1. Introduction
Grovity Services LLC ("Grovity", "we", "us", or "our") is committed to protecting the privacy of the people who visit our websites ("Visitors"), the people and entities who register to use our services ("Clients"), the natural persons whose data is processed through the Grovity platform by our Clients ("Data Subjects"), and the people who attend our corporate events ("Attendees"). This Privacy Agreement describes Grovity's privacy practices regarding our websites and the related services and applications offered by Grovity (collectively, the "Service").
If you have questions or complaints regarding this Privacy Agreement or our practices, please contact us at info@grovity.ai.
2. Covered Websites and Services
This Privacy Agreement covers the information practices of websites and services that link to it, including without limitation https://www.grovity.ai, https://app.grovity.ai, https://api.grovity.ai, and any associated subdomains, applications, APIs, and channels operated by Grovity.
Our websites may contain links to third-party websites. Grovity is not responsible for the information practices or content of such third-party websites and encourages you to review the privacy statements of any external sites you visit.
3. Information Collected by Grovity
Grovity collects information from Visitors, Clients, Data Subjects, and Attendees through sources that include, but are not limited to, content syndication, website registration forms, webinars, conference registration forms, customer support channels, and the use of the Service itself.
3.1. Personal Information You Provide to Us
Grovity receives and stores any information entered when you express interest in obtaining more information about the Service, register to use the Service, or otherwise interact with our channels. "Personal Information" may include:
Contact information: name, email addresses, phone numbers, physical or postal addresses.
Identification information: government-issued ID number, tax identification number, professional credentials.
Demographic information.
Account information: username, password (stored as a hash), preferences.
Billing and financial information: billing contact, billing address, and payment instrument details processed by certified payment providers.
Content uploaded to the Service: text, files, audio, images, contact lists, and any data the Client chooses to process through the Platform.
Communications: messages exchanged with Grovity support, sales, or commercial teams.
3.2. Information Collected Automatically
When you visit our websites or use the Service, Grovity may automatically collect:
Technical data: IP address, device identifiers, browser type, operating system, language settings.
Usage data: pages visited, features used, timestamps, referring URLs, click paths.
Cookies and similar technologies (see Section 5).
4. Other Third-Party Tracking
Grovity contracts with third parties who use web beacons, pixels, and scripts to help operate and improve the content of our websites. Grovity does not sell Personal Information to third parties but may link information collected from third-party tracking to Personal Information of Visitors for analytics and marketing purposes, in accordance with applicable law.
5. Cookies
Grovity uses cookies to enable functionality, measure performance, and personalize content on our websites. Some cookies are essential for the operation of the Service; others (such as analytics and marketing cookies) are optional and may be configured through the cookie banner or your browser settings.
Most browsers allow you to manage or disable cookies. Disabling certain cookies may affect the functionality of our websites and the Service.
Cookies set by third-party providers integrated with Grovity (such as analytics or payment partners) are governed by the privacy policies of those providers.
6. Data Controller and Contact
Grovity Services LLC
[REGISTERED ADDRESS], United States
Email: info@grovity.ai
Website: https://www.grovity.ai
7. Objective and Scope
Grovity recognizes the importance of the security, privacy, and confidentiality of the personal information of our Clients, employees, suppliers, and Data Subjects, and is committed to its protection and adequate treatment in accordance with the personal data protection regime applicable to each country where we operate.
The objective of this Privacy Agreement (the "Policy") is to communicate to our Clients, employees, suppliers, Visitors, and, in general, to the holders of personal information, the categories of data collected, the purposes of processing, the rights that assist data subjects, and the procedures to exercise such rights.
Any form of processing of personal data carried out by Grovity will uphold the principles of lawfulness, fairness, transparency, purpose limitation, storage limitation, data minimization, accuracy, integrity, and confidentiality, in accordance with Regulation (EU) 2016/679 (GDPR), the California Consumer Privacy Act (CCPA), Colombian Law 1581 of 2012 and Decree 1377 of 2013 (Habeas Data), and the Brazilian General Personal Data Protection Law (LGPD, Law 13,709/2018).
8. Definitions
For the interpretation of this Policy, the following definitions apply:
Authorization: prior, express, and informed consent of the Data Subject to carry out the processing of personal data.
Database: organized set of personal data subject to processing.
Personal Data: any information associated with an identified or identifiable natural person.
Sensitive Data: data that affects the privacy of the Data Subject or whose improper use may generate discrimination, such as data revealing racial or ethnic origin, political opinions, religious beliefs, trade-union membership, health, sexual life, biometric data, or financial data.
Data Controller: the natural or legal person who, alone or jointly, decides on the database and/or processing of personal data.
Data Processor: the natural or legal person who processes personal data on behalf of the Data Controller.
Habeas Data: the right of every Data Subject to know, update, rectify, or oppose the processing of their personal data.
Processing: any operation or set of operations performed on personal data, such as collection, recording, storage, use, circulation, or deletion.
Transmission: the communication of personal data by the Data Controller to a Processor, whether within or outside the national territory, so that the Processor, on behalf of the Controller, processes personal data.
9. Principles Applicable to the Processing of Personal Data
Grovity is committed to the following principles in the processing of personal data:
Legality: processing follows legitimate purposes and complies with applicable law.
Purpose: data is processed for previously informed legitimate purposes.
Freedom and Consent: Grovity processes data only after the Data Subject has given prior, express, and informed consent, except where another legal basis applies.
Veracity or Quality: data must be truthful, complete, accurate, updated, verifiable, and intelligible.
Transparency: Data Subjects can obtain information about the data Grovity holds about them.
Access and Restricted Circulation: processing is carried out only by authorized persons.
Security: Grovity applies reasonable technical, human, and administrative measures aligned with SOC 2 and ISO 27001 to protect personal data.
Confidentiality: all personnel involved in processing are bound to confidentiality, including after the end of their relationship with Grovity.
Accountability: Grovity is accountable for compliance and can demonstrate it.
10. Grovity as Data Controller — Duties
When Grovity acts as Data Controller, it complies with the following duties:
Guarantee the Data Subject the full and effective exercise of habeas data rights.
Request and keep, under the legally required conditions, a copy of the relevant authorization granted by the Data Subject.
Properly inform the Data Subject about the purpose of collection and the rights afforded by the authorization.
Keep information under security conditions that prevent adulteration, loss, unauthorized consultation, use, or access.
Process queries and claims under the terms of applicable law.
Maintain an internal procedures manual for habeas data attention.
Notify the data protection authority of relevant security breaches as required by law.
11. Grovity as Data Processor
In its capacity as Data Processor for personal data submitted by Clients through the Platform, Grovity will:
Verify that the Client (acting as Data Controller) is authorized to provide the personal data.
Guarantee Data Subjects the full and effective exercise of habeas data rights.
Keep the information under appropriate security conditions and isolated per tenant.
Timely update, rectify, or delete data following the Controller's instructions.
Process queries and claims under the terms of applicable law.
Allow access to information only to persons authorized by the Data Subject or empowered by law.
Notify the Client without undue delay (and within seventy-two (72) hours of becoming reasonably aware) of any security incident affecting personal data processed on behalf of the Client.
Refrain from using Client personal data for purposes other than those instructed by the Controller.
Grovity's role as Data Processor will be formalized through a Data Processing Addendum (DPA) when required by applicable law (including, where applicable, the GDPR Article 28 obligations and Standard Contractual Clauses for international transfers).
12. Temporary Limits to the Processing of Personal Data
Grovity will only collect, store, use, or circulate personal data for as long as is reasonable and necessary in accordance with the purposes that justified the processing, taking into account legal, administrative, accounting, fiscal, and historical retention requirements. Once the purpose has been fulfilled and absent any legal obligation to retain the data, Grovity will delete the personal data in its possession.
The Data Subject may, at any time, revoke the consent given for the processing of their personal data, unless Grovity is legally or contractually required to continue processing the information, by sending a written communication to info@grovity.ai with a copy of an identification document.
