Lashvae AI v1.0 is live - train agents in minutes. Get Started
Lashvae AI/Legal & Compliance Documents

Privacy Policy

Lashvae Technologies Ltd. · Effective from: 27 July 2026 · Version 1.0

Lashvae Technologies Ltd. ("Lashvae", "we", "us", "our") is a company registered in the United Kingdom, with its office at Office 18036, 182–184 High Street North East, Ham, London, E6 2JA.

We provide an AI-powered inbox that helps businesses manage messages from channels such as Instagram, WhatsApp, Facebook, Telegram, YouTube, and Google Maps in one place.

This Notice explains what personal data we collect, why we collect it, and what rights you have over it. It applies to visitors to our website, our business customers, and the end-users who message our customers through the Lashvae platform. For end-user message data, our business customers act as the data controller and we act as their data processor under a Data Processing Agreement. For your account, billing, and website visitor data, we act as the data controller.

For purposes of the General Data Protection Regulation (GDPR) and other applicable data protection laws, we rely on a number of legal bases to process your Personal Data:

  • The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018;
  • The EU General Data Protection Regulation (GDPR), where it applies to individuals located in the EU;
  • India's Digital Personal Data Protection Act, 2023 ("DPDPA") once the DPDPA enters into effect, and rules issued thereunder. Further, the term "data controller" includes "data fiduciaries," and the term "data subject" includes "data principal," both as defined in the DPDPA.
  • Where our business customers or their end-users are located in other jurisdictions (for example, US states with comprehensive privacy laws), we assess and, where required, comply with those laws as well.

Where these laws use different terms for the same thing, we use the plain-English version in this Notice (for example, we say "we" instead of "Data Controller" or "Data Fiduciary").

a. Information you give us directly

  • Account details: name, email address, phone number, company name, billing address, and payment information.
  • Files or documents you upload to use our services.

b. Information created when you use our service

  • Messages and conversation details (timestamps, status, who was involved).
  • Analytics data about which features are used, and error logs.
  • Lead scores, customer intent, and engagement metrics generated from conversations.

c. Technical information

  • IP address, device type, browser, and operating system.
  • Session IDs, login (authentication) tokens, and cookie identifiers (if cookies are enabled in future).
  • The web page you came from, and how you interact with our platform.

d. Information you choose to give us (optional)

  • Consent to let us use conversation data to train AI models. Where the conversation involves an end-user, we require our business customer to obtain the end-user's consent (or rely on another valid legal basis) before enabling this feature, in addition to the business customer's own opt-in.
  • Marketing preferences, or participation in beta programs.

Important:We do not read the content of your customers' conversations for any purpose other than delivering the service to you, unless you've given clear, explicit consent (for example, for AI training). Because our Service processes free-text messages, special category (sensitive) data may incidentally be present within message content (for example, if an end-user mentions health information). We do not deliberately seek to collect sensitive personal data, and we apply access controls to limit exposure of message content.

We collect information from:

  • Our business customers and their end-users;
  • Our website and account sign-up forms;
  • Social media platforms and APIs connected to your account (e.g., Instagram, WhatsApp, Facebook, Telegram, YouTube, Google);
  • Bookings and support requests; and
  • Technical logs generated automatically when you use our platform.

We use personal data for the purposes below. Under the GDPR, every use of personal data needs a "legal basis" — a lawful reason recognised by the law. We've set these out here for transparency.

What we doWhyGDPR legal basisDPDPA basis
Creating and managing your account, providing the dashboard, authenticating usersTo deliver the service you've signed up forPerformance of a contract (Art. 6(1)(b))Consent under Section 6, or, where applicable, a legitimate use enumerated under Section 7
Managing conversations, automated & manual customer support, bookings, FAQsCore service deliveryFor our business customers: Performance of a contract (Art. 6(1)(b)). For end-users: processed by us on our business customer's behalf as processor — the business customer's own legal basis with its end-user appliesConsent
Billing, invoicing, and subscription managementTo charge you correctly and keep accurate recordsPerformance of a contract (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c))Consent; legitimate use for specified purpose
Product updates, support messages, security alerts, administrative noticesTo keep you informed and secureLegitimate interests (Art. 6(1)(f))Consent
Marketing communicationsTo tell you about relevant offersConsent (Art. 6(1)(a))Consent
Analytics, lead scoring, generating business insights, detecting anomaliesTo improve the platform and keep it secureLegitimate interests (Art. 6(1)(f))Consent / legitimate use
Using conversation content to train AI modelsOnly where you've opted inConsent (Art. 6(1)(a))Consent
Security monitoring, fraud and abuse preventionTo protect our systems and usersLegitimate interests (Art. 6(1)(f))Legitimate use
Complying with tax, accounting, and other legal obligationsBecause the law requires itLegal obligation (Art. 6(1)(c))Legitimate use (compliance with law)

Where we rely on your consent, you can withdraw it at any time by contacting us at privacy@lashvae.com, without affecting anything we did before you withdrew it. Please note that where your data has already been used to train an AI model, withdrawing consent stops further use of your data going forward but cannot remove its influence on a model already trained.

We do not sell your personal data to anyone.

We may share personal data with:

  • Our own staff — support and engineering teams who need it to run the service.
  • Service providers we've contracted with (and who are bound by confidentiality/NDA obligations) — such as hosting providers, email providers, AI providers, payment processors, and analytics providers.
  • Connected platforms you choose to link to your account — such as Instagram, Facebook, Telegram, YouTube, and Google.
  • Enterprise customers, limited strictly to that enterprise customer's own account data — we do not share one customer's data with another customer, where this is part of a specific contractual arrangement for custom services.
  • Legal or regulatory authorities, where we're required to by law.

All third parties we work with are required to protect your data and use it only for the purposes we specify.

How we share it:We share only the data each recipient needs to do its job — for example, our payment processor receives billing details but not your conversation content, and our hosting provider stores data securely on our behalf under a data processing agreement. We don't hand over full, unrestricted access to your data to any third party, and none of this sharing is for the third party's own marketing purposes.

Some of our service providers (for example, cloud hosting on AWS EU or US regions) may store or process data in a country other than the one you live in.

Where we transfer personal data out of the UK or EU, we put appropriate safeguards in place, such as Standard Contractual Clauses, the UK International Data Transfer Addendum, or reliance on an applicable adequacy decision. Where we transfer personal data out of India, we do so consistently with the requirements of the DPDPA, including by not transferring data to any country restricted by the Central Government from time to time.

  • Account data: kept for as long as your subscription is active, plus 90 days after cancellation.
  • Conversation logs: kept for 12 months by default. Enterprise customers can request a custom retention period. If your account is cancelled before the 12-month period ends, conversation logs are deleted no later than 90 days after cancellation, consistent with our account data retention above.
  • Backups: may retain copies for up to 90 days after deletion, for operational continuity, even after you've asked us to delete your data elsewhere.

You can ask us to delete your data at any time by emailing privacy@lashvae.com.

Depending on where you live, you may have the following rights over your personal data:

  • Access — the right to request a copy of the personal data we process about you, subject to certain exceptions and conditions.
  • Correction — the right to request that we correct inaccurate personal data we retain about you.
  • Erasure — the right to request that we delete personal data collected from you when you use our Services, subject to certain exceptions.
  • Restriction — ask us to limit how we use your data in certain situations.
  • Portability — ask us for your data in a portable, machine-readable format.
  • Objection — object to us using your data for direct marketing, or on grounds relating to your particular situation.
  • Withdraw consent — where we rely on consent, withdraw it at any time.
  • Grievance redressal/nomination — under the DPDPA, you can raise a grievance about how we handle your data, and nominate another individual to exercise your rights in the event of your death or incapacity.
  • Complain to a regulator — you also have the right to complain to the data protection supervisory authority responsible for us. You can contact the data protection authority in your place of residence, which will then forward your request to the competent authority.

To exercise any of these rights, contact us as outlined below. We will respond within reasonable time under the appropriate law. However, please be aware that these rights are subject to certain limitations; we may decline a request if we have a lawful reason for doing so. That said, we strive to prioritize the protection of personal data, and comply with all applicable privacy laws.

Process for exercising your data protection rights

To exercise your rights, you or an authorized agent may submit a request by contacting us. After we receive your request, we may verify it by requesting information sufficient to confirm your identity (e.g. email address, billing details). Where a third party representative submits a request on behalf of a data subject, we require evidence of authorization to act on behalf of the data subject.

