Privacy Policy
Last updated: 2026-08-05
Effective date: August 5, 2026
This Privacy Policy explains how OXVO collects, uses, discloses, and protects personal data when you visit our websites, create or administer an account, communicate with us, or use OXVO Builder, OXVO Console, OXVO Sessions, AI features, hosting, publishing, messaging, voice, APIs, SDKs, widgets, integrations, and related services (collectively, the "Service"). It also explains privacy choices and rights.
1. Who we are and when this Policy applies
"OXVO", "we", "us", and "our" mean the OXVO legal entity identified as the supplier on the applicable Order Form, checkout, invoice, or account billing page. If none is identified, OXVO means the operator of oxvo.com that provides the relevant Service. Registered details for the applicable entity may be requested at privacy@oxvo.com or legal@oxvo.com.
This Policy applies to personal data OXVO processes as a controller when deciding why and how to process data about website visitors, prospects, account users, administrators, business contacts, and people who communicate directly with OXVO.
Customers also use the Service to process personal data about their own End Users, contacts, employees, or other individuals. For that data, the customer generally determines the purposes and means of processing and OXVO acts as a processor or service provider. The customer's privacy notice, not this Policy alone, should explain that processing. If your data was collected through a customer's website, app, chat, inbox, replay, call, or workflow, contact that customer first.
This Policy does not cover third-party products and services that have their own privacy policies or a customer's independent practices.
2. Personal data we collect
The data collected depends on the features, configuration, integrations, and how the Service is used.
2.1 Account, workspace, and business data
We may collect names, work email addresses, phone numbers, company and job information, profile images, authentication and recovery data, workspace and team membership, roles, permissions, language and interface preferences, plan and entitlement information, security settings, consent records, and account activity. If single sign-on or another identity provider is used, we receive identifiers and attributes authorized through that provider.
2.2 Builder, project, and runtime data
When Builder is used, we may process prompts, instructions, product ideas, project names, source code, repositories, branches, files, uploads, screenshots, reference URLs, external-source content, design and page structure, database schemas, generated text, code, images, video, audio, or 3D assets, version history, previews, terminal commands and output, build and deployment logs, runtime diagnostics, source snapshots, publishing settings, model selections, and usage or credit records.
Connected repositories, storage, search, crawling, model, or media services may provide access tokens, connection metadata, files, content, and results according to the permissions selected by the customer.
2.3 Hosted apps, domains, databases, and storage
For apps or sites built, connected, previewed, or hosted through OXVO, we may process domain and DNS data, certificate and routing data, deployment metadata, app assets and configuration, user-submitted form or account data, database records, storage objects, authentication events, API traffic, errors, logs, security events, and other data the customer configures the Hosted App to collect. Publicly published content may be accessed, indexed, cached, copied, or archived by others.
2.4 Console, contacts, messages, and support operations
OXVO Console may process contact profiles, email addresses, telephone numbers, social or channel identifiers, customer attributes, messages, emails, chats, tickets, notes, assignments, tags, attachments, knowledge sources, routing and SLA data, conversation and support history, agent activity, summaries, orders, billing or refund context, automation events, and data received from connected messaging, social, commerce, CRM, telephony, email, and other channels.
2.5 Session replay, analytics, and diagnostics
When a customer enables OXVO Sessions or related features, we may process page URLs and titles, page structure and visible text, navigation, clicks, scrolling, cursor and viewport activity, form and input interactions, timestamps, event and funnel data, referrers, traffic sources, session and user identifiers, IP address, approximate location derived from IP, device and browser data, console errors, performance and network diagnostics, and replay event streams.
Depending on configuration, network request metadata, selected headers, or request and response bodies may be captured. Input values may be masked or excluded depending on field type and customer settings. Masking reduces, but does not eliminate, the possibility of capturing personal or sensitive data.
