PRIVACY POLICY

Privacy Policy

Effective date: July 28, 2026 · Last updated: July 28, 2026

Qevya is a product of Pyntexia (Pty) Ltd, a company registered in South Africa (“we”, “us”, “our”). We operate the Qevya platform, an AI-powered business management tool that helps small business owners manage client conversations, orders, invoices, and business communications across messaging channels.

This Privacy Policy explains what personal information we collect, why we collect it, how we use it, and your rights regarding your data. It applies to all users of the Qevya platform.

We are committed to compliance with the Protection of Personal Information Act 4 of 2013 (POPIA) of South Africa, the General Data Protection Regulation (EU) 2016/679 (GDPR), and the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).

1. Who We Are

Data Responsible Party / Data Controller:

Pyntexia (Pty) Ltd
South Africa
Email: legal@qevya.com

For users in the European Union, Pyntexia (Pty) Ltd acts as the data controller of your personal information. Your data is stored on servers located in Ireland (EU West, eu-west-1), within the European Economic Area.

2. Information We Collect

2.1 Information you provide directly

  • Full name and business name when creating your account
  • Email address and password (passwords are encrypted and never stored in plain text)
  • Business phone number
  • Business profile information including business type, services offered, working hours, pricing range, payment methods, delivery areas, and communication preferences
  • Messages you send through the Qevya platform
  • Channel connection details (such as WhatsApp Business number or OAuth tokens for connected messaging channels)

2.2 Information generated through your use of Qevya

  • Conversation data from connected messaging channels (WhatsApp Business, Instagram Business, Facebook Messenger, Telegram, and Viber), which Qevya processes to extract orders, invoices, and business intelligence
  • Gmail is the exception — Qevya only sends emails you've asked it to draft; it never reads your Gmail inbox. See Section 2.4.
  • Orders, invoices, tasks, and calendar entries created or extracted within the platform
  • Client profiles generated from conversation data
  • AI-generated summaries, tags, and business insights derived from your conversations

2.3 Information collected automatically

  • Authentication session data (managed by Supabase Auth)
  • Account activity logs for security purposes
  • IP address at the time of account creation, used solely to detect your approximate currency for display purposes during onboarding

We do not use cookies for tracking or advertising. We do not use Google Analytics or any third-party tracking scripts on our platform.

2.4 Gmail Account Access

Data Accessed: If you connect a Gmail account as a messaging channel, Qevya requests access to your Gmail account via Google OAuth, limited to the following scope:

  • gmail.send — to send emails you've asked Qevya to draft, on your behalf

Qevya does not request access to read your inbox, delete your emails, manage your Google Account settings, or access any other Google service.

Data Usage: These are used solely to send, at your explicit request, emails you've asked Qevya to draft — Qevya never reads, imports, or otherwise processes incoming messages from your Gmail inbox.

Data Sharing: We do not share, sell, or disclose your Gmail data or access tokens with any third party.

Data Storage & Protection: When you connect Gmail, we store: your connected email address, an encrypted access token and refresh token (AES-256 encryption), the token's expiry time, and the specific scope you granted. Encrypted tokens are stored in our database (Supabase, EU West, Ireland) and are never transmitted to Anthropic or any other service.

Data Retention & Deletion: Encrypted tokens are retained until you disconnect your Gmail account or delete your Qevya account, whichever comes first. You can disconnect your Gmail account at any time from Settings, which stops Qevya from accessing it going forward. You can also review or revoke Qevya's access directly from your Google Account at myaccount.google.com/permissions.

Limited Use Disclosure: Qevya's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

3. How We Use Your Information

PurposeLegal basis (GDPR)POPIA condition
Providing the Qevya serviceContract performanceContract
Processing conversation data to extract orders and invoicesContract performanceContract
Sending emails you've drafted via your connected Gmail accountContract performanceContract
Generating AI-powered replies and business insightsContract performance / Legitimate interestsContract / Legitimate purpose
Sending transactional emails (account verification, password reset)Contract performanceContract
Improving and maintaining the platformLegitimate interestsLegitimate purpose
Complying with legal obligationsLegal obligationLegal obligation

We do not use your personal information for advertising, profiling for third-party purposes, or any purpose not listed above.

4. Artificial Intelligence and Conversation Processing

Qevya uses artificial intelligence (provided by Anthropic, Inc.) to read, analyse, and respond to messages in your connected messaging channels. This AI processing:

This applies to your connected WhatsApp, Instagram, Facebook Messenger, Telegram, and Viber channels. Gmail is the exception: Qevya's AI never reads your Gmail inbox — it only drafts outbound emails using your business data (clients, orders, conversations from other channels), never your Gmail content.

  • Reads incoming client messages to extract business-relevant information (orders, invoices, client details, follow-up requirements)
  • Drafts replies in your configured business voice
  • Generates business insights from patterns in your conversation history

Important:Qevya processes conversation content only to extract business-relevant information on your behalf. We do not read, store, or sell the personal content of your client conversations for any purpose other than providing you with the Qevya service. Conversation content is processed by Anthropic's API under a data processing agreement that prohibits use of your data to train Anthropic's models. Because Qevya never reads your Gmail inbox, no Google user data is ever transmitted to Anthropic or any AI model, for training or any other purpose.

5. Data Sharing and Third Parties

We do not sell your personal information. We do not share your personal information with third parties for advertising purposes.

We share your data with the following service providers solely to operate the Qevya platform:

ProviderPurposeLocation
Supabase, Inc.Database, authentication, and file storageEU West (Ireland)
Anthropic, Inc.AI conversation processingUnited States
Vercel, Inc.Website hosting and deploymentGlobal CDN

Each of these providers operates under a data processing agreement and is prohibited from using your data for their own purposes. Where data is transferred to the United States (Anthropic, Vercel), such transfers are conducted under appropriate safeguards including standard contractual clauses.

6. Data Retention

We retain your personal information for as long as your account is active. When you close your account, we will delete your personal data within 30 days, except where we are required to retain it for longer by law.

Conversation data and extracted business records are retained for the duration of your subscription and deleted upon account closure.

7. Data Security

We implement industry-standard security measures to protect your personal information, including:

  • Encryption of data in transit (TLS) and at rest
  • Row-level security on all database tables, ensuring each user can only access their own data
  • Server-side authentication verification for all data access
  • Passwords stored using bcrypt hashing (never in plain text)
  • Regular security reviews of our codebase and infrastructure

Despite these measures, no system is completely secure. If we become aware of a data breach that affects your personal information, we will notify you as required by applicable law.

8. Your Rights

Under POPIA (South Africa — all users)

  • Right to access your personal information
  • Right to correct inaccurate personal information
  • Right to delete your personal information
  • Right to object to processing
  • Right to lodge a complaint with the Information Regulator of South Africa

Under GDPR (European Union users)

All POPIA rights above, plus:

  • Right to data portability
  • Right to restrict processing
  • Right to withdraw consent where processing is based on consent
  • Right to lodge a complaint with your local supervisory authority

Under CCPA/CPRA (California residents)

  • Right to know what personal information we collect, use, and share
  • Right to delete your personal information
  • Right to correct inaccurate personal information
  • Right to opt out of the sale or sharing of personal information (we do not sell or share your data)
  • Right to non-discrimination for exercising your rights

To exercise any of these rights, contact us at legal@qevya.com. We will respond within 30 days (POPIA/CCPA) or within 30 days (GDPR, extendable to 60 days for complex requests).

9. Children's Privacy

Qevya is not directed at children under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us at legal@qevya.com and we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email at least 14 days before the changes take effect. Your continued use of Qevya after that date constitutes acceptance of the updated policy.

The current version of this policy is always available on this page.

11. Contact

Pyntexia (Pty) Ltd
Email: legal@qevya.com

Information Regulator (South Africa): inforeg.org.za