We will respond to your request within the period required by the data protection law that applies to you. For example, where the EU GDPR, UK GDPR, or DPDPA applies, we will respond within one calendar month of receiving a verifiable request, and where your request is complex or you have made a number of requests within a short timeframe, we may extend that period by up to a further two months. Where another law applies to you and sets a different period, we will respond within that period.

To exercise your data protection rights related to Personal Data we process as a data controller or data processor, contact us as outlined below. If you believe we have not properly handled your rights request, you can escalate to the appropriate Data Protection Authority.

We do not currently use tracking or advertising cookies on our website. We use a strictly necessary session/authentication token (which may be cookie-based or an equivalent mechanism) solely to keep you securely logged in. In the future, we may use:

  • Strictly necessary cookies — for authentication and session security.
  • Functional cookies — to remember preferences like theme or language.
  • Analytics cookies — for aggregate usage insights, via tools such as PostHog.

We do not use third-party advertising or tracking cookies. When we do start using cookies, you'll be able to manage your preferences through your browser, or by emailing privacy@lashvae.com.

We use industry-standard security measures, including HTTPS encryption, password hashing, encrypted authentication tokens, role-based access controls, separation of customer data between accounts, restricted database access, firewalls, rate limiting, webhook verification, audit logs, regular backups, and ongoing security monitoring.

Some of our features involve automated processing of your data:

  • Lead scoring and intent detection: we automatically analyse conversation metadata to flag likely leads, complaints, or booking requests to our business customers.
  • AI-generated replies: where enabled, our AI drafts or sends responses to messages based on conversation content.

This processing helps our business customers respond faster — it does not produce a legal effect or similarly significant effect on you (for example, it does not decide whether you get a service, a job, credit, or a price). It is designed to support, not replace, human judgement, and our business customers remain able to review, override, or intervene in any automated output. We have assessed this processing and do not consider it high-risk under Art. 35 GDPR given the human-review safeguards described above; we will carry out a Data Protection Impact Assessment before deploying any feature that could produce legal or similarly significant effects on individuals.

If this changes in the future — for example, if any automated process starts producing decisions with legal or similarly significant effects on individuals — we will update this Notice, explain the logic involved, and tell you about your right to request human intervention, express your point of view, and contest the decision.

Our services are intended for business use and are not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data (a child being someone under the relevant digital consent age in their jurisdiction — for example, 13–16 under GDPR/UK GDPR member state law, or 18 under the DPDPA), please contact us at privacy@lashvae.com so that we can delete the data and deactivate any associated account within a reasonable period, and take any other appropriate action.

If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you using the email address associated with your account or the contact details you've provided to us.

Timeline.We will notify the relevant supervisory authority within 72 hours where required (e.g., under UK/EU GDPR or under any law), or to the Data Protection Board of India under the DPDP Rules, 2025, which requires reporting within 72 hours regardless of the breach's severity, and will notify affected individuals without undue delay where the breach poses a risk to you.

What we'll tell you.Our breach notification will include the information required by applicable law, which may cover: the nature of the breach, the categories and approximate number of individuals and records affected, the likely consequences of the breach, the measures we've taken or propose to take to address it, and how to contact us for more information.

What you should do. If you receive a breach notification from us, please follow any specific guidance included in that notice (for example, updating your password). We will investigate the breach and work to resolve the matter as soon as possible, and will keep you updated on any significant developments.

We may update this Notice from time to time, for example if our practices change or the law requires it. We'll post any updates on this page, along with the date they take effect.

If you have complaints about how we handle your personal data or if you believe we have violated your data rights, contact us:

Data Controller: Lashvae Technology Ltd

Represented by Vishal T U

#37, Louise De Marillac House, Smithy St, Stepney Green, London E1 3HP

+44 7405 933901

Email: Vishal@lashvae.com

Email: dpo@lashvae.com

For questions about privacy, data requests, or cookies, contact us:

Lashvae Technology Ltd

Office 18036, 182–184 High Street North East, Ham, London E6 2JA

Email: privacy@lashvae.com

We will investigate and respond within 30 days or as may be within the time frame prescribed by the law under governance.

Grievance Officer (for the purposes of the Digital Personal Data Protection Act, 2023): Vishal T U, Grievance Officer, contactable at Vishal@lashvae.com.

This Notice is governed by the laws of England and Wales, without prejudice to your statutory rights under the data protection law of your own country of residence.