Havilo
Sign in

Privacy Policy

Effective date
September 5, 2026

On this page

  1. 1Scope
  2. 2Information We Process
  3. 3How We Use Information
  4. 4AI and Automated Processing
  5. 5Cookies, Analytics, and Preference Signals
  6. 6How We Disclose Information
  7. 7Retention and Deletion
  8. 8Security
  9. 9Privacy Rights and Requests
  10. 10Age Requirement
  11. 11Updates and Contact
On this page11 sections

On this page

  1. 1Scope
  2. 2Information We Process
  3. 3How We Use Information
  4. 4AI and Automated Processing
  5. 5Cookies, Analytics, and Preference Signals
  6. 6How We Disclose Information
  7. 7Retention and Deletion
  8. 8Security
  9. 9Privacy Rights and Requests
  10. 10Age Requirement
  11. 11Updates and Contact
1

Scope

This Privacy Policy explains how Havilo, Inc., which operates Havilo ("Havilo," "we," "us," or "our"), handles personal information in connection with https://havilo.ai, the Havilo platform, and related services (collectively, the "Services").

Havilo provides the Services to enterprise and institutional customers ("Customers"). When we process information in Customer Content on a Customer's behalf, the Customer determines why and how that information is used, and its own privacy notices and instructions may also apply. We separately determine how we use information for account administration, sales, support, security, website analytics, and our business operations.

This policy applies to Customers, their authorized users, visitors to our website, and people who communicate with us about the Services. It does not govern a third party's independent handling of information.

2

Information We Process

We process the following broad categories of information:

  • Account and contact information. This includes names, business contact details, organization and workspace associations, authentication information, account settings, and communication preferences.
  • Customer Content. This includes content, records, files, communications, and other materials submitted, connected, or generated through the Services. Customers and authorized users decide what Customer Content they provide or authorize us to process.
  • Commercial and support information. This includes business contact details and records concerning proposals, orders, invoices, payment status, support requests, feedback, and our relationship with a Customer.
  • Technical and usage information. This includes IP address, device and browser information, application and account identifiers, logs, approximate location derived from IP address, feature activity, diagnostic information, and security or audit records.

We receive information from Customers and authorized users, when they direct other services or parties to provide information to us, and from service providers that help us operate the Services. We may also receive business contact information when someone communicates with us or when it is otherwise lawfully available for legitimate business purposes.

Sensitive personal information. Customer Content may contain sensitive personal information depending on what a Customer or authorized user chooses to submit, connect, or generate through the Services. Havilo does not intentionally solicit sensitive personal information that is unnecessary to provide the contracted Services. Customers and users should provide it only when permitted, appropriate, and necessary for their use of the Services.

Where a Customer uses a payment method supported by a third-party payment processor, that provider processes payment credentials under its own terms. Havilo generally receives transaction and payment-status information rather than full payment credentials.

Browser extension and mail add-ins. The Havilo browser extension and mail add-ins show Havilo's existing record for the email conversation open in Gmail or Outlook. To do that they read the address of the signed-in mailbox and the identifiers of the open conversation, message, and draft, and send them to Havilo to look up that conversation in the workspace the user connected. Text a user types into a Havilo control inside their mail client is sent to Havilo as that user's instruction. They do not read or send the content of mail from the mail client; mail content reaches Havilo only through a mailbox the Customer has connected to the Services. A sign-in credential for the connected workspace is stored on the user's device and removed when the user disconnects. Nothing collected by the extension or add-ins is sold, used for advertising, or shared for any purpose other than providing the Services.

Connected Google accounts

When you connect Google, Havilo uses your account email address to identify the connection. Gmail messages, attachments, and metadata support email, CRM, and AI features, including summaries, drafts, sending, and mailbox updates. Saved contacts and Other contacts are searched for correspondent photos. Calendar event and attendee information supports meetings, CRM context, and invitation responses. You choose which services to connect and which workspaces may use them.

Havilo and its hosting and AI service providers process Google data to deliver these features. Our use and transfer of Google data comply with the Google API Services User Data Policy, including its Limited Use requirements. These restrictions take precedence over any broader disclosure provisions in this policy.

3

How We Use Information

We use information to:

  • provide, configure, administer, maintain, and support the Services;
  • authenticate users and manage Customer workspaces and permissions;
  • process Customer Content in accordance with Customer instructions and agreements;
  • communicate about accounts, support, security, and changes to the Services;
  • monitor reliability, diagnose problems, and improve the Services;
  • protect Customers, users, Havilo, and the public from misuse, fraud, and security threats;
  • administer proposals, orders, invoices, and Customer relationships; and
  • comply with law, enforce agreements, and establish, exercise, or defend legal claims.

We use Customer Content to provide and support the Services for the applicable Customer, not for unrelated advertising or resale.

4

AI and Automated Processing

The Services may use artificial intelligence and other automated technologies to organize, retrieve, analyze, summarize, and generate information requested by a Customer or authorized user. These technologies may process Customer Content as part of providing the requested functionality.

We may engage AI infrastructure and service providers to process information on our behalf under contractual, technical, and organizational controls. Havilo remains responsible for handling Customer Content as described in this policy and the applicable Customer Agreement.

Havilo does not use Customer Content, including Google user data, to train artificial intelligence or machine learning models and requires its AI service providers not to use Customer Content to train their models.

5

Cookies, Analytics, and Preference Signals

We use cookies and similar technologies for authentication, preferences, security, reliability, and operation of the Services. Your browser may allow you to block or remove cookies, but doing so may prevent parts of the Services from working correctly.

We use Google Analytics to understand how our website and Services are used. Analytics data may include device and browser information, pages or features used, timestamps, approximate location, and pseudonymous session, device, or user identifiers where configured. Google processes this information under its own terms. We do not use Google Analytics to analyze Customer Content. You can learn about Google's privacy practices on its Privacy & Terms page and use the Google Analytics opt-out browser add-on.

Some browsers offer a Do Not Track setting. Because Do Not Track is not a uniform legal standard, we do not respond to it as a standalone signal. It is distinct from browser preference signals that may have legal effect under applicable law. You may contact us to exercise an applicable opt-out right.

6

How We Disclose Information

We may disclose information in the following circumstances:

  • Within a Customer account. Customer administrators and authorized users may access information according to the Customer's configuration, permissions, and instructions.
  • Service providers. We use providers that support hosting, security, authentication, communications, analytics, AI functionality, support, and business operations. They may process information only to perform services for us and subject to appropriate obligations.
  • Customer-directed recipients. We disclose information when a Customer or authorized user directs us to do so, including through services the Customer chooses to connect or use.
  • Legal and safety purposes. We may disclose information when reasonably necessary to comply with law or legal process, protect rights and safety, investigate misuse, or enforce our agreements.
  • Professional advisers and corporate transactions. We may disclose information to advisers under confidentiality obligations and in connection with a financing, merger, acquisition, reorganization, or sale of all or part of our business.

Havilo does not sell Customer Content or use Customer Content for third-party advertising. Some privacy laws define "sale" or "sharing" more broadly; applicable rights are described below.

7

Retention and Deletion

You can disconnect Google in Settings → Connected accounts to stop future access and synchronization. Saved workspace records remain subject to the retention terms below. To request deletion of Google data held by Havilo, email support@havilo.ai.

We retain personal information for as long as reasonably necessary to provide the Services, maintain the Customer relationship, fulfill the purposes described in this policy, and meet legal, security, fraud-prevention, accounting, and audit obligations. Retention may vary based on the type of information, the Customer Agreement, and applicable law.

When a Customer relationship ends, transition assistance and export access are governed by the applicable Customer Agreement. We delete or anonymize Customer Content from active systems when it is no longer needed, subject to legal holds and limited information retained for security, fraud prevention, dispute resolution, and audit purposes.

Information in backups is protected and removed through our ordinary backup lifecycle. We do not use backup copies for ordinary processing after deletion from active systems.

8

Security

We use reasonable technical and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure. These measures include controls appropriate to the nature of the information and the Services.

No method of transmission or storage is completely secure. Customers and users are also responsible for protecting credentials, configuring access appropriately, and notifying us promptly about suspected unauthorized use.

9

Privacy Rights and Requests

Depending on where you live and subject to applicable exceptions, you may have rights to access, correct, delete, or obtain a copy of personal information; restrict or object to certain processing; opt out of certain disclosures or uses; limit certain uses of sensitive personal information; or appeal a decision on a privacy request. We do not discriminate against people for exercising applicable privacy rights.

To submit a request, email support@havilo.ai. We may ask for information reasonably necessary to verify your identity, authority, and request. An authorized agent may submit a request where permitted by law, subject to verification.

If your request concerns Customer Content controlled by an organization that uses Havilo, please contact that organization first. We assist Customers with verified requests as required by applicable law and our agreements.

United States state privacy rights

Residents of states with comprehensive privacy laws may exercise the rights available under those laws when they apply to Havilo's processing. Rights, exceptions, verification requirements, response periods, and appeal procedures vary by jurisdiction. You may submit or appeal a request using the contact method above.

10

Age Requirement

The Services are designed for authorized business users who are at least 18 years old. They are not directed to children, and a person under 18 may not create an account or use the Services as an authorized user. If you believe a person under 18 has provided information directly to us in violation of this requirement, contact us so we can investigate and take appropriate action.

11

Updates and Contact

We may update this Privacy Policy to reflect changes to the Services, our practices, or applicable law. We will post the revised policy with a new effective date and, when appropriate, provide additional notice of material changes.

Questions, concerns, and privacy requests may be sent to support@havilo.ai.

Havilo, Inc., a Delaware corporation with operations in Alameda County, California

Havilo

The relationship intelligence platform for modern institutions.

Platform

  • Matchmaking
  • Enrichment
  • Data Ingestion
  • Meeting Intelligence
  • Interviewer
  • Proactive Intelligence
  • Workflow Automation

Solutions

  • Accelerators
  • University Programs

Company

  • Support
  • Contact
SOC 2 Type IIIn progress·GDPRIn progress
·
Trust center·Status
© 2026 Havilo, Inc.·Support·Privacy·Terms