:
- Default: 1 to 6 months (configurable per Client)
- Clients on on-premises deployments have full control over log retention, archival, and deletion
- Cloud deployments provide self-service log management controls
- Logs may be retained longer for legal/compliance purposes upon Client request or regulatory requirement.
Access and Privacy:
- Logs are encrypted at rest and in transit
- Access limited to authorised personnel and systems
- Clients can request log export, deletion, or archival per their DPA.
Artificial Intelligence and Agent Transparency
How AI Agents Process Data
Tovie's AI agents may process personal data through:
- LLM-based reasoning: Sending data to external or internal Large Language Models for analysis, generation, and decision-making
- Tool integrations: Querying external systems (CRM, databases, APIs) to enrich or update data
- RAG (Retrieval-Augmented Generation): Searching and retrieving information from knowledge bases and documents
- Orchestration: Multi-agent workflows where data flows through multiple processing steps
- Action execution: Initiating business processes (ticket creation, notifications, database updates)
Data Usage for Model Training:
Tovie AI does not use Client data for model training, model fine-tuning, or feature development.
Client data remains confidential and is used solely for:
- Executing the Client's configured agent workflows
- Providing the services specified in the contract
- Complying with legal obligations.
Agent Types and Capabilities
Tovie's platform supports the following agent types configured by Clients:
- Text Chat Agents: Conversational AI for customer service, support, and engagement
- Voice Agents: Automated voice assistants for IVR, customer service, and outbound calling
- Multi-Agent Orchestrators: Coordinated workflows involving multiple specialized agents
- Tool Agents: Agents specialized for specific integrations (CRM, search, calculations, RAG, etc.)
- FAQ/Support Agents: Agents specialized for knowledge base queries and support deflection
- Action Agents: Agents that initiate actions (create tickets, send notifications, update records).
Depending on Client configuration and permissions, agents may perform:
- Creating and updating records in CRM/service desk systems
- Initiating phone calls
- Sending messages (chat, email, SMS)
- Making HTTP/API calls to external systems
- Reading and writing to Client databases
- Searching knowledge bases and RAG repositories
- Triggering workflows and business processes.
Personal Data Protection
We employ a variety of measures to safeguard the collection, transmission, and storage of the personal data we collect. These measures vary based on the sensitivity of the information we process and the results of the Data Protection Impact Assessment which is a part of our Risk Management Process.
To protect your personal data we have implemented and maintain technical, administrative (or organisational) and physical controls in accordance with all applicable laws and regulations including but not limited to the following:
- We have integrated personal data protection into our Information Security Management System and implemented all relevant controls, as well as keeping them up to date.
- We perform the Data Protection Impact Assessment (DPIA) when we are going to use any new technologies, or if the processing is likely to result in a high risk to the rights and freedoms of data subjects. The results of the DPIA are used to make decisions regarding further processing and controls to be implemented to mitigate the risks associated with such processing.
- We include privacy as an inherent part of our Awareness and Training programme.
- We use encryption to keep your data confidential at rest and in transit.
- We provide access to personal data only to those of our employees who need this information to process it. Anyone who has such access is subject to strict contractual obligations regarding confidentiality and may be subject to disciplinary action if they do not fulfil them.
- We require our Suppliers who can access your personal data to ensure the level of security no less than the level of security they ensure regarding their sensitive information, and we require them to provide guarantees and assurance regarding the state of their information security processes.
- For Processor-managed data, we maintain detailed records of processing activities and make them available to Controllers upon request.
- We conduct regular security audits, vulnerability assessments, and penetration testing.
- We implement role-based access controls and least-privilege principles.
- We maintain incident response and breach notification procedures in compliance with GDPR Article 33 and applicable local laws.
Privacy Policy Updates
We may update this Privacy Policy from time to time by posting a new version on our websites. You should visit it regularly to stay informed. If required by applicable law, we will notify you of material changes through any other applicable communication channels before such changes become effective.
Contacts
If you have a complaint or a question regarding this Privacy Policy, or if you would like to make a request concerning the processing of your personal data, please contact us by email at privacy@tovie.ai.
