Privacy Policy
Last updated: August 22, 2025
1. Overview
Cllavio (“we”, “us”, “our”) provides a platform for sending email campaigns and transactional messages using your own SMTP server or our Email API. This Privacy Policy explains what we collect, how we use it, and the choices you have. By using our services, you agree to this Policy.
2. Scope
This Policy applies to our website, web application, related services, and customer support interactions. It covers data that we process for account management, delivery of emails via SMTP or Email API, analytics, and legal compliance.
3. Key Definitions
- Account Data: Info you provide to create and manage your account (e.g., name, email, organization).
- Email Content: Subject lines, bodies, attachments, templates you send through campaigns or API.
- Email Metadata: Sender/recipient addresses, timestamps, delivery events, open/click logs (if enabled).
- SMTP Credentials: Host, port, username, and secret used to send via your server.
- OAuth Tokens: Limited-scope tokens if you connect a mailbox via OAuth (e.g., Google).
4. Information We Collect
4.1 Account & Organization Data
Name, email, password (hashed), organization name, role, and audit logs of account activity (e.g., login time, settings changes).
4.2 Email Content & Recipients
When you send emails via campaigns or API, we process the content and recipient addresses necessary to deliver the message. We may store delivery results and event logs (bounces, complaints, opens/clicks if you enable tracking).
4.3 SMTP Credentials & OAuth Tokens
If you connect your own SMTP server, we store the credentials securely for sending. If you connect an external mailbox using OAuth, we store and refresh limited-scope tokens to send on your behalf. We do not sell or share these secrets and restrict access internally on a need-to-know basis.
4.4 Usage, Device & Log Data
IP address, browser/OS, pages viewed, timestamps, and diagnostic logs to secure and improve the service, troubleshoot, and prevent abuse.
4.5 Cookies & Similar Technologies
We use necessary cookies for authentication and security, and (if consented where required) analytics cookies to understand usage and improve features.
5. How We Use Information
- Provide, maintain, and secure the platform.
- Authenticate users and operate organizations, roles, and permissions.
- Send emails via your SMTP or our Email API as you instruct.
- Log delivery outcomes and optional open/click analytics if enabled by you.
- Prevent abuse, detect fraud, and enforce acceptable use.
- Provide support and improve features based on aggregated usage.
- Comply with legal obligations and respond to lawful requests.
6. Legal Bases (GDPR/UK GDPR)
- Contract – to provide the services you request.
- Legitimate interests – securing our services, preventing abuse, improving features.
- Consent – where required (e.g., certain analytics, marketing emails).
- Legal obligation – to comply with applicable law.
7. Your Rights & Choices
Depending on your location, you may have rights to access, correct, delete, object to, or restrict processing of your personal data, and to portability. You can also opt out of non-essential cookies and certain analytics. To exercise your rights, contact support@cllavio.com.
8. Security
We apply administrative, technical, and physical safeguards appropriate to the risk, including encryption in transit, least-privilege access controls, and audit logging. No method of transmission or storage is 100% secure.
9. Data Retention
We retain account data for as long as you maintain an account and for a reasonable period thereafter for backup, audit, dispute resolution, and legal compliance. Email delivery logs and analytics are retained for operational needs and then deleted or anonymized. You can request deletion of your account data at any time.
10. International Transfers
If data is transferred across borders, we implement appropriate safeguards (e.g., Standard Contractual Clauses where applicable) to protect it in accordance with relevant law.
12. Third-Party Services & Integrations
You may connect third-party services (e.g., SMTP providers, cloud storage, analytics). Your use of those services is governed by their own terms and policies. We process data from integrations only to operate features you enable.
15. Children’s Privacy
Our services are not directed to children under the age of 16, and we do not knowingly collect personal data from them.
16. Changes to this Policy
We may update this Policy from time to time. Material changes will be posted here with an updated “Last updated” date. Continued use of the services constitutes acceptance of the revised Policy.
17. Contact Us
Questions or requests? Reach us at:
Email: support@cllavio.com