Skip to content
Back to ZavyraPrivacy & data use

Zavyra Privacy Policy

Effective date: 2 September 2026

This Policy explains what Zavyra collects, why it is needed, how long it is kept, and how you can disconnect or delete connected-platform data. Zavyra does not sell personal data, Google Ads data, or Amazon Information. We do not use connected account data for advertising unrelated to the service.

Controller and processing roles

ProWEB Agency, Parowa 18, 59-724 Osiecznica, Poland, NIP 612-174-56-24 ("Zavyra", "we", "us") is the controller of account, website, security, support and billing data. Privacy requests can be sent to office@zavyra.com.

For personal data that a business customer imports from its stores, marketplaces or workforce, that customer normally remains the controller and Zavyra acts as a processor under the applicable Data Processing Agreement (DPA).

Core data, purposes and legal bases

Depending on the features you use, we process:

  • account identity, business contact, workspace membership and authentication data;
  • company, billing, subscription and invoice data;
  • IP address, session, device, security, diagnostic and audit-log data;
  • support correspondence and preferences;
  • connected-platform identifiers, authorisations and business records; and
  • prompts, selected records and outputs when a user invokes an AI feature.

We use this data to perform the service contract, secure accounts, provide selected integrations, process payments, comply with law, respond to support and legal claims, and improve reliability. The legal bases are contract performance, legal obligation, legitimate interests in operating and protecting the service, and consent where the law or a feature requires it.

Disconnecting, revoking and deleting Google data

  1. Disconnect in Zavyra: open Settings → Advertising, choose the Google connection and select Disconnect. Zavyra makes a best-effort Google token revocation request, removes locally stored active credentials and disables the connected advertising accounts.
  2. Revoke at Google: open your Google Account's third-party connections page and remove Zavyra's access. Revoking at Google stops future API access. To make sure Zavyra also receives the instruction and removes local credentials, disconnect inside Zavyra or contact office@zavyra.com.
  3. Delete imported records: deleting a connection does not automatically erase historical campaign and metric records because customers may need them for workspace reporting. Delete the relevant workspace where that control is available, or request deletion at office@zavyra.com. We verify authority before fulfilling a request.

Deletion removes data from active systems unless retention is required by law. Residual copies are isolated in backups, are not used for normal processing and expire through the protected backup cycle; deletion instructions are reapplied if a backup is restored.

Amazon SP-API data

The current Zavyra Amazon SP-API integration is designed for business operations data. It does not request Restricted Data Tokens and does not import buyer names, buyer email addresses, recipient names, delivery addresses or other Amazon customer PII.
Data typeUseRetention
Seller ID, region, marketplaces, participation status, country, currency and time zoneIdentify the seller account and configure permitted marketplace operationsWhile the connection or workspace is active; deleted on verified request or workspace deletion, subject to law
Encrypted refresh token, temporary access token and authorisation stateAuthenticate SP-API requests selected by the userRefresh credentials remain only while connected. One-time OAuth state expires after 10 minutes. Active credentials are deleted on disconnect
Product and offer data: SKU, ASIN, title, description, bullets, identifiers, images, price, currency, availability, fulfilment, variations and bounded listing issuesImport, display, audit and prepare supported catalogue or listing operationsOnly as needed for the authorised service and no longer than 18 months unless law requires otherwise; deleted earlier on verified request
Inventory quantities and fulfilment stateProvide inventory views and synchronisation diagnosticsOnly as needed for the authorised service and no longer than 18 months unless law requires otherwise
Order and order-item IDs, status, dates, SKU, product title, quantity, price, tax, shipping, discount, cancellation and fulfilment totalsProvide order operations and reportingOnly as needed for the authorised service and no longer than 18 months unless law requires otherwise
Amazon customer PIINot used by the current integrationNot requested or stored. If this changes, Zavyra will update this Policy, permissions and controls before processing it

Amazon deletion, backups and personnel access

Disconnect and revocation

An owner or administrator with the required account security checks can disconnect Amazon in Zavyra. Disconnecting deletes the encrypted refresh credential from the active connection, clears token caches, disables the connection and cancels queued or retrying Amazon jobs. Imported non-PII business records are preserved for workspace continuity only within the retention limits above, unless the customer deletes them or requests deletion. Revoking Zavyra in Amazon Seller Central may not automatically deliver a deletion instruction to Zavyra; also disconnect in Zavyra or contact office@zavyra.com.