2.6 Co-browsing, AI Live Assist, voice, and automated actions
Live-assist features may process current page context, semantic page snapshots, cursor or guidance events, temporary visual context, microphone or call audio, text and voice transcripts, language, consent and permission records, agent or AI instructions, tool calls, proposed and completed actions, confirmations, handoff context, and safety or audit logs.
Whether audio, transcripts, visual context, or action history is retained depends on the feature, channel, customer configuration, plan, and applicable notice. Some audio may be streamed in real time to communications or AI providers. Calls through connected channels may be recorded or retained when the customer enables recording.
2.7 AI Inputs and Outputs
AI Features may process prompts, code, files, screenshots, images, audio, video, conversations, session context, app context, documentation, knowledge sources, analytics, bugs, feedback, instructions, tool results, and other customer-selected data. We may store Inputs, Outputs, evaluations, safety signals, and usage metadata according to the feature and customer settings.
2.8 Billing, payments, and transactions
We and our payment providers may collect billing name and address, company and tax data, payment method type, limited card details such as brand and last digits, payment tokens, invoices, subscription and plan data, credits, usage, transaction status, chargebacks, and fraud signals. For supported alternative payments, we may process wallet or public transaction identifiers. OXVO generally does not receive or store full payment-card numbers.
2.9 Device, cookie, log, and security data
We collect IP address, device and browser type, operating system, identifiers, pages and features used, clicks, timestamps, referring pages, API requests, quota usage, performance metrics, crashes, errors, authentication events, security events, and audit or access logs. We and our providers may use cookies, local storage, pixels, SDKs, and similar technologies as described below.
2.10 Communications, sales, events, and feedback
When you contact support or sales, request a demo, join an event, answer a survey, participate in research, report abuse, or communicate with us, we may collect contact details, message content, attachments, call or meeting information, notes, feedback, preferences, and related metadata.
2.11 Sensitive personal data
The Service is not designed to receive highly sensitive or regulated data unless an expressly supported feature or written agreement permits it. Customers should not submit full payment-card data, bank credentials, health records subject to HIPAA, biometric templates, genetic data, government identifiers, authentication secrets, or children's data without a valid legal basis, appropriate safeguards, and any required written agreement. If sensitive data is incidentally included in Customer Content, we process it under the customer's instructions and applicable contract.
3. Sources of personal data
We collect personal data:
directly from you when you register, configure the Service, submit content, connect a property, purchase a plan, or communicate with us;
from account administrators, teammates, customers, and End Users who submit or connect data to the Service;
automatically through the Service, cookies, SDKs, scripts, logs, APIs, widgets, replay, analytics, and security systems;
from Third-Party Services you or a customer connects, including identity, repository, communications, social, commerce, CRM, payment, database, hosting, model, search, and analytics providers;
from public sources or websites selected as references or sources by a customer; and
from service providers, partners, event organizers, and business contacts where permitted by law.
4. How we use personal data
We use personal data to:
create, authenticate, secure, and administer Accounts, workspaces, users, permissions, plans, and settings;
provide Builder, Console, Sessions, AI Features, hosting, publishing, domains, databases, storage, messaging, calls, APIs, widgets, SDKs, and integrations;
generate, edit, preview, deploy, host, deliver, and troubleshoot apps and digital assets;
process conversations, contacts, support requests, sessions, replay, analytics, co-browsing, live assist, routing, automation, and handoffs;
process payments, credits, usage, invoices, taxes, renewals, refunds, disputes, and account administration;
generate Output, summaries, classifications, recommendations, code, media, replies, and approved app or workflow changes;
verify permissions and confirmations for tool use, browser actions, communications, or transactions;
monitor performance, debug errors, manage capacity, maintain continuity, and improve usability, reliability, safety, and features;
detect, investigate, and prevent fraud, spam, malware, attacks, policy violations, unauthorized access, and other abuse;
provide support, respond to requests, communicate product, billing, security, legal, or service information, and send marketing where permitted;
comply with law, enforce agreements, establish or defend claims, respond to valid requests, and protect rights, safety, and property; and
conduct corporate transactions and internal business operations.