For data processing agreements, sub-processor queries, and processor-related matters, also contact: privacy@tovie.ai
If you wish to lodge a complaint with a supervisory authority (Data Protection Authority), you may contact the appropriate authority in your jurisdiction:
Annex I – Categories of Personal Data Processing
Controller role
| Data Subject | Our Role | Processing Purpose | Personal Data We Process | Lawful Basis | Data Processing Term |
| Website Visitors | Controller | Provision of demo-versions and consulting | Full name, E-mail, Company name, Business phone number, Message text | Contract | Until demo/consulting complete + 1 year |
| Website Visitors | Controller | Contacting regarding website/service | Full name, E-mail, Company name, Message text | Consent | Until service rejection or contract signature + 1 year |
| Website Visitors | Controller | Sending guides and materials | Full name, E-mail, Company name, Requested guides/materials | Contract | Until materials sent + 1 year |
| Newsletter Subscribers | Controller | Sending news and advertisements | E-mail | Consent | Until unsubscription |
| Identity Provider Users | Controller | Service registration via Google/GitHub | Name, E-mail, Profile ID (from provider) | Contract/Consent | Until account deletion + 6 years (or applicable statute of limitations in the relevant jurisdiction for legal claims, tax or compliance) |
| Data Subject | Our Role | Processing Purpose | Personal Data We Process | Lawful Basis | Data Processing Term |
| Customers/Clients | Controller | User registration | Full name, E-mail, Phone number, Password, Profile ID, Google/GitHub profile, Country/region, Interface language, Timezone | Terms of Service | Until contract end + 6 years (or applicable statute of limitations in the relevant jurisdiction for legal claims, tax or compliance) |
| Customers/Clients | Controller | Service provisioning | Full name, E-mail, Phone number, Password, Profile ID, Google/GitHub profile, Country/region, Content metadata | Terms of Service | Until contract end + 6 years (or applicable statute of limitations in the relevant jurisdiction for legal claims, tax or compliance) |
| Customers/Clients | Controller | Subscription pricing requests | Company name, E-mail, Phone number, Request text | Terms of Service | Until contract end + 6 years |
| Customers/Clients | Controller | Limit extension requests | Company name, E-mail, Phone number, Request text | Terms of Service | Until contract end + 6 years |
| Customers/Clients | Controller | Connection requests | Company name, E-mail, Phone number | Terms of Service | Until connection agreement signed or cooperation refused + 1 year |
| Data Subject | Our Role | Processing Purpose | Personal Data We Process | Lawful Basis | Data Processing Term |
| Customers/Clients | Controller | Packages payment | Full name, E-mail, Phone number, Password, Profile ID, Google/GitHub profile, Country/region, Bank details | Terms of Service | Until contract end + 6 years (or applicable statute of limitations in the relevant jurisdiction for legal claims, tax or compliance) |
| Data Subject | Our Role | Processing Purpose | Personal Data We Process | Lawful Basis | Data Processing Term |
| Partners | Controller | Partner requests | Full name, E-mail, Company name, Company website, Phone number | Contract | Until partnership agreement ends + 1 year |
| Customers/Clients | Controller | Bot development requests | Full name, E-mail, Company name, Company website, Phone number, Project description, Uploaded files | Contract | Until development ends + 1 year |
| Data Subject | Our Role | Processing Purpose | Personal Data We Process | Lawful Basis | Data Processing Term |
| Website Visitors | Controller | Analytics and user tracking (per Cookies Policy) | Cookies, IP address, Device type, Behavioural data | Consent (per cookie banner) | Cookie lifetime |
Processor role
Platform Agent Processing (All platform URLs)
| Data Subject | Our Role | Processing Purpose | Personal Data Categories | Lawful Basis | Data Processing Term |
| End-users, customers, employees of our Clients | Processor | Execution of Client-configu red AI agent scenarios (chatbots, voice agents, orchestrators, tool agents, FAQ agents, action agents) | Identifiers: Name, E-mail, Phone, User/Customer ID, Session/Cookie ID; Interaction content: Chat messages, Email content, Voice queries/transcripts, File attachments; Client system data: CRM/ERP fields, Order/transaction data, Status information; Documents: Uploaded files, Jira/Confluence/SharePoint content, RAG repositories; Technical: Request metadata, Execution logs, Performance metrics | We rely on lawful basis established by Controller (Contract, Legitimate Interest, Consent) | Logs: 1–6 months (configurable); Client data: per Client DPA and retention schedule + 6 years (statute of limitations) |
