Privacy Policy
Effective date: 11 August 2026 · Last updated: 11 August 2026
This policy explains what personal data Orvi processes, why, where it is stored,
how long it is kept, and how it can be deleted. It covers data we receive through
the WhatsApp Business Platform and the Instagram Messaging API.
1. Who we are
Orvi is operated by Individual Entrepreneur Emil Iskandarov,
registered in Georgia, identification number 12001051056
("Orvi", "we", "us").
Contact for any privacy request or question:
emiliskanderov@gmail.com.
2. What Orvi does, and our role
Orvi is a booking and client management platform for service businesses. A business
that uses Orvi (a "Business Client") connects its own WhatsApp Business account and
Instagram professional account, and Orvi helps it receive and answer messages from
its customers, manage bookings and keep a client list.
This gives us two distinct roles, and they matter for your rights:
-
For the account data of the Business Client itself, we are the
data controller: we decide why and how that data is processed.
-
For messages and contact details of the Business Client's own customers
("End Customers"), we act as a data processor. The Business
Client is the controller: it decides what is collected and for what purpose,
and we process that data only on its instructions.
If you are an End Customer, the business you messaged is your first point of
contact. You may also write to us directly and we will act on the request or pass
it to the responsible Business Client without undue delay.
3. What data we process
3.1 Business Client account data
- name of the business and of the person operating the account;
- email address and phone number;
- identifiers of the connected accounts: Facebook Page ID, Instagram professional
account ID, WhatsApp Business phone number and phone number ID;
- access tokens issued by Meta that allow Orvi to send and receive messages on
behalf of the Business Client;
- subscription and payment records.
3.2 Message data received through Meta platforms
- the content of messages exchanged between the Business Client and its End
Customers on WhatsApp and Instagram, including text and attached media;
- message metadata: timestamps, direction, delivery and read status, message and
conversation identifiers;
- the End Customer's identifiers as provided by the platform: WhatsApp phone
number, Instagram username and platform-scoped user ID, and profile name.
3.3 End Customer data held in the Business Client's records
- name and contact details entered or confirmed during a conversation;
- bookings: service, date and time, assigned staff member, status;
- notes the Business Client adds about the customer or the booking.
3.4 Technical data
- IP address, browser type and request logs of the web interface;
- diagnostic and error logs needed to keep the service running.
We do not ask for and do not intentionally collect special
categories of data — health, biometric, religious or political data. Please do not
send such data through the service. If it reaches us inside message content, it is
stored and deleted under the same rules as any other message data.
4. How we receive data from Meta
Data described in section 3.2 reaches us only after the Business Client explicitly
connects its accounts and grants the corresponding permissions to Orvi through
Meta's own login and authorisation flow. Messages are delivered to us by Meta
through webhooks, and we send replies back through Meta's APIs.
A Business Client can withdraw those permissions at any time in its Facebook or
Instagram settings. After that we stop receiving new messages immediately. Data
already stored is deleted as described in section 8 and in our
Data Deletion Instructions.
5. Why we process data, and on what legal basis
-
To provide the service — deliver and display messages, manage
bookings and client records, send booking confirmations and reminders.
Legal basis: performance of a contract with the Business Client; for End
Customer data, the instructions of the Business Client as controller.
-
To operate and secure the platform — authentication, backups,
fraud and abuse prevention, diagnosing failures.
Legal basis: our legitimate interest in a working and secure service.
-
To support our users — answering questions and investigating
reported problems. Legal basis: performance of a contract and legitimate interest.
-
To meet legal obligations — accounting and tax records.
Legal basis: compliance with a legal obligation.
We do not sell personal data, do not share it with data brokers,
and do not use data obtained through WhatsApp or Instagram for advertising,
ad targeting, profiling or for building any product other than the service
described here.
6. Who we share data with
-
Meta Platforms — as the operator of the WhatsApp Business
Platform and Instagram Messaging API. Message content necessarily passes
through Meta's infrastructure in order to be delivered.
-
Our hosting provider — Hetzner Online GmbH, Germany, which
provides the servers on which the service runs. Hetzner acts as our
sub-processor and has no independent right to use the data.
-
Public authorities — only where we are legally required to
disclose data, and only to the extent required.
We do not transfer data to any other third party without a legal basis and, where
required, the instruction or consent of the responsible controller.
7. Where data is stored and how it is protected
All service data is stored on servers located in Germany (European
Union), operated by Hetzner Online GmbH. Traffic between your browser or
Meta's servers and ours is encrypted with TLS. Access to production systems is
limited to the operator of Orvi and protected by key-based authentication.
Access tokens and credentials are stored separately from application data and are
not exposed in the user interface.
No system is perfectly secure. If a data breach occurs that is likely to affect
your rights, we will notify the affected Business Clients and the competent
authority as required by applicable law.
8. How long we keep data
- Message content and message metadata — 12 months from the date
the message was received or sent, then automatically deleted.
- Bookings and client records — for as long as the Business
Client's account is active, and 90 days after the account is closed.
- Business Client account data and access tokens — for the
duration of the account. Tokens are revoked and deleted immediately when the
account is disconnected or closed.
- Technical and diagnostic logs — 90 days.
- Backups — kept on a rolling basis for up to 30 days, after
which deleted data disappears from backups as well.
- Accounting and tax records — for the period required by
Georgian tax and accounting legislation, regardless of any deletion request.
These records contain billing data, not message content.
An explicit deletion request is honoured earlier than these periods — see
section 10.
9. Your rights
Subject to applicable law, you have the right to:
- obtain confirmation of whether we process your data, and receive a copy of it;
- have inaccurate data corrected;
- have your data deleted;
- restrict or object to processing;
- receive your data in a structured, machine-readable format;
- withdraw consent at any time, where processing is based on consent, without
affecting processing already carried out;
- lodge a complaint with a supervisory authority. In Georgia this is the Personal
Data Protection Service; in the EU/EEA, the data protection authority of your
country of residence.
To exercise any of these rights, write to
emiliskanderov@gmail.com. We answer
within 30 days. We may ask for information confirming that the request comes from
you or from an authorised person — for example, that you control the phone number
or Instagram account concerned.
10. Deleting your data
Deletion is described step by step on a separate page:
Data Deletion Instructions. In short: send a request
to emiliskanderov@gmail.com, and the
data is deleted within 30 days, with an email confirming that it is done.
11. Children
Orvi is a tool for businesses and is not directed at children. We do not knowingly
process data of persons under 16. If we learn that such data has reached us, we
delete it.
12. International transfers
We are established in Georgia and our servers are in Germany, so data is
transferred between these countries. Where data of individuals in the EU/EEA is
transferred outside it, we rely on the safeguards provided by applicable data
protection law. Meta processes message data under its own terms and its own
transfer mechanisms.
13. Changes to this policy
We may update this policy. The effective date at the top always shows the current
version. If a change materially affects how we handle personal data, we notify
Business Clients by email before it takes effect.
14. Contact
Individual Entrepreneur Emil Iskandarov, Georgia, ID 12001051056
emiliskanderov@gmail.com