Privacy Policy

Last updated: 12 September 2026

This Privacy Policy explains how Canvena Ltd (“Plaithy”, “we”, “us”) collects, uses and safeguards your personal data when you visit our website or use the Plaithy platform. Plaithy is hosted in the European Union and complies with Regulation (EU) 2016/679 (the “GDPR”).

1. Controller

The controller responsible for the processing of your personal data is:

Canvena Ltd
Lieutenant Georgios M. Savvas 26, Shop 1-2, 8201 Geroskipou, Paphos, Cyprus
Email: hello@plaith.ai

2. Categories of Personal Data

  • Account data: name, email, password hash, role.
  • Authentication data: session tokens, MFA secrets, IP address.
  • Usage telemetry: requests issued to the platform, cost metrics, model latency, audit events.
  • Content data: prompts, files and any other data you submit to the platform.
  • Billing data: subscription tier, invoices, payment status.
  • Contact and conversation data: details from the contact form and transcripts of conversations with the chat and voice assistant on our start page (sections 13 and 14).

3. Purposes & Legal Bases (Art. 6 GDPR)

  • Providing the service and fulfilling our contract with you — Art. 6(1)(b) GDPR.
  • Securing the platform, fraud detection and audit logging — Art. 6(1)(f) GDPR (legitimate interest).
  • Sending operational emails and trial reminders — Art. 6(1)(b)/(f) GDPR.
  • Optional analytics & marketing cookies — Art. 6(1)(a) GDPR (your consent, see Cookie Policy).
  • Chat and voice assistant on the start page and the Meta pixel — Art. 6(1)(a) GDPR (your consent, sections 13 and 17).
  • Handling contact requests and payment processing — Art. 6(1)(b) GDPR (sections 14 and 15).
  • Tax and accounting retention — Art. 6(1)(c) GDPR.

4. Recipients

Our servers are located in the EU (Hetzner Online GmbH, Germany). We rely on a curated set of EU-hosted sub-processors (hosting, managed databases, payment processing, transactional email). The current list is available on request from hello@plaith.ai. Sub-processors outside the EEA are bound by the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914).

The complete, up-to-date list — including upcoming changes and the 30-day notice window — is published on our Sub-processor page.

5. Third-Country Transfers

Personal data is stored and processed inside the European Union. Where third-country transfers are unavoidable (for example, model inference with a sub-processor located outside the EEA) we apply the Standard Contractual Clauses and perform a Transfer Impact Assessment.

6. Retention

  • Account data: for the lifetime of the account + 30 days.
  • Audit logs: 12 months, then automatically pruned.
  • Billing data: 10 years (statutory tax retention).
  • Cookie consent records: 24 months for the audit trail.

7. Your Rights

You have the following rights under Articles 15–22 GDPR:

  • Right of access (Art. 15).
  • Right to rectification (Art. 16).
  • Right to erasure / right to be forgotten (Art. 17).
  • Right to restriction of processing (Art. 18).
  • Right to data portability (Art. 20).
  • Right to object (Art. 21).
  • Right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal (Art. 7(3)).

To exercise any of these rights, contact us at hello@plaith.ai. You can also export your data and request deletion directly from the in-app GDPR control center.

8. Cookies

We use a small set of strictly necessary cookies for login, security and session continuity. Optional analytics and marketing cookies are only set after your explicit consent via the cookie banner. Full details are in our Cookie Policy.

9. Right to Lodge a Complaint

If you believe our processing of your personal data infringes the GDPR you may lodge a complaint with the supervisory authority of your habitual residence, place of work or the place of the alleged infringement. Our lead supervisory authority is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus.

10. Changes to this Policy

We may update this Privacy Policy from time to time. The version in force is the one published on this page. For substantive changes we notify registered users via email at least 30 days before the new version takes effect.

11. Data from Meta Ad Accounts

When you hire us to manage your advertising on Facebook and Instagram and connect a Meta ad account to Plaithy for that purpose, we process data from that account. This section explains which data that is, what we use it for and who receives it. Sections 1 to 10 apply in all other respects.

Which data we process

In connection with your Meta ad account we store:

  • The IDs of your ad account, your pixel and your Facebook page.
  • Campaigns, ad sets and ads we created or changed, with their settings (e.g. budget, schedule, countries, audience traits, placements, destination URL, who the ad runs for and who pays for it) and Meta's notices about them, such as rejection reasons.
  • Ad creatives: headlines and ad texts, the images and videos we created or uploaded, and preview images from Meta.
  • Performance figures per campaign, ad set, ad and day: spend, impressions, reach, clicks, frequency, leads, purchases and purchase value, conversions and video views.
  • Audiences we created in your ad account: ID, name and size — no member lists.
  • Conversion events we reported to Meta (e.g. lead, purchase, appointment): type, event ID, campaign, ad and day, plus the consent information sent along, as a daily count. We do not store names, email addresses, phone numbers or IP addresses; only for events from your CRM we keep a hash of the email address or phone number so the same event is not reported twice.
  • The roles in your ad account from our account check; people appear there only as a hash of their Meta user ID, without names.
  • Competitors we monitor for you, with details from Meta's public Ad Library (advertiser, page, ad, run time).
  • Reports, analyses and campaign plans our AI team creates from this data, and lessons from successful ads (texts and figures).
  • Access tokens for the Meta API.

What we use this data for

We use this data only to provide the advertising management you hired us for:

  • Creating and managing campaigns, ad sets and ads in your ad account.
  • Creating and checking creatives (images, videos and texts) and uploading them to your ad account.
  • Reading results from your ad account to report to you and to improve your own campaigns.
  • Sending conversion events from your website and your CRM to your own pixel at Meta.
  • Checking your ad account regularly — including who has which access to it.
  • Monitoring your competitors' ads in Meta's public Ad Library to plan your campaigns.

