Legal

Privacy Policy

Last updated: June 25, 2026

JIVIQ ("JIVIQ", "we", "us", "our") is an all-in-one operating system for service professionals and small businesses. This policy explains what personal data we collect, why, how we use and share it, how long we keep it, and the rights you have over it. It covers three different groups of people, and it is important to understand which one you are, because our role and your rights differ:

  • Account holders — the professionals, business owners, and team members who sign up for and use JIVIQ.
  • Visitors to jiviq.com — anyone who browses our marketing website.
  • Your customers (end-users) — the people who book appointments with you, chat with you through our embedded chat widget on your website, fill in your forms, or send you feedback. For this group, you are the data controller and we act as your data processor (see Section 1).

If anything here is unclear, write to support@jiviq.com. The service is operated by Stratus Labs (registered address: C4 602, Edenn Towers CHS, Pune 411057, India), which is the data controller / Data Fiduciary for the data described in this policy where we act as a controller.

1. Our two roles: controller and processor

JIVIQ wears two different hats depending on whose data is involved:

  • We are the controller for: data about our account holders (your name, login, billing, and how you use the product) and about visitors to jiviq.com. For this data we decide the purposes and means of processing, and the rights in Sections 15–17 apply directly between you and us.
  • We are a processor for: the personal data of your customers that flows through JIVIQ because you use it to run your business — for example, a client who books an appointment, a website visitor who chats with you through our embedded widget, or someone who completes one of your forms. You are the controller of that data. We process it only to provide the service to you, on your instructions, governed by a Data Processing Agreement (DPA). If one of your customers asks us to access or delete their data, we will direct them to you and assist you in responding.

Because the chat widget runs on your website, the people who use it are usually governed by your privacy notice, not this one. You are responsible for telling your own customers how you use JIVIQ to handle their data and for having a lawful basis to do so. Our DPA is available to any customer on request via support@jiviq.com.

2. What JIVIQ does

JIVIQ is more than scheduling. So you understand what data the product can collect, here is the full set of capabilities. Not every account uses every capability.

  • Scheduling & booking — public booking pages, appointments, services, availability, reminders.
  • Embedded chat widget — a chat box you can add to your own website so your visitors can message you. It captures the messages, optional contact details, and any files visitors send.
  • Website visitor analytics — when the chat widget is installed, it can record which pages a visitor views and where they came from, to help you understand your audience (Section 6).
  • Forms — public forms (hosted on forms.jiviq.com) that collect responses from the people who fill them in.
  • Feedback — a channel for collecting feedback and support requests from your customers.
  • Customer records (CRM) — contact and relationship information about your clients.
  • AI assistant — optional AI features that help draft replies and answer questions, including an assistant that can respond in chat (Section 8).

3. Information we collect

  • Account data — name, email, phone, business name, locale, timezone. Sign-in is handled by Google Firebase Authentication; your password is held by Firebase, not by us.
  • Business data you create — services, availability, appointments, customer records, notes, form definitions, knowledge-base content, and similar.
  • Usage & device data — IP address, device type, browser, operating system, pages visited, and timestamps, used for security, rate-limiting, and to keep the product working.
  • Billing data — subscription and billing identifiers handled by our Merchant of Record, Paddle (Section 10). We store only references (such as a customer/subscription ID); we do not store full card numbers.
  • Support communications — emails and in-product messages you send us.
  • Usage & device data — as above, for security and to operate the site.
  • Approximate, IP-derived location — see Section 7.
  • Browser storage — a theme preference and, where you interact with the chat widget on our own site, the items in Section 9.

When you use JIVIQ to serve your customers, we process — strictly to provide the service to you — data such as:

  • Booking data — your client's name, phone or email, the appointment, and any notes; a one-time code (OTP) used to verify their identity.
  • Chat data — the messages your website visitors send through the widget, any name/email/phone they provide, and any files they upload.
  • Form responses — whatever a respondent enters into your forms.
  • Feedback — the content and identity a person provides when they send you feedback.
  • Website-visitor activity — a persistent anonymous identifier and the pages a visitor views on your site, plus an approximate location where you have enabled that feature (Sections 6 and 7).
  • Technical data — IP address (used transiently — see Section 7), browser, operating system, device type, and the address of the page the widget is on.

You decide what personal data your customers give you, and you are responsible for the lawful basis to collect it. Please don't use free-text fields (chat, notes, form answers) to collect special-category data unless you have your own lawful basis to do so.

4. How we use data

  • To operate the service — create accounts, take bookings, run your chat widget and forms, send reminders and notifications.
  • To secure the service — detect and prevent fraud, abuse, and unauthorized access.
  • To support you — answer your questions and fix problems.
  • To improve the product — understand how features are used (we do this with our own data, not third-party ad trackers).
  • To comply with legal obligations — tax, accounting, and lawful requests.

We do not sell your personal data, and we do not share your client lists with third parties for their own marketing.

