Vivollo
Demo

Legal

Privacy Policy

How Vivollo collects, uses, shares and protects personal data — and the rights you have over it.

Last updated: September 4, 2026Effective: June 27, 2026

This Privacy Policy explains how Kabi Partners Bilişim Teknolojileri A.Ş. ("Vivollo", "we", "us") handles personal data when you visit our website, create an account, or use the Vivollo platform. It applies to website visitors, customers (the businesses that use Vivollo), and the end-customers who talk to a Vivollo agent.

1. Who we are

The data controller is Kabi Partners Bilişim Teknolojileri A.Ş., registered at Çınarlı Mahallesi, 1572. Sokak, No

Konak/İzmir. You can reach us about privacy at privacy@vivollo.com. For processing governed by Turkish law (KVKK), see also our KVKK disclosure.

2. Data we collect

  • Account data — name, work email, company, role, and billing details you provide when you sign up.
  • Usage data — how you use the panel: pages, actions, device and browser information, IP address and approximate location.
  • Content you provide — your knowledge base, product data, files and settings used to configure your agent.
  • Conversation data — messages exchanged between your end-customers and your agent across connected channels, and metadata such as timestamps and channel.
  • Cookies and similar technologies — see Cookies below.

For end-customer conversations, you (our customer) are the controller and Vivollo is your processor. We handle that data on your behalf, under your instructions.

3. How we use data

We use personal data to:

  • provide, operate and maintain the platform and its channels;
  • set up, train and improve your agent using your content;
  • respond to support requests and communicate service notices;
  • monitor, secure and troubleshoot the service and prevent abuse;
  • handle billing and manage your subscription;
  • comply with legal obligations and enforce our Terms.

We do not sell personal data, and we do not use one customer's conversation data to build features for another customer.

Where Turkish law (KVKK) or the GDPR applies, we rely on: performance of a contract with you; our legitimate interests in running and securing the service; your consent (for example, certain cookies and marketing); and compliance with legal obligations.

5. Sharing and sub-processors

We share personal data only with service providers that help us run Vivollo, under contracts that require them to protect it: Amazon Web Services (AWS) (hosting), OpenAI, Google Gemini and Cohere (AI models), Weaviate (vector database), Stripe (payment), Google Analytics and Amazon SES (analytics and email), and the messaging channels you connect (such as WhatsApp and Instagram). A current list of sub-processors is available on request at privacy@vivollo.com. We may also disclose data where required by law.

6. International transfers

Some providers may process data outside Türkiye. Where they do, we use safeguards permitted by KVKK and the GDPR (such as adequacy decisions or standard contractual clauses). Details are available on request.

7. Cookies

We use strictly necessary cookies to run the site and the panel, and — with your consent — analytics cookies to understand usage. You can control non-essential cookies through your browser and our cookie banner.

8. Retention

We keep personal data only as long as needed for the purposes above or as required by law. Account and billing records are kept for the duration of your subscription and any statutory period after it. Conversation data is retained per your account settings and instructions, after which it is deleted or anonymised.

9. Security

We protect personal data with encryption, access controls and tenant isolation. See our Security overview for details.

10. Your rights

Subject to applicable law, you can ask to access, correct, delete or restrict your personal data, object to certain processing, withdraw consent, and receive a copy of data you provided. Turkish users have the rights in Article 11 of the KVKK — see the KVKK disclosure. To exercise any right, contact privacy@vivollo.com; we respond within the period set by applicable law.

11. Children

Vivollo is a business tool and is not directed to children. We do not knowingly collect data from children.

12. Changes

We may update this policy as the service or the law evolves. We'll post the new version here and update the "Last updated" date; material changes will be notified through the service.

13. Google User Data

This section applies when you connect a Google account to Vivollo. It describes the Google data path specifically; the rest of this policy still applies.

  • What we access. Vivollo requests the drive.file permission. It gives us access to the content of the individual Google Sheets, Drive and Docs files you select in Google's own file picker — and to nothing else in your Drive. We also receive the email address of the Google account you connect, so we can show you which account is linked.
  • Why we access it. Only to provide the user-facing features described on our Google Workspace integration page: reading live data from a Sheet you selected, writing rows back to it, and adding the files you selected to your agent's knowledge base. Access is triggered at the moment your agent needs it to answer one of your customers — there is no background crawl of your account.
  • How we store it. Access and refresh tokens are encrypted at rest and stored in the European Union (AWS, Frankfurt). Sheet content is held only in a short-lived cache of about 60 seconds. Files you add to the knowledge base are indexed and stored in the same region until you remove them or disconnect.
  • Who we share it with. To generate a reply, the relevant content is sent to the AI providers listed in section 5 — OpenAI, Google Gemini and Cohere — under their paid API terms. Under those terms this content is not used to train their models. Vivollo staff do not read your Google data, except where security incident response, a legal obligation, or your own explicit support request requires it. We share it with no one else.
  • Retention and deletion. You can disconnect at any time from the Vivollo panel, and you can revoke our access independently under Third-party apps & services in your Google Account. On disconnection we revoke the tokens and delete them, together with any indexed file content, within 30 days. The short-lived cache expires on its own.
  • What we never do. We do not sell Google user data, do not transfer it for advertising or ad personalisation, and do not use it to assess credit-worthiness or for lending purposes.

Vivollo's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

14. Contact

Questions about this policy or your data: privacy@vivollo.com.