We may use aggregated or de-identified information for analytics, benchmarking, research, security, and product improvement. We do not attempt to re-identify data treated as de-identified except to test whether de-identification is effective or as law permits.
5. Legal bases for processing
Where EEA, UK, Swiss, or similar law requires a legal basis, OXVO relies on:
Contract: to create and administer an Account, provide requested Service features, process transactions, and perform our agreement with you.
Legitimate interests: to operate, secure, support, analyze, market, and improve the Service; communicate with business contacts; prevent fraud and abuse; and protect legal rights, after considering the effects on individuals.
Consent: for activities that require consent, such as certain cookies, marketing, recordings, or optional features. Consent may be withdrawn prospectively.
Legal obligation: to comply with tax, accounting, sanctions, law-enforcement, regulatory, and other legal requirements.
Legal claims and vital interests: where necessary to establish, exercise, or defend claims or protect a person's vital interests.
When OXVO acts as a processor, the customer is responsible for identifying its legal basis, providing notices, obtaining consent, and issuing lawful instructions.
6. Controller and processor roles
6.1 OXVO as controller
OXVO is generally controller for data about visitors to OXVO's own sites, prospects, account users, administrators, billing contacts, and people who contact OXVO directly. We may also act as controller for limited security, fraud-prevention, compliance, metering, and service-administration data generated while providing the Service.
6.2 OXVO as processor or service provider
For Customer Content submitted by or collected for a customer, OXVO generally processes data only to provide, secure, support, and maintain the Service under the customer's instructions and our contract. Our Data Processing Terms or a signed DPA govern this processing. We do not sell Customer Content or use it for cross-context behavioral advertising.
6.3 Customer responsibilities
Customers decide which data to collect, which features to enable, who may access data, how long to retain it, and what instructions to give OXVO. Customers are responsible for privacy notices, legal bases, cookie and recording consent, data minimization, sensitive-field exclusion, access controls, retention, and responses to End User rights requests.
7. AI and automated features
7.1 AI providers and data use
OXVO may use OXVO systems and Third-Party Services to process AI Inputs and produce Outputs. We share the data reasonably necessary to provide the selected feature and apply contractual, technical, and configuration safeguards appropriate to the processing. Providers may process limited data for delivery, security, and abuse prevention under their applicable enterprise or API terms.
Unless a customer expressly opts in or an agreement states otherwise, OXVO does not use Customer Content to train generalized OXVO or third-party foundation models. We may use Usage Data and aggregated or de-identified information to evaluate and improve product quality, reliability, and safety.
7.2 Transparency and human review
AI interactions, synthetic content, and automated actions may require disclosure, labeling, consent, or human oversight. Customers are responsible for configuring those measures for their End Users and use cases. AI Output may contain errors or personal data and should be reviewed before it is sent, published, or used for consequential decisions.
7.3 Automated decision-making
OXVO does not use personal data it controls to make solely automated decisions that produce legal or similarly significant effects on an individual unless we separately disclose the processing and provide safeguards required by law. Customers may configure AI Features to support their own decisions or actions. In that case, the customer is responsible for its legal basis, notices, human review, and rights process; questions should be directed to that customer.
8. Session replay, co-browsing, live assist, and voice
These are customer-configured features. A customer may determine pages and fields captured, masking and exclusion settings, network capture, retention, access, consent flows, and whether co-browsing, visual context, microphone, call recording, transcripts, or browser actions are enabled.
Certain input types may be masked by default, but settings, custom components, page content, network payloads, and implementation choices can affect capture. Customers must test configurations and avoid collecting passwords, payment-card data, authentication secrets, health data, government identifiers, and other unnecessary sensitive data.
Co-browsing or live assist may allow an authorized human or AI to see page context, guide a cursor, suggest steps, or perform a customer-authorized action. Permission and confirmation records may be logged. Customers must provide required notices and obtain consent under privacy, cookie, wiretap, eavesdropping, call-recording, employment, and consumer laws. End Users should contact the relevant customer to stop or ask about a recording or assistance session.