13. Purposes of Processing
Grovity processes personal data for the purposes listed in this section, always consistent with its corporate purpose and the ordinary course of its activities. Specific purposes will be informed to the Data Subject at or before the time of collection.
13.1. General Purposes
Applicable to all Data Subjects who have authorized the processing of their personal data:
Confirm, comply with, and provide the services and/or products purchased, directly and/or with the participation of third-party providers.
Inform about material changes to this Policy.
Establish and manage the pre-contractual, contractual, commercial, labor, civil, or any other relationship arising by virtue of the fulfillment of a legal or contractual obligation.
Respond to requests, queries, claims, and/or complaints from the holders of personal information through the channels enabled by Grovity.
Transfer or transmit personal data to judicial and/or administrative authorities or to third-party providers when required for fulfillment of legal or contractual obligations.
13.2. Candidates for a Vacancy
Recruitment, selection, and hiring processes, including competency tests and reference checks.
13.3. Employees
Execution of the employment relationship, payroll, benefits, social security, training, performance assessment, work tool assignment, and compliance with labor obligations.
13.4. Suppliers and Contractors
Management of the contractual relationship, payment processing, evaluation of services, compliance with legal obligations, and access control.
13.5. Clients and Commercial Prospects
Evaluation, registration, contracting, provision of services, customer support, loyalty programs, marketing communications (subject to opt-in where required), satisfaction surveys, statistical analysis, and credit risk assessment.
13.6. Data Subjects Reached Through the Platform by Our Clients
When a Client uses Grovity to interact with their own customers, leads, or third parties, Grovity acts as a Data Processor and processes the Data Subject's personal data exclusively to provide the contracted Service to the Client and in accordance with the Client's instructions. The Client (as Data Controller) is responsible for: (i) obtaining all necessary legal bases and authorizations; (ii) informing the Data Subject of the processing; and (iii) responding to data subject rights requests, with reasonable assistance from Grovity.
14. Special Requirements for Sensitive Data
Grovity identifies sensitive data that may be collected or processed and applies enhanced controls including reinforced security measures, restricted access, and stricter retention and authorization controls.
15. Personal Data of Minors
Grovity's services are not directed at children. Processing of personal data of minors will only occur when authorized by the legal representative, respecting the best interests of the child, their fundamental rights, and their opinion to the extent reasonably possible.
16. Transmission of Personal Data to Third Parties
Grovity does not sell, license, or disclose Personal Information to third parties except in the following cases:
When the Data Subject has expressly authorized it.
When it is necessary to enable our contractors or agents (subprocessors) to provide the services entrusted to them, including infrastructure providers, AI model providers, messaging providers, analytics providers, payment processors, and integration partners.
When it is necessary for the effective provision of the contracted Service.
When it is necessary for the management of a merger, consolidation, acquisition, divestiture, or other restructuring.
When required or permitted by law or competent authority.
When Grovity transmits personal data to Processors located in Colombia or other jurisdictions, it must rely on (i) prior, express, and informed authorization from the Data Subject, or (ii) a personal data transmission contract that contains the requirements set out in Article 2.2.2.25.5.2 of Decree 1074 of 2015. For transfers from the European Economic Area, Grovity uses Standard Contractual Clauses (SCCs) adopted by the European Commission and complementary measures where appropriate.
17. Security, Integrity, and Confidentiality
Grovity has adopted technical, human, and administrative measures necessary and adequate to protect records containing personal information against adulteration, loss, unauthorized consultation, fraudulent access, or unauthorized use. These measures are aligned with SOC 2 and ISO 27001 principles and include:
Encryption in transit using TLS 1.2 or higher (with TLS 1.3 preferred).
Encryption at rest using AES-256 (managed by cloud providers and, for the most sensitive credentials, with additional application-level encryption).
Strict per-tenant isolation, ensuring that data of one Client cannot be accessed by another Client.
Role-based access controls, multi-factor authentication, and access logging for personnel.
Continuous monitoring, vulnerability management, and periodic penetration testing.
