Carvia

GDPR Information

How Carvia meets its GDPR obligations: the lawful bases for processing, data transfers, retention periods, and how to make a data subject request.

Overview

Carvia is committed to compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and, where relevant, related national implementation rules. This page provides supplementary information for EU users about how we process personal data, the lawful bases we rely on, and the rights available to data subjects.

For a broader description of our data practices, please also review our Privacy Policy.

Data Controller

For personal data processed in connection with your use of the Carvia platform, Improvia acts as the Data Controller. Our contact details:

Where business customers use Carvia to process data relating to their own clients, leads, employees, or partners, the relevant customer may act as controller and Carvia may act as a processor or sub-processor for that customer data.

Lawful Basis for Processing

We rely on the following lawful bases under Article 6 GDPR:

  • Contract (Art. 6(1)(b)): processing necessary to provide the Services, manage accounts, and perform subscription obligations.
  • Legitimate interests (Art. 6(1)(f)): service security, fraud prevention, diagnostics, product improvement, and business operations, provided those interests are not overridden by your rights and freedoms.
  • Legal obligation (Art. 6(1)(c)): compliance with accounting, tax, anti-fraud, and other legal duties.
  • Consent (Art. 6(1)(a)): marketing communications, non-essential cookies, and other processing where opt-in is required.

Your GDPR Rights

As a data subject under GDPR, you may have the following rights:

  • Right of access: request confirmation of whether we process your personal data and obtain a copy.
  • Right to rectification: request correction of inaccurate or incomplete data.
  • Right to erasure: request deletion where the legal conditions are met.
  • Right to restriction: request limited processing in certain circumstances.
  • Right to portability: receive certain data in a structured, commonly used, machine-readable format.
  • Right to object: object to certain processing, especially direct marketing or processing based on legitimate interests.
  • Right to withdraw consent: where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
  • Rights related to automated decision-making: not to be subject to solely automated decisions producing legal or similarly significant effects, except where permitted by law.

To exercise any of these rights, email [email protected]. We may request reasonable identity verification before completing a request.

International Data Transfers

Personal data may be processed outside Slovenia or the European Economic Area where our infrastructure or service providers operate internationally. When GDPR applies and data is transferred outside the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses or other valid transfer mechanisms where required.

Data Processing Agreement

Business customers who use Carvia to process personal data on behalf of others may require a Data Processing Agreement to support their own GDPR obligations. Our standard DPA is available upon request from [email protected].

  • Subject matter, nature, and purpose of processing.
  • Types of personal data and categories of data subjects.
  • Roles and responsibilities of controllers and processors.
  • Sub-processor framework and change procedures.
  • Security, incident handling, and deletion or return obligations.

Data Protection Officer

Carvia has designated a privacy contact for GDPR-related inquiries. We do not state that a formal Data Protection Officer is appointed unless required by law, but data protection matters can be directed to [email protected].

Retention Periods

  • Account data: retained for the duration of the account and a limited follow-up period where needed for support, disputes, or compliance.
  • Transaction and billing records: retained for the period required under applicable accounting and tax rules.
  • Consent and preference records: retained while relevant to demonstrate compliance.
  • Security and audit logs: retained for a limited period appropriate to security monitoring, investigations, and compliance.
  • Uploaded customer content: retained until deleted, removed under retention logic, or no longer required for service delivery and compliance.

Supervisory Authority Complaints

If you believe our handling of your personal data does not comply with GDPR, you have the right to lodge a complaint with the supervisory authority in your country of residence, place of work, or place of the alleged infringement. In Slovenia, this is the Information Commissioner of the Republic of Slovenia.

Contact