Imvora Privacy Notice
Effective date: 9.8.2026
Controller: SAXA Real Košice s.r.o., Pri Teleku 1522/12, Košice - mestská časť Krásna, 04018, Slovakia (SK), 57459363 (“Imvora”, “we”)
Privacy contact: hello@imvora.app
This notice explains how Imvora processes personal data when you visit or use https://imvora.app. It covers personal data for which Imvora acts as controller, such as account, billing, support, and website data. Where a Customer enters personal data about its own leads, clients, or contacts into the CRM, that Customer is the controller and Imvora acts as its processor under the Imvora Data Processing Agreement.
1. Personal data we process
| Context | Data | Purpose and legal basis |
|---|---|---|
| Account and organization administration | name, work email address, account role, organization, login and account settings | Create and administer accounts, authenticate users, provide the Service. Necessary for performance of a contract (GDPR Art. 6(1)(b)); legitimate interests in account security (Art. 6(1)(f)). |
| Billing | owner/contact details, plan, invoices, payment status, tax information and payment references | Contract performance, accounting, tax, fraud prevention, and legal compliance (Arts. 6(1)(b), 6(1)(c), 6(1)(f)). Payment card data is handled by Stripe, not stored by Imvora. |
| Support and communications | name, email, correspondence, support request details | Respond to requests and operate the customer relationship (Arts. 6(1)(b), 6(1)(f)). |
| Security and essential cookies | IP address, device/browser information, log data, authentication and Laravel session identifiers | Secure the Service, prevent abuse, maintain sessions, and diagnose faults (Art. 6(1)(f); where required, applicable cookie rules). |
| Product analytics | product usage events and related online/device identifiers processed through PostHog | Understand and improve the Service; our legitimate interests (Art. 6(1)(f)). If PostHog uses non-essential cookies or similar technologies, we will obtain consent where required before setting them. |
We do not intentionally collect special-category data through account administration. Customers must not enter such data into CRM records unless they have an appropriate legal basis and safeguards.
2. CRM data entered by Customers
Customers may store names, phone numbers, email addresses, notes, lead details, client details, listings, and related records. Imvora processes that data only on the Customer’s documented instructions to provide, secure, and support the Service. The Customer is responsible for providing data-subject notices and responding to data-subject requests concerning that CRM data. If you are a contact of an Imvora Customer, contact that Customer first.
3. Recipients and processors
We use service providers that process personal data under contract and only as necessary to provide their services:
| Provider | Service |
|---|---|
| OVHcloud | hosting and infrastructure |
| Cloudflare | security, content delivery, and web performance |
| Resend | transactional email delivery |
| PostHog | product analytics |
| Stripe | payment processing (generally an independent controller for payment services) |
We may also disclose data where required by law, to professional advisers under confidentiality, or in connection with a corporate transaction subject to appropriate safeguards.
Some providers may process data outside the EEA. Where this occurs, we use a transfer mechanism permitted by GDPR Chapter V, such as an adequacy decision or the European Commission’s Standard Contractual Clauses, and apply supplementary measures where appropriate. Current hosting location and applicable provider terms should be recorded in the subprocessor list before publication.
4. Retention
We retain account data for the account lifetime and for a reasonable period afterward to handle requests, disputes, and security. We retain billing and accounting records for the period required by applicable law. Support and security records are retained only as long as needed for their purpose. Customer CRM data is deleted upon the Customer’s written request sent to hello@imvora.app, subject to the DPA, legal obligations, and limited backup retention. We may retain anonymized or aggregated information that no longer identifies a person.
5. Your rights
Subject to GDPR conditions and limitations, you may request access, correction, erasure, restriction, objection, and portability of personal data for which Imvora is controller. Where processing is based on consent, you may withdraw it at any time; this does not affect earlier processing. To exercise rights, email [hello@imvora.app]. We may need to verify your identity. You may lodge a complaint with the Slovak supervisory authority, Úrad na ochranu osobných údajov Slovenskej republiky, or with the authority where you live or work.
6. Cookies and similar technologies
Imvora uses essential authentication and Laravel session cookies necessary for sign-in and core functionality. We do not use marketing cookies. We use PostHog for product analytics. If the implementation uses non-essential cookies or similar identifiers, we will show an appropriate consent choice before using them where required. You can manage browser cookies, but disabling essential cookies may prevent the Service from working.
7. Security and changes
We use appropriate technical and organizational measures designed to protect personal data, including access controls and measures appropriate to the risks of online services. No system is completely secure. We may update this notice when our processing or legal requirements change. We will post the updated notice and update its effective date; for material changes, we will provide additional notice where appropriate.