Privacy Policy
Version 2.0 · Last updated: 17 April 2026
Alvoru attaches great importance to the protection of personal data. This privacy policy has been drafted in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679, hereinafter: GDPR) and its implementing legislation, and describes how Alvoru collects, processes, secures and deletes personal data.
1. Data controller
The data controller within the meaning of Article 4(7) GDPR is:
Alvoru (sole proprietorship)
Owner: Yousri
Registered office: Cuijk, the Netherlands
Chamber of Commerce number: 42071779
Email: info@alvoru.com
Phone: 06-34783929
Contact for privacy matters: Yousri via info@alvoru.com. Under the GDPR, Alvoru is not required to appoint a Data Protection Officer (DPO).
2. Which personal data do we process?
Alvoru processes only personal data that is necessary to deliver our services. Depending on the service, this may include:
- Contact and company details: name, company name, email address, phone number, address, KVK number and job details.
- Account details: login credentials, password hash, session cookies, preferences.
- Conversation content: messages and conversations between end users and our AI channels (chatbot and email).
- Booking and calendar data: name, contact details, time and subject of appointments.
- Technical data: IP address, browser and operating system, timestamp, page behavior.
- Cookie data: see section 10.
- Payment data: invoice details and payment history; credit-card and IBAN data are not stored by Alvoru but processed solely by payment processor Mollie.
3. Purposes and legal grounds (Article 6 GDPR)
| Purpose | Legal basis |
|---|---|
| Performance of the Agreement and delivery of the Service | Performance of contract (Art. 6(1)(b)) |
| Invoicing, payments and administration | Legal obligation (Art. 6(1)(c)) — statutory tax retention |
| Customer service and support | Performance of contract |
| Security, fraud detection and abuse prevention | Legitimate interest (Art. 6(1)(f)) |
| Improvement of the Service and product development | Legitimate interest |
| Marketing email to existing customers about similar services | Legitimate interest (with opt-out) |
| Newsletter to non-customers | Consent (Art. 6(1)(a)) |
| Analytics cookies | Consent (cookie banner) |
For processing based on legitimate interest (Art. 6(1)(f) GDPR), Alvoru has carried out a legitimate interests assessment (LIA). Specifically for security, fraud detection and abuse prevention: Alvoru has a legitimate interest in protecting its systems and customer data. Your interests do not override this legitimate interest, because the processing is limited to technical data (IP address, timestamp), is strictly necessary to protect all users, and you are informed of it through this privacy policy.
4. Retention periods
Alvoru does not retain personal data longer than necessary for the purposes for which it was collected:
- Customer data (active): for the duration of the Agreement and up to 60 days after termination (see Terms and Conditions art. 11).
- Invoices and financial records: 7 years, in accordance with the statutory tax retention obligation.
- AI conversation logs: 12 months, unless the Client agrees a shorter period in writing.
- Marketing opt-in: until consent is withdrawn.
- Lead data (non-customer): up to 12 months.
- Technical log files and security logs: up to 12 months.
- Backups: up to 90 days.
5. Sharing with third parties and transfers
Alvoru shares personal data only with sub-processors that are strictly necessary for the service. A data processing agreement in accordance with Article 28 GDPR has been concluded with each sub-processor.
| Sub-processor | Purpose | Location / safeguard |
|---|---|---|
| Anthropic | AI text generation (Claude) — primary | US — SCCs + additional measures |
| Voyage AI | Vector embeddings for RAG search | United States (SCC) |
| OpenAI | AI text generation (GPT) — fallback | US — DPF + SCCs |
| Resend | Transactional email delivery | US — DPF-certified |
| Hetzner Online | Hosting and data storage | Germany / Finland (EU) |
| Cloudflare | CDN, DDoS protection, DNS & Email Routing | Worldwide — DPF + SCCs |
| Sentry | Error monitoring (technical logs, 30 days) | Germany (EU) |
| Meta Platforms Ireland | WhatsApp Business API (only if activated) | Ireland (EU) and US — SCCs + DPF |
| Google LLC | Workspace mail routing and Maps Platform (public business data) | US — DPF + SCCs |
| Moneybird | Invoicing and accounting | The Netherlands (EU) |
| Mollie | Payment processing | The Netherlands (EU) |
| n8n | Workflow automation (lead prospecting, self-hosted on Hetzner) | Germany (EU) — self-hosted, no external transfer |
| Litestream | Continuous SQLite replication (offsite backup to Hetzner Storage Box) | Germany (EU) — data stays within the EU |
| AbuseIPDB | IP reputation check for bot protection (IP address only, no further personal data) | US — legitimate interest, minimal data |
Transfers to countries outside the EEA take place solely on the basis of a valid adequacy decision, a DPF certification or the EU Standard Contractual Clauses, supplemented with additional technical and organizational measures where required.
