GDPR & Data Rights
Your data rights and how to exercise them.
- Last updated
- Entity
- The Growth Locker FZC · SPC Freezone, Sharjah, United Arab Emirates
Interim policy, pending final legal review. This is a good-faith interim version. Questions: [email protected]
Who we are
Cervito is a service of The Growth Locker FZC, SPC Freezone, Sharjah, United Arab Emirates. Our production application and database are hosted in the European Union (currently the Netherlands).
Who is responsible for your data
If you chatted with the associate on a store, the store (the merchant) is the controller of your data and Cervito is the processor acting on the merchant's behalf. If you are a Cervito merchant, The Growth Locker FZC is the controller of your account data. See our Privacy Policy and DPA.
You're talking to an AI
The associate is an AI assistant, not a human. See our AI disclosure. It removes email addresses, phone numbers, and card numbers from conversation text before sending it to our AI provider, but it does not remove names you type, so please don't enter sensitive details in the chat.
Your rights
If you are in the EU, EEA, or UK, you have the right to access, correct, delete, restrict, or object to the processing of your personal data, and to data portability. California residents have access and deletion rights, and we do not sell or share personal information.
How to exercise them
- Shoppers (fastest route): use the self-service portal to get a copy of, or delete, your data. After you verify control of your email address, the request runs across every Cervito-powered store that holds that email. Exports are delivered to you; erasure is executed across those stores.
- By email: [email protected] with the email or session associated with your data and the store domain. We respond within the timelines the law requires.
Shopify GDPR webhooks (and what each one does)
For Shopify stores, Cervito honors all three mandatory webhooks within Shopify's stated timelines:
customers/redact: deletes the relevant customer data automatically.shop/redact: purges the whole store's data when a store uninstalls.customers/data_request: compiles the export and forwards it to the merchant to deliver to the shopper. This webhook does not deliver directly to the shopper. The merchant must forward it. For a copy delivered directly to you, use the self-service portal above.
Other platforms: these automatic webhooks are a Shopify feature. For a connected Magento store, erasure is via the self-service portal and a written request, not a platform webhook.
What we retain after erasure
We delete conversation transcripts, analyses, attribution data, and contact records, and anonymize the visitor profile. We may retain a minimized order record (reference, amount, date, with personal identifiers removed) where the store, as controller, is legally required to keep it for its own financial records.