# Privacy policy

Source: https://kavralab.com/privacy/

Last updated September 19, 2026
This notice explains how SIA ADVERTIMO, a company registered in Latvia (EU/EEA), trading as Kavra Lab at kavralab.com, processes personal data. We describe two different things in one place because they are genuinely different: the IP-intelligence reference data we build ourselves, and the real-time checks our business Customers send us about their own visitors. Section 1 explains which role applies to which.

## In short

- Two roles, not one. We are the controller for the IP-intelligence reference data we compile ourselves, and a processor when a Customer sends us data about one of their own visitors for a real-time check.

- The bot check itself needs no cookie. That does not make every part of our stack cookie- or transfer-free — see §6 and §10 for what actually happens.

- EU data plane baseline. Our main processing runs on EU infrastructure; some service providers and data sources sit outside the EEA, disclosed honestly in §6, not hidden behind a blanket "EU-only" claim.

- Retention is bounded, not indefinite — see §7 for the actual periods.

- No certification claimed. This page describes our practices; we do not present it as proof that compliance has been independently verified.

## Who we are, and in what role

Kavra Lab ("Kavra," "we," "us") is a product of SIA ADVERTIMO, registration number
42103094905, registered office Pulkveža Brieža iela 21–6, Rīga, LV-1010, Latvia. We
provide bot, automation and fraud-detection technology (the "Service") that business Customers embed
in their own websites and apps, plus a related IP-Intelligence data service.

We act in two different roles, and which one applies depends on which dataset is involved:

- We are a processor when a Customer's website or app sends us data about one of their own
visitors — an IP address, browser signals — for a real-time fraud check. The Customer is the
controller of that data: they decide why and how the check is used, and we act on their
instructions. If you have a question about a specific check performed on a site you visited, that
site is the right first point of contact; we will assist them if they refer your request to us.

- We are the controller for our own IP-Intelligence reference data: the classifications we
build from public and licensed sources (network type, ASN ownership, coarse geolocation and
reputation signals) that our detection product checks incoming IPs against. This notice covers
that controller processing in detail, and describes the processor processing above in general
terms.

## What we process, and where it comes from

CategoryExamplesSource

Network / IP dataIP address, ASN, hosting/VPN/proxy/Tor classification, network reputationObserved directly at the point of a request; enriched against our reference dataset
Coarse geolocationCountry, and where enabled, city/region-level location derived from the IPThird-party geolocation databases
Browser/device signalsTechnical characteristics of the browser/runtime used to reach a Customer's site — not your name, email or account detailsCollected by our client script, running on the Customer's site, only where the Customer has integrated it
Threat/reputation intelligenceWhether an IP has previously been associated with abuse, scanning or known malicious infrastructurePublic and licensed threat-intelligence feeds
Enquiry / lead data (this website)Name, work email, company you provide via a form on kavralab.comProvided directly by you
Account & support dataAccount, billing-contact and support-ticket details for business CustomersProvided by the Customer

Some reference data above is obtained indirectly, from third-party sources rather than from you
directly. We treat an IP address as personal data as a matter of policy, consistent with the CJEU's
reasoning in Breyer v. Germany (C-582/14), even though we do not ourselves hold the
subscriber records that would identify a specific person from it. We do not collect or infer health,
political opinion, religious belief, sexual orientation or other special-category data (Art. 9
GDPR).

## Why we process it, and our legal basis

Our purpose is fraud, automation and abuse prevention — for our own platform and for
Customers' platforms. Our legal basis is legitimate interests (Art. 6(1)(f) GDPR); Recital 47
specifically recognises fraud prevention as a legitimate interest. Where a Customer submits
additional personal data to us directly, that data is processed on the Customer's instruction, under
whatever basis the Customer itself has established with you.

For enquiry/lead data you send us through kavralab.com, our basis is taking steps at your request
before a possible contract, and our legitimate interest in responding to business enquiries.

Cookies and device access are separate. Where any part of our stack reads from or writes to
your device, that requires consent or a specific legal exception under ePrivacy rules in addition to
the basis above — legitimate interests alone do not permit access to your device. See §10.

## Automated decision-making

Our Service produces evidence-based risk indicators, not a final allow/deny decision. The
score and the reason category are derived from the same underlying evidence, so they cannot
contradict each other, and that evidence is available to the Customer through an explain interface.
The decision to block, challenge or allow a specific action is made by the Customer's own
system, not by us — if you believe a decision made against you was incorrect, the Customer operating
the site you visited is responsible for that decision and any review process. Where your case turns
out to depend on data we hold, we will provide the Customer with what is needed to explain it.

## Who we share data with

- Sub-processors who help us run the Service, such as hosting, DNS and certificate providers.

- Data source providers whose published data we consume to build our reference dataset. For
most of these we receive bulk published data and do not send them your data. Where we make a
live per-IP query to an external service, that specific address is disclosed to that
provider — a separate outbound disclosure, and an international transfer where the provider sits
outside the EEA (see §6).

