Privacy Policy
Last updated: 2026-03-03
Govyn ("we", "us", "our") is operated by a company registered in Portugal, European Union. We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (GDPR) (EU 2016/679) and Portuguese data protection law (Lei n.º 58/2019).
1. Data controller
The data controller responsible for your personal data is:
Govyn
Portugal, European Union
Contact: privacy@govynai.com
2. What data we collect
2.1 Website visitors
When you visit govynai.com, we may collect:
- Usage data — pages visited, referral source, browser type, device type, and approximate location (country/region). Collected only with your consent via analytics cookies.
- Contact data — email address, if you voluntarily submit it through our waitlist or contact forms.
2.2 Govyn proxy users (self-hosted)
When you self-host Govyn, no data is sent to us. The proxy runs entirely on your infrastructure. All API requests, responses, logs, and policy data remain on your servers. We have no access to your agents' data, your LLM provider credentials, or any content processed through the proxy.
2.3 Govyn Cloud users (managed service)
If you use our managed cloud service, we process:
- Account data — name, email, company name, billing information.
- Proxy metadata — request counts, token usage, cost tracking, policy evaluation results. We do not store the content of your LLM requests or responses unless you explicitly enable replay logging.
- Replay logs — if you enable replay logging, request and response content is stored encrypted on your dedicated storage. PII redaction is applied if configured.
3. Legal basis for processing
We process personal data under the following legal bases (GDPR Article 6):
- Consent (Art. 6(1)(a)) — for analytics cookies and marketing communications. You can withdraw consent at any time.
- Contract performance (Art. 6(1)(b)) — to provide the Govyn service when you sign up for an account.
- Legitimate interest (Art. 6(1)(f)) — for security monitoring, fraud prevention, and improving our service. We balance our interests against your rights and freedoms.
4. How we use your data
- To provide and maintain the Govyn service
- To communicate with you about your account or our service
- To improve our website and product
- To comply with legal obligations
- To send you product updates (only with your consent)
5. Data sharing
We do not sell your personal data. We may share data with:
- Service providers — hosting (EU-based), payment processing, email delivery. All bound by data processing agreements (DPAs).
- Legal authorities — when required by Portuguese or EU law.
6. International transfers
We store and process data within the European Economic Area (EEA). If any sub-processor is located outside the EEA, we ensure adequate safeguards are in place through Standard Contractual Clauses (SCCs) or adequacy decisions per GDPR Chapter V.
7. Data retention
- Account data — retained while your account is active, then deleted within 30 days of account closure.
- Usage analytics — aggregated and anonymized after 26 months.
- Contact form submissions — retained for 12 months, or until you request deletion.
- Proxy logs (Cloud) — retained according to your configured retention policy, then permanently deleted.
8. Your rights (GDPR Articles 15-22)
As an EU resident, you have the right to:
- Access — request a copy of your personal data.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion of your data ("right to be forgotten").
- Restriction — restrict processing in certain circumstances.
- Portability — receive your data in a structured, machine-readable format.
- Object — object to processing based on legitimate interests.
- Withdraw consent — at any time, without affecting prior processing.
To exercise any of these rights, contact us at privacy@govynai.com. We will respond within 30 days as required by GDPR.
9. Cookies
We use cookies and similar technologies on our website. For details on which cookies we use and how to manage your preferences, see our Cookie Policy.
We only set non-essential cookies (analytics, marketing) after you provide explicit consent through our cookie banner, in compliance with the ePrivacy Directive and GDPR.
10. Security
We implement appropriate technical and organizational measures to protect your personal data, including encryption in transit (TLS 1.3), encryption at rest, access controls, and regular security reviews. The self-hosted Govyn proxy runs entirely on your infrastructure, giving you full control over data security.
11. Children
Govyn is not directed at individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at privacy@govynai.com.
12. Supervisory authority
You have the right to lodge a complaint with the Portuguese Data Protection Authority:
Comissão Nacional de Proteção de Dados (CNPD)
www.cnpd.pt
13. Changes to this policy
We may update this privacy policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. We encourage you to review this policy periodically.
14. Contact us
For any questions about this privacy policy or our data practices:
privacy@govynai.com