We use this data only for you — never for another client.

Legal basis

The legal basis is the performance of our contract with you (Art. 6(1)(b) GDPR), as described in section 3.

Recipients

This data is received by:

  • Meta, where we send campaigns, ads, creatives and conversion events to your ad account and your pixel.
  • Our hosting provider, where we store this data.
  • AI model providers: when our AI team analyses results, writes reports and ad texts or checks creatives, the data the task needs — such as performance figures, campaign settings, ad texts and images, and details from the Ad Library — goes to the provider of the model in use.
  • Providers we use to create ad images, videos and voice-overs: they receive the instructions, texts and source images the creative is made from.

Which providers these are, where they are based and on what basis data goes to third countries is listed on our Sub-processor page; section 5 applies to third-country transfers.

Retention

There is currently no fixed retention period for this data, and we do not delete it automatically — not even when you end our access. We delete it on your request, except for what we have to keep under section 6.

Ending our access and requesting deletion

How to end our access to your ad account yourself at any time, and how to request deletion of this data, is explained in our Data Deletion Instructions. Ending our access alone does not delete data we have already stored.

Meta's own terms

Data that already sits in your Meta ad account is subject to Meta's own terms. Your campaigns and ads stay there until you delete them at Meta; conversion events we have already reported to Meta are held by Meta.

12. Contact

General inquiries: hello@plaith.ai
Privacy / DSGVO inquiries: hello@plaith.ai

13. Chat and Voice Assistant on the Start Page

On our start page you can chat or talk to an AI assistant. It is only loaded once you open it and agree to its use; before that, no data is sent to the provider.

Provider: we use Google Gemini (Google Ireland Ltd., Dublin, Ireland, and Google LLC, USA) to generate the answers. The voice function streams your microphone audio in real time to Google Gemini Live (USA) only after you click “Agree and start”; without that click no audio is transmitted. In the event of an outage a fallback provider (OpenAI, USA) may generate the answer.

Legal basis: your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time with effect for the future by ending the conversation or changing your choice in the cookie settings. The transfer to the United States takes place under Art. 46 GDPR on the basis of the Standard Contractual Clauses or the EU-US Data Privacy Framework, under which Google LLC is certified.

Storage: we store the transcript (questions, answers, page visited, language, time) for handling and quality assurance on our own infrastructure in the EU (Hetzner Online GmbH, Germany) and delete it 90 days after the conversation ends. We do not store IP addresses in the transcript; as with every page view, they appear in the logs of our web server (section 3, securing the platform).

Contact details from the conversation: contact details you mention in the conversation are detected automatically and stored together with the transcript. We pass your contact details to our lead system (section 14) only if you explicitly enter them in our contact form and submit it; the assistant directs you there. The form then also transmits the ID of your conversation so that we can read your request in context.

Please do not share special categories of personal data (for example health data) in the conversation. If the assistant offers you an appointment link, it opens Cal.com (USA) in a new tab under Cal.com's own privacy policy; nothing is loaded from Cal.com on our page.

14. Contact Form and Lead Management

When you submit our contact form, Canvena Ltd processes your details in order to answer your request and to make you an offer.

The details from the form (subject, name, email address, company or website, your offer, message, language, page visited, time, the assistant's conversation ID where applicable, and campaign parameters from the address bar) are stored in our lead system on servers of Hetzner Online GmbH in Germany (EU). We notify ourselves of new requests internally by email through our email provider Resend (USA; see the sub-processor page).

Legal basis: steps prior to entering into a contract and performance of the contract (Art. 6(1)(b) GDPR) and the consent to being contacted that you give in the form (Art. 6(1)(a) GDPR). The consent box is never pre-ticked.

Retention: we keep your request for as long as we are handling it and can make you an offer. You can request deletion and withdraw your consent with effect for the future at any time by emailing hello@plaith.ai. If a contract is concluded, the periods in section 6 apply.

15. Payment Processing (Stripe)

The setup fee and the Performance Team packages are paid through Stripe Payments Europe, Ltd. (Dublin, Ireland). You enter card or bank details directly on Stripe's payment page; we do not receive them. From Stripe we receive only the confirmation of payment, the amount and the details needed for the invoice (name, company, billing address, email address). Stripe's own privacy policy additionally applies to the processing of your payment data; Stripe safeguards transfers to Stripe, Inc. (USA) with Standard Contractual Clauses.

Legal basis: performance of the contract (Art. 6(1)(b) GDPR). Billing data is retained as set out in section 6.

Your choice in the cookie banner is stored in your browser's storage under the key plaithy_consent (with a mirror copy plaithy_cookie_consent for the application) for 12 months (first-party, not transmitted to third parties). In addition we record your decision with its time and an anonymous session identifier so that we can demonstrate consent (Art. 7(1) GDPR; audit logging under Art. 6(1)(f) GDPR); we keep these records for 24 months (section 6).

You can change or withdraw your choice at any time via the Cookie Settings link on our start page and in the footer of every other page.

17. Meta Pixel (only with consent)

We plan to use the Meta pixel (Meta Platforms Ireland Ltd., Dublin, Ireland) on our start page to measure the effectiveness of our own ads. It is loaded only if you agree to the “Marketing” category in the cookie banner (Art. 6(1)(a) GDPR); without your consent no Meta script is loaded and no cookie is set. Meta may transfer data to the United States; Meta Platforms, Inc. states that it is certified under the EU-US Data Privacy Framework.

The Meta pixel is currently not in use. Once it is active, we will add the cookies it sets and their lifetimes to the Cookie Policy.