Gatavo — Privacy Policy
Effective date: 20 September 2026 Last updated: 20 September 2026
This Privacy Policy explains how Gatavo, LLC, a Delaware limited liability company with its registered office at 131 Continental Dr, Suite 305, Newark, DE 19713, United States ("Gatavo", "we", "us"), handles personal data in connection with the Gatavo application at app.gatavo.eu, the website at gatavo.eu, and related services (the "Service").
We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and other applicable data protection law.
1. Two different roles: please read this first
Gatavo is used by service businesses ("Companies") to run their operations — including managing their own customers. That creates two distinct relationships:
We are the controller for data about the people who use Gatavo directly: account owners, managers, and agents. This covers registration, billing, support, security, and service communications. Sections 3 to 7 describe this.
We are a processor for the personal data a Company enters or collects about its own clients, prospects, and end customers. Here the Company is the controller — it decides what data to collect and why. We only process it on the Company's instructions, to provide the Service. Section 8 describes this.
If you are a customer of a business that uses Gatavo — for example, you received an invoice, a visit reminder, or a review request generated by Gatavo — that business controls your data, not us. Please contact them directly with any request. If you contact us, we will pass your request to them and assist them in responding.
2. Where your data is processed
We are a United States company. Our application infrastructure is located in the European Union, but some of our service providers are based in or store data in the United States. Section 10 explains the transfer safeguards we rely on.
We have no establishment in the European Union.
3. What we collect as controller
Account and profile data
- For managers: name, email address, password (stored hashed) or Google account identifier, chosen interface language, timezone, and currency.
- For team members: name, email address, phone number, role, primary city, hourly rate, and interface language. Much of this is entered by the manager who invites them.
- For agents under the income-split model: legal name, activity or company code, VAT registration status and code, IBAN, and bank name — entered by the manager and used to generate co-branded invoices, certificates, and settlement statements.
Company data
- Company name, logo, contact details, address, company code, VAT registration and rate, and banking details (bank name, IBAN, SWIFT/BIC), which are used on documents and to generate the pay-by-bank QR code.
Billing data
- Plan, subscription status, billing history, seat usage, and payment records. Card details are collected and stored by Stripe; we never receive or store full card numbers.
Technical and usage data
- IP address, browser and device information, log data, timestamps, and records of actions taken in the Service. Used for security, abuse prevention, troubleshooting, and reliability.
Email delivery data
- Delivery, bounce, and open events for emails sent through the Service. Automated scanner and bot opens are filtered out so that the "opened" signal reflects likely human activity.
Support and correspondence
- Messages you send us and our replies.
Website data
- Page analytics from gatavo.eu. See Section 11.
4. Why we process it, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating and running your account; providing the Service and its features | Performance of a contract — Art. 6(1)(b) |
| Subscription billing, invoicing you, and collecting payment | Contract; legal obligation — Art. 6(1)(b), (c) |
| Service emails: verification, password reset, assignment and schedule notifications | Contract |
| Security, abuse and fraud prevention, tenant isolation, rate limiting | Legitimate interests — Art. 6(1)(f) |
| Troubleshooting and providing support | Contract; legitimate interests |
| Maintaining, improving, and developing the Service | Legitimate interests |
| Sending you product news and marketing about Gatavo | Consent, or legitimate interests where permitted — always with an unsubscribe link |
| Meeting tax, accounting, and other legal obligations | Legal obligation |
| Establishing, exercising, or defending legal claims | Legitimate interests |
Where we rely on legitimate interests, we have assessed that our interest in operating a secure and functioning service is not overridden by your rights. You may object at any time (Section 9).
5. What we do not do
We do not sell personal data. We do not share it with advertisers or data brokers. We do not use it to train machine learning models. We do not carry out automated decision-making that produces legal or similarly significant effects.
6. Who we share it with
We use a limited set of service providers ("sub-processors"). Each is bound by contract to process data only on our instructions and to maintain appropriate security.
| Provider | Role | Location |
|---|---|---|
| Railway | Application hosting and PostgreSQL database | European Union |
| Cloudflare (R2) | Storage of uploaded photos, receipts, and attachments | European Union (EU-jurisdiction bucket); Cloudflare is a US company |
| Postmark (ActiveCampaign) | Transactional and client-facing email delivery | United States |
| Stripe | Payment processing, subscription billing, billing portal | United States and Ireland |
| Vercel | Marketing website hosting and privacy-friendly page analytics | United States / global edge |
| Optional sign-in; map links; redirection of reviewers to a Google profile | United States |
This list is kept current in Annex 3 of our Data Processing Agreement, and we give advance notice of changes as described there.
We also disclose personal data where necessary to professional advisers under confidentiality, to a buyer or successor in a merger or acquisition (with notice to you), and to authorities where legally required, after assessing the legality of the request.
Endpoints you configure. If you enable webhooks or integrations, data is sent to the destinations you choose (for example Zapier, Make.com, or your own systems). Those destinations are outside our control and are your responsibility.
7. How long we keep it
| Data | Retention |
|---|---|
| Account and profile data | For the life of the account, then up to 12 months |
| Customer Data (Section 8) | Deleted or anonymized within 90 days of account termination |
| Billing and accounting records | 7 years, as required by tax and accounting law |
| Technical logs | Up to 12 months |
| Email delivery events | Up to 12 months |
| Support correspondence | Up to 24 months after resolution |
| Marketing consent records | Until withdrawn, plus 3 years as proof of consent |
Longer retention applies where needed to establish, exercise, or defend legal claims, or where required by law.
8. Data we process on behalf of Companies
When a Company uses Gatavo, it enters and generates personal data about its own clients and prospects. This can include:
- names, company names, email addresses, phone numbers, and service addresses;
- job records, descriptions, visit history, internal notes, and photographs — including photographs uploaded by the Company's own clients through the lead capture form;
- quotes, invoices, work certificates, payment status, and financial totals;
- review requests, star ratings, written feedback, and email open signals;
- time entries and expense records naming team members.
For all of this:
- the Company is the controller and we are the processor. We act only on the Company's documented instructions, which consist primarily of providing the Service as the Company has configured it;
- we use it to host and display records, generate documents, send the Company's client-facing emails, deliver webhook payloads to endpoints the Company configures, and produce the Company's analytics;
- we apply the security measures in Section 12 and the sub-processors in Section 6;
- we assist the Company in responding to data subject requests and in meeting its obligations under Articles 32 to 36 GDPR;
- on termination we delete or anonymize the data within 90 days, unless retention is legally required.
The full terms of this relationship are set out in our Data Processing Agreement at gatavo.eu/dpa, which forms part of our Terms of Use and satisfies Article 28 GDPR. Companies do not need to sign it separately; accepting the Terms of Use accepts the DPA.
9. Your rights
Where we are the controller, you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate or incomplete data;
- erase your data, where one of the grounds in Article 17 applies;
- restrict processing in certain circumstances;
- object to processing based on legitimate interests, and to direct marketing at any time and absolutely;
- portability — receive data you provided in a structured, machine-readable format, and have it transmitted to another controller where technically feasible;
- withdraw consent at any time, without affecting processing already carried out.
Write to info@gatavo.eu. We respond within one month, extendable by two months for complex requests, and we will tell you if we need an extension. We may ask for information to verify your identity. Exercising these rights is free unless a request is manifestly unfounded or excessive.
Complaints. You may lodge a complaint with a supervisory authority in your country of residence or work. In Lithuania this is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), vdai.lrv.lt.
If your data was entered by a Company using Gatavo, contact that Company — it is the controller. We will forward your request and support them in answering it.
10. International transfers
We are established in the United States, and some sub-processors listed in Section 6 process data there. This means personal data originating in the European Economic Area may be transferred outside it.
For these transfers we rely on the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914), incorporated into our agreements with the relevant providers, together with supplementary technical and organizational measures including encryption in transit and at rest, access controls, and data minimization. Where a provider is certified under the EU–US Data Privacy Framework, we may also rely on that adequacy decision.
You may request a copy of the relevant transfer safeguards by writing to info@gatavo.eu.
11. Cookies and analytics
Strictly necessary cookies. We use cookies that are essential to the Service: authentication and session management, security and abuse prevention, and remembering your language choice. These cannot be switched off and do not require consent.
Website analytics. gatavo.eu uses Vercel Web Analytics, which is cookieless and does not track visitors across sites or build individual profiles.
You can block or delete cookies in your browser, but blocking strictly necessary cookies will prevent you from signing in.
12. Security
We apply appropriate technical and organizational measures, including:
- encryption in transit (TLS) and encryption at rest;
- passwords stored using a strong one-way hashing algorithm;
- role-based access control enforced on the server, not merely hidden in the interface;
- strict separation of each Company's data from every other Company's;
- signed webhooks with one-time secret display, secret rotation, and replay protection;
- invisible spam and bot protection on public forms, plus rate limiting;
- access logging and restricted internal access on a need-to-know basis;
- regular dependency updates and security patching.
No system is completely secure. If you suspect a security problem or unauthorized access, contact info@gatavo.eu immediately. Where a personal data breach is likely to result in a risk to individuals, we notify the competent supervisory authority within 72 hours where required, and we notify affected Companies without undue delay so they can meet their own obligations.
13. Children
The Service is intended for business use by adults. We do not knowingly collect personal data from anyone under 16. If you believe a child's data has been provided to us, contact us and we will delete it.
14. Changes to this Policy
We may update this Policy as the Service and the law develop. Material changes will be announced in the Service or by email before they take effect. The "Last updated" date at the top always reflects the current version, and we keep prior versions available on request.
15. Contact
Gatavo, LLC 131 Continental Dr, Suite 305 Newark, DE 19713 New Castle County, United States
Privacy enquiries and data subject requests: info@gatavo.eu