Privacy Policy

Last updated: 12 September 2026

This Privacy Policy explains how Canvena Ltd (“Plaithy”, “we”, “us”) collects, uses and safeguards your personal data when you visit our website or use the Plaithy platform. Plaithy is hosted in the European Union and complies with Regulation (EU) 2016/679 (the “GDPR”).

1. Controller

The controller responsible for the processing of your personal data is:

Canvena Ltd
Lieutenant Georgios M. Savvas 26, Shop 1-2, 8201 Geroskipou, Paphos, Cyprus
Email: hello@plaith.ai

For data we receive through our Meta app “Plaithy” (app ID 1474811601118762) — in particular data from the Meta ad accounts, Facebook Pages and pixels that clients share with us (section 11) — Canvena Ltd and its parent company Canvena Consulting LLC, 3119 Coral Way, Miami, FL 33145, USA, are joint controllers under Art. 26 GDPR. Canvena Consulting LLC operates the Meta app and the Meta business portfolio (business ID 1222653552033942) to which clients grant partner access; Canvena Ltd provides the Plaithy service and is your point of contact for all data protection requests. You can exercise your rights against either company. On request we provide the essence of our arrangement.

2. Categories of Personal Data

  • Account data: name, email, password hash, role.
  • Authentication data: session tokens, MFA secrets, IP address.
  • Usage telemetry: requests issued to the platform, cost metrics, model latency, audit events.
  • Content data: prompts, files and any other data you submit to the platform.
  • Billing data: subscription tier, invoices, payment status.
  • Contact and conversation data: details from the contact form and transcripts of conversations with the chat and voice assistant on our start page (sections 13 and 14).

3. Purposes & Legal Bases (Art. 6 GDPR)

  • Providing the service and fulfilling our contract with you — Art. 6(1)(b) GDPR.
  • Securing the platform, fraud detection and audit logging — Art. 6(1)(f) GDPR (legitimate interest).
  • Sending operational emails and trial reminders — Art. 6(1)(b)/(f) GDPR.
  • Optional analytics & marketing cookies — Art. 6(1)(a) GDPR (your consent, see Cookie Policy).
  • Chat and voice assistant on the start page and the Meta pixel — Art. 6(1)(a) GDPR (your consent, sections 13 and 17).
  • Handling contact requests and payment processing — Art. 6(1)(b) GDPR (sections 14 and 15).
  • Sending conversion events to a client’s Meta pixel through the Conversions API — on the client’s instructions as their processor, Art. 28 GDPR (section 11).
  • Tax and accounting retention — Art. 6(1)(c) GDPR.

4. Recipients

Our servers are located in the EU (Hetzner Online GmbH, Germany). We use sub-processors for hosting, databases, payment processing, email, web search, the creation of ad creatives and AI model inference. Some of them are located outside the EEA, in the United States and — for AI model inference — in the People’s Republic of China. Questions about our sub-processors: hello@plaith.ai. For each sub-processor, its location and the basis for transfers to third countries are stated on the sub-processor page.

The complete, up-to-date list — including upcoming changes and the 30-day notice window — is published on our Sub-processor page.

5. Third-Country Transfers

We store personal data in the European Union (Hetzner Online GmbH, Germany). When our AI team works on a task, the data the task needs can be transferred to AI model providers outside the EEA: in the United States on the basis of the EU-US Data Privacy Framework where the provider is certified, otherwise on the basis of the Standard Contractual Clauses under the provider’s data processing terms; in the People’s Republic of China (DeepSeek), for which there is no adequacy decision, under the provider’s own terms. Our sub-processor page lists each provider, its location and the transfer basis.

6. Retention

  • Account data: for the lifetime of the account + 30 days.
  • Audit logs: 12 months, then automatically pruned.
  • Billing data: 10 years (statutory tax retention).
  • Cookie consent records: 24 months for the audit trail.
  • Backups: overwritten within 14 days.
  • Aggregated statistics that can no longer be linked to a person, a business or an ad account: not deleted, because they are no longer personal data.

7. Your Rights

You have the following rights under Articles 15–22 GDPR:

  • Right of access (Art. 15).
  • Right to rectification (Art. 16).
  • Right to erasure / right to be forgotten (Art. 17).
  • Right to restriction of processing (Art. 18).
  • Right to data portability (Art. 20).
  • Right to object (Art. 21).
  • Right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal (Art. 7(3)).

To exercise any of these rights, contact us at hello@plaith.ai. You can also export your data and request deletion directly from the in-app GDPR control center.

8. Cookies

We use a small set of strictly necessary cookies for login, security and session continuity. Optional analytics and marketing cookies are only set after your explicit consent via the cookie banner. Full details are in our Cookie Policy.

9. Right to Lodge a Complaint

If you believe our processing of your personal data infringes the GDPR you may lodge a complaint with the supervisory authority of your habitual residence, place of work or the place of the alleged infringement. Our lead supervisory authority is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus.

10. Changes to this Policy

We may update this Privacy Policy from time to time. The version in force is the one published on this page. For substantive changes we notify registered users via email at least 30 days before the new version takes effect.

11. Data from Meta Ad Accounts

When you hire us to manage your advertising on Facebook and Instagram and give us partner access to your Meta ad account for that purpose, we process data from that account. You do not use Plaithy yourself; only our team works in it, and you receive your results from us as reports. This section explains which data that is, what we use it for and who receives it. Sections 1 to 10 apply in all other respects.

Which data we process

In connection with your Meta ad account we store:

  • The IDs of your ad account, your pixel and your Facebook page, and the name and profile picture of the Facebook Pages you shared with us.
  • Campaigns, ad sets and ads we created or changed, with their settings (e.g. budget, schedule, countries, audience traits, placements, destination URL, who the ad runs for and who pays for it) and Meta's notices about them, such as rejection reasons.
  • Ad creatives: headlines and ad texts, the images and videos we created or uploaded, and preview images from Meta.
  • Performance figures per campaign, ad set, ad and day: spend, impressions, reach, clicks, frequency, leads, purchases and purchase value, conversions and video views.
  • Audiences we created in your ad account: ID, name and size — no member lists.
  • Conversion events we reported to Meta (e.g. lead, purchase, appointment): type, event ID, campaign, ad and day, plus the consent information sent along, as a daily count. We do not store names, email addresses, phone numbers or IP addresses; only for events from your CRM we keep a hash of the email address or phone number so the same event is not reported twice.
  • The roles in your ad account from our account check; people appear there only as a hash of their Meta user ID, without names.
  • Competitors we monitor for you, with details from Meta's public Ad Library (advertiser, page, ad, run time).
  • Reports, analyses and campaign plans our AI team creates from this data, and lessons from successful ads (texts and figures).
  • Access tokens for the Meta API.

What we use this data for

We use this data only to provide the advertising management you hired us for:

  • Creating and managing campaigns, ad sets and ads in your ad account.
  • Creating and checking creatives (images, videos and texts) and uploading them to your ad account.
  • Reading results from your ad account to report to you and to improve your own campaigns.
  • Sending conversion events from your website and your CRM to your own pixel at Meta.
  • Checking your ad account regularly — including who has which access to it.
  • Reading the name, ID and profile picture of the Facebook Pages you share with us and of the Pages in our business portfolio, so that the right Page is chosen as the advertiser of your ads.
  • Monitoring your competitors' ads in Meta's public Ad Library to plan your campaigns.

We use this data only for you — never for another client.

Legal basis

The legal basis is the performance of our contract with you (Art. 6(1)(b) GDPR), as described in section 3. We and our parent company Canvena Consulting LLC process this data as joint controllers (section 1). When we send conversion events about your website visitors or CRM contacts to your pixel through Meta’s Conversions API, we do so on your instructions as your processor (Art. 28 GDPR); you are responsible for informing these people and, where required, obtaining their consent.

Recipients

This data is received by:

  • Meta, where we send campaigns, ads, creatives and conversion events to your ad account and your pixel. Conversion events can contain the email address, phone number and name of a website visitor or CRM contact (sent only as a hash), their IP address, browser user agent and Meta click and browser IDs (fbc, fbp).
  • Our hosting provider, where we store this data.
  • AI model providers: when our AI team analyses results, writes reports and ad texts or checks creatives, the data the task needs — such as performance figures, campaign settings, ad texts and images, and details from the Ad Library — goes to the provider of the model in use.
  • Providers we use to create ad images, videos and voice-overs: they receive the instructions, texts and source images the creative is made from.
  • Our email provider (Resend, USA), which delivers the reports and alerts we send you; they contain campaign names and figures.
  • Our web search provider (Tavily, USA), which receives the search queries of our AI team; they can contain wording from your campaigns and offer.

Which providers these are, where they are based and on what basis data goes to third countries is listed on our Sub-processor page; section 5 applies to third-country transfers.

Retention

We keep this data for as long as we manage your advertising. After you end our access or our contract ends, we delete the data listed on our Data Deletion Instructions page within 90 days. On your request we delete it earlier, without undue delay and at the latest within one month. Backups are overwritten within 14 days; billing data is kept under section 6. Aggregated statistics that can no longer be linked to you or your ad account are not deleted (section 6).

Ending our access and requesting deletion

How to end our access to your ad account yourself at any time, and how to request deletion of this data, is explained in our Data Deletion Instructions. Once our access has ended, the 90-day deletion described under “Retention” applies.

Meta's own terms

Data that already sits in your Meta ad account is subject to Meta's own terms. Your campaigns and ads stay there until you delete them at Meta; conversion events we have already reported to Meta are held by Meta.

12. Contact

General inquiries: hello@plaith.ai
Privacy / DSGVO inquiries: hello@plaith.ai

13. Chat and Voice Assistant on the Start Page

On our start page you can chat or talk to an AI assistant. It is only loaded once you open it and agree to its use; before that, no data is sent to the provider.

Provider: we use Google Gemini (Google Ireland Ltd., Dublin, Ireland, and Google LLC, USA) to generate the answers. The voice function streams your microphone audio in real time to Google Gemini Live (USA) only after you click “Agree and start”; without that click no audio is transmitted. In the event of an outage a fallback provider (OpenAI, USA) may generate the answer.

Legal basis: your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time with effect for the future by ending the conversation or changing your choice in the cookie settings. The transfer to the United States takes place under Art. 46 GDPR on the basis of the Standard Contractual Clauses or the EU-US Data Privacy Framework, under which Google LLC is certified.

Storage: we store the transcript (questions, answers, page visited, language, time) for handling and quality assurance on our own infrastructure in the EU (Hetzner Online GmbH, Germany) and delete it 90 days after the conversation ends. We do not store IP addresses in the transcript; as with every page view, they appear in the logs of our web server (section 3, securing the platform).

Contact details from the conversation: contact details you mention in the conversation are detected automatically and stored together with the transcript. We pass your contact details to our lead system (section 14) only if you explicitly enter them in our contact form and submit it; the assistant directs you there. The form then also transmits the ID of your conversation so that we can read your request in context.

Please do not share special categories of personal data (for example health data) in the conversation. If the assistant offers you an appointment link, it opens Cal.com (USA) in a new tab under Cal.com's own privacy policy; nothing is loaded from Cal.com on our page.

14. Contact Form and Lead Management

When you submit our contact form, Canvena Ltd processes your details in order to answer your request and to make you an offer.

The details from the form (subject, name, email address, company or website, your offer, message, language, page visited, time, the assistant's conversation ID where applicable, and campaign parameters from the address bar) are stored in our lead system on servers of Hetzner Online GmbH in Germany (EU). We notify ourselves of new requests internally by email through our email provider Resend (USA; see the sub-processor page).

Legal basis: steps prior to entering into a contract and performance of the contract (Art. 6(1)(b) GDPR) and the consent to being contacted that you give in the form (Art. 6(1)(a) GDPR). The consent box is never pre-ticked.

Retention: we keep your request for as long as we are handling it and can make you an offer. You can request deletion and withdraw your consent with effect for the future at any time by emailing hello@plaith.ai. If a contract is concluded, the periods in section 6 apply.

15. Payment Processing (Stripe)

The setup fee and the Performance Team packages are paid through Stripe Payments Europe, Ltd. (Dublin, Ireland). You enter card or bank details directly on Stripe's payment page; we do not receive them. From Stripe we receive only the confirmation of payment, the amount and the details needed for the invoice (name, company, billing address, email address). Stripe's own privacy policy additionally applies to the processing of your payment data; Stripe safeguards transfers to Stripe, Inc. (USA) with Standard Contractual Clauses.

Legal basis: performance of the contract (Art. 6(1)(b) GDPR). Billing data is retained as set out in section 6.

Your choice in the cookie banner is stored in your browser's storage under the key plaithy_consent (with a mirror copy plaithy_cookie_consent for the application) for 12 months (first-party, not transmitted to third parties). In addition we record your decision with its time and an anonymous session identifier so that we can demonstrate consent (Art. 7(1) GDPR; audit logging under Art. 6(1)(f) GDPR); we keep these records for 24 months (section 6).

You can change or withdraw your choice at any time via the Cookie Settings link on our start page and in the footer of every other page.

17. Meta Pixel (only with consent)

We plan to use the Meta pixel (Meta Platforms Ireland Ltd., Dublin, Ireland) on our start page to measure the effectiveness of our own ads. It is loaded only if you agree to the “Marketing” category in the cookie banner (Art. 6(1)(a) GDPR); without your consent no Meta script is loaded and no cookie is set. Meta may transfer data to the United States; Meta Platforms, Inc. states that it is certified under the EU-US Data Privacy Framework.

The Meta pixel is currently not in use. Once it is active, we will add the cookies it sets and their lifetimes to the Cookie Policy.