Legal
Privacy policy
Last updated September 19, 2026
This notice explains how SIA ADVERTIMO, a company registered in Latvia (EU/EEA), trading as Kavra Lab at kavralab.com, processes personal data. We describe two different things in one place because they are genuinely different: the IP-intelligence reference data we build ourselves, and the real-time checks our business Customers send us about their own visitors. Section 1 explains which role applies to which.
In short
- Two roles, not one. We are the controller for the IP-intelligence reference data we compile ourselves, and a processor when a Customer sends us data about one of their own visitors for a real-time check.
- The bot check itself needs no cookie. That does not make every part of our stack cookie- or transfer-free — see §6 and §10 for what actually happens.
- EU data plane baseline. Our main processing runs on EU infrastructure; some service providers and data sources sit outside the EEA, disclosed honestly in §6, not hidden behind a blanket "EU-only" claim.
- Retention is bounded, not indefinite — see §7 for the actual periods.
- No certification claimed. This page describes our practices; we do not present it as proof that compliance has been independently verified.
Who we are, and in what role
Kavra Lab ("Kavra," "we," "us") is a product of SIA ADVERTIMO, registration number 42103094905, registered office Pulkveža Brieža iela 21–6, Rīga, LV-1010, Latvia. We provide bot, automation and fraud-detection technology (the "Service") that business Customers embed in their own websites and apps, plus a related IP-Intelligence data service.
We act in two different roles, and which one applies depends on which dataset is involved:
- We are a processor when a Customer's website or app sends us data about one of their own visitors — an IP address, browser signals — for a real-time fraud check. The Customer is the controller of that data: they decide why and how the check is used, and we act on their instructions. If you have a question about a specific check performed on a site you visited, that site is the right first point of contact; we will assist them if they refer your request to us.
- We are the controller for our own IP-Intelligence reference data: the classifications we build from public and licensed sources (network type, ASN ownership, coarse geolocation and reputation signals) that our detection product checks incoming IPs against. This notice covers that controller processing in detail, and describes the processor processing above in general terms.
What we process, and where it comes from
| Category | Examples | Source |
|---|---|---|
| Network / IP data | IP address, ASN, hosting/VPN/proxy/Tor classification, network reputation | Observed directly at the point of a request; enriched against our reference dataset |
| Coarse geolocation | Country, and where enabled, city/region-level location derived from the IP | Third-party geolocation databases |
| Browser/device signals | Technical characteristics of the browser/runtime used to reach a Customer's site — not your name, email or account details | Collected by our client script, running on the Customer's site, only where the Customer has integrated it |
| Threat/reputation intelligence | Whether an IP has previously been associated with abuse, scanning or known malicious infrastructure | Public and licensed threat-intelligence feeds |
| Enquiry / lead data (this website) | Name, work email, company you provide via a form on kavralab.com | Provided directly by you |
| Account & support data | Account, billing-contact and support-ticket details for business Customers | Provided by the Customer |
Some reference data above is obtained indirectly, from third-party sources rather than from you directly. We treat an IP address as personal data as a matter of policy, consistent with the CJEU's reasoning in Breyer v. Germany (C-582/14), even though we do not ourselves hold the subscriber records that would identify a specific person from it. We do not collect or infer health, political opinion, religious belief, sexual orientation or other special-category data (Art. 9 GDPR).
Why we process it, and our legal basis
Our purpose is fraud, automation and abuse prevention — for our own platform and for Customers' platforms. Our legal basis is legitimate interests (Art. 6(1)(f) GDPR); Recital 47 specifically recognises fraud prevention as a legitimate interest. Where a Customer submits additional personal data to us directly, that data is processed on the Customer's instruction, under whatever basis the Customer itself has established with you.
For enquiry/lead data you send us through kavralab.com, our basis is taking steps at your request before a possible contract, and our legitimate interest in responding to business enquiries.
Cookies and device access are separate. Where any part of our stack reads from or writes to your device, that requires consent or a specific legal exception under ePrivacy rules in addition to the basis above — legitimate interests alone do not permit access to your device. See §10.