Regular backups stored in encrypted form in geographically redundant cloud infrastructure.
Personnel processing personal data are bound by signed confidentiality obligations and follow Grovity's security protocols.
18. Rights of Personal Data Subjects
Data Subjects may exercise the following rights before Grovity, subject to applicable law:
Right of access: to know whether their personal data is being processed and to obtain a copy.
Right to rectification: to request correction of inaccurate or incomplete data.
Right to deletion: to request deletion of personal data when no longer necessary or when the legal basis has been revoked.
Right to restriction: to request the restriction of processing in certain circumstances.
Right to portability: to receive their personal data in a structured, commonly used, machine-readable format.
Right to object: to oppose certain types of processing for reasons related to their particular situation.
Right to withdraw consent: at any time, without affecting the lawfulness of prior processing.
Right to lodge a complaint with the competent data protection authority.
These rights may be exercised by the Data Subject, their attorney, or their successor in title. For minors, rights must be exercised through the legal representative.
19. How to Exercise Habeas Data Rights
Data Subjects may exercise their habeas data rights at any time through the following channels:
Email: info@grovity.ai
Website: https://www.grovity.ai
Requests must include the Data Subject's identification, a clear description of the request, and a means of contact. Grovity may request additional information to verify identity.
20. Procedures for Queries and Complaints
Query procedure: queries will be answered within a maximum term of ten (10) business days from the date of receipt. When it is not possible to attend the query within said term, Grovity will inform the interested party, stating the reasons for the delay and the date on which the query will be attended, which may not exceed five (5) additional business days.
Claim procedure: claims will be processed under the following rules:
The claim will be submitted in writing, with the identification of the Data Subject, a description of the facts, the address, and supporting documents.
If the claim is incomplete, the interested party will be required within five (5) business days to correct the deficiencies. After two (2) months without a response, the claim will be deemed withdrawn.
A caption "claim in process" will be included in the database within two (2) business days of receipt and maintained until resolved.
The maximum term to resolve the claim is fifteen (15) business days, extendable by up to eight (8) additional business days when justified.
21. International Transfers
Grovity hosts its infrastructure primarily in cloud regions located in the United States (and, where applicable, in additional regions configured for specific Clients). International transfers of personal data are carried out with appropriate safeguards, including Standard Contractual Clauses for GDPR transfers, the contractual mechanisms required by Colombian Law 1581/2012 and Decree 1074/2015, the international transfer rules of the Brazilian LGPD, and equivalent mechanisms in other jurisdictions.
22. Specific Information about AI Models
Grovity uses both proprietary processing and third-party AI models to deliver the Service. To ensure transparency and user control:
Third-party AI providers: Grovity integrates with leading AI providers under enterprise-grade plans (including OpenAI, Anthropic, Google, and others). Specific providers in use may vary by tenant configuration.
Data shared with providers: Grovity transmits the minimum data necessary to operate the Service (such as the conversation context required to generate a response).
Purpose: to generate responses, classify intents, transcribe audio, synthesize voice, or perform retrieval over Client knowledge bases.
No training on Client data: enterprise-grade plans contracted by Grovity incorporate "Zero Data Retention for Training" or equivalent terms by default, meaning Client Content is not used to train the providers' general models.
Strict tenant isolation: data from one Client is not used to optimize agents, knowledge bases, or models serving other Clients.
Opt-in controls: where applicable, Grovity offers Clients granular controls to limit or reject specific data-sharing options.
23. Explicit Consent and AI Disclosures
Users are informed about the use of AI models and any potential data sharing involved through clear notices within the Service and in this Privacy Agreement. Where required by law, Grovity obtains explicit opt-in consent before sharing data with third-party AI models for purposes that are not strictly necessary to operate the Service.
24. Marketing Communications and Opt-Out
Grovity may send commercial communications about products, services, events, and promotions where permitted by law and where the User has consented. Every commercial communication includes an unsubscribe option. Grovity processes unsubscribe requests as promptly as reasonably possible, generally within fifteen (15) business days.
