Controller and processing roles
ProWEB Agency, Parowa 18, 59-724 Osiecznica, Poland, NIP 612-174-56-24 ("Zavyra", "we", "us") is the controller of account, website, security, support and billing data. Privacy requests can be sent to office@zavyra.com.
For personal data that a business customer imports from its stores, marketplaces or workforce, that customer normally remains the controller and Zavyra acts as a processor under the applicable Data Processing Agreement (DPA).
Core data, purposes and legal bases
Depending on the features you use, we process:
- account identity, business contact, workspace membership and authentication data;
- company, billing, subscription and invoice data;
- IP address, session, device, security, diagnostic and audit-log data;
- support correspondence and preferences;
- connected-platform identifiers, authorisations and business records; and
- prompts, selected records and outputs when a user invokes an AI feature.
We use this data to perform the service contract, secure accounts, provide selected integrations, process payments, comply with law, respond to support and legal claims, and improve reliability. The legal bases are contract performance, legal obligation, legitimate interests in operating and protecting the service, and consent where the law or a feature requires it.
Google Ads data
Data types and purpose
| Data | Why Zavyra accesses it | How it is used |
|---|---|---|
| Google principal ID, customer account IDs, display name, currency and time zone | Identify the authorised Google user and ad accounts available to the workspace | Show and select the correct advertising account and prevent cross-workspace access |
| OAuth access token, refresh token, granted scopes and token expiry | Maintain the connection authorised by the user | Call Google Ads APIs; tokens are encrypted and are not shown back to users |
| Campaign and budget IDs, names, status, channel type and configuration | Create, display, synchronise, pause or enable campaigns requested by the user | Operate Zavyra campaign-management and audit functions |
| Daily cost, impressions, clicks, conversions and conversion value | Provide reporting and performance views | Calculate workspace-level metrics and historical comparisons |
Storage, retention and recipients
Credentials are stored in Zavyra's encrypted application secrets store. Account, campaign and metric records are stored in the Zavyra production database and protected backup systems used to provide the service. OAuth credentials are retained only while the connection remains active and are removed from active systems when Zavyra receives a disconnect or deletion request. Imported identifiers and reporting records are kept while required for the workspace's connected reporting, until the workspace or records are deleted, or for a longer period required by law. Google may limit the historical reporting data available through its API.
Data may be disclosed only to authorised Zavyra personnel and infrastructure, monitoring or security processors that need it to operate the service, to Google when making the authorised API request, or where law requires disclosure. Zavyra does not sell Google user data, use it to build advertising profiles unrelated to the customer's workspace, or allow humans to read it except where necessary for security, support, legal compliance or a user-authorised operation.
Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements, and the Google Ads API Terms and Conditions.
Disconnecting, revoking and deleting Google data
- Disconnect in Zavyra: open Settings → Advertising, choose the Google connection and select Disconnect. Zavyra makes a best-effort Google token revocation request, removes locally stored active credentials and disables the connected advertising accounts.
- Revoke at Google: open your Google Account's third-party connections page and remove Zavyra's access. Revoking at Google stops future API access. To make sure Zavyra also receives the instruction and removes local credentials, disconnect inside Zavyra or contact office@zavyra.com.
- Delete imported records: deleting a connection does not automatically erase historical campaign and metric records because customers may need them for workspace reporting. Delete the relevant workspace where that control is available, or request deletion at office@zavyra.com. We verify authority before fulfilling a request.
Deletion removes data from active systems unless retention is required by law. Residual copies are isolated in backups, are not used for normal processing and expire through the protected backup cycle; deletion instructions are reapplied if a backup is restored.
Amazon SP-API data
| Data type | Use | Retention |
|---|---|---|
| Seller ID, region, marketplaces, participation status, country, currency and time zone | Identify the seller account and configure permitted marketplace operations | While the connection or workspace is active; deleted on verified request or workspace deletion, subject to law |
| Encrypted refresh token, temporary access token and authorisation state | Authenticate SP-API requests selected by the user | Refresh credentials remain only while connected. One-time OAuth state expires after 10 minutes. Active credentials are deleted on disconnect |
| Product and offer data: SKU, ASIN, title, description, bullets, identifiers, images, price, currency, availability, fulfilment, variations and bounded listing issues | Import, display, audit and prepare supported catalogue or listing operations | Only as needed for the authorised service and no longer than 18 months unless law requires otherwise; deleted earlier on verified request |
| Inventory quantities and fulfilment state | Provide inventory views and synchronisation diagnostics | Only as needed for the authorised service and no longer than 18 months unless law requires otherwise |
| Order and order-item IDs, status, dates, SKU, product title, quantity, price, tax, shipping, discount, cancellation and fulfilment totals | Provide order operations and reporting | Only as needed for the authorised service and no longer than 18 months unless law requires otherwise |
| Amazon customer PII | Not used by the current integration | Not requested or stored. If this changes, Zavyra will update this Policy, permissions and controls before processing it |
Amazon deletion, backups and personnel access
Disconnect and revocation
An owner or administrator with the required account security checks can disconnect Amazon in Zavyra. Disconnecting deletes the encrypted refresh credential from the active connection, clears token caches, disables the connection and cancels queued or retrying Amazon jobs. Imported non-PII business records are preserved for workspace continuity only within the retention limits above, unless the customer deletes them or requests deletion. Revoking Zavyra in Amazon Seller Central may not automatically deliver a deletion instruction to Zavyra; also disconnect in Zavyra or contact office@zavyra.com.