6. Rights of data subjects
Under the GDPR you have the following rights:
- Access (Art. 15) — to know which data we process about you.
- Rectification and correction (Art. 16) — you have the right to have inaccurate or incomplete personal data corrected. You can submit a correction request via info@alvoru.com with a description of which data is inaccurate and what the correct data is. Alvoru processes your request within one month and confirms the correction made in writing by email.
- Erasure (Art. 17, "right to be forgotten").
- Restriction of processing (Art. 18).
- Portability (Art. 20) — to receive your data in a machine-readable format.
- Objection (Art. 21) — to processing based on legitimate interest or direct marketing.
- Withdrawal of consent (Art. 7(3)) — for processing based on consent, without affecting the lawfulness of earlier processing.
- Human intervention (Art. 22) for automated decision-making (see section 7).
You can submit a request via info@alvoru.com. Alvoru responds within one month, in accordance with Article 12(3) GDPR. To verify your identity, Alvoru may request additional information.
If you believe Alvoru is violating the GDPR, you have the right to lodge a complaint with the Autoriteit Persoonsgegevens (Postbus 93374, 2509 AJ The Hague, autoriteitpersoonsgegevens.nl).
7. Automated decision-making and AI
Alvoru's AI chatbot and email automation process messages automatically and can generate responses independently. For bookings and automated reservations, this may lead to decisions with legal effect for the end user within the meaning of Article 22 GDPR.
Under Article 22(3) GDPR, end users have the right to:
- obtain human intervention;
- express their point of view;
- contest the decision.
This right can be exercised by contacting the business that uses Alvoru's Service, or Alvoru itself via info@alvoru.com.
Deletion of chat conversations (art. 17): Visitors who have had a conversation via the AI chatbot on a website operated by Alvoru can request deletion of their chat history by sending an email to info@alvoru.com stating: the website on which the conversation took place, the approximate date, and a description of the conversation. Alvoru will process the request within 30 days. Chat data older than 90 days is automatically anonymised.
In accordance with Article 50 of the EU AI Act (2024/1689), our AI systems clearly inform end users that they are communicating with an AI system.
7a. Chatbot visitors on customer websites
Our customers deploy the Alvoru AI chatbot on their own websites. As a visitor to such a customer website, your chat conversations are processed by Alvoru as a sub-processor. In that case the customer is the data controller within the meaning of the GDPR. Alvoru processes your chat data solely on the instruction of and for the benefit of the relevant customer. See the privacy policy of the website on which you use the chatbot for more information about how that customer processes your data.
8. Security
Alvoru takes appropriate technical and organisational measures to protect personal data against loss or any form of unlawful processing (Article 32 GDPR), including:
- TLS 1.2+ encryption for all communication (HTTPS).
- Salted password hashing (bcrypt) and session management with rotation.
- Firewall and fail2ban on all servers.
- Rate limiting on APIs and login attempts.
- Minimal permissions (principle of least privilege) for service users.
- Restrictive file permissions (600) on configuration and data files.
- Automatic daily encrypted backups.
- Logging and monitoring of access to sensitive data.
- Two-factor authentication for administrative access.
- Security updates within 72 hours of disclosure of critical vulnerabilities.
9. Data breaches
A data breach is reported to the supervisory authority within 72 hours of detection, in accordance with Article 33 GDPR, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.
If the data breach entails a high risk to data subjects, Alvoru will inform the data subjects without undue delay, in accordance with Article 34 GDPR, so that they can take appropriate measures.
Alvoru maintains a register of data breaches in accordance with Article 33(5) GDPR.
10. Cookies
Alvoru uses cookies and similar techniques on the basis of applicable ePrivacy legislation:
- Functional cookies (always active, no consent required): session, preferences, CSRF protection, DDoS protection (Cloudflare).
- Analytics and marketing cookies: Alvoru does not currently place any no analytics or marketing cookies. No Google Analytics, Meta Pixel or similar tracker runs on alvoru.com. The cookie banner is present so that, if we do want to use analytics in the future, we first ask for your explicit opt-in.
You can change your cookie preferences via the link at the bottom of every page or the cookie banner. For a full overview, see the Cookie Statement.
10a. Is providing data mandatory?
You are not legally or contractually obliged to provide us with personal data, unless stated otherwise. If you do not provide data, we may not be able to deliver the service to you. For example, providing an email address is required to create an account and receive service messages, whereas providing a phone number is usually optional.
11. Changes
Alvoru may amend this privacy policy from time to time. Material changes will be announced at least 30 days before they take effect, by email to existing customers and on this page. The most current version is always available at alvoru.com/privacy.