Automated decision-making
Our Service produces evidence-based risk indicators, not a final allow/deny decision. The score and the reason category are derived from the same underlying evidence, so they cannot contradict each other, and that evidence is available to the Customer through an explain interface. The decision to block, challenge or allow a specific action is made by the Customer's own system, not by us — if you believe a decision made against you was incorrect, the Customer operating the site you visited is responsible for that decision and any review process. Where your case turns out to depend on data we hold, we will provide the Customer with what is needed to explain it.
International transfers
Our main processing runs on infrastructure located in the European Union. We do not claim that no data ever leaves the EEA: some supporting flows involve recipients or providers outside the EEA — for example domain-name and certificate infrastructure, any live per-IP query to a non-EEA provider (§5), an internal messaging channel used for lead follow-up, and email — and some of the reference data we consume comes from providers based outside the EEA. Where such a transfer takes place, we rely on an appropriate safeguard, such as an adequacy decision, a specifically certified recipient under the EU-U.S. Data Privacy Framework, or the EU Standard Contractual Clauses. If we add processing capacity in additional regions to reduce latency, this notice is updated and safeguards are put in place before that capacity goes live.
Retention
We keep data only as long as necessary for the purpose above, on a bounded schedule rather than by default forever:
- Raw, exact-IP observation data is retained for a bounded period before it is either reduced to a genuinely anonymised aggregate, or converted to a pseudonymous, keyed record that preserves abuse-history value — kept for approximately 90 days from the original observation — without retaining the raw IP.
- Anonymised reporting and abuse-statistics output derived from that data is kept for approximately 13 months.
- Lead/enquiry data submitted through kavralab.com is kept for a limited period after our last meaningful contact with you.
- Periods run from the original observation, not from a later time the record is queried, rebuilt or re-observed. No dataset is retained indefinitely by default; any longer period needs a specific, documented purpose.
Backups are a bounded, encrypted exception to the schedule above, not a way to keep data indefinitely — see Security & trust for how data flows through the Service.
Your rights
Subject to applicable law and the fraud-prevention limitation below, you may have the right to:
- Ask what data we hold about a specific IP address or device (access, Art. 15).
- Ask us to correct inaccurate data (Art. 16).
- Ask us to erase your data, or restrict its processing (Art. 17, 18).
- Receive data you provided to us in a portable format, where applicable (Art. 20).
- Object to our processing based on legitimate interests (Art. 21).
- Lodge a complaint with a supervisory authority — see §11.
Fraud-prevention limitation: we may decline or narrow a request where honouring it would defeat the fraud-prevention purpose itself — for example, an erasure request used specifically to clear a documented record of malicious activity associated with an IP. This is not a blanket refusal right: erasure, objection and the "manifestly unfounded or excessive" test (Art. 12(5)) are each handled on their own terms, any refusal states specific grounds, and genuine, unrelated personal data is still honoured.
How to exercise a right: contact us using the details in §11. Because an IP address or device signal is not by itself a verified identity, we may ask for reasonable additional information to confirm the request relates to you, without demanding excessive proof.
Response time: we respond within one calendar month of receiving your request (the clock runs from receipt, not from a later verification step), with a possible extension for complex requests, which we will tell you about within that first month.
Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls, secret-management practices that keep credentials out of source control, and logging designed to exclude personal data from cleartext logs by default. See Security & trust for the data-flow and retention detail behind this statement. We describe these measures; we do not present this page as an independent certification.
Contact and complaints
- Controller: SIA ADVERTIMO, Pulkveža Brieža iela 21–6, Rīga, LV-1010, Latvia (reg. no. 42103094905).
- Privacy contact: [email protected] — if that address doesn't reach us, write to [email protected] instead.
- We are established in the EU, so an Art. 27 EU representative is not required.
- You have the right to lodge a complaint with a supervisory authority. Ours is the Datu valsts inspekcija (DVI), Elijas iela 17, Rīga, LV-1050, Latvia, [email protected]. You may also complain to the authority in your own EU/EEA country.
Changes to this notice
We will update this notice when our processing changes materially — for example, before activating a new processing region — and update the date at the top when we do.
Note: this notice describes our current practices in plain language. It is not a certification, and we do not present "GDPR compliant" as a badge we have earned. Questions are welcome in the meantime at [email protected].