This policy explains how Zirvo OÜ collects and uses personal data when you visit our website, contact us, or use our services as a business customer. We process personal data in accordance with the EU General Data Protection Regulation (GDPR).
1. Controller
Zirvo OÜ, registry code 17611162, Comerç 39, 08620 Sant Vicenç dels Horts, Barcelona, Spain.
Privacy contact: privacy@zirvo.ai
2. Data we collect and why
| Situation | Data | Purpose | Legal basis (GDPR) |
|---|---|---|---|
| Visiting our website | IP address, browser type, date and time of access (technical server logs) | Delivering the website securely and preventing abuse | Legitimate interest, Art. 6(1)(f) |
| Contacting us by email | Name, email address, company, content of your message | Answering your request and following up | Legitimate interest, Art. 6(1)(f), or steps prior to a contract, Art. 6(1)(b) |
| Customer account | Name, business email, phone number, company details, user settings | Providing the services and managing your account | Performance of a contract, Art. 6(1)(b) |
| Billing | Company name, billing address, VAT number, payment details (handled by Stripe), invoices | Charging fees and keeping accounting records | Contract, Art. 6(1)(b), and legal obligation, Art. 6(1)(c) |
| Support and service emails | Contact details and communication history | Support, service notices and security alerts | Contract, Art. 6(1)(b) |
| Signing in with Google | Name, email address, profile picture and Google account identifier | Creating your account and signing you in (see section 3) | Contract, Art. 6(1)(b) |
We do not sell personal data and we do not use it for advertising profiles.
3. Sign in with Google (Google user data)
Our restaurant product, Zirvo Risto (zirvo.ai/risto), lets you sign in with your Google account. This section explains exactly what we receive from Google and what we do with it.
- What we receive: only your name, email address, profile picture and Google account identifier, through the
openid,emailandprofilepermissions. We do not request access to Gmail, Google Drive, Google Calendar, your contacts or any other Google data. - How we use it: to create your Zirvo Risto account, to sign you in securely, and to show your name and picture inside the app. We confirm with Google that your email address is verified.
- What we never do: we do not sell Google user data, we do not use it for advertising or profiling, we do not use it to train artificial intelligence models, and we do not let anyone read it except as described here.
- Sharing: we do not share Google user data with third parties, except with the infrastructure providers that host Zirvo Risto on our behalf under data processing agreements, or when the law requires it.
- Storage and protection: the data is stored with your account in our database, protected with encrypted connections, access controls and two-factor authentication on our systems.
- Retention and deletion: we keep it while your account exists and delete it within 30 days after your account is closed. You can ask us to delete it at any time by writing to privacy@zirvo.ai, and you can remove Zirvo Risto's access from your Google account at myaccount.google.com/permissions.
Zirvo Risto's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. Data we process on behalf of our customers
When restaurants and other businesses use Zirvo to manage bookings, calls or messages, we process data about their guests and callers (for example names, phone numbers, booking details, messages and call recordings or transcripts) on their behalf and according to their instructions. In that case the business is the controller and Zirvo is the processor. If you are a guest or caller, please contact the business you interacted with to exercise your rights; we will assist them.
5. Cookies and tracking
Our website currently does not use cookies, analytics or tracking tools, and our fonts are hosted on our own server, so no data is sent to third-party font or analytics providers. If this changes, we will update this policy and ask for your consent where required.
6. Service providers (processors)
We use carefully selected providers that process personal data on our behalf under data processing agreements:
| Provider | Purpose | Location |
|---|---|---|
| GitHub, Inc. (GitHub Pages) | Website hosting | USA (EU–US Data Privacy Framework / Standard Contractual Clauses) |
| Zoho Corporation B.V. | Business email | EU data centres |
| Stripe Payments Europe, Ltd. | Payment processing | Ireland (EU); some processing in the USA under appropriate safeguards |
Before our product processes customer data, the providers used for the product itself (such as cloud hosting, telephony, messaging and AI model providers) will be listed in this section and in our Data Processing Agreement.
7. International transfers
Where personal data is transferred outside the European Economic Area, we ensure an adequate level of protection, for example through an adequacy decision of the European Commission (including the EU–US Data Privacy Framework) or Standard Contractual Clauses.
8. How long we keep data
- Emails and enquiries: as long as needed to handle them, and up to 2 years after the last contact.
- Customer account data: for the duration of the contract, then deleted within 30 days after the end of the export period, unless the law requires longer retention.
- Invoices and accounting records: for the period required by accounting law (in Estonia, generally 7 years).
- Server logs: for a short period as determined by our hosting provider for security purposes.
9. Your rights
Under the GDPR you have the right to access your personal data, to have it corrected or deleted, to restrict or object to its processing, and to data portability. Where processing is based on consent, you can withdraw your consent at any time. To exercise your rights, write to privacy@zirvo.ai. We will respond within one month.
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state where you live or work. Our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), www.aki.ee.
10. Security
We use appropriate technical and organisational measures to protect personal data, including encrypted connections (HTTPS), access controls and two-factor authentication on our systems.
11. Changes to this policy
We may update this policy when our services or legal requirements change. The current version is always available on this page, with the date of the last update at the top.
12. Contact
Questions about privacy: privacy@zirvo.ai