Privacy Policy (GDPR)
Last updated: September 1, 2026
Drixavo is provided by Drixavo, Inc., a corporation incorporated in Delaware. This policy explains how we collect, use, share, and protect information when you use the Drixavo website, application, and related integrations.
1. Information we collect
- Account data: name, email address, organization name, and authentication credentials you provide during registration.
- Operational data: tasks, reminders, contacts, partner records, comments, and other content you add into the product.
- Usage and technical data: browser type, IP address, device information, and interaction logs required to operate, secure, and improve the service.
- Billing data: subscription and payment information handled through our billing partner. We do not store full payment card details.
- Connected service data: if you connect Google services, we may receive limited account and integration data inside the scopes you explicitly authorize.
2. How we use information
- To provide, maintain, and improve the Drixavo service.
- To support authentication, access control, billing, and product security.
- To send important service, billing, and security notifications.
- To power AI features and optional third-party integrations you enable.
3. AI processing
When AI features are enabled, task and team context may be processed by third-party AI providers configured by your organization administrator. AI processing is tenant-scoped and used only for the organization that enabled it. Customer data is not used by Drixavo to train foundation models. Disclaimer: You are interacting with an AI system. The AI may make errors or provide inaccurate information. Always verify critical business data.
4. Google services integration
If you choose to connect Google services, Drixavo will access only the scopes you explicitly authorize. Calendar access may be used to show personal calendar context in the product and support bounded assistant workflows. Google Drive access is used only when you explicitly connect files or documents for operational context. You can disconnect Google integrations at any time from product settings. Drixavo's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including Limited Use requirements.
5. Data sharing
We do not sell personal information. Data may be shared with infrastructure and service providers strictly for hosting, security, email delivery, payment processing, AI processing, and product operations. For a detailed list, see our Sub-processors page.
6. Data isolation and security
Drixavo is a multi-tenant system with organization-level isolation. Organization data is logically separated by workspace. We use encrypted connections, role-based access control, row-level security, and audit logging to protect your data. No method of transmission or storage is absolutely secure, so absolute security cannot be guaranteed.
7. Data retention
We retain data for as long as needed to provide the service and meet legal obligations. When an account is deleted, we remove or anonymize personal data within a reasonable timeframe, except where retention is required or permitted for legal, security, fraud-prevention, or operational-integrity reasons.
- Billing, invoice, and tax records may be retained for the period required by applicable accounting and tax laws.
- Security, fraud-prevention, and audit logs may be retained when necessary to protect the service, investigate abuse, and satisfy legitimate business or legal obligations.
- Operational history shared with other team members may be preserved in anonymized form so that tasks, comments, assignments, and audit trails do not break for the rest of the workspace. In those cases, personal identifiers are replaced with labels such as Deleted User.
You can request account deletion from inside the product or through our public deletion page: Account deletion instructions.
8. Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete, port, restrict, or object to the processing of your personal data. For GDPR-regulated users, lawful bases may include contractual necessity, legitimate interests, legal obligations, or consent, depending on context.
You may review or correct account information in product settings. You may also request access, correction, or deletion by contacting info@drixavo.com. We will verify and respond to requests as required by applicable law.
You can export your personal data (tasks you created, your comments, your AI messages, and profile information) in JSON format from Settings → Data Export. Organization administrators can additionally export workspace-wide data including all tasks, team members, and partner records.
9. Cookies and similar technologies
Drixavo uses essential website and application cookies for security, session continuity, and preferences. Drixavo does not use the public site for cross-site tracking, targeted advertising, or the sale of personal data, and does not authorize third parties to collect personally identifiable information about your online activities over time and across different websites for their own purposes. Because those practices are not used, browser Do Not Track and Global Privacy Control signals do not change the public site's behavior. For a more specific explanation, review our Cookie Policy.
10. Changes and contact
We may update this policy from time to time. Material changes will be posted here with a revised effective date, and we will provide account or email notice when required by applicable law. For privacy-related inquiries, contact us at info@drixavo.com or use our contact page.