Privacy Policy
Legal · Coventia AI

Privacy Policy

Coventia WhatsApp — whatsapp.coventia.es

Last updated: 11 March 2026

1. Data Controller

In compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and with Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD), the user is hereby informed that the controller responsible for the processing of their personal data is:

2. Purpose and Scope

This Privacy Policy governs the processing of personal data carried out by Coventia Legal S.L. (hereinafter, “Coventia” or “the Controller”) through the Coventia WhatsApp platform (hereinafter, “the Platform” or “the Service”), accessible at https://whatsapp.coventia.es.

Coventia WhatsApp is a SaaS (Software as a Service) platform that enables businesses and professionals to manage communications with their customers through Meta's WhatsApp Business API, to integrate email channels (via OAuth connection with providers such as Google/Gmail) and, where applicable, to use artificial intelligence features for customer service.

This policy applies both to the users who contract and administer the Platform (hereinafter, “Business Users” or “Clients”) and to the end users whose data may be processed through it.

3. Personal Data We Collect

3.1. Data provided directly by the user

  • Registration and identification data: first name, surname, email address, telephone number, company name, tax identification number (CIF/NIF) and job title.
  • Billing data: tax address, banking or payment details necessary for the provision of the service.
  • Communication data: content of the messages exchanged through the Platform (WhatsApp, email and other integrated channels).

3.2. Data collected automatically

  • Technical browsing data: IP address, browser type, operating system, pages visited, time spent and cookie data (in accordance with our cookie policy).
  • Platform activity logs: date and time of access, actions performed, conversations managed and service usage metrics.

3.3. Data obtained through third-party integrations

When the Business User connects third-party services to the Platform, Coventia may access certain data from the relevant provider. In particular:

3.3.1. Google User Data

When the Business User connects their Google/Gmail account to the Platform via the OAuth 2.0 protocol, Coventia accesses the following Google user data:

  • Email address: the Gmail or Google Workspace address associated with the connected account, used as the identifier of the email channel and as the sending/receiving address.
  • Basic account profile: name and profile picture associated with the Google account, used exclusively to identify the connected account within the Platform interface.
  • Email messages (reading and sending): the Platform accesses the messages in the user's inbox in order to display them as an integrated communication channel, and allows emails to be sent on the user's behalf through the Gmail API. This access is strictly limited to the unified inbox functionality offered by the Platform.
  • Email labels and metadata: information about the organisation of the messages (labels, read status, date, sender, recipient and subject), used to display and manage the inbox within the Platform.

Coventia does not access data from Google Drive, Google Calendar, Google Contacts or any other Google service that is not strictly necessary to provide the email channel functionality within the Platform.

3.3.2. WhatsApp Business API Data (Meta)

  • WhatsApp Business telephone number and business profile name.
  • Content of the WhatsApp messages exchanged between the Business User and their end customers.
  • Conversation metadata: delivery status, read status, date and time.

4. Purposes of Processing

Personal data is processed for the following purposes:

  • Provision of the service: to manage multichannel communications (WhatsApp, email and others) through the Platform, including the sending and receiving of messages and the management of the unified inbox.
  • Management of the contractual relationship: to administer onboarding, billing, technical support and customer service arising from the contracting of the Platform.
  • Service improvement: to analyse the use of the Platform on an aggregated and anonymised basis in order to improve its functionality and performance.
  • Legal compliance: to comply with applicable legal, tax and accounting obligations.
  • Commercial communications: solely with the user's prior express consent, to send information about news, updates or services related to the Platform.

5. Use and Protection of Google User Data

Coventia's use of information received through Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. In particular:

  • Exclusive use to provide the service: Google user data is used solely to provide and improve the integrated email inbox functionality within the Platform. It is not used for any other purpose.
  • No sale of data: Coventia does not sell, assign or transfer Google user data to third parties, except where necessary to provide or improve user-facing features, to comply with applicable law, or as part of a merger, acquisition or sale of assets (with prior notice to the user).
  • No use for advertising: Google user data is not used to display, serve or personalise advertisements, nor for retargeting, personalised or interest-based advertising.
  • No use for profiling: Google user data is not used to build user profiles for purposes unrelated to the direct provision of the contracted service.
  • No use for creditworthiness determination: Google user data is not used to assess the user's creditworthiness or for any lending purpose.
  • Limited human access: human access to Google user data is limited to what is strictly necessary to provide technical support to the user who requests it, to investigate security incidents or to comply with legal obligations, and always with the user's consent where applicable.

