What data we process, why, and on whose behalf.
SOVRAS IO SpA operates an enterprise AI agent platform. This policy separates the data we control from the Customer Data we process on a business customer’s instructions.
Updated September 16, 2026When this Policy applies
SOVRAS IO SpA (“SOVRAS”, “we” or “our”) builds and operates an enterprise artificial intelligence agent platform that lets organizations connect channels, systems, information and tools in order to handle and execute business operations.
This Policy explains how we process personal data when a person visits our websites, creates or uses a SOVRAS account, communicates with us, uses our applications, APIs or tools, or interacts with an organization that uses SOVRAS.
When SOVRAS is the controller
This Policy applies where SOVRAS determines the purposes and means of processing, for example in respect of:
- users, administrators and contacts of business customers;
- people requesting information, demos or support;
- visitors to our websites;
- account, security, billing, usage and commercial relationship information.
When SOVRAS acts on a customer’s behalf
Business customers may also connect their own channels, systems and information sources to SOVRAS, or use SOVRAS to process messages, contacts, files, documents, recordings, transcripts, instructions, tool outputs and other content (“Customer Data”).
In respect of personal data contained in Customer Data, the business customer normally determines the purpose of the processing and SOVRAS acts on that company’s behalf as a vendor, processor or service provider, as applicable under the relevant law and the contract entered into with the customer.
If you are an end user of a company that uses SOVRAS and your request concerns information controlled by that company, you should normally direct your request to that company first. SOVRAS will assist its customers in meeting the obligations that fall to them.
Information we may process
Depending on how SOVRAS is used, we may process the following categories of information.
Account and organization information
- name and contact details;
- business email address;
- company, job title, team or role;
- account configuration;
- permissions and access controls;
- information needed to authenticate and protect the account.
Integration and connected system information
- identifiers for accounts, companies, assets and resources;
- configuration information;
- permissions granted;
- tokens, credentials or secure references needed to operate an integration;
- the status of connections, authorizations and services.
Credentials and secrets are processed only to the extent necessary to operate authorized integrations and must be kept protected through appropriate controls.
Customer Data
Depending on the channels, systems and features each business customer enables, Customer Data may include:
- messages and conversations;
- names, phone numbers, email addresses and other contact details;
- WhatsApp, Meta or other provider identifiers;
- files, images, documents and media content;
- voice notes, calls, recordings and transcripts where applicable;
- orders, quotes, payments, cases, requests, claims, visits, statuses and operational records;
- prompts, instructions, agent configurations and knowledge bases;
- inputs to and outputs from tools or enterprise systems;
- results, evidence and traceability of actions executed through SOVRAS.
Technical and usage information
- IP address;
- browser, device and operating system;
- date and time of access;
- product activity;
- API calls;
- events and webhooks;
- usage metrics;
- errors, logs, telemetry and security signals;
- information needed to prevent fraud, abuse or unauthorized access.
Commercial and support information
- demo requests;
- commercial communications;
- technical support;
- contracts, order forms and billing information;
- feedback, interviews, surveys or other communications with SOVRAS.
How we obtain the information
- directly from you or your organization;
- from a business customer that uses SOVRAS;
- from the channels and systems an organization chooses to connect;
- from Meta, WhatsApp and other providers when an organization authorizes an integration;
- automatically when you use our sites, applications or APIs;
- from vendors and partners involved in delivering the service;
- from public sources where the law permits.
What we use the information for
- to provide, configure, maintain and improve SOVRAS;
- to create and administer accounts, companies, permissions and configurations;
- to connect and operate authorized channels and systems;
- to receive, understand and respond to communications;
- to let AI agents execute the actions authorized by the business customer;
- to maintain continuity, context, evidence and traceability of operations;
- to process files, documents, audio, images or other content enabled by the customer;
- to run integrations, APIs, webhooks and tools;
- to provide support;
- to monitor performance, availability, quality and security;
- to prevent fraud, abuse and incidents;
- to meet legal obligations;
- to manage the commercial relationship, billing and administration;
- to develop and improve SOVRAS features using aggregated, anonymized or de-identified information where reasonably possible.
Where SOVRAS processes Customer Data on a company’s behalf, it does so to deliver the contracted services and in line with the applicable instructions, configurations, authorizations and agreements.
Artificial intelligence
SOVRAS may use artificial intelligence, language, vision, transcription, voice or other automated technologies and providers to deliver certain features. Depending on the customer’s configuration, information needed for a feature may be transmitted to the technology providers involved in that feature.