Deletion and backups
On a verified customer or Amazon deletion instruction, Zavyra removes the affected Amazon Information from active systems within the applicable contractual deadline. Where Amazon's policy applies, the deletion workflow is initiated within 30 days and remaining live or network-accessible copies are removed no later than 90 days, unless retention is legally required. Backup copies are access-controlled, are not restored for ordinary use, expire according to the protected backup cycle, and inherit the deletion instruction if restoration is required.
Restricted personnel access
Amazon Information is available only to approved personnel and service providers with a documented need to know. Access follows least-privilege roles, is logged where supported, is reviewed at least quarterly, and is removed promptly when a person changes role or leaves. Credentials are not returned through the user interface or written to application logs. Zavyra follows the applicable Amazon Services API Data Protection Policy and Acceptable Use Policy.
AI providers and connected-platform data
| Source | Sent to an AI provider? | Trigger, purpose and filtering |
|---|---|---|
| Google Ads | No, not in the current implementation | Google tokens, account IDs, campaign configuration and advertising metrics are not automatically or manually routed into the current AI tools |
| Amazon orders | Only after an authorised user explicitly invokes Copilot for an Amazon-order question | Zavyra sends a bounded projection needed to answer the request: internal order references, channel, status, totals, dates and item title/SKU/quantity/price. Customer names, email addresses, delivery addresses and external customer identifiers are excluded |
| Amazon-imported products | Only after a user explicitly starts an AI content feature for the selected product | Zavyra may send selected catalogue fields such as title, description, categories, tags, variants, SKU, price, inventory and image count to generate or improve content |
| Prompts and attachments | Yes, when the user submits them to an AI feature | Used to produce the requested response. Images are sent only when the selected feature requires image analysis |
AI output is returned to the requesting workspace for review. Zavyra filters credentials, secrets and unsupported customer PII from structured integrations before an AI request. Users should not place sensitive personal data in free-text prompts. OpenAI states that business and API data is not used for model training by default; see the OpenAI business data commitments and API data usage controls.
Recipients and international transfers
Data may be processed by providers of hosting, database, backups, security, monitoring, email, support, accounting and legal services; payment operators including Stripe; OpenAI for selected AI requests; and platforms that the customer chooses to connect, including Google, Amazon, Shopify, Allegro or Etsy. Public authorities receive data only where legally required.
Some recipients may process data outside the European Economic Area. Where GDPR requires a transfer safeguard, we rely on an adequacy decision, Standard Contractual Clauses and supplementary measures, or another lawful mechanism. Current infrastructure locations and subprocessors are documented in the applicable customer contract, DPA or subprocessor list.
General retention
Account and workspace data is kept for the duration of the contract and then only as needed for legal claims, fraud prevention or statutory duties. Billing and tax records are kept for the period required by applicable law. Security and audit logs are retained for a period proportionate to the security risk and applicable platform rules. Support records are kept while the issue and related claims remain relevant.
When Zavyra acts as a processor, deletion or return follows the customer's verified instruction, the DPA, technical backup cycles and any mandatory legal hold. Anonymised statistics that no longer identify a person or connected account may be retained to measure service reliability.
Your privacy rights
Depending on the legal basis and your location, you may request access, correction, deletion, restriction or portability, object to processing, or withdraw consent without affecting earlier lawful processing. Send requests to office@zavyra.com. We may verify identity and workspace authority before acting.
If Zavyra processes your information only for a business customer, contact that business first; Zavyra will assist it as required by the DPA. You may lodge a complaint with the President of the Personal Data Protection Office in Poland or another competent authority.
Cookies and security
Necessary cookies and similar storage support sign-in, sessions, security and language or workspace preferences. Optional analytics or marketing technologies are used only where a valid legal basis, including consent when required, is available.
Zavyra applies safeguards appropriate to risk, including encrypted transport, encryption of integration credentials, role-based access controls, multi-factor checks for sensitive administration, logging, protected backups, vulnerability management and software updates. No system is completely secure; report suspected incidents immediately to office@zavyra.com.
Policy changes and contact
We update this Policy when law, service functions, providers or data practices change. Material changes will be announced in the platform, by email or through another reasonable notice before they take effect where required.
Questions, access revocation notices and deletion requests: office@zavyra.com. Postal contact: ProWEB Agency, Parowa 18, 59-724 Osiecznica, Poland.