- Enquiry follow-up: lead/enquiry details you send via kavralab.com are handled by our
lead-processing service and may be passed to an internal messaging channel for follow-up.

- We do not sell our compiled data to third parties. Pseudonymised or aggregated data is not
automatically safe to share, so any distribution is decided on its own merits, not assumed.

- We disclose data where required by law, or to protect rights, safety or the integrity of the
Service.

## International transfers

Our main processing runs on infrastructure located in the European Union. We do not claim that
no data ever leaves the EEA: some supporting flows involve recipients or providers outside the EEA —
for example domain-name and certificate infrastructure, any live per-IP query to a non-EEA provider
(§5), an internal messaging channel used for lead follow-up, and email — and some of the reference
data we consume comes from providers based outside the EEA. Where such a transfer takes place, we
rely on an appropriate safeguard, such as an adequacy decision, a specifically certified recipient
under the EU-U.S. Data Privacy Framework, or the EU Standard Contractual Clauses. If we add
processing capacity in additional regions to reduce latency, this notice is updated and safeguards
are put in place before that capacity goes live.

## Retention
We keep data only as long as necessary for the purpose above, on a bounded schedule rather than by
default forever:

- Raw, exact-IP observation data is retained for a bounded period before it is either reduced to a
genuinely anonymised aggregate, or converted to a pseudonymous, keyed record that preserves
abuse-history value — kept for approximately 90 days from the original observation — without
retaining the raw IP.

- Anonymised reporting and abuse-statistics output derived from that data is kept for approximately
13 months.

- Lead/enquiry data submitted through kavralab.com is kept for a limited period after our last
meaningful contact with you.

- Periods run from the original observation, not from a later time the record is queried,
rebuilt or re-observed. No dataset is retained indefinitely by default; any longer period needs a
specific, documented purpose.

Backups are a bounded, encrypted exception to the schedule above, not a way to keep data indefinitely
— see Security & trust for how data flows through the Service.

## Your rights
Subject to applicable law and the fraud-prevention limitation below, you may have the right to:

- Ask what data we hold about a specific IP address or device (access, Art. 15).

- Ask us to correct inaccurate data (Art. 16).

- Ask us to erase your data, or restrict its processing (Art. 17, 18).

- Receive data you provided to us in a portable format, where applicable (Art. 20).

- Object to our processing based on legitimate interests (Art. 21).

- Lodge a complaint with a supervisory authority — see §11.

Fraud-prevention limitation: we may decline or narrow a request where honouring it would
defeat the fraud-prevention purpose itself — for example, an erasure request used specifically to
clear a documented record of malicious activity associated with an IP. This is not a blanket refusal
right: erasure, objection and the "manifestly unfounded or excessive" test (Art. 12(5)) are each
handled on their own terms, any refusal states specific grounds, and genuine, unrelated personal data
is still honoured.

How to exercise a right: contact us using the details in §11. Because an IP address or device
signal is not by itself a verified identity, we may ask for reasonable additional information to
confirm the request relates to you, without demanding excessive proof.

Response time: we respond within one calendar month of receiving your request (the
clock runs from receipt, not from a later verification step), with a possible extension for complex
requests, which we will tell you about within that first month.

## Security

We apply technical and organisational measures appropriate to the risk, including encryption in
transit, access controls, secret-management practices that keep credentials out of source control,
and logging designed to exclude personal data from cleartext logs by default. See
Security & trust for the data-flow and retention detail behind this
statement. We describe these measures; we do not present this page as an independent certification.

## Cookies and similar technologies

The check that tells a real visitor from automation on a Customer's site needs no cookie to run.
That is a statement about the bot check specifically, not a claim that nothing on kavralab.com or in
our supporting infrastructure ever touches your device. Where any part of our stack does read from or
write to your device, that requires consent or a specific statutory exception under ePrivacy rules,
separately from the GDPR basis in §3 — one does not substitute for the other. The cookies this
marketing website itself sets, and how to change your choice, are described in full in our
cookie policy.

## Contact and complaints

- Controller: SIA ADVERTIMO, Pulkveža Brieža iela 21–6, Rīga, LV-1010, Latvia (reg. no.
42103094905).

- Privacy contact: privacy@kavralab.com — if that address
doesn't reach us, write to hello@kavralab.com instead.

- We are established in the EU, so an Art. 27 EU representative is not required.

- You have the right to lodge a complaint with a supervisory authority. Ours is the
Datu valsts inspekcija (DVI), Elijas iela 17, Rīga, LV-1050, Latvia,
pasts@dvi.gov.lv. You may also complain to the authority in
your own EU/EEA country.

## Changes to this notice

We will update this notice when our processing changes materially — for example, before activating a
new processing region — and update the date at the top when we do.

Note: this notice describes our current practices in plain language. It is not a certification, and
we do not present "GDPR compliant" as a badge we have earned. Questions are welcome in the meantime
at privacy@kavralab.com.