9. How we disclose personal data
We may disclose personal data to:
Service providers and subprocessors supporting cloud infrastructure, hosting, content delivery, databases, storage, AI models, communications, telephony, email, authentication, customer support, payments, analytics, observability, security, fraud prevention, and professional services;
Customers and authorized users according to Account roles, sharing settings, workflows, support relationships, and customer instructions;
Customer-enabled integrations and Third-Party Services when a customer connects or directs data to them;
End Users and the public when a customer publishes content, creates a public Hosted App, sends a communication, or configures information to be shared;
Affiliates and corporate participants for internal operations or in a merger, financing, acquisition, reorganization, bankruptcy, or asset transfer, subject to appropriate protections;
Authorities, courts, rights holders, and other parties when reasonably necessary to comply with law, respond to valid process, enforce agreements, investigate abuse, protect safety or rights, or establish and defend claims; and
Other recipients with direction or consent, or in aggregated or de-identified form that does not reasonably identify an individual.
A current subprocessor list or additional information about provider categories may be made available through our Trust Center, contract materials, or on request. Providers may change as the Service evolves.
10. Sale, sharing, targeted advertising, and financial incentives
OXVO does not sell Customer Content or personal data for money and does not use Customer Content for cross-context behavioral advertising. Our public websites may use analytics, marketing, or advertising-measurement technologies. Where such activity is legally treated as a sale, sharing, or targeted advertising, we provide a legally required opt-out and honor valid universal opt-out signals such as Global Privacy Control for the relevant browser or device.
We do not knowingly sell or share personal data of individuals under 16. We do not use sensitive personal information to infer characteristics except as needed to provide a requested Service, maintain security, or as otherwise permitted by law. We do not offer a financial incentive for personal data unless separate terms and a notice describe its material terms.
For California residents, Sections 2, 3, 4, 9, 10, and 13 provide our notice at collection, including categories, sources, purposes, recipients, and retention criteria for data collected during the preceding 12 months.
11. Cookies and similar technologies
We and our providers use cookies, local storage, pixels, SDKs, and similar technologies to authenticate users; maintain sessions; remember preferences; secure and operate the Service; analyze performance and use; troubleshoot; and, where permitted, measure or personalize marketing.
Cookies may be strictly necessary, functional, analytics, or marketing. You can use browser controls and, where available, our cookie preference controls. Blocking cookies may impair functionality. Customers are responsible for consent and cookie controls on their Customer Properties and Hosted Apps.
Some browsers send "Do Not Track" signals, for which there is no uniform industry standard. We respond to legally recognized universal opt-out mechanisms, including Global Privacy Control, where required for applicable activities.
12. International data transfers
OXVO and its providers may process personal data in countries other than the country where it was collected. Those countries may have different data-protection laws. Where required, we use a recognized transfer safeguard, such as an adequacy decision, standard contractual clauses, the UK Addendum, or another lawful mechanism, and apply supplementary measures where appropriate.
Customers authorize transfers needed to provide the Service under the applicable contract. Contact privacy@oxvo.com for information about relevant safeguards where you have a legal right to request it.
13. Data retention
We retain personal data only as long as reasonably necessary for the purposes described in this Policy, including to provide the Service, follow customer instructions, maintain security and continuity, comply with law, resolve disputes, and enforce agreements.
Retention depends on the data, feature, plan, settings, Account status, contractual commitments, legal limitation periods, and operational need. Account and billing records may be retained through the relationship and applicable legal period. Customer Content is generally retained under customer configuration and contract. Replay, logs, recordings, transcripts, AI history, runtime artifacts, backups, databases, and Hosted App data may have different or configurable periods.
Deletion from active systems may not immediately remove copies from backups, security archives, legal holds, or provider systems. We may retain de-identified data without a fixed period. When OXVO acts as processor, the customer controls deletion subject to our contract and lawful retention.
14. Security
We use commercially reasonable technical and organizational measures designed to protect personal data, which may include access controls, encryption in transit and at rest where appropriate, logging, monitoring, network safeguards, secure development practices, backups, incident procedures, and vendor diligence. Measures vary by feature, sensitivity, and risk.
No transmission or storage system is completely secure, and we cannot guarantee absolute security. Customers are responsible for Account credentials, administrators, permissions, code, domains, DNS, integrations, secrets, databases, app logic, End User authentication, privacy settings, and data they choose to collect. Contact info@oxvo.com promptly if you suspect an Account or data-security issue.
15. Privacy rights and choices
Depending on location and subject to exceptions, you may have rights to access, know, correct, delete, restrict, object, withdraw consent, or receive a portable copy of personal data. You may also have rights concerning automated decisions, sensitive data, sale or sharing, targeted advertising, profiling, and appeals.
To exercise rights for data OXVO controls, email privacy@oxvo.com and describe the request. We may verify identity and authority, request information needed to locate data, and retain a record of the request. Authorized agents may act where permitted, subject to proof of authority and verification. We will not discriminate for exercising a privacy right.
15.1 EEA, UK, Switzerland, UAE, and similar jurisdictions
You may have rights to access, rectify, erase, restrict processing, object to processing based on legitimate interests or direct marketing, receive portable data, withdraw consent, and complain to a competent data-protection authority. Withdrawal does not affect prior lawful processing. You may also request information about international-transfer safeguards.
15.2 United States
Residents of California and certain other states may have rights to know or access categories and specific pieces of personal data, correct inaccuracies, delete data, obtain portability, opt out of sale, sharing, targeted advertising, or certain profiling, limit certain uses of sensitive personal information, and appeal a denied request. We honor valid Global Privacy Control signals where required. To appeal, reply to our decision or email privacy@oxvo.com with "Privacy Appeal" in the subject.
15.3 Data controlled by an OXVO customer
If OXVO processes your data for a customer, submit the request to that customer. We may refer you to the customer and will assist it as required by contract and law. We cannot independently change or delete customer-controlled data without authorization unless law requires it.
15.4 Account, communications, and cookie choices
You may update certain Account information and settings in the Service. Marketing emails include an unsubscribe method; operational, security, billing, and legal messages may still be sent. Cookie and universal opt-out choices are described in Sections 10 and 11.
16. Children's privacy
OXVO Accounts and OXVO's own sites are not directed to people under 18. We do not knowingly collect personal data as controller from children under 13, or a higher protected age where applicable, without legally valid authorization.
Customers may not use the Service for a child-directed property or knowingly process children's data unless OXVO expressly permits the use in writing and the customer complies with parental-consent, notice, minimization, security, and other legal requirements. If you believe a child provided personal data directly to OXVO, contact privacy@oxvo.com.
17. Third-party services, customer properties, and public content
Third-Party Services, customer websites and apps, and external links have their own terms and privacy practices. OXVO is not responsible for those independent practices. Review their notices before providing data or enabling an integration.
A customer controls the content and data practices of its Customer Properties and Hosted Apps. Information intentionally published or sent to public channels may be viewed, indexed, cached, copied, or redistributed by others. Do not publish information you do not want made public.
18. Changes to this Privacy Policy
We may update this Policy to reflect changes in the Service, law, providers, or processing. We will post the updated version with a new date and provide additional notice of material changes where required. We will not apply a materially different use to previously collected personal data without a valid legal basis and any required notice or consent.
19. Contact
For privacy questions, requests, or complaints, contact:
Privacy: privacy@oxvo.com
Legal: legal@oxvo.com
General support: info@oxvo.com
The relevant OXVO controller is the entity identified on your Order Form, checkout, invoice, or account billing page; for visitors without an Account, it is the operator of oxvo.com. You may also lodge a complaint with your local data-protection authority where applicable.