Kavaro

About

Pricing

Sign inGet started

Privacy Policy

Last updated: March 19, 2026


1. Introduction & Data Controller

This Privacy Policy explains how VonHofmeister ApS (CVR: 35826297, VAT: DK35826297), operating as "Kavaro" ("we", "us", or "our"), a company registered in Denmark, collects, uses, shares, and protects your personal information when you use our platform at kavaro.ai and all associated subdomains.

VonHofmeister ApS is the data controller responsible for your personal data under the EU General Data Protection Regulation (GDPR) and other applicable data protection laws. For any questions about this policy or our data practices, contact us at privacy@kavaro.ai.

2. Information We Collect

We collect the following categories of personal information:

Account Information

When you sign up, we receive your name, email address, and profile picture from your chosen authentication provider (Google, Microsoft, Apple, or Facebook). We do not store passwords — authentication is handled entirely through these third-party OAuth providers.

Organization Data

Organization names, member roles, settings, and preferences that you configure within the platform.

Content You Create

Application templates, deployed instances, database schemas, application code, configurations, and any other content you build or upload using the platform.

AI Conversation Data

Messages you send to the AI builder, AI-generated responses, tool call inputs and outputs, and related metadata. This data is stored in our database and is also sent to third-party AI providers to generate responses. See Section 5 for full details.

Payment Information

Billing details are processed securely by Stripe, our payment processor. We do not store your full credit card number or payment credentials on our servers.

Usage & Technical Data

Feature usage patterns, session information, login timestamps, IP addresses, browser type, device information, and similar technical data collected through server logs and, with your consent, analytics cookies.

Integration Data

If you connect third-party services (such as Google Workspace, Microsoft 365, e-conomic, or FattureInCloud), we access and process data from those services only within the OAuth scopes you authorize.

3. How We Use Your Information

We use your information for the following purposes:

  • Provide, operate, and maintain the Kavaro platform
  • Process AI requests by sending conversation context to third-party AI providers to generate responses
  • Process payments and manage subscriptions through Stripe
  • Send transactional emails and service notifications through Resend
  • Generate text embeddings for knowledge base search through Voyage AI
  • Authenticate your identity through OAuth providers
  • Analyze usage patterns to improve the platform (with your consent, via Google Analytics)
  • Provide customer support and respond to your requests
  • Comply with legal obligations, including tax and accounting requirements
4. Legal Basis for Processing

Under the EU General Data Protection Regulation (GDPR), we process your personal data on the following legal grounds:

  • Performance of a contract (Art. 6(1)(b)) — Account creation, service delivery, AI conversation processing, and payment processing are necessary to provide the service you signed up for.
  • Legitimate interests (Art. 6(1)(f)) — Platform security, fraud prevention, service improvement, and troubleshooting. We balance these interests against your rights and freedoms.
  • Consent (Art. 6(1)(a)) — Analytics cookies, marketing communications, and optional third-party integrations. You can withdraw consent at any time without affecting the lawfulness of prior processing.
  • Legal obligation (Art. 6(1)(c)) — Retaining tax and financial records as required by Danish and EU law.
5. AI Data Processing & Chat Storage

Kavaro is an AI-powered platform. It is important you understand how your data is handled when you interact with our AI features:

  • Your conversations with the AI builder — including your messages, AI responses, and tool call data — are stored in our database on servers located in Germany (EU).
  • To generate AI responses, your conversation content and relevant project context are sent to third-party AI providers. The providers we currently use include: Anthropic/Claude (United States), OpenAI/GPT (United States), Google/Gemini (United States), Mistral (France), and DeepSeek (China).
  • Organization administrators can configure which AI model is used for their projects, giving you control over which providers process your data.
  • You can delete your AI conversation history at any time from within the platform.
  • Anonymous support chat on our landing page is ephemeral — conversations are automatically deleted after 30 minutes and are not linked to any user account.
  • We do not use your conversations to train our own AI models. Each AI provider has their own data processing and retention policies, which we encourage you to review.
6. Third-Party Service Providers

We do not sell, rent, or trade your personal information. We share data with the following categories of service providers solely to operate the platform:

AI Providers

Anthropic (US), OpenAI (US), Google (US), Mistral (France), DeepSeek (China) — receive conversation content and project context to generate AI responses.

Payment Processing

Stripe (US) — processes billing and payment information.

Email Service

Resend (US) — delivers transactional emails and service notifications.

Text Embeddings

Voyage AI (US) — processes document text to generate semantic search embeddings.

Analytics

Google Analytics (US) — collects usage data to help us improve the platform. Only activated with your consent.

Authentication Providers

Google, Microsoft, Apple, and Facebook (US) — provide secure login through OAuth. We receive your name, email, and profile picture.

