At a glance
Never sold
We don't sell personal data or use it for advertising.
Your customers, your call
Businesses control their conversations; we process them on their behalf.
Hosted in the EU
Kuvra's database is in the European Union.
Rights respected
Access, correction, deletion and export under UK GDPR.
01Who we are
Kuvra is a customer support product operated by Sukses360 Ltd, a company registered in England and Wales (“we”, “us”). This policy explains how we handle personal data when you visit our website, create a Kuvra account, or chat with a business through a Kuvra widget.
We process personal data under the UK General Data Protection Regulation and the Data Protection Act 2018. For privacy questions, contact us at privacy@kuvra.dev.
02Our two roles
As a controller. We decide how data is used for our own website, for Kuvra accounts (the people who sign up and their teammates), and for billing and support of our customers.
As a processor. When a business uses Kuvra to talk to its own customers, that business is the controller of the conversations, visitor details and knowledge base content in its workspace. We process that data only to provide Kuvra to the business and on its instructions. If you chatted with a business through its Kuvra widget and want to exercise your rights, please contact that business first; we will help them respond.
03What we collect
Account data: your name, email address, password (stored by our authentication provider in hashed form), profile picture, language and time zone, workspace role, and two-factor authentication settings if you turn them on.
Workspace content: knowledge base articles and imported pages, conversations, internal notes and team messages, macros, saved replies, settings, and files uploaded to the workspace.
Widget visitor data (processed for our customers): messages and attachments, an email address if the visitor provides one, IP address, browser and device type, browser language, the referring site and page, and conversation ratings.
Integration data:when a workspace connects an app such as Gmail, Slack, HubSpot, Linear or Shopify, the access needed to act in that app on the workspace’s behalf, and the data returned when a teammate uses it.
Usage and technical data: counts of AI replies and other usage needed for plan limits and billing, and logs of requests used for security and rate limiting.
04How we use it, and why
| Purpose | What it covers | Lawful basis |
|---|---|---|
| Providing Kuvra | Storing conversations, delivering messages in real time, sending the notifications you choose | Contract |
| AI features | Answers from a workspace's knowledge base, translation, article suggestions, teammate assistance | Contract; for visitor data, our customer's instructions |
| Security | Rate limiting, blocking abuse, investigating incidents | Legitimate interests |
| Billing and support | Invoicing, account support, service announcements | Contract and legal obligations |
We do not sell personal data, and we do not use workspace content or visitor conversations to train our own AI models.
05AI processing
When the AI features are used, the relevant question, parts of the conversation and matching knowledge base passages are sent to our AI providers to produce a response. These providers act as our subprocessors and process the data only to return that response. AI output can be wrong; businesses using Kuvra are responsible for reviewing how it is used with their customers.
07International transfers
Kuvra’s database is hosted in the European Union. Some subprocessors may process data in other countries, including the United States. Where personal data leaves the UK, we rely on UK adequacy regulations or appropriate safeguards such as the International Data Transfer Addendum to the EU Standard Contractual Clauses.
08How long we keep it
We keep account data and workspace content for as long as the account or workspace is active. Businesses using Kuvra decide how long their conversations and visitor data are kept, and can delete them.
When an account is closed, we delete or anonymise its personal data within a reasonable period, except where we must keep it for legal, tax or security reasons. Backups are overwritten on a rolling basis.
09Security
We protect data with encryption in transit, access controls, optional two-factor authentication, rate limiting and abuse protection. No system is perfectly secure, and we will notify affected customers and the relevant authority of a personal data breach where the law requires it. More detail is on our Security page.
10Your rights
Under UK data protection law you can ask to access, correct, delete, restrict or port your personal data, and object to processing based on legitimate interests. Where we rely on consent, you can withdraw it at any time.
To make a request, email privacy@kuvra.dev. We will respond within one month. You also have the right to complain to the Information Commissioner’s Office (ico.org.uk), though we’d appreciate the chance to help first.
12Children
Kuvra is a business product and is not directed at children under 16. We do not knowingly collect their personal data for our own purposes.
13Changes to this policy
We will update this page when our practices change and revise the date at the top. For significant changes, we will notify account owners by email or in the product.