This policy explains what we do with the personal data that reaches Ofivia, both through this site
and through the application at app.ofivia.com.
It is written against two frameworks at once. Ecuador’s Ley Orgánica de Protección de Datos Personales and its implementing regulation apply to everything we do, because the operation, the team and the servers are in Ecuador. The European Union’s General Data Protection Regulation applies on top of that when we handle data of people located in the Union, in the cases described in section 1. Where the two ask for different things, we meet the stricter one and use the shorter deadline.
1. The two roles and the two laws
There is a distinction worth understanding before you read on, because it changes almost everything else.
- For your company’s data inside the application we are a processor, in the sense of Article 28 of the European Regulation. The controller is the client company. It decides what data goes in, what for and for how long. We handle that information on its documented instructions, and the terms are in the data processing agreement, which the company named in section 2 signs.
- For commercial contact details, billing details and site browsing data we are the controller. That is what this policy governs, and the controller is the company named in section 2.
The European Regulation reaches us in two situations. First, when we offer the service to people or companies located in the European Union, under Article 3(2)(a). This site is published in Spanish and English and we accept European clients, so we take that condition as met and do not argue the point. Second, when a client company established in the Union instructs us to process data: there the controller is subject to the Regulation and we are bound as its processor through the contract.
Being subject to the European Regulation does not take us out of Ecuadorian law. The two stack.
2. Who handles your data
Ofivia is operated by [legal entity name], a Delaware company, registered at [registered address], tax identification [tax ID]. That company is the controller for the data this policy describes, it is the party that contracts with every client wherever they are, and it is the party that signs the data processing agreement. The team, the day-to-day operation and the servers are in Ecuador.
- Address for any privacy matter and for exercising rights: hola@ofivia.com. Phone: +593 96 175 0101.
- Data protection officer: [data protection officer name], [data protection officer email].
- Representative in the European Union under Article 27 of the European Regulation: [EU representative under Article 27 GDPR].
The brackets are literal. We do not have those details settled yet and we do not publish invented ones, so they appear as placeholders until they exist. Two of them are obligations of ours, not decoration: Ecuadorian rules require us to appoint a data protection officer, because the processing runs from Ecuador and we provide information technology services built on artificial intelligence, and Article 27 of the European Regulation requires us to appoint a representative in the Union because we offer services there without being established there. Incorporating in the United States removes neither duty. Neither appointment is in place as of the date of this document. In the meantime, the address and the phone above reach a person and get answered.
3. What data we handle
If you write to us or fill in a form on this site
In the signup form: name, work email, company, role, team size, the plan you picked and whatever you write in the open field about your case. We also keep the page language, the source parameter if the link carried one, and the date.
The contact form does not reach us through a server. The button opens your own mail program with the message already drafted and you decide whether to send it. If you send it, it arrives as an ordinary email.
In the blog newsletter box, the address you type stays in your browser. There is no mailing list behind it today and that address is not transmitted to any server of ours.
If your company opens an account
Name, corporate email, password stored as an argon2id digest and never in the clear, role within the company, account status and the date of the last login.
Your IP address travels to the server at login. Two mechanisms slow down brute force there and they are not the same thing. The failed-attempt counter is keyed by the email address submitted, not by IP, and it is held in cache for fifteen minutes. On top of that, the credential routes carry a per-IP limit applied at the entry point, which caps how many attempts one address gets per minute. Neither writes an IP address column into our database; whatever remains, remains in the server’s technical logs.
When you use the application
Here we are a processor and your company decides the scope. What the platform ends up storing:
- Vault content: notes and documents in Markdown, and the files you upload, up to 1.5 GB per file, including audio up to 25 MB, images, video, PDFs and office documents. Also the indexed chunks and their vectors, which are computed on our own infrastructure.
- Agent conversations: the full thread of every turn and the tools that ran.
- Team chat: the messages and the files you attach from the vault.
- Voice: the recording and its transcript. Transcription runs on our server with a local model, so that audio does not leave the machine.
- Images and video generated with artificial intelligence: the text you asked for, the resulting file and the reference to the conversation with the provider that produced it.
- Company email, if you contract that module: the domain, the signing identifiers, the mailboxes and their aliases. Message content lives on the mail server we operate, not in the application database.
- Artificial intelligence usage per company, user, project and process, with the model, the tokens and the cost. We record the size of the text in each call, never the text.
- Agent audit: a hash chain with the name of every tool that ran and a sha256 digest of its arguments. The arguments themselves are not stored in the clear.
- Project activity log: an extract of the agent’s reply of around 280 characters, the files it touched, the model and the cost.
- Your company’s secrets: encrypted in the database. No endpoint returns them; they are listed by name only.
- Workspace state, bookmarks, scheduled tasks, credit requests and notifications.
Browser notifications
If you turn them on, we store the subscription your browser issues: the push service address, which identifies that device, and the two keys each notice is encrypted with. One row per device. The row deletes itself when the push service reports the subscription is dead, and you can revoke it from the site permissions in your browser.
Payment data
Card payment happens on a page hosted by Stripe. Your card number does not pass through our servers and we do not store it. From that operation we keep the customer and subscription identifiers Stripe returns, the last four digits, the card brand, the invoice history and the billing details you type, including your tax identification where your country requires it on the invoice. Stripe also processes those details on its own account to prevent fraud, and answers for that processing.
When you visit this site
The server keeps the ordinary technical logs, with the IP address, the page requested and the time. This site sets no analytics or advertising cookies. Typefaces are served from our own domain, so opening a page does not disclose your IP address to a font provider. The detail of what is stored in your browser is in the cookie policy.
4. On what legal basis
| Processing | Basis under Ecuadorian law | Basis under the European Regulation |
|---|---|---|
| Answering your commercial inquiry | Pre-contractual steps taken at your request | Article 6(1)(b) |
| Providing the service to a client company | Performance of the contract | Article 6(1)(b) |
| Handling content inside the application | The controller’s instruction | The client company sets the basis |
| Charging the subscription | Performance of the contract | Article 6(1)(b) |
| Preventing payment fraud | Legitimate interest | Article 6(1)(f) |
| Security records, access control and audit logs | Legitimate interest in protecting the service and its users | Article 6(1)(f) |
| Invoicing and accounting retention | Compliance with a legal obligation | Article 6(1)(c) |
| Browser notifications | Consent, which you give by turning them on | Article 6(1)(a) |
| Sending you content you did not ask for | Consent, which you can withdraw at any time | Article 6(1)(a) |
Where the basis is legitimate interest, you can object and explain your situation. We assess it and answer you in writing.
If you do not give us the data a signup form asks for, we cannot create the account or answer the inquiry, because there is nothing to work with. If you give us inaccurate data, notices and invoices go where they should not, and we will not be able to verify a rights request arriving from another address.
5. What we use it for
To answer what you ask, create and administer your company’s account, provide support, keep the service running, bill what is owed and meet legal obligations. We do not sell personal data or hand it to third parties for advertising.
We do not train artificial intelligence models on our clients’ content. Indexing and search run on an embedding model hosted on our own infrastructure, so that text does not leave it. The same goes for audio transcription and for calls. When the agent works, the slice of content needed to answer that particular request is sent to the model provider, and the same happens with image and video generation. Which provider receives what is set out in the sub-processor list.
6. Automated assessments and decisions
The platform handles your information with artificial intelligence systems. The agent drafts, summarizes, classifies and carries out tasks over vault content, and those outputs are produced automatically.
The agents do not on their own take decisions with legal effects on a person, or decisions that affect them similarly significantly. Where an automated assessment feeds a decision that concerns you, you have the right to ask for a reasoned explanation, to know the assessment criteria, to know which types of data were used and where they came from, to submit observations and to contest the decision. That holds under Article 20 of the Ecuadorian law and Article 22 of the European Regulation, and it cannot be waived in advance.
The detail of what artificial intelligence does inside Ofivia, and where it gets things wrong, is on the artificial intelligence page.