User-Connected Integrations

When you choose to connect third-party services (e.g., Google Workspace, Microsoft 365, e-conomic, FattureInCloud), data is exchanged with those services only within the OAuth scopes you authorize. You can disconnect integrations at any time.

7. International Data Transfers

Your data is primarily stored on Hetzner servers located in Germany (EU). However, to provide our services, some of your data is transferred to providers located outside the EU/EEA:

  • Transfers to US-based providers (Anthropic, OpenAI, Google, Stripe, Resend, Voyage AI) are protected by the EU-US Data Privacy Framework and/or EU Standard Contractual Clauses (SCCs).
  • Transfers to DeepSeek (China) only occur when an organization administrator explicitly selects this AI model. These transfers are protected by EU Standard Contractual Clauses (SCCs) and supplementary safeguards.
  • Transfers to Mistral (France) remain within the EU/EEA.

Organization administrators can control which AI model is used for their projects, giving you control over where your conversation data is processed.

8. Data Retention

We retain your personal information for the following periods:

  • Account data — Retained for the lifetime of your account. We do not automatically delete account data, as content you create may constitute intellectual property. You can request deletion at any time by contacting us.
  • AI conversation history — Retained while your account is active. You can delete your conversation history at any time from within the platform.
  • Payment and billing records — Retained for 7 years as required by Danish tax and accounting law (Bogføringsloven).
  • Server logs — Retained for 90 days for security and troubleshooting purposes.
  • Anonymous support chat — Automatically deleted after 30 minutes.
  • Analytics data — Retained according to Google Analytics retention settings (14 months), and only collected with your consent.
9. Data Security

We implement appropriate technical and organizational measures to protect your personal information:

  • Data is stored on dedicated servers in Hetzner data centers in Germany, which are ISO 27001 certified.
  • All data in transit is encrypted using TLS/HTTPS.
  • Authentication is handled through OAuth providers — we do not store passwords.
  • Role-based access controls limit data access within organizations.

No method of electronic transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

10. Your Rights
Rights for All Users

Regardless of your location, you can:

  • Access your personal data by contacting us
  • Correct inaccurate or incomplete information
  • Request deletion of your account and personal data
  • Request a copy of your data in a portable format
  • Delete your AI conversation history at any time through the platform
Additional Rights Under GDPR (EU/EEA Users)
  • Object to processing based on legitimate interests
  • Request restriction of processing
  • Withdraw consent at any time without affecting the lawfulness of prior processing
  • Lodge a complaint with your local data protection authority. Our lead supervisory authority is the Danish Data Protection Agency (Datatilsynet).
Additional Rights Under CCPA/CPRA (California Residents)
  • Right to know what personal information is collected, used, and disclosed
  • Right to delete your personal information
  • Right to correct inaccurate personal information
  • Right to opt-out of the sale or sharing of personal information — we do not sell or share your personal information for cross-context behavioral advertising
  • Right to non-discrimination for exercising your privacy rights
  • You may designate an authorized agent to make requests on your behalf
Additional Rights Under PIPEDA (Canadian Users)
  • Right to access your personal information held by us
  • Right to challenge the accuracy of your information and have it amended
  • Right to withdraw consent, subject to legal or contractual restrictions and reasonable notice

To exercise any of these rights, please contact us at privacy@kavaro.ai. We will respond within 30 days or within the timeframe required by applicable law.

11. Cookies & Tracking

We use cookies to operate the platform and, with your consent, to analyze usage patterns. Our cookies fall into three categories:

  • Essential cookies — Required for authentication, security, and core platform functionality. These cannot be disabled.
  • Analytics cookies — Help us understand how you use the platform (Google Analytics). Only set with your explicit consent.
  • Marketing cookies — Used for advertising relevance, if applicable. Only set with your explicit consent.

You can manage your cookie preferences at any time through our cookie consent banner or by visiting our Cookie Policy page.

12. Children's Privacy

Our platform is not directed to children under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have inadvertently collected data from a child under 16, we will take steps to delete it promptly. If you believe a child has provided us with personal data, please contact us at privacy@kavaro.ai.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we do, we will update the "Last updated" date at the top of this page. We encourage you to review this page periodically to stay informed about how we protect your data. Your continued use of the platform after changes are posted constitutes your acceptance of the updated policy.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices:

  • Email: privacy@kavaro.ai
  • Company: VonHofmeister ApS, CVR: 35826297, Denmark

If you are located in the EU/EEA and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. Our lead supervisory authority is the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark.

Kavaro

Automate your work, simplify your life. Built for individuals and small businesses.

About

Pricing

Terms of Service

Privacy Policy

Cookie Policy


© 2026 Kavaro. All rights reserved.