25. Modifications to this Policy
This Policy may be adjusted or modified at any time. Grovity will publish the latest version on its corporate website and, for material changes, will notify Users in accordance with the Terms and Conditions.
26. Data Protection Officer
Grovity has designated an internal Data Protection Officer ("DPO") responsible for implementing the policies and procedures adopted to comply with applicable personal data protection laws. The DPO can be reached at info@grovity.ai.
27. Date of Entry into Effect
This Policy is effective from the date indicated at the top of this document.
28. Annex — Specific Provisions for the European Union and the European Economic Area
For Visitors, Clients, and Data Subjects located in the European Union or the European Economic Area, the following provisions apply in addition to the body of this Policy:
28.1. Method of Obtaining Personal Data
Grovity collects personal data each time the Service is used, including interactions with our websites, applications, customer support channels, and through Clients who use the Platform to engage with their own end-users.
28.2. Data Collected and Processed
Categories of personal data that may be processed include:
General identification data: name, date of birth, identification or ID number, profession, postal and/or electronic address.
Socio-economic data: billing information, payment instrument data processed by certified payment providers.
Sensitive data: biometric data (such as images, voices, fingerprints) only when strictly necessary and with appropriate legal basis.
Technical data: IP address, cookies, device location.
28.3. Purposes
In addition to the general purposes listed in Section 13, Grovity will process personal data of EU/EEA Data Subjects for:
Performance of contractual obligations.
Compliance with legal obligations.
Marketing activities and personalization (subject to opt-in consent where required).
Loyalty programs.
Analysis and processing through Artificial Intelligence.
28.4. Retention Period
Personal data provided by Clients or Users will be kept as long as the commercial or contractual relationship is in force. Notwithstanding the foregoing, data may be retained for the years necessary to comply with legal obligations (especially accounting, fiscal, and tax obligations), up to ten (10) years. For marketing purposes, personal data will be kept until the User requests its deletion or withdraws consent.
28.5. Legal Bases
The legal bases for processing include: (i) performance of a contract; (ii) compliance with a legal obligation; (iii) legitimate interest (such as fraud prevention or service improvement); and (iv) consent. Users may withdraw consent at any time without prejudice to the lawfulness of prior processing.
28.6. Recipients
Personal data may be communicated to: (i) service subprocessors (under data protection agreements); (ii) commercial partners (when required for service delivery); (iii) competent authorities (when required by law). Grovity will not sell personal data to third parties.
28.7. Rights and Complaints
EU/EEA Data Subjects may exercise all rights set forth in Section 18, including the right to lodge a complaint with the competent data protection authority of their country of residence.
29. Annex — Specific Provisions for Colombia
Processing of personal data of Data Subjects located in Colombia is carried out in accordance with Law 1581 of 2012, Decree 1377 of 2013, and applicable regulations of the Superintendencia de Industria y Comercio (SIC). Data Subjects may file complaints before the SIC after exhausting the channels enabled by Grovity.
30. Annex — Specific Provisions for Brazil (LGPD)
Processing of personal data of Data Subjects located in Brazil is carried out in accordance with the Lei Geral de Proteção de Dados (LGPD, Law 13,709/2018). Data Subjects in Brazil have the rights set forth in Article 18 of the LGPD, including confirmation of processing, access, correction, anonymization, blocking or deletion of unnecessary or non-compliant data, portability, deletion of data processed with consent, information about sharing, and revocation of consent. Complaints may be filed before the Autoridade Nacional de Proteção de Dados (ANPD).
31. Annex — Specific Provisions for the United States (CCPA / CPRA)
California residents have the rights set forth in the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), including the right to know, the right to delete, the right to correct, the right to opt-out of the sale or sharing of personal information, and the right to non-discrimination for exercising these rights. Grovity does not sell personal information of California residents.
32. Validity
This Privacy Agreement is effective from the date of its publication and supersedes any prior privacy notice for the relationships it governs.
Grovity Services LLC
[REGISTERED ADDRESS]
info@grovity.ai | https://www.grovity.ai