Legal
Privacy Policy
Last updated: April 2026 · Effective from: April 2026
1. Introduction
Zovanion ("we", "our platform") respects your privacy and is committed to protecting your personal data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable legislation.
This policy explains what data we collect, how we use it, and what your rights are.
2. Data Controller
- Name: Gregor Škof
- Service: Zovanion — AI platform for business operations
- Contact: zovanion@gmail.com
- Country: Slovenia, European Union
3. What data do we collect?
- Account data: Email address and password (stored as bcrypt hash — never in plain text)
- Document content: Text you enter or upload to generate SOPs and policies
- Technical data: JWT token for session management (stored in your browser's localStorage)
- Metadata: Document creation date and document title
🔒 We do not collect: IP addresses for tracking, location data, behavioral data, advertising profiles, or third-party data.
4. Why do we collect data?
- To create and manage your account (legal basis: contract)
- To generate AI documents on your request (legal basis: contract)
- To store your documents in your personal vault (legal basis: contract)
- For platform security and abuse prevention (legal basis: legitimate interest)
5. Cookies and local storage
Zovanion does not use tracking or advertising cookies. We only store:
- JWT token (localStorage) — for managing your login session. Valid for 30 days.
- Theme settings (localStorage) — to save your colour theme preference.
- Cookie consent (localStorage) — to record your consent decision.
Google Fonts is loaded from Google's CDN. Google may collect non-personal technical data (browser type, IP). If you reject consent, Google Fonts will not be loaded.
6. Artificial Intelligence (AI Act)
🤖 Zovanion uses Claude AI (Anthropic) to generate documents
In accordance with the EU AI Act, we inform you:
- All documents generated on the platform are created using artificial intelligence (Anthropic Claude)
- AI does not make decisions that directly affect your rights (employment, credit, education)
- Zovanion is classified as a low-risk AI system under the EU AI Act
- Content you enter is passed to the Anthropic API for processing — see Anthropic's Privacy Policy
- Generated documents are advisory only — final responsibility for content lies with you
7. Third-party providers
- Anthropic (Claude API): AI request processing. Data is transferred in accordance with GDPR standard contractual clauses.
- Railway.app: Backend hosting in EU region (europe-west4).
- Vercel: Frontend hosting. Vercel is GDPR-compliant.
- Google Fonts: Fonts (only upon consent).
8. Data storage and security
- Data stored in SQLite database on Railway volume (EU region)
- Passwords protected with bcrypt (12 salt rounds)
- All communication over HTTPS
- JWT tokens expire after 30 days
- Data access restricted by JWT authentication
9. Your rights (GDPR)
As an EU user you have the following rights:
- Right of access — request a copy of your data
- Right to rectification — correct inaccurate data
- Right to erasure — "right to be forgotten" — we delete your account and all documents
- Right to data portability — receive your data in a machine-readable format
- Right to object — object to processing based on legitimate interest
- Right to lodge a complaint — file a complaint with the Information Commissioner of RS (ip-rs.si)
10. Data retention
- Account data: for as long as you have an active account
- Documents: until you delete them or close your account
- After account closure: data deleted within 30 days
11. Policy changes
We will notify you of significant changes by email at least 14 days before they take effect. The date of the last change is always shown at the top of this page.