Privacy Policy
Version 1 · 6 October 2026
This policy explains what we do with your personal data as a Kavix account holder.
It does not cover the people who sign your agreements. For them you are the controller and we act on your instructions — that is governed by the Data Processing Agreement, and the notice those people see is the one you write.
The English text is the authoritative version.
Who we are
Kavix is operated by Yossi Raz, trading as Innovago, in Israel. Contact: privacy@innovago.com
We are a sole trader, not a company, and no data protection officer is appointed — the thresholds that would require one are not met. The contact above reaches the person responsible.
What we collect about you
| Data | Why | Lawful basis |
|---|---|---|
| Your name and email address | to create and identify your account | performance of a contract |
| Your password, stored only as a scrypt hash | to let you sign in | performance of a contract |
| Your business's legal details | they appear on your agreement and in mail sent on your behalf | performance of a contract |
| Session records: device description, times | to keep you signed in and let you end sessions | performance of a contract |
| Sign-in attempts, with IP address | to limit abuse of the sign-in form | legitimate interest in keeping accounts secure |
| Error and operational logs | to keep the Service working | legitimate interest in operating a reliable service |
We do not profile you, advertise to you, sell anything about you, or build a picture of you across other services. There are no analytics or advertising trackers in Kavix.
Cookies
Two, both strictly necessary, both without consent requirements:
- a session cookie holding a random token, so you stay signed in
- a short-lived sign-in state cookie during Google sign-in, which protects against cross-site request forgery and is deleted immediately afterwards
No analytics cookies, so no cookie banner. That is a design decision, not an oversight.
Where your data is, and who else touches it
Everything is hosted in the European Union.
| Who | What they do | Where |
|---|---|---|
| Vercel | runs the application | Frankfurt |
| Neon | the database | Frankfurt |
| Brevo | sends email | France |
| optional sign-in, if you choose it | EU/US under its own terms |
These are our sub-processors. The current list is published and we will give notice before adding one.
How long we keep it
Your account data is kept while the account is open, and for 12 months after it is closed — long enough to answer a question about what happened, not long enough to be a collection. Sign-in attempt records are kept for 90 days. Operational logs are kept for 30 days.
Your rights
Under the GDPR and Israel's Privacy Protection Law you may ask for a copy of your data, correction of it, deletion of it, or restriction of how it is used; you may object to processing based on legitimate interest, and you may ask for your data in a portable form.
Write to privacy@innovago.com. We answer within one month. If we refuse, we will say why and tell you how to complain.
If you are unhappy with the answer you may complain to your data protection authority, or in Israel to the Privacy Protection Authority.
Security
Passwords are stored as scrypt hashes, never in plain text. Session tokens and email links are stored only as hashes. Your customers' personal data is encrypted with per-record keys, and a database copy alone decrypts nothing because the master key is not in the database. Access between businesses is enforced by the database itself rather than by application code.
No system is immune. If a breach affects you we will tell you without undue delay.
Changes
We will notify material changes to the address on your account at least 14 days before they take effect. Earlier versions are kept.
Drafted with care, not by a lawyer, and to be reviewed by one before the Service is offered commercially.