Privacy Policy
Version 1.0 — last updated 5 August 2026
This policy explains what personal data LAVAN LABS LTD handles when you use Coworkkit, why, and what your rights are.
LAVAN LABS LTD · registered in England & Wales, company number 17361107 · registered office 128 City Road, London EC1V 2NX. Contact: privacy@coworkkit.ai.
1. The two groups of people in this policy
Coworkkit is developer infrastructure, so there are two very different groups of people whose data passes through it. Almost everything below depends on which one you are.
If you're our customer — a developer or company with a Coworkkit account — we hold your account, billing and usage data, and we are the data controller for it. Sections 2, 4 and 7 are about you.
If you're an end-user — someone using an application built by one of our customers, who talks to the AI co-worker — you have no account or relationship with us. Your voice and what you say passes through our systems so we can provide the service to the company that built the application. For that data we act as a data processor on that company's instructions, and they are the controller. Section 3 is about you, and section 8 explains where to take a request.
2. Data we hold about our customers
| What | Why | Lawful basis |
|---|---|---|
| Name, email, account credentials | to create and secure your account | performance of a contract |
| Company name, billing country | to bill you and meet tax obligations | contract / legal obligation |
| Payment details | we don't hold these — Paddle does (see section 5) | — |
| Usage records — session counts, minutes, tokens, API calls | to meter usage, bill you, and manage capacity | contract / legitimate interests |
| Support correspondence | to answer you | contract / legitimate interests |
3. Data that passes through when an end-user talks to the co-worker
When someone speaks to a Coworkkit co-worker inside our customer's application, the following flows through our systems:
- Voice audio — captured in the browser and streamed to our speech-recognition service so it can be turned into text.
- The transcript — what was said, and what the co-worker said back.
- Context from the page — information about the screen the user is on, which our customer's application chooses to send.
- Technical session data — connection details, timings and duration, used to run the session and meter it.
We process this on our customer's instructions, to provide the service to them. We don't use it to build a profile of the end-user, we don't sell it, we don't use it for advertising, and we do not use it — or permit Google to use it — to train AI models.
Is voice "biometric data"?
No — not as we use it. Under data protection law, voice becomes biometric data only when it's processed specifically to identify a person — a voiceprint. Coworkkit does not do speaker identification. We convert speech to text so the AI can respond, which makes it ordinary personal data rather than a special category.
⚠️ But what someone says is a different matter. A person can mention their health, their beliefs or anything else in the course of a conversation, and that would sit in a transcript. If your application is likely to prompt conversations of that kind, that's a factor in your own data protection assessment as the controller.
4. How long we keep things
We do not record calls. We do not store voice audio, and we do not store transcripts of what is said. This is the most important thing in this policy, so we'll be specific:
- Voice audio is streamed to speech recognition during the live session and is never written to storage. There is no recording, and no audio file is created.
- Transcripts exist only for the moment — shown to the user as live captions, and held in memory so the AI can respond during that one session. They are not written to our database and not written to our logs.
What we do keep:
- Account and organisation records — your email, name, company and role — while your account is open, and afterwards for as long as tax and company law require us to (six years under UK law).
- Usage metadata — minutes used, session timings, and lifecycle events. This is metadata only; it contains none of the conversation content. We keep it while your account exists and for as long as we need it to bill you and settle any dispute.
Because we hold no audio and no transcripts, there is nothing of your end-users' actual conversations for us to retain, expose in a breach, or be compelled to hand over.
5. Who else processes data for us
We use a small number of service providers. Each is bound to process data only on our instructions.
| Provider | What they do | Where |
|---|---|---|
| Google Cloud — incl. Firebase Auth, Vertex AI, Speech-to-Text, Text-to-Speech (Google Ireland Ltd) | hosting, database, sign-in and identity, the AI language model, speech recognition and speech synthesis | Storage, audio, speech recognition and speech synthesis in europe-west4 (Netherlands); only the AI language-model step runs on Google's global endpoint — see §6 |
| Paddle (Paddle.com) | payments, invoicing and tax, as merchant of record. They hold your payment details; we don't. | UK / EU — see §6 |
| LiveKit | real-time voice transport | self-hosted on our own EU infrastructure |
| Resend | transactional email — sign-in links, and billing/low-balance notices | EU/US |
| Cloudflare Turnstile | bot protection on our product signup form — it sees the visitor's IP address | — |
We use no third-party analytics or session-recording tool in the product — no PostHog, Segment, Mixpanel or Sentry, and no advertising or tracking SDK.
Google Cloud acts as our processor under its Cloud Data Processing Addendum, which is automatically part of our agreement with Google. Google commits not to use the data we send it to train its models without our permission, and we give none.
We'll keep this list current, and it forms part of the data processing terms in our Terms of Service (§9), which apply to every customer.
6. Where data is processed
Your data is stored in the European Union. Our database, our servers, the real-time voice transport, speech recognition and speech synthesis all run in the EU (europe-west4, Netherlands) — speech recognition uses Google's EU regional endpoint. And as §4 says, we store no audio and no transcripts anywhere.
One step of the processing currently reaches Google's global infrastructure, and we'd rather tell you than imply otherwise. As we run the service today, the AI language model (Google Vertex AI Gemini) is called at Google's global endpoint, which doesn't guarantee a processing location. So the text of a conversation — what was said, sent to the model, and the model's reply — may be processed by Google outside the UK and EEA. Where that happens, it's covered by Google's data-processing terms and the EU Standard Contractual Clauses within them, applied to UK data-protection law. Google acts as our processor throughout; this affects where Google processes, not who does.
So, plainly: your stored data, your audio, speech recognition and speech synthesis all stay in the EU; the language-model step is currently processed globally. This reflects how the service is configured today, not a permanent limitation — and we don't claim otherwise either way.
Paddle, as merchant of record, processes your billing data under its own data-processing terms, which use adequacy decisions or Standard Contractual Clauses for any transfer outside the UK/EEA.
7. Your rights
If you're our customer, you can ask us to: give you a copy of your data; correct it; delete it; restrict or object to how we use it; or send it to another provider. You can also withdraw consent where we relied on it.
Email privacy@coworkkit.ai. We'll respond within one month.
8. If you're an end-user of an application built with Coworkkit
Your request should go to the company whose application you were using — they decide what data is collected and why, and they're the controller. We'll help them respond, but we can't act on their data without their instruction.
If you're not sure who that is, contact us at privacy@coworkkit.ai and we'll point you in the right direction.
9. Cookies and analytics
We use only strictly necessary cookies — the ones that keep you signed in and make the product work. These don't require consent, and we set no analytics or advertising cookie.
Our public website at coworkkit.ai has its own separate Website Privacy Notice covering what it does with data. The product itself uses no analytics and sets no tracking cookie.
10. Security
We protect data with encryption in transit, access controls, and infrastructure managed through code in a single hardened cloud project.
We'll be straight with you about the limits: we're a young company and we don't hold SOC 2 or ISO 27001. We don't claim certifications we don't have. If you need a security review before buying, ask us and we'll answer honestly.
11. Children
Coworkkit is a business tool and isn't directed at children. If you build with Coworkkit, you're responsible for ensuring your application isn't directed at children under 16, and for any consents required if children could use it.
12. Complaints
If you're unhappy with how we've handled your data, tell us first at privacy@coworkkit.ai — we'd rather fix it.
You can also complain to a data protection authority. In the UK that's the Information Commissioner's Office (ico.org.uk). If you're in the EU or EEA, you can complain to your local supervisory authority.
13. Changes to this policy
We may update this policy. Material changes will be notified by email to account holders at least 30 days in advance, and the version number and date at the top will change.
14. Contact
LAVAN LABS LTD · company number 17361107 · 128 City Road, London EC1V 2NX privacy@coworkkit.ai