5. Legal bases (GDPR)

Where the EU/UK GDPR applies and we are the controller, we rely on:

  • Contract — to deliver the service you signed up for.
  • Legitimate interests — to secure, maintain, and improve the service (balanced against your rights; balancing assessment available on request).
  • Consent — for marketing emails, which you can withdraw at any time.
  • Legal obligation — tax, audit, and lawful requests.

Where we act as your processor (Section 1), you determine the lawful basis for your customers' data; we process it on your documented instructions. For individuals in India, our basis is described in Section 17.

6. Website-visitor analytics and the visitor identifier

When the JIVIQ chat widget is installed on a website (yours, or our own jiviq.com), it can record basic visitor activity to power audience analytics:

  • A persistent anonymous identifier is stored in the browser (a random value, not your name or email) so that repeat visits and the path through a site can be recognised. It is created when the page loads.
  • For each page view we record the page address (stripped of query strings), the referring site, and any campaign (UTM) tags — used to build visit and journey analytics.
  • A short-lived "who is on the site now" presence signal may be sent every ~30 seconds while a page is open; it includes the current page and the visitor's timezone and is discarded within minutes.
  • If a visitor later identifies themselves (for example, by giving their name in chat or verifying a one-time code), the previously anonymous activity can be associated with that person so you can see their history.

On your website this is processing of your customers' data, for which you are the controller; you should disclose it in your own privacy notice. A visitor can object to analytics processing (Section 15); we maintain a suppression list so that future page views are not analytics-stamped. We do not use third-party advertising or cross-site tracking networks.

7. IP-derived approximate location

Where this feature is enabled, when a page carrying the JIVIQ widget is loaded (including on jiviq.com), the visitor's IP address is read transiently and passed through a MaxMind GeoLite2 database held locally on our own servers in Mumbai (asia-south1) to derive an approximate country and city. We then:

  • discard the IP address — it is never stored, logged, or persisted alongside the result;
  • keep only the derived country and city — we store no latitude or longitude and do no reverse geocoding to a street address;
  • never transmit the IP address to MaxMind — lookups run entirely on our servers against a licensed database file. MaxMind is a data licensor, not a sub-processor, and receives no personal data.

We use the derived location for service security, fraud and abuse prevention, and basic aggregate analytics. Aggregated location data (visitor counts by city and country) is used for product analytics. In addition, once you identify yourself to a business that uses JIVIQ — for example, by giving your details in chat or booking an appointment — your approximate city-level location may also be shown to that business on your customer profile within their JIVIQ account; you can object at any time (see below), and we store no street address and no precise coordinates. Where the GDPR applies we rely on our legitimate interest under Article 6(1)(f) (balancing assessment available on request); we do not use it for any solely-automated decision producing legal or similarly significant effects about you. Your right to object (Article 21 GDPR): email support@jiviq.com and we will record a suppression preference so your future visits are not geo-stamped, confirming within 30 days. We retain the derived country and city for 12 months from the event date, after which an automated job deletes them. For individuals in India, see Section 17.

8. AI processing

Some features use AI. When you use them, the relevant content is sent to our AI sub-processors to generate a result, and is not used by them to train their general models:

  • AI assistant & reply drafting — chat messages and related context are sent to the Google Gemini API to generate suggested or automated replies.
  • Knowledge-base search — your knowledge-base content and search queries are sent to Google Gemini (for embeddings) and to ZeroEntropy (for search re-ranking) to return relevant answers.

AI features that process your customers' content are part of the processor relationship in Section 1. You control whether to enable them.

9. Cookies & browser storage

We do not use third-party advertising cookies, and we do not run third-party web-analytics products such as Google Analytics. We use:

  • Strictly necessary storage — for authentication and keeping you signed in (handled by Firebase Authentication).
  • Functional storage — preferences such as your theme, and saved drafts.
  • The visitor identifier described in Section 6 — a functional identifier the chat widget stores in the browser to support audience analytics.

You can clear browser storage at any time through your browser settings. A detailed, per-key inventory is in our Cookies & Local-Storage Policy.

10. Sub-processors

We use a small set of trusted sub-processors to run the service:

  • Google Cloud Platform (data primarily in asia-south1, Mumbai) — infrastructure: Cloud Run, Cloud SQL, Cloud Storage, Cloud Tasks, Cloud KMS, and Firebase Authentication & Hosting.
  • Google Gemini API (United States) — AI processing for the assistant, reply drafting, and knowledge-base embeddings, when those features are used.
  • ZeroEntropy (United States) — search re-ranking for knowledge-base answers.
  • Paddle.com Market Ltd — Merchant of Record for subscription billing, payments, and tax.
  • ZeptoMail (Zoho Corporation) — transactional email (verification, one-time codes, invitations, booking confirmations, and notifications).
  • Sentry (United States) — error and crash diagnostics for our admin application (captures technical error details from account holders' browsers).

Each sub-processor that processes personal data on our behalf is bound by a data-processing agreement. We will update this list before engaging a new sub-processor; material changes are notified by email or in-product banner. Customers who require a signed DPA can request one via support@jiviq.com.

Licensed data source (no personal data shared)

  • MaxMind, Inc. (51 Pleasant Street, Suite #1020, Malden, MA 02148, USA) — provides the GeoLite2 City database, a binary lookup file we license and host. IP-to-geography lookups are performed locally within our own infrastructure; MaxMind receives no personal data and acts as a data licensor, not a processor. This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.

11. International data transfers

Your data is primarily processed in India (asia-south1) and in your own region. Some of our sub-processors are based in the United States — specifically Google (Gemini), ZeroEntropy, and Sentry. When personal data is transferred out of the EU/EEA, UK, or India, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the EU–US / UK / Swiss Data Privacy Framework where applicable, and equivalent contractual protections. A list of safeguards is available on request.

12. Data retention & deletion

We keep personal data only as long as we need it. Indicative retention periods:

  • Account & business data — for as long as your account is active.
  • Booking, chat, form, and feedback records — retained while your account is active so you have your business history; deleted or anonymised on account closure (below) or on a verified deletion request.
  • IP-derived location (country/city) — 12 months, then automatically deleted (Section 7).
  • Short-lived signals — the "who is on the site now" presence signal is discarded within minutes; uploaded files removed on deletion are kept for a 30-day recovery grace period; AI-feature diagnostic logs are purged within 30 days.
  • Legal/financial records — kept as long as tax, accounting, or other law requires.

When you close your account, we delete or anonymise your personal data and the personal data we processed on your behalf within 90 days, except where law requires longer retention (for example, tax records). You can also request deletion at any time (Section 15). Some records are held in append-only, tamper-evident logs for integrity and audit; where we cannot delete an individual entry without breaking that integrity, we irreversibly redact the personal data within it instead.

13. Security

We use encryption in transit (TLS) and at rest, least-privilege access controls, tenant isolation enforced at the database layer, and continuous monitoring. No system is perfectly secure — if we learn of a breach that affects you, we will act as described in Section 14.

14. Data breach notification

If we become aware of a personal-data breach, we will contain and assess it promptly. Where the breach is likely to result in a risk to people's rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours, and we will notify affected individuals and — where we are your processor — the affected business customers without undue delay so they can meet their own obligations.

15. Your rights

Depending on where you live, you have the right to access, correct, export (port), delete, or restrict your personal data, and to object to certain processing. Most of this can be done directly in the product; for anything else, email support@jiviq.com from your account address and we will respond within 30 days (45 days for requests under the CCPA, where permitted). See our Data & Privacy Requests page for how to submit a request and how we verify identity.

If you are someone else's customer — for example, you booked an appointment or chatted with a business that uses JIVIQ — that business is the controller of your data. Please send your request to them; if you contact us, we will forward your request to the relevant business and assist them in responding.

You also have the right to lodge a complaint with a data-protection authority — in the EU/EEA, the authority in your country of residence, place of work, or where the issue occurred; in the UK, the Information Commissioner's Office; in India, the Data Protection Board of India. We would welcome the chance to resolve your concern first at support@jiviq.com.

16. California privacy rights (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect and how we use it; to request access to, correction of, or deletion of your personal information; to opt out of the "sale" or "sharing" of personal information; and not to be discriminated against for exercising these rights.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. The categories of personal information we collect, the purposes, and the sub-processors we disclose it to are described in Sections 3, 4, and 10. To exercise a California right, email support@jiviq.com; we will respond within 45 days (an extension may apply for complex requests) and will not discriminate against you for asking. You may use an authorised agent to submit a request on your behalf.

17. India — Digital Personal Data Protection Act, 2023

For individuals in India, you can raise any question or grievance about how we handle your personal data under the Digital Personal Data Protection Act, 2023 (DPDP Act) with our Data Protection Officer:

  • Data Protection Officer
  • Email: support@jiviq.com
  • Postal address: C4 602, Edenn Towers CHS, Pune 411057, India

We will acknowledge your grievance within 7 working days and respond within the period required under the Act and its rules. You may withdraw any consent you have given as easily as you gave it (withdrawal does not affect processing already carried out), and you may nominate another individual to exercise your rights in the event of death or incapacity. Please use this mechanism first; if your grievance is not satisfactorily resolved, you may complain to the Data Protection Board of India established under the Act. Where we process the personal data of your customers on your behalf, you are the Data Fiduciary and we act as your Data Processor.

18. Children

JIVIQ is not intended for anyone under 16 (or the minimum age of digital consent in your country, if higher). We do not knowingly collect personal data from children. If you believe a child has given us their data, contact support and we will delete it.

19. Changes to this policy

We may update this policy from time to time. Material changes will be announced by email or in-product notice at least 30 days before they take effect.

20. Contact

This service is operated by Stratus Labs (registered address: C4 602, Edenn Towers CHS, Pune 411057, India), the data controller / Data Fiduciary responsible for your personal data where we act as a controller.

Questions, requests, or complaints: support@jiviq.com.