Deletion and backups

On a verified customer or Amazon deletion instruction, Zavyra removes the affected Amazon Information from active systems within the applicable contractual deadline. Where Amazon's policy applies, the deletion workflow is initiated within 30 days and remaining live or network-accessible copies are removed no later than 90 days, unless retention is legally required. Backup copies are access-controlled, are not restored for ordinary use, expire according to the protected backup cycle, and inherit the deletion instruction if restoration is required.

Restricted personnel access

Amazon Information is available only to approved personnel and service providers with a documented need to know. Access follows least-privilege roles, is logged where supported, is reviewed at least quarterly, and is removed promptly when a person changes role or leaves. Credentials are not returned through the user interface or written to application logs. Zavyra follows the applicable Amazon Services API Data Protection Policy and Acceptable Use Policy.

AI providers and connected-platform data

Zavyra uses OpenAI's API for selected, user-invoked AI features. Zavyra does not opt API data into training general-purpose models. API requests are made with storage disabled by Zavyra; the provider may still retain limited abuse-monitoring logs under its standard API policy unless a separate zero-retention arrangement applies.
SourceSent to an AI provider?Trigger, purpose and filtering
Google AdsNo, not in the current implementationGoogle tokens, account IDs, campaign configuration and advertising metrics are not automatically or manually routed into the current AI tools
Amazon ordersOnly after an authorised user explicitly invokes Copilot for an Amazon-order questionZavyra sends a bounded projection needed to answer the request: internal order references, channel, status, totals, dates and item title/SKU/quantity/price. Customer names, email addresses, delivery addresses and external customer identifiers are excluded
Amazon-imported productsOnly after a user explicitly starts an AI content feature for the selected productZavyra may send selected catalogue fields such as title, description, categories, tags, variants, SKU, price, inventory and image count to generate or improve content
Prompts and attachmentsYes, when the user submits them to an AI featureUsed to produce the requested response. Images are sent only when the selected feature requires image analysis

AI output is returned to the requesting workspace for review. Zavyra filters credentials, secrets and unsupported customer PII from structured integrations before an AI request. Users should not place sensitive personal data in free-text prompts. OpenAI states that business and API data is not used for model training by default; see the OpenAI business data commitments and API data usage controls.

Recipients and international transfers

Data may be processed by providers of hosting, database, backups, security, monitoring, email, support, accounting and legal services; payment operators including Stripe; OpenAI for selected AI requests; and platforms that the customer chooses to connect, including Google, Amazon, Shopify, Allegro or Etsy. Public authorities receive data only where legally required.

Some recipients may process data outside the European Economic Area. Where GDPR requires a transfer safeguard, we rely on an adequacy decision, Standard Contractual Clauses and supplementary measures, or another lawful mechanism. Current infrastructure locations and subprocessors are documented in the applicable customer contract, DPA or subprocessor list.

General retention

Account and workspace data is kept for the duration of the contract and then only as needed for legal claims, fraud prevention or statutory duties. Billing and tax records are kept for the period required by applicable law. Security and audit logs are retained for a period proportionate to the security risk and applicable platform rules. Support records are kept while the issue and related claims remain relevant.

When Zavyra acts as a processor, deletion or return follows the customer's verified instruction, the DPA, technical backup cycles and any mandatory legal hold. Anonymised statistics that no longer identify a person or connected account may be retained to measure service reliability.

Your privacy rights

Depending on the legal basis and your location, you may request access, correction, deletion, restriction or portability, object to processing, or withdraw consent without affecting earlier lawful processing. Send requests to office@zavyra.com. We may verify identity and workspace authority before acting.

If Zavyra processes your information only for a business customer, contact that business first; Zavyra will assist it as required by the DPA. You may lodge a complaint with the President of the Personal Data Protection Office in Poland or another competent authority.

Cookies and security

Necessary cookies and similar storage support sign-in, sessions, security and language or workspace preferences. Optional analytics or marketing technologies are used only where a valid legal basis, including consent when required, is available.

Zavyra applies safeguards appropriate to risk, including encrypted transport, encryption of integration credentials, role-based access controls, multi-factor checks for sensitive administration, logging, protected backups, vulnerability management and software updates. No system is completely secure; report suspected incidents immediately to office@zavyra.com.

Policy changes and contact

We update this Policy when law, service functions, providers or data practices change. Material changes will be announced in the platform, by email or through another reasonable notice before they take effect where required.

Questions, access revocation notices and deletion requests: office@zavyra.com. Postal contact: ProWEB Agency, Parowa 18, 59-724 Osiecznica, Poland.