Legal
GDPR and data protection.
You are the controller. We are, mostly, not even a processor.
Kavita is self-hosted, so for your customers’ personal data we are neither controller nor processor — it never reaches us. Export and erasure are built in and free on every plan.
Last updated · draft
The unusual bit
Kavita is self-hosted. Your customers’ data goes into your own database on your own hosting and never reaches us, so for the personal data your business collects we are neither controller nor processor. That is a genuinely different position from every hosted booking service you will compare us against.
What the plugin gives you
Export and erasure are built in and free on every plan, including the free one, because a legal obligation is not a feature to sell.
- Export everything held about one customer, as a file you can hand over
- Erase a customer, with bookings anonymised rather than deleted so your accounts still balance
- A consent line at booking, shown only when you have written wording for it
- Message bodies from WhatsApp are never stored — only that a question was asked and whether it was answered
Sub-processors your setup may introduce
These are yours, under your own accounts, chosen by you: your payment gateway, Twilio if you use WhatsApp or SMS, your SMTP provider, your calendar provider, and your LLM provider if you switch the assistants on. We do not sit between you and any of them.
Data we hold about you as a customer
Purchase records and support correspondence. See privacy.
A DPA
[To be drafted by counsel.] Where one is needed for the licence relationship we will sign one. Given the plugin never receives your customers’ data, the scope should be small — but that is a lawyer’s judgement and not ours.