Skip to content

Legal

Privacy policy

Last updated August 20, 2026

Who we are

Kavo Publicity operates kavopublicity.com and the private client + team platform behind it. We're a marketing and creative studio based in Romania. For anything below, you can reach us at contact@kavopublicity.com.

Company registration details (CUI, address, Registrul Comerțului number) are published in our contract with each client.

What personal data we hold, and why

We only collect what we need to run the business relationship. Categories, sources, and purposes:

  1. Onboarding form data — name, email, phone (optional), brand name, website, socials, industry, goals, budget range, timeline, services of interest, notes. Collected when you fill out the “Get in touch” wizard. Legal basis: consent (Art. 6(1)(a) GDPR) and steps prior to entering into a contract (Art. 6(1)(b)).
  2. Account data — email, full name, optional nickname, optional avatar, workspace assignment. Created by an admin when you're invited. Legal basis: contract (Art. 6(1)(b)).
  3. Workspace content — messages you post in team chat, questions you ask, feedback surveys, files you upload. Legal basis: contract.
  4. Technical data — IP address (rate-limiting), browser user agent (session cookie), pages visited (only if you agreed to analytics). Legal basis: legitimate interest (Art. 6(1)(f)) for security items; consent for analytics.

Who processes it on our behalf

We use a small set of established EU/US processors. Each has its own GDPR-compliant Data Processing Agreement with us.

ProcessorWhat they doLocation
Supabase, Inc.Database + authentication + file storageEU region
Vercel Inc.Website hosting + edge computeUS (SCCs)
Vercel AnalyticsCookie-free page-view stats (only if opted in)US (SCCs)
Resend, Inc.Transactional email deliveryUS (SCCs)
OneSignal, Inc.Web push notifications (only if opted in)US (SCCs)

We do not sell your data. We do not use it for advertising. We do not run Google Analytics, Meta Pixel, TikTok Pixel, or any other cross-site tracker.

How long we keep it

  • Onboarding submissions — until you request deletion, or 24 months of inactivity if we never sign a contract.
  • Client accounts + workspace data — for the duration of the contract, plus up to 12 months for handover / re-engagement, then deleted.
  • Financial records — retained for as long as Romanian tax law requires (currently 10 years).
  • Audit logs (admin actions) — 24 months, to investigate any security incident.

Your rights

Under GDPR, you can at any time ask us to:

  • Access — get a copy of the personal data we hold about you.
  • Rectify — correct anything that's wrong.
  • Erase — delete it (subject to the retention rules above where legally required).
  • Restrict processing — pause our use of it while a dispute is resolved.
  • Portability — receive it in a machine-readable format.
  • Object — to any processing based on legitimate interest.
  • Withdraw consent — for anything based on consent (analytics, push, marketing emails). Withdrawal doesn't affect processing that already happened lawfully.

We respond within 30 days. If we can't honour a request (e.g. a legal retention obligation applies), we'll explain why in writing.

Cookies + trackers

See the dedicated Cookie policy for the full list. In short: one session cookie is necessary to keep you signed in. Everything else (page-view analytics, push notifications) only fires if you tick it in the consent banner.

Data transfers outside the EU

Some of our processors (Vercel, Resend, OneSignal, Vercel Analytics) are US-based. Each transfer is covered by the EU Standard Contractual Clauses (SCCs) and, where available, the EU–US Data Privacy Framework. No data is transferred outside the EU/US without those safeguards in place.

Security

All traffic is HTTPS-only (HSTS preloaded, 2-year lifetime). Session cookies use the framework's httpOnly + secure flags. The database has row-level security switched on — even a leaked client-side key can't read another client's data. Passwords used in admin invites are checked against known breach corpora (haveibeenpwned) before being accepted. Sensitive admin actions (account creation/deletion, workspace deletion, chat moderation) are recorded in an insert-only audit log.

Filing a complaint

If you believe we've mishandled your data, you have the right to complain to the Romanian data protection authority:

ANSPDCP — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, București
anspdcp@dataprotection.ro · www.dataprotection.ro

You can also complain to the DPA in your own EU country of residence. We'd appreciate the chance to fix things directly first — contact@kavopublicity.com.

Changes to this policy

If we change how we handle your data — for example, adding a new processor — we'll update this page and bump the “Last updated” date at the top. For material changes we'll also notify signed-in users inside the platform.

← Back to kavopublicity.com