| End-users interacting with agents | Processor | Data flows to Client-specific integrations | As above, plus data from external systems (CRM, ERP, ticketing, email, messaging, databases) | Per Controller instructions | Per integration and Client retention policies |
| End-users interacting with agents | Processor | LLM processing (if Client configures) | May include conversation context, identifiers, relevant data from conversations | Per Controller configuration and instructions | Retained by LLM provider per provider's policy; Tovie AI logs: 1–6 months (configurable) |
Platform Logs and Technical Data
| Data Subject | Our Role | Processing Purpose | Personal Data Processed | Lawful Basis | Data Processing Term |
| Platform users (Clients, agents, end-users) | Processor | System logging, debugging, operations | User messages, Execution events, API calls, Errors, Metrics (time, tokens, status codes), Session metadata, Technical logs | Per DPA instructions and legitimate interest in system operations | 1–6 months by default (configurable); longer with explicit Client request or legal requirement |
Invited Users (Cloud Platform)
| Data Subject | Our Role | Processing Purpose | Personal Data We Process | Lawful Basis | Data Processing Term |
| Invited users (from registered Customers/Clients) | Controller (for invitation process) | User invitations to platform accounts | E-mail, Groups, Roles (provided by inviting Customer) | Contract | Until user registration or 1 year after request from inviting Customer |
Special Categories and High-Risk Processing
Scenario: Client uses platform to process special categories (health, financial, biometric, etc.)
| Aspect | Details |
| Data Subject | End-users whose special categories are processed through Client agents |
| Our Role | Processor (following Client Controller instructions) |
| Lawful Basis | Client must establish basis under GDPR Art. 9(2) (explicit consent, employment law, vital interests, nonprofit, political data, etc.) |
| Deployment | Default: On-premises (Client-managed). Cloud deployment requires explicit written approval and additional DPIA. |
| Data Categories | Health data, financial information, biometric identifiers, genetic data, religious/political beliefs, union membership, sex life data, or other Art. 9 categories |
| Processing Purpose | As configured by Client (e.g., claims processing, financial assessment, identity verification) |
| Technical Measures | Data masking (Tovie Data Mask), encryption at rest/in transit, role-based access controls, audit logging |
| DPIA Requirement | Client must conduct DPIA per GDPR Art. 35; Tovie AI assists; results shared with Tovie AI before processing begins |
| Data Processing Term | Per Client DPA + 6 years (statute of limitations) or legal hold |
| Responsibility | Client responsible for Art. 9 basis, DPIA, consent mechanisms, and data subject notification. Tovie AI provides technical safeguards per DPA. |
Sub-Processors and Third Parties
Current Sub-Processors
Category: Cloud Infrastructure
- Amazon Web Services (AWS)
- Google Cloud Platform (GCP)
- IBM Cloud
Category: LLM and AI Services (Client-configured; may vary by deployment)
- OpenAI (USA)
- Other LLM providers per Client selection
Category: Backup and Disaster Recovery
- Cloud provider native backup services
- Third-party backup providers (details available on request)
Category: Monitoring and Logging
- Cloud provider monitoring services
- Third-party logging and analytics platforms (details available on request)
Category: Our Own Website and Marketing (Controller capacity)
- Stripe (USA) – Payment processing
- Mailchimp/Rocket Science Group (USA) – Email marketing
- Salesforce Inc. (USA) – CRM
- Apollo/ZenLeads Inc. (USA) – Lead enrichment
- Zendesk (USA) – Customer support
- Google Analytics and other analytics tools (per Cookies Policy)
Note: For Processor-managed Client data, sub-processor use depends on Client configuration. Clients are notified of sub-processor lists and changes, with right to object per DPA.
Data Subject Rights – Contact Instructions
Data Subject is a Visitor/Newsletter Subscriber (Tovie AI = Controller)
Contact: privacy@tovie.ai
Subject line: "Access Request" / "Rectification Request" / "Erasure Request" / "Data Portability Request" / "Processing Restriction Request" / "Objection to Processing".
Data Subject is Using a Client's AI Agent (Tovie AI = Processor)
Primary contact: The Client/organisation operating the agent (they are the Controller)
- Check their privacy notice or contact form for requests
Tovie AI assistance: If the Client requests Company's support, they should contact privacy@tovie.ai with the subject "Processor Assistance – [Request Type]".