SOVRAS does not use Customer Data to train generalized models intended for other customers, unless the business customer expressly authorizes it or a specific agreement permits that use.
Where we use third-party artificial intelligence providers, we seek to use settings and commercial terms designed to limit the use of Customer Data for training the provider’s general models, where such options are available.
Artificial intelligence output may be inaccurate or incomplete. SOVRAS builds in controls, permissions, policies, review, evidence and other mechanisms intended to reduce risk, but the business customer remains responsible for deciding how it uses its agents and what level of oversight its operation requires.
Grounds for processing
We process personal data in accordance with applicable law and, depending on the context, on the basis of:
- performance of a contract or steps requested before entering into one;
- consent, where required;
- compliance with legal obligations;
- legitimate purposes compatible with the existing relationship, where applicable law allows;
- protection of the security, integrity and continuity of the services;
- documented instructions from a business customer where SOVRAS acts on its behalf.
The business customer is responsible for holding the authorizations, notices, legal bases and other requirements needed in respect of the Customer Data it instructs SOVRAS to process.
Who we may share information with
Vendors and subprocessors
We may use providers of cloud infrastructure, databases, storage, security, monitoring, artificial intelligence, transcription, voice, telephony, email, messaging, support, analytics, billing and other technical services. We give them only the information reasonably necessary to deliver the relevant function and, where applicable, we require contractual obligations of confidentiality, security and data protection.
The list of subprocessors in use is published at Subprocessors.
Platforms and integrations enabled by the customer
When a company connects services such as Meta, WhatsApp, Microsoft, Google, enterprise systems, payment providers or other platforms, SOVRAS transmits and receives the information needed to execute the requested integration.
Your organization
Administrators and other authorized users of the same organization may access certain information in line with their permissions.
Authorities and advisers
We may disclose information where necessary to meet a legal obligation, respond to a valid request, protect rights, investigate abuse, or work with professional advisers bound by confidentiality obligations.
Corporate transactions
In a reorganization, financing, merger, acquisition or sale of assets, certain information may be disclosed to the parties and advisers involved, subject to appropriate safeguards.
International transfers and processing
SOVRAS and its providers may process information in Chile and in other countries where the technology providers needed to deliver the service operate.
Where applicable law requires specific measures for international transfers, SOVRAS will use the relevant contractual, technical or organizational mechanisms.
Retention
We retain information for as long as reasonably necessary to deliver the service, maintain the customer relationship, execute and document operations, meet legal obligations, resolve disputes, protect security, prevent abuse and keep reasonably necessary audit records.
Retention periods may vary depending on the nature of the information, the contracted service, the customer’s instructions and applicable legal obligations.
When an account, project, connection or set of Customer Data is deleted, SOVRAS will delete or anonymize the corresponding information from its active systems within a reasonable period, subject to legal obligations, security, fraud prevention, necessary audit records and normal backup cycles.
Security
SOVRAS uses technical and organizational measures designed to protect information against loss, alteration, unauthorized access, disclosure or use.
These measures may include, as applicable, access controls, per-organization segregation, authentication, encryption supported by the infrastructure used, protection of secrets and credentials, audit logs, monitoring, permission management, backup, recovery and incident response.
No system can guarantee absolute security. Customers are also responsible for protecting their credentials, configuring permissions correctly, limiting access and keeping their own systems and connected accounts secure.
Rights and requests
Depending on applicable law and on the relationship in which SOVRAS processes your data, you may have the right to request:
- access to your personal data;
- rectification of inaccurate information;
- deletion or erasure;
- blocking or restriction of processing;
- objection to certain processing;
- portability, where applicable;
- withdrawal of consent where processing depends on it;
- information about the processing carried out.
To make a request regarding information controlled directly by SOVRAS, write to contacto@sovras.io with enough information to identify the relationship and the request. We may ask for reasonable information to verify identity, standing or authority before responding.
If your information forms part of the Customer Data of a company that uses SOVRAS, you should direct the request to that company. SOVRAS will assist the company as appropriate.
See also our Data Deletion Instructions.
Children’s data
SOVRAS is an enterprise service and is not directed at children.
Business customers must not use SOVRAS to process children’s data where doing so would require special conditions, authorizations or safeguards that have not been agreed and enabled for that case.
Changes to this Policy
We may update this Policy to reflect legal, technical or service changes.
Where a change is material, we will use reasonable means to communicate it where appropriate. The date shown at the top indicates the current version.
Contact
SOVRAS IO SpA
Email: contacto@sovras.io
Website: sovras.io
Related documents: Terms of Service, Data Processing Addendum, Subprocessors, Data deletion and Cookies.