7. How long we keep it
- Commercial inquiries that do not lead to a contract: up to twenty-four months from the last contact.
- Active account data: for as long as the relationship with the client company lasts.
- Team chat messages and notifications: ninety days by default, unless your contract sets another period. If you need to keep a conversation longer, save it into the vault.
- Agent activity log: ninety days.
- Per-call artificial intelligence usage log: thirty days. The daily per-company summary is kept for the life of the account.
- Generated image and video ledger: thirty days.
- After the contract ends: vault content and the database are deleted within the period agreed in the data processing agreement, except for what we must keep by law.
- Backups: daily backups rotate at fourteen days, so deleted data disappears completely within that window.
- Documentation supporting the lawfulness of an international transfer: at least three years, because Ecuadorian rules require it.
- Accounting and tax records: for whatever period the accounting and tax rules that apply to the invoicing company and to the operation in Ecuador require.
8. Who we share it with
Only with processors we need in order to operate, and under contract. The categories are:
| Category | What for |
|---|---|
| Infrastructure and hosting | Running the platform and storing the database and the vault |
| Providers of the model that serves the agent’s turns | Producing the agent’s reply over the content the request needs |
| Image and video generation providers | Producing the files you ask those tools for |
| Object storage | Archiving heavy material that stops being used day to day |
| Transactional email and outbound relay | Verifications, security notices and mail leaving your company’s mailboxes |
| DNS and reverse proxy | Publishing your domain’s records and serving site traffic |
| Browser push services | Delivering the notification to the subscribed device |
| Payment processor | Charging the subscription and issuing the invoice |
| External video render and audio separation machine | Producing heavy exports off the platform |
The list naming each one and where it processes is on the sub-processors page and forms part of the annex to the data processing agreement. We give notice before adding a new one, and the controller can object on reasoned grounds.
Some pieces look like a third-party service and are not. The embedding model that indexes and searches, audio transcription, the call server, the database, the cache and the mail server all run on our own infrastructure in Ecuador. That data does not leave the machine.
We also hand over information when a competent authority requires it through legal channels.
9. Content that can leave the session
Four features of the application can put content outside the authenticated session. The client company turns them on, and the decision is its own.
- Signed reference links. When you ask for an image or a video generated from a file of yours, the platform publishes that file behind a signed link that expires after thirty minutes, so the provider can download it. The link points at a single file of a single company and lists nothing else. We cannot revoke it before it expires. Anyone holding that address within the window downloads the file without logging in.
- Autologin into an embedded console. Opening one of the linked consoles from the application, such as conversations, automations or webmail, mints a link carrying a signed token that lasts five minutes. We cannot revoke that one either. Whoever holds it inside that window lands in that project’s session on that console without going through an Ofivia login.
- Published sites. The publishing tool puts your project’s site on the open internet, under a subdomain of ours or under your company’s own domain. There is no token and no expiry: whatever goes up there is public until someone unpublishes it.
- Published agent templates. Marking a template as published offers it to other companies on the platform, along with the knowledge text you put inside it.
10. International transfers
The map first, then the reasoning. The client can be anywhere, the European Union included. The controller, and the party that signs, is the Delaware company in section 2, in the United States. The operation, the team and the servers are in Ecuador. Part of the processing sits with providers in the United States and in Europe. We do not promise that your data stays in a single country, because that is a promise we could not keep today. If your company needs that guarantee, the route is self-hosting: you install Ofivia on the server and in the country you choose.
On the Ecuadorian side, two things get confused often and need separating. Entrusting processing to a processor is neither a transfer nor a disclosure of data, and it is governed by the processing agreement. Where there is a real transfer to a third party acting on its own account, it rests on the safeguards the law requires, including the recipient’s express submission to the jurisdiction, the rules and the resolutions of Ecuador’s data protection authority and to the orders of Ecuadorian courts. We keep the documentation supporting each transfer for at least three years.
On the European side, data coming from a client established in the Union reaches a controller in the United States and infrastructure in Ecuador. Both are third countries under Chapter V of the Regulation, and neither adequacy route is open to us:
- Ecuador has no adequacy decision from the European Commission.
- The Commission decision of 10 July 2023 on the EU-US Data Privacy Framework covers only organizations certified under that framework and listed as such by the United States Department of Commerce. [legal entity name] is not certified, so that decision covers nothing of ours and we do not lean on it. If the certification ever happens, this document will say so.
The transfer therefore rests on an Article 46 safeguard: the Standard Contractual Clauses of Implementing Decision (EU) 2021/914, signed as an annex to the processing agreement, with the United States company as data importer. The processing continuing on the infrastructure in Ecuador and at each sub-processor travels as an onward transfer under Clause 8.8 of module two, and every sub-processor is bound by equivalent terms.
Two limits, stated before you find them yourself:
- Recital 7 of that Decision allows the Standard Contractual Clauses only to the extent that the importer’s processing does not itself fall under the Regulation. The Commission announced specific clauses for that case and, as of the date of this document, has not adopted them. We sign the 2021 ones and will migrate to the new ones when they exist.
- We do not yet have a documented transfer impact assessment at the level asked for by Recommendations 01/2020 of the European Data Protection Board. We commit to documenting it before we take on the first client with data in the European Union. Until then we do not claim to have it.
11. Your rights and the deadlines
Ecuadorian law gives you the right to access your data, rectify it, update it, delete it, object to the processing, request temporary suspension, obtain a portable copy and not be subject to automated decisions. The European Regulation adds the right to restriction of processing. Under both, you can withdraw consent where consent is the basis, without affecting what was processed before.
The deadlines we work to:
| Request | Deadline |
|---|---|
| Access, rectification, update, deletion, objection and suspension under Ecuadorian law | 15 days |
| Requests, petitions, complaints and claims under Article 62 of the Ecuadorian law | Term of 10 business days |
| Clarifying an incomplete request | We ask once, within a term of 5 business days, and you have a term of 10 business days to answer |
| Rights under Articles 15 to 22 of the European Regulation | One month, extendable by two more if the case is complex, telling you why within the first month |
Where two deadlines apply to the same request, we use the shorter one.
To exercise them, write to hola@ofivia.com from the address associated with your data, or attach something that identifies you. If we ask for extra verification it is because handing data to the wrong person is worse than a slow answer.
If you work for a client company and your request concerns data held inside that company’s account, we route it to that company, which is the controller, and support them on the technical side.
If you believe we handled your request badly, you can complain to Ecuador’s Superintendencia de Protección de Datos Personales. If you are in the European Union, you can also complain to the supervisory authority of your habitual residence, your place of work or the place of the alleged infringement, and go to court.
12. Data breaches
No system is invulnerable. If a security breach affects personal data, this is what we do and how fast:
- Where we are the controller, we notify Ecuador’s Superintendencia de Protección de Datos Personales and the Agencia de Regulación y Control de las Telecomunicaciones as soon as possible and within a term of five business days from becoming aware, unless the breach is unlikely to present a risk. If we go past that, we explain why.
- We notify you within a term of three business days from knowing there is a risk to your rights.
- Where the European Regulation applies, notification to the supervisory authority goes without undue delay and, where feasible, within 72 hours, and communication to the affected person without undue delay where the risk is high.
- Where we are a processor, we tell the client company without undue delay and in any case within 48 hours. Notifying the authority and the individuals is its job, and we help with whatever it needs.
The notice carries what we know at that point: the nature of the incident, the categories and approximate volume of data affected, the likely consequences and the measures taken or proposed.
13. Security
The technical measures are described in detail and without decoration on the security page, including a list of what we do not have yet. Two worth keeping in mind: we do not encrypt documents at the application layer at rest, and we hold no SOC 2 or ISO 27001 certification and no third-party audit report.
14. Minors
Ofivia is a work tool and is not aimed at minors. We do not knowingly collect their data.
15. Changes
If this policy changes, we update the date in the header and, when the change is substantial, we email client companies before it takes effect.