What Kavra processes
| Category | Examples | Notes |
|---|---|---|
| Network data | IP address, network owner, proxy, VPN, Tor and datacenter classification | We treat an IP address as personal data as a matter of policy |
| Device and browser signals | Graphics, screen, hardware and browser properties, automation artifacts | Used as evidence, never as the identifier |
| Interaction signals | How the page was used before the protected action, such as pointer and timing patterns | Used to tell people from scripts |
| Identity data | Names, emails, phone numbers | Not needed; Kavra does not ask for them |
Roles and legal basis
When your site or app sends Kavra a check about one of your visitors, you are the controller and Kavra Lab (SIA ADVERTIMO) acts as your processor. For our own IP-intelligence reference data, we are the controller. Both roles are described in the privacy policy.
The rules that apply follow the visitor, not your company. You declare your legal basis per region; Kavra applies it to each visitor from their network location and respects your consent manager. Where a persistent identifier is not permitted, the script does not read browser storage at all.
How data is protected
Encrypted collection
Browser evidence travels in an application-layer encrypted envelope on top of TLS, so intermediaries cannot read or alter it.
Tamper-resistant tokens
Tokens are signed, single-use, short-lived and bound to one action. Replayed tokens are refused and reported.
Strict tenant isolation
Every project has its own keys. There is no cross-customer tracking or linking of your visitors with anyone else's.
Pseudonymous identities
Visitors appear under opaque, server-assigned IDs. Fingerprint values are keyed per project and used only as evidence.
Data minimization
Addresses used for internal consistency checks are hashed in the browser with a per-session salt, location is kept coarse, and no third-party services are called from your visitors' browsers.
Access control
Console roles (owner, operator, viewer), API keys that are shown once and can be revoked, and an audit log of every change.
Where data is processed and how long it is kept
| Topic | Practice |
|---|---|
| Location | EU infrastructure as the baseline; service providers outside the EEA are disclosed in the privacy policy |
| Retention | Bounded periods, defined per data type in the privacy policy; not indefinite |
| Erasure | Deletion support for data-subject requests |
| Automated decisions | Kavra recommends and explains; your backend decides, which supports your obligations around automated decision-making |
Certifications and procurement
We do not claim security certifications we do not hold. This page and the privacy policy describe our practices; they are not a statement that compliance has been independently verified. For procurement, we share a data processing agreement and security documentation with your team on request through the contact form.
Found a security issue? Report it through the contact form and choose "Something else"; it goes straight to the team.