1. Who we are
Integrava is an AI support platform operated by Customer Success Point SRL ("we", "us"). For the purposes of applicable data protection law, Customer Success Point SRL is the data controller for personal data processed through the Integrava service, except where your organization acts as controller of data you upload or collect from your own customers.
Registered office: Romania, Bucharest, Drum Gura Putnei 133 Et. POD Ap. 19 Cod 032603. Unique registration code: 45173010.
Privacy enquiries, data subject requests, and law enforcement / legal-process requests: contact@integrava.ai. For legal-process requests, include Legal request in the subject line.
2. Scope
This policy applies to:
- Visitors to our marketing site and documentation
- Users who register for or administer an Integrava workspace (owners, admins, agents, and other roles)
- End users who interact with an Integrava embed widget, email assistant, or help center published by a customer workspace
If you use Integrava on behalf of an organization, your organization may have its own privacy notice for end-customer interactions. Integrava processes that data as a processor/service provider on your organization's instructions.
3. Personal data we collect
Account and workspace data — name, email address, password hash, workspace name, role, team invitations, email verification and password-reset tokens, and audit logs of administrative actions.
Authentication and session data — when you sign in, we set a first-party httpOnly cookie named integrava_session (about seven days) and a CSRF cookie named integrava_csrf. In production these cookies use the .integrava.ai domain so the app and API can share the session. Your browser's local storage holds the active workspace id and interface preferences, not the session token. We do not use third-party advertising cookies. These cookies are required to keep you signed in and to protect requests from forgery.
Knowledge and content you upload — documents, URLs, text, metadata, extracted content, embeddings, and AI-generated summaries that you or your team add to train the assistant. This may include personal data if present in your source material.
Conversations and support tickets — messages, subjects, ticket status, assignee information, internal notes, CSAT scores, custom fields, mass-incident records, and playground or investigation threads.
Email channel data — if you connect Gmail or Microsoft 365, we store connected inbox addresses, OAuth tokens (encrypted), email thread metadata, message bodies, and sender/recipient addresses needed to provide shared inbox and AI-assisted replies.
Integration credentials and synced content — encrypted API keys and OAuth tokens for connected services (for example Notion, Zendesk, Google Drive, Mixpanel, Stripe, and custom HTTP integrations), plus content synced from those systems into your workspace.
AI configuration — your workspace's encrypted AI provider API keys (OpenAI, Anthropic, Google, xAI, or an OpenAI-compatible base URL you set) and an optional Tavily key. Prompts, retrieved knowledge, and embeddings are sent to the provider you configure, under that provider's terms. Integrava does not use your content to train foundation models. If Tavily is configured, the search query (up to 500 characters, which can include customer message text) is sent to Tavily.
Embed widget and SDK end-user data — session identifiers, optional external user IDs, display labels, traits, IP-derived request metadata, allowed-domain checks, and chat messages submitted through widgets you deploy.
Analytics and usage — workspace analytics events (for example tickets created, messages sent, token usage estimates), saved reports, and operational metrics used for billing limits and product performance.
Billing and demo integrity — Stripe customer and subscription identifiers, billing email, organization email domain (for business accounts), hashed checkout IP address, and payment-method fingerprint used to detect duplicate demo abuse. Payment card details are handled by Stripe, not stored on Integrava servers.
Support and operator access — a workspace owner can grant support access for 1, 3, 7, 14, or 30 days (7 days if no duration is chosen). Access ends when that period expires or when you turn it off. Operator actions are logged.
4. How we use personal data
- Provide, secure, and maintain the Integrava platform
- Authenticate users and enforce workspace roles and entitlements
- Generate AI-assisted responses grounded in your knowledge base
- Operate email, embed, CRM, workflow, QA, and analytics features you enable
- Process subscriptions, the demo, invoices, and abuse prevention
- Send transactional emails (invitations, password reset, verification, export delivery)
- Improve reliability, security, and support quality
- Comply with legal obligations and respond to lawful requests
We process data on the legal bases of contract performance, legitimate interests (security, fraud prevention, and service improvement), and consent where required (for example optional marketing communications, if offered).
6. Retention
We retain personal data for as long as your workspace account is active and as needed to provide the service, resolve disputes, enforce agreements, and meet legal requirements. Scheduled deletion runs after a grace period: 14 days for a personal login account and 30 days for a workspace. While a workspace deletion is scheduled, the Stripe subscription stays active so you can cancel the deletion and keep access. The subscription is cancelled when deletion runs.
After a workspace is deleted we keep only:
- A billing and tax archive (amounts, Stripe identifiers, subscription dates)
- The platform audit record of the deletion request
- Anonymised demo-abuse signals (hashed checkout IP and payment-method fingerprint), detached from the workspace
Shorter schedules apply while the workspace is active: workspace audit logs are deleted after 45 days by default, investigation history after 15 days, Ask Insights queries after 90 days, and analytics daily facts after about 13 months. Database backups follow the infrastructure backup schedule and can still contain deleted data until that backup window expires.
A legal hold set for a valid preservation matter blocks scheduling and running workspace deletion until the hold is cleared. Where we are required to preserve data by valid legal process, we may retain it beyond the schedules above, as described in section 7.
Workspace owners can delete many categories of data directly in the dashboard (tickets, knowledge documents, team members, and integrations). Contact us if you need assistance with a broader deletion request.
7. Law enforcement and legal requests
Integrava may disclose personal data when we believe in good faith that disclosure is required by valid legal process — for example a subpoena, court order, search warrant, or equivalent binding request from a competent authority.
Contact for authorities: contact@integrava.ai with subject line Legal request. Use the same address for general privacy enquiries and data subject requests without that subject line.
We review each request for validity, scope, and jurisdiction. We may challenge, narrow, or refuse overbroad, improper, or invalid requests.
Controller vs processor: For data your organization controls — such as end-customer support tickets, embed conversations, email threads, and help center content — your organization is typically the data controller and Integrava acts as a processor on your instructions. We may direct authorities to you where appropriate, or disclose only what we are legally required to produce in our role as processor, consistent with our Terms of Service.
Notification: Where permitted by law and the request, we will notify the affected workspace owner before disclosure.
Availability limits: Data deleted under our retention and deletion policies — including account deletion, workspace deletion, audit log purge, and investigation history expiry — may no longer be available. See sections 6, 8, and 9.
International requests: Cross-border requests should use appropriate mutual legal assistance or equivalent channels where required by applicable law.
8. Deleting your Integrava login account
Workspace members can schedule deletion of their personal login account from Account security in the dashboard. This removes your name, email, and password from Integrava after a 14-day grace period during which you may cancel.
Deletion is automatic and irreversible once the grace period ends. You will receive email confirmation when deletion is scheduled. Historical references in your workspace(s) appear as "Deleted user" so ticket and audit history remain intact.
This does not delete your organisation's workspace, customer tickets, knowledge base, or other content your organisation controls. Workspace owners are typically the data controller for that content; Integrava processes it as a processor on their instructions. Owners must transfer ownership to another member before deleting their own account.
You may download a JSON export of your account profile and workspace memberships from Account security (right of access / data portability).
9. Deleting a workspace (organisation)
Workspace owners can schedule deletion of the entire workspace from Settings → Danger zone. This permanently removes workspace data — tickets, conversations, knowledge, integrations, widgets, help center, and team access — after a 30-day grace period during which owners may cancel.
Deletion is automatic and irreversible once the grace period ends. Integrava does not automatically export your data; export anything you need to retain before the deadline. Stripe stays active during the 30-day grace period so canceling deletion restores access. The subscription is cancelled when deletion actually runs.
We retain minimal records separately where required: billing and tax archives (amounts, Stripe identifiers, subscription dates), platform audit logs of the deletion request, and anonymised demo-abuse signals for fraud prevention. If the person who scheduled deletion later deletes their personal login account, audit records show "Deleted user" instead of their email.
10. Disconnecting OAuth integrations
Workspace owners and admins can disconnect third-party integrations (Gmail, Microsoft 365, Google Drive, Notion, Zendesk, and others) from the Integrations hub, each integration's settings page, or Settings → Integrations.
When you disconnect, you choose one of two options:
- Disconnect only — we invalidate and remove stored OAuth tokens from our servers and remove the connection. Content already imported into your workspace (for example email threads in Conversations or knowledge documents from Google Drive) remains unless you remove it separately.
- Disconnect and remove imported data — in addition to disconnecting, you can permanently remove data synced from that integration (for example Gmail email threads, Google Drive knowledge documents, or Notion/Zendesk articles). This action requires typing I confirm and is not reversible; Integrava cannot restore removed data.
Google (Gmail and Google Drive): when you disconnect we call Google's token cancellation endpoint to invalidate the refresh or access token we hold. Purging imported data removes matching knowledge documents and embeddings from your workspace.
Microsoft 365: when you disconnect we invalidate stored refresh tokens from our servers and remove local credentials. Microsoft Entra ID may retain application consent until you remove Integrava from My Apps or your administrator removes the enterprise application.
Notion and Zendesk: disconnect removes stored OAuth tokens and the sync catalog from our systems. Optional purge permanently deletes knowledge documents and embeddings imported from those sources.
11. Security
We use technical and organizational measures including encryption of sensitive credentials, workspace isolation, access controls, domain-restricted embed widgets, audit logging, and infrastructure security practices. No method of transmission or storage is completely secure; please use strong passwords and limit team access to what each role requires.
12. International transfers
Account and workspace data is hosted in the European Economic Area (AWS eu-north-1, Stockholm). When you configure an AI or search provider, or connect an integration, content needed for that feature is sent to that provider on your instructions. Those providers may process data outside the EEA. For workspace content we process as your processor, the safeguards are described in our Data Processing Addendum, including Standard Contractual Clauses where a transfer you instruct leaves the EEA.
13. Your rights
Depending on your location, you may have rights to access, rectify, erase, restrict, object to, or port your personal data, and to withdraw consent where processing is consent-based. You may also lodge a complaint with your local supervisory authority.
To exercise these rights, email contact@integrava.ai. We may need to verify your identity and, for end-customer data handled on behalf of a workspace, coordinate with that workspace's administrator.
14. Children
Integrava is a business service and is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will take appropriate steps to delete it.
15. Changes to this policy
We may update this policy from time to time. Material changes will be reflected on this page with an updated "Last updated" date. Continued use of the service after changes take effect constitutes acceptance of the revised policy where permitted by law.
16. Contact
Customer Success Point SRL — Romania, Bucharest, Drum Gura Putnei 133 Et. POD Ap. 19 Cod 032603. Unique registration code: 45173010.
Questions about this policy or our data practices: contact@integrava.ai
Law enforcement and legal-process requests: contact@integrava.ai (subject: Legal request).
Product documentation: Documentation · Terms of Service · Refund Policy · Data Processing Addendum · Subprocessors
