Privacy Policy
1. Data Boundary Architecture
Autvy is architected from first principles to isolate customer data. The Autvy host worker runs directly on your server environment inside your own infrastructure boundary.
Data that NEVER leaves your server: WordPress database records (wp_users, wp_posts, wp_woocommerce_order_items, customer passwords, hashed tokens), file uploads, and media attachments.
Data sent to Autvy Supervisor: System telemetry including PHP runtime version, WordPress core and plugin version manifests, crash stack traces, synthetic TTFB latency response times, and machine action receipts.
2. Lawful Basis for Processing (GDPR & CCPA)
Under GDPR Article 6(1)(b), we process necessary telemetry strictly for the performance of our contract to maintain and protect your WordPress application.
Under GDPR Article 6(1)(f), we process aggregated crash statistics to improve system stability and identify universal plugin conflicts across the network.
3. Data Retention Windows
Real-time metric telemetry (CPU, TTFB, memory usage) is automatically rolled up and deleted after 90 days.
Remediation receipts and atomic rollback logs are retained for 365 days for regulatory audit compliance, after which they are permanently expunged.
4. Contact & Data Protection Officer
Questions or requests regarding data privacy may be directed to [email protected]. Requests for data export or deletion under GDPR are fulfilled within 14 business days.