Privacy and personal information
Privacy Policy
This policy explains what data Loquava processes, why it is needed, who may receive it and how you can exercise your rights.
- Effective
- August 6, 2026
- Last updated
- August 9, 2026
The French version prevails if a translation is inconsistent.
At a glance
Two roles, clearly separated
Loquava controls its accounts and acts as a service provider when a business processes its own customers’ data.
No sale of personal information
Personal information is not sold or used for another tenant’s targeted advertising.
A person answers
Access, correction and deletion requests are received at privacy@loquava.com.
Who we are and our roles
In this policy, “Loquava” means the service operated by de Oliveira Delfino, Wesllen in Québec, Canada.
Loquava is responsible for information relating to its website, prospects, subscribers and account administration. When a customer business uses Loquava to communicate with its own customers, that business generally determines why the information is processed and Loquava acts as its service provider.
Person in charge of the protection of personal information
de Oliveira Delfino, Wesllen — privacy@loquava.com
Scope
This policy covers website visitors, people requesting a demo or support, account holders, authorized tenant users and, where the relevant features are enabled, people who communicate with a customer business by phone, SMS, email, WhatsApp, Messenger or Instagram.
Customer businesses remain responsible for their own notices, lawful authority, consents and practices toward their customers. A customer’s own privacy policy may therefore also apply.
Information we may process
- Identity and contact details: name, email, phone number, language and organization.
- Account and security data: technical identifiers, roles, tenant, sign-in logs and security events.
- Subscription and billing data: plan, payment status, invoices and transaction references; full card data is handled by the payment provider.
- Business data entrusted by a customer: customer profiles, appointments, availability, services, consents and communication preferences.
- Communications: message content and metadata, attachments, channel or phone identifiers and conversation history when a module is enabled.
- Voice and automation data: call metadata, transcripts, summaries or recordings only where the relevant feature is enabled and required notices or consents are in place.
- Website and support data: IP address, device, browser, essential cookies and the content of requests sent to our teams.
We seek to limit collection to what is necessary. Do not send us passwords, access tokens, full card numbers or sensitive information that is not required for the requested service.
Why we use it
- Provide, configure, secure and improve Loquava.
- Authenticate users, enforce roles and isolate each tenant’s data.
- Route communications and run automations selected by the customer business.
- Manage demos, support, subscriptions, billing and administrative communications.
- Detect abuse, investigate incidents and preserve required evidence.
- Meet legal obligations and respond to valid individual requests.
We do not use one tenant’s data to target advertising for another tenant, and we do not sell personal information.
WhatsApp, Messenger, Instagram and other channels
When a business connects a channel, Loquava may receive identifiers for the Page, professional account, WhatsApp Business number or conversation, together with messages, attachments, delivery status, public names and the permissions required for the requested operation.
Connection is initiated by an authorized owner or administrator. Loquava never needs the owner’s personal Facebook or Instagram password. Permissions can be withdrawn in Loquava or with the relevant platform. Removing access at Meta stops future access, but a request to Loquava may still be needed to delete copies already retained by the service.
Deleting Meta integration data
See /data-deletion for the steps, required information and applicable legal limitations.
Artificial intelligence and human decisions
Some features may classify a request, suggest a reply, summarize a conversation or assist with an appointment. Availability depends on enabled modules. Automated output may be incomplete or inaccurate and requires supervision whenever professional judgment is needed.
Loquava is not designed for emergencies and must not be used on its own to make medical, legal, financial, employment or other decisions with a significant effect on a person.
Providers, disclosure and transfers
We may use providers for hosting and infrastructure, identity, payments, communications, telephony, artificial intelligence, monitoring and support. Depending on enabled modules, these may include Microsoft Azure, Vercel, Stripe, Meta and providers for the selected channel.
Providers receive only the information needed for their function, under their terms and applicable safeguards. Some may process information outside Québec or Canada. Before enabling affected production processing, Loquava assesses the risks and applies appropriate contractual, organizational and technical measures.
We may also disclose information where required by law, to protect people’s rights and safety, or as part of a legitimate business transaction with appropriate safeguards.
Retention and deletion
We retain information only as long as needed for the purposes described, the applicable agreement and legal, tax, security or evidentiary requirements. The period varies by data category, account status, module and customer business choices.
After a valid request or when the need ends, data is deleted, anonymized or isolated for deletion, subject to retention duties. Protected backups and security logs expire on their own cycle and are not returned to active use except for an authorized recovery.
Your rights and choices
You may request access to or correction of your information, withdraw consent where applicable, request deletion and exercise any other right provided by law by writing to privacy@loquava.com. We may verify your identity and authority before acting.
For an access or correction request governed by Québec law applicable to businesses, we respond within 30 days of receipt. If you are a customer of a business using Loquava, contact that business first; we will assist it with the request.
You may also complain to our person in charge of personal information and, where applicable, to Québec’s Commission d’accès à l’information.
Cookies and security
The website uses cookies and technologies strictly required for sessions, security, preferences and requested functionality. If non-essential technologies are added, required information and choices will be presented before use where the law requires it.
Measures include encrypted communications, role-based access, tenant isolation, least privilege, security logging and backup practices. No system is risk-free; responsibly report a vulnerability to security@loquava.com.
Children
Loquava is a business service and is not offered directly to children. A customer business processing a minor’s information must have the required authority, notices and consents.
Changes and contact
We may update this policy when our practices, providers or applicable requirements change. The date above will be revised and appropriate notice will be provided when a change is material.
Privacy questions, requests or complaints: de Oliveira Delfino, Wesllen, person in charge of the protection of personal information, Québec City, Québec, Canada — privacy@loquava.com.
At a glance
A question about your information?
Write directly to the person in charge of personal information. Never send a password or access token by email.