The use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. Legal Basis for Processing

  • Performance of the contract (Art. 6.1.b GDPR): the processing of data is necessary for the provision of the service contracted by the Business User.
  • Consent of the data subject (Art. 6.1.a GDPR): for the sending of commercial communications and for the connection of third-party accounts (such as Google/Gmail) via OAuth.
  • Legitimate interest of the controller (Art. 6.1.f GDPR): for the improvement of the service through aggregated analysis and for fraud prevention and the security of the Platform.
  • Compliance with a legal obligation (Art. 6.1.c GDPR): to comply with legal, tax and accounting obligations.

7. Data Retention

Personal data will be retained for as long as necessary to fulfil the purpose for which it was collected and to determine any liabilities arising from that purpose and from the processing of the data. In particular:

  • Contractual relationship data: for the duration of the contract and, once terminated, for the applicable legal limitation periods (generally, 5 years pursuant to Article 1964 of the Civil Code).
  • Billing and tax data: 4 years pursuant to the General Tax Act.
  • Google user data: for as long as the Google account remains connected to the Platform. Once the account is disconnected by the user, the Google data will be deleted from our systems within a maximum period of 30 days, unless there is a legal obligation to retain it.
  • Communications data (messages): for the duration of the Business User's contract. After cancellation of the service, it will be deleted within a maximum period of 90 days, unless there is a legal obligation to retain it.

8. Recipients and Transfers of Data

Personal data may be disclosed to the following recipients:

  • Meta Platforms, Inc.: as the provider of the WhatsApp Business API, for the management of communications through WhatsApp. Data is transferred in accordance with the standard contractual clauses approved by the European Commission.
  • Google LLC / Google Ireland Limited: as the provider of the Gmail API services, for the email channel functionality. The connection is made via OAuth 2.0 and the data is processed in accordance with the Google API Services User Data Policy.
  • Infrastructure and hosting providers: servers and cloud services necessary for the provision of the service, located in the European Union or in countries with an adequate level of protection.
  • Public authorities and government bodies: where there is a legal obligation to disclose data.

Coventia does not share, sell or assign Google user data to third parties for advertising, marketing, profiling or any purpose other than the provision of the contracted service.

9. Users' Rights

The user may exercise the following rights in relation to their personal data:

  • Right of access: to obtain confirmation as to whether their data is being processed and to access it.
  • Right to rectification: to request the correction of inaccurate or incomplete data.
  • Right to erasure: to request the deletion of their data when it is no longer necessary for the purpose for which it was collected.
  • Right to object: to object to the processing of their data in certain circumstances.
  • Right to restriction of processing: to request the restriction of the processing of their data.
  • Right to data portability: to receive their data in a structured and commonly used format.
  • Right to withdraw consent: to withdraw the consent given at any time, including disconnecting the Google account linked to the Platform, without affecting the lawfulness of processing based on consent prior to its withdrawal.

To exercise these rights, the user may contact Coventia Legal S.L. through:

  • Email: wa@coventia.es
  • Postal address: Coventia Legal S.L., Murcia, Spain

Likewise, the user has the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es if they consider that the processing of their data does not comply with current regulations.

10. Revocation of Access to Google Data

The user may revoke Coventia WhatsApp's access to their Google account at any time by any of the following methods:

  • From the Platform: by accessing the channel settings and disconnecting the linked Google/Gmail account.
  • From Google: by accessing the security settings of their Google account (myaccount.google.com/permissions) and removing Coventia WhatsApp's access.

Once access has been revoked, Coventia will cease to access the data in the user's Google account and will delete the stored data within a maximum period of 30 days.

11. Security Measures

Coventia has adopted the technical and organisational measures necessary to ensure the security of personal data and to prevent its alteration, loss, unauthorised processing or access, in accordance with Article 32 of the GDPR. These include, among others:

  • Encryption of data in transit (TLS/SSL) and at rest.
  • Role-based access control with secure authentication.
  • Monitoring and logging of access to the Platform.
  • Regular backups and a disaster recovery plan.
  • Secure storage of OAuth tokens with encryption and restricted access.
  • Regular review of security measures and impact assessments where appropriate.

12. Cookie Policy

The Platform uses its own and third-party cookies. For detailed information about the cookies used, their purpose and how to manage them, the user may consult our Cookie Policy, accessible from the Platform itself.

13. Amendments to this Policy

Coventia reserves the right to modify this Privacy Policy in order to adapt it to legislative, case-law or industry-practice developments. Any modification will be communicated to users through the Platform or by email with sufficient notice. Where the modifications affect the processing of Google user data, the user's consent will be requested again before applying the changes.

14. Contact

For any query relating to this Privacy Policy or to the processing of their personal data, the user may contact Coventia Legal S.L.: