Carvia

Privacy Policy

How Carvia collects, uses, stores and protects personal data, which processors are involved, and the rights you can exercise over your information.

Introduction

Carvia is committed to protecting personal data in accordance with applicable European Union and Slovenian data protection rules, including the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable local legislation.

This Privacy Policy explains what personal data we collect, how we use it, with whom we share it, how long we keep it, and what rights you have when you use the Carvia website, platform, AI-assisted tools, and related services (together, the "Services").

This document is a privacy notice. It explains our data processing practices. It does not replace commercial terms, service terms, or other contractual disclaimers that may apply to use of specific features.

Controller Information

For personal data described in this Privacy Policy, the data controller is Improvia.

If a business customer uses Carvia for its own customer, vehicle, or marketing records, that customer may act as an independent controller for certain data it uploads into the platform. In those cases, we typically act as a processor or sub-processor for the relevant customer data.

Information We Collect

Information you provide directly

  • Account data: name, email address, password, language, role, and workspace-related settings.
  • Billing and transaction data: invoice and subscription details, payment status, and limited payment-related metadata provided by payment partners.
  • Content you upload or create: vehicle details, inventory records, descriptions, images, files, prompts, publishing drafts, and other materials submitted through the Services.
  • Communications: support requests, feedback, email correspondence, and other messages you send to us.

Information collected automatically

  • Technical and usage data: IP address, browser type, operating system, device information, session timestamps, access logs, feature usage, and page interactions.
  • Diagnostic and security data: authentication events, error logs, abuse prevention signals, and audit records relevant to account and platform security.
  • Cookie-related data: information collected through essential and, where applicable, optional cookies and similar technologies. For more detail, see our Cookie Policy.

Information from third parties

  • Identity and login providers you choose to use, such as Google or similar sign-in services.
  • Payment providers and billing partners.
  • Social media, cloud, or integration providers that you explicitly connect to the Services.
  • Business customers or colleagues who invite you into a workspace or share records with you.

How We Use Information

We use personal data only where we have a valid legal basis, including contractual necessity, legitimate interests, legal obligation, or consent where required.

  • To create and manage accounts, workspaces, permissions, and subscriptions.
  • To provide core product functionality, including inventory, publishing, AI-assisted content generation, file handling, and related workflows.
  • To communicate with you about your account, support matters, product updates, billing, and security issues.
  • To maintain platform performance, detect abuse, troubleshoot issues, and improve the Services.
  • To meet accounting, tax, anti-fraud, security, and other legal or regulatory obligations.
  • To send non-essential marketing communications only where permitted by law and subject to your preferences or opt-out rights.

We do not sell your personal data.

AI Features and Review

Some Carvia features process uploaded images, text, and structured business data using AI-assisted tools. This may include generating descriptions, improving visual presentation, suggesting copy, or preparing materials for publishing.

AI-assisted outputs can contain inaccuracies, unusual visual details, unexpected additions, omissions, or other artifacts. Users are responsible for reviewing generated outputs before publication, customer use, or external sharing.

Where AI-related providers are used, we aim to use them under appropriate contractual and security arrangements. However, this Privacy Policy does not guarantee that every AI-generated result will be error-free, complete, or suitable for a specific legal, commercial, or advertising purpose.

Carvia is not responsible for business decisions, publication choices, or third-party consequences arising from unreviewed AI-generated outputs.

Sharing and Processors

We share personal data only where necessary and on an appropriate legal basis.

  • Service providers and processors: hosting, infrastructure, email, authentication, analytics, support, payment, and AI-processing providers that help us operate the Services.
  • Workspace users and customers: data may be visible to other authorized users within the same workspace, depending on permissions and feature usage.
  • Legal and compliance disclosures: where required by law, valid official request, court order, or to protect rights, security, and integrity of the Services or others.
  • Corporate transactions: in connection with a merger, financing, restructuring, acquisition, or asset sale, subject to appropriate confidentiality and legal safeguards.

Private drafts expire after 24 hours. Results expire 24 hours after completion. See our privacy policy for AI processing and provider retention.

Data Retention

We keep personal data only for as long as necessary for the purposes described in this Policy, including contractual, operational, accounting, security, and legal reasons.

  • Account and workspace data: usually for the duration of the account or business relationship and a reasonable period afterwards where required for legitimate follow-up, dispute handling, or compliance.
  • Billing and accounting records: as required by applicable tax and accounting laws.
  • Security and audit logs: for a limited period appropriate to security monitoring, incident investigation, and compliance.
  • Uploaded and generated content: until deleted by the customer, removed under retention rules, or no longer required for service delivery and compliance.

Your Rights

If GDPR applies to you, you may have the right to request access, rectification, erasure, restriction, portability, and objection, and to withdraw consent where processing is based on consent.

  • Access: request information about the personal data we hold about you.
  • Rectification: request correction of inaccurate or incomplete data.
  • Erasure: request deletion where the legal conditions for deletion are met.
  • Restriction: request limitation of processing in certain circumstances.
  • Portability: request a structured, commonly used, machine-readable copy of data where applicable.
  • Objection: object to certain processing, especially direct marketing or processing based on legitimate interests.
  • Complaint: lodge a complaint with a supervisory authority, including the Slovenian Information Commissioner where relevant.

You can exercise your rights by contacting us at [email protected]. We may request reasonable identity verification before acting on a request.

If you are in Slovenia, you may also contact the Information Commissioner of the Republic of Slovenia.

Cookies

We use cookies and similar technologies for essential site operation, security, authentication, preferences, analytics, and other platform functionality. Where required by law, non-essential cookies are used only on the basis of consent. See our Cookie Policy for more detail.

Security

We use technical and organizational measures designed to protect personal data against unauthorized access, accidental loss, misuse, alteration, or disclosure. These measures may include access controls, transport encryption, audit logging, environment segregation, and least-privilege practices.

No system can guarantee absolute security. If you believe your account or data has been compromised, contact us promptly at [email protected].

International Transfers

Personal data may be processed outside Slovenia or the European Economic Area, including where our infrastructure or service providers operate in other countries. When GDPR applies and data is transferred outside the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses or other recognized transfer mechanisms where required.

Children's Privacy

Carvia is intended for business and professional use. It is not directed to children, and we do not knowingly collect personal data from children under the age at which such processing would require parental authorization under applicable law.

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated "Last updated" date and, where appropriate, communicated through the Services or by email.

Contact

If you have questions about this Privacy Policy or would like to exercise your privacy rights, contact us at: