WEBIVIO PLATFORM PRIVACY POLICY
effective as of 03.06.2026
§1. Introduction
Dear User,
We make every effort to ensure the security and confidentiality of your personal data. We care about your privacy both when you visit the Webivio Platform, use our services, sign up for a webinar, contact us, or use the functionality of the Platform.
We operate in accordance with applicable law, in particular in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council ("GDPR").
This Privacy Policy explains:
- what data we process,
- for what purpose,
- on what legal basis,
- how long we retain it,
- with whom we may share it,
- what rights you have.
§2. Data controller
The controller of personal data is:
Cashly Finance sp. z o.o.
Wolska 11A
20-411 Lublin
Poland
KRS: 0001058641
NIP: 7123461765
REGON: 526438114
Contact email: support@webivio.com
The Platform has not appointed a Data Protection Officer.
§3. How we obtain personal data
Personal data may be obtained:
- during account registration,
- during subscription purchase,
- when you contact us,
- when using the Platform,
- when signing up for a webinar,
- when using webinars,
- when sending and receiving WhatsApp messages (when the Creator enables this channel),
- when the Creator connects a WhatsApp Business account within the Platform,
- automatically through analytical technologies and cookies,
- through marketing and analytical integrations.
§4. What data we process
Creator data
We may process:
- first and last name,
- email address,
- company details,
- business address,
- NIP,
- billing data,
- payment data,
- technical data,
- IP address,
- security logs,
- data concerning the use of the Platform.
Webinar Participant data
To the extent that we act as a data processor on behalf of Creators, we may process:
- first name,
- last name,
- email address,
- phone number,
- IP address,
- user-agent and device data,
- browser data,
- webinar attendance status,
- webinar viewing time,
- CTA clicks,
- webinar activity,
- chat messages,
- traffic sources,
- UTM data,
- analytical data,
- time zone,
- purchase data provided via integrations,
- the content of WhatsApp messages sent to the Participant and the Participant's replies (when the WhatsApp channel is active),
- WhatsApp message delivery metadata (e.g., sent, delivered, read status, error codes),
- technical identifiers of the Creator's WhatsApp Business account (e.g., WABA ID, Phone Number ID) — solely to the extent necessary to provide the service.
§5. Roles of the parties and processing of webinar data
The Creator as data controller
The Creator organizing a webinar is the controller of the personal data of the Webinar Participants.
The Creator is responsible for:
- the lawfulness of data collection,
- fulfilling information obligations,
- obtaining appropriate consents,
- the compliance of marketing activities with the law.
Webivio as data processor
The Webivio Platform acts as a processor of personal data on behalf of Creators in accordance with Article 28 of the GDPR.
We process data solely:
- for the purpose of providing the Platform's services,
- on the documented instructions of the Creator,
- in accordance with the concluded Data Processing Agreement (DPA).
§6. Purposes and legal bases for processing data
Provision of the Platform's services
We process data in order to:
- maintain user accounts,
- fulfill subscriptions,
- handle webinars,
- send system messages,
- handle payments,
- maintain infrastructure.
Legal basis: Article 6(1)(b) of the GDPR.
Fulfilling legal obligations
We process data in order to:
- maintain accounting records,
- fulfill tax obligations,
- fulfill obligations related to the protection of personal data.
Legal basis: Article 6(1)(c) of the GDPR.
Platform security
We process data in order to:
- protect infrastructure,
- monitor security,
- detect abuse,
- prevent spam,
- detect unauthorized access,
- maintain security logs.
Legal basis: Article 6(1)(f) of the GDPR.
Analytics and Platform development
We process data in order to:
- analyze the use of the Platform,
- improve functionality,
- monitor errors,
- develop services,
- analyze webinar performance.
Legal basis: Article 6(1)(f) of the GDPR.
Marketing of Webivio services
We process data in order to:
- send a newsletter,
- promote services,
- carry out remarketing,
- conduct advertising campaigns,
- engage in marketing contact.
Legal basis: Article 6(1)(a) or (f) of the GDPR.
WhatsApp communication (webinar notifications)
When the Creator enables the WhatsApp channel, the Platform processes Participant data in order to:
- send webinar sign-up confirmations,
- send reminders before the webinar,
- send follow-up messages after the webinar,
- handle Participant replies (incoming messages),
- notify the Creator of a Participant's reply (e.g., email, Slack).
The legal basis for processing by the Creator (as the controller of the Participant's data) is determined by the Creator — usually Article 6(1)(a) of the GDPR (consent) or (b) of the GDPR (performance of a contract / steps prior to entering into a contract for participation in the webinar).
The Webivio Platform processes this data as a processor on the basis of Article 28 of the GDPR and the Data Processing Agreement (DPA).
The Creator is responsible for obtaining the required opt-in and for fulfilling information obligations toward Participants, in accordance with the law and the WhatsApp Business Policy.
§7. AI and automation
The Platform may develop features that use artificial intelligence, including:
- webinar analysis,
- participant activity analysis,
- content generation,
- message generation,
- webinar chatbots,
- webinar effectiveness analysis,
- automated recommendations.
AI features may use data provided to the Platform to the extent necessary to provide the given functionality.
The Service Provider does not use customer data to train its own AI models without an appropriate legal basis.
§8. Cookies and analytical technologies
The Platform uses:
- technical cookies,
- security cookies,
- analytical cookies,
- marketing cookies.
We may use, among others:
- Google Analytics,
- Meta Pixel,
- remarketing tools,
- security tools,
- error monitoring tools.
Marketing and analytical cookies are used after obtaining the appropriate consent of the user, where such consent is required by law.
Detailed information can be found in the Cookie Policy.
§9. Sub-processors and data recipients
We may use the services of third parties that support the operation of the Platform, in particular:
- Supabase,
- Railway,
- Vercel,
- AWS,
- Cloudflare,
- Stripe,
- Amazon SES,
- MailerLite,
- Sentry,
- Google,
- Meta (including WhatsApp Business Platform / Cloud API),
- OpenAI.
Creators may additionally integrate the Platform with:
- MailerLite,
- GetResponse,
- ActiveCampaign,
- SMSAPI,
- WhatsApp Business Platform (Meta),
- Kit,
- Klaviyo.
§9a. WhatsApp communication (WhatsApp Business Platform)
The Webivio Platform enables Creators to send webinar notifications through the WhatsApp Business Platform channel (Meta Cloud API). This section supplements the information required by Meta and by data protection regulations.
Scope of processing
In connection with the use of the WhatsApp integration, we may process:
Webinar Participant data (as a processor on behalf of the Creator):
- phone number (in international format),
- first name and other data provided in the message template parameters,
- the content of messages sent and received,
- technical metadata (delivery status, read status, message identifiers, timestamps),
- data related to the webinar sign-up (e.g., webinar title, link).
Creator data (as a controller or processor — depending on the context):
- WhatsApp Business account identifiers (WABA ID, Phone Number ID),
- Meta API access tokens (stored in a secured form),
- the number's display name (Display Name),
- information about the state of Meta billing (e.g., whether a payment method has been added),
- Meta login data within Embedded Signup (when the Creator connects the account via Facebook Login for Business).
Third party — Meta
To send and receive WhatsApp messages, we use the infrastructure of Meta Platforms Ireland Limited and Meta Platforms, Inc. (USA).
Meta processes data in order to:
- deliver WhatsApp messages,
- manage message templates,
- handle billing for the use of the WhatsApp Business platform,
- ensure security and compliance with Meta's policies.
Information about the processing of data by Meta:
Data transfer outside the EEA
Transferring data to Meta (including to the USA) may involve a transfer outside the European Economic Area. We apply appropriate safeguards provided for by the GDPR, in particular standard contractual clauses and — where applicable — compliance mechanisms provided for by the European Commission (e.g., the EU–US Data Privacy Framework).
Retention period
We retain data related to WhatsApp messages:
- for the time necessary to provide the webinar notification service,
- for the period required to handle Participant replies and Creator notifications,
- in accordance with the Platform's retention policy and the DPA,
- in security logs — for the period necessary for diagnostics and infrastructure protection.
Participants' rights and opt-out
A Webinar Participant whose data concerns WhatsApp communication should direct requests regarding their data (access, rectification, deletion, objection, withdrawal of consent) to the Creator (the data controller).
The Creator should enable the Participant to opt out of WhatsApp messages in accordance with applicable regulations and Meta's rules (including through a clear opt-out mechanism, e.g., contacting the Creator or replying with a request to stop sending — depending on the Creator's configuration).
The Platform may send the Creator notifications of incoming messages (e.g., email) so that the Creator can respond in Meta Business Suite or another tool indicated by the Creator.
Rules for using WhatsApp data
In accordance with Meta's requirements:
- we use the data obtained through WhatsApp communication solely to the extent necessary to handle messages with the given Participant and to provide the Platform's services,
- we do not use the content of WhatsApp conversations for purposes unrelated to handling webinars and communication at the Creator's request,
- we do not share data from one conversation with other Platform customers.
§10. Data transfer outside the EEA
As a rule, data is processed within the European Economic Area.
However, some technology providers' services may involve the transfer of data outside the EEA.
In such cases, we apply appropriate safeguards required by the GDPR, in particular:
- standard contractual clauses,
- compliance mechanisms provided for by the European Commission,
- appropriate technical and organizational safeguards.
§11. Cloud infrastructure and external integrations
The Webivio Platform uses the cloud infrastructure of technology providers whose main resources used by the Platform are located within the European Union, in particular within the countries of the European Economic Area (EEA).
In particular, Platform data may be processed using infrastructure located within the EU by providers such as:
- Supabase,
- Railway,
- Vercel,
- AWS,
- Cloudflare,
- Amazon SES.
At the same time, the Platform enables integration with the services and applications of third parties used by Creators. Some of these services may use infrastructure or servers located outside the European Economic Area (EEA), in particular in the United States.
This applies, among others, to services such as:
- Google Analytics,
- Meta Pixel,
- MailerLite,
- ActiveCampaign,
- GetResponse,
- Klaviyo,
- OpenAI,
- Meta (WhatsApp Business Platform),
- Kit,
- other integrations activated by the Creator.
Where data is transferred outside the EEA, appropriate safeguarding mechanisms required by the GDPR are applied, in particular standard contractual clauses approved by the European Commission or other compliance mechanisms provided for by law.
§12. How long we retain data
We retain data for the period:
- necessary to provide the services,
- required by law,
- necessary to protect against claims,
- required by the security and backup policy.
After an account is deleted, data may be temporarily stored in backups and security logs in accordance with the retention policy.
After the retention period ends, data is deleted or anonymized.
§13. How we protect data
We apply security measures appropriate to the risk, including:
- TLS encryption,
- backups,
- security monitoring,
- rate limiting,
- infrastructure monitoring,
- error monitoring,
- access control,
- security logs,
- cloud infrastructure safeguards.
§14. What rights you have
You have the right to:
- access your data,
- rectify your data,
- erase your data,
- restrict processing,
- object,
- data portability,
- withdraw consent.
If you wish to exercise your rights, contact us: support@webivio.com
§15. Complaint to the supervisory authority
You have the right to lodge a complaint with the President of the Personal Data Protection Office.
§16. Server logs
Using the Platform involves sending requests to the server.
Logs may include:
- IP address,
- date and time,
- browser information,
- device information,
- operating system information.
Logs are used solely for technical, security, and Platform administration purposes.
§17. Amendments to the Privacy Policy
We may update this Privacy Policy.
We will inform users of significant changes through:
- a notice within the Platform,
- an email message,
- the publication of a new version of the document.
§18. Contact
For matters related to the protection of personal data, contact us: