Skip to content
OOwevaro
ProductUGC creatorsResourcesFree toolsPricing
Open demoDemo
Home/Legal center/Owevaro Privacy Notice

Canonical public document

Official-language notice. This confirmed English translation is published for convenience. The Italian source remains canonical and prevails in the event of a discrepancy.

Owevaro Privacy Notice

Version
2026-08-14-privacy-v9
Last reviewed
14 August 2026
Status
in_review
SHA-256
32bd939dc3ea93259e7353beab619ca4470a0970c400af1ac0b7e2b325955277

> Published English translation confirmed by the owner on 17 August 2026. The Italian source remains canonical and prevails in the event of a discrepancy. The underlying document retains status in_review and effective_from: null.

Draft intended for professional review. The processing of real documents is not authorised. Email and calendar integrations are available only in an allowlisted private test operated by the controller; they are not open to the public.

Identity and contact details

Alin Daniel Epure, Italian VAT number 17835711007, Via Antonio Banfi 10, 00166 Rome, Italy. Current contact: info@lentita.com; certified email (PEC): a.epure@pec.it. Whether to introduce a dedicated Owevaro address remains an open decision; a non-existent contact address is not published.

Roles by purpose

Owevaro acts as an independent controller for registration, authentication, account and workspace management, security, logging, abuse prevention, support, complaints, privacy requests, legal obligations, establishment, exercise or defence of legal claims, operational communications and future billing.

Owevaro normally acts as a processor when a professional customer or organisation determines the purposes of the workspace and entrusts personal data on the basis of documented instructions and a final DPA. That business flow is closed.

In the consumer flow, the user is not assumed to be the controller for every item of counterparty data. The legal basis, necessity and Article 14 obligations concerning counterparties, representatives, signatories, collaborators and other named persons are still under assessment: real consumer documents remain prohibited.

Data, data subjects and sources

The Agency Summary aggregates amounts already recorded by customer and by an optional organisational group; Owevaro does not receive, hold or transfer funds.

Account and session data, declared capacity, notice/acceptance events, technical logs, workspace records and synthetic files. In the private integration test, following separate authorisations by the controller, Owevaro processes account/provider details, scopes, encrypted tokens and — for no more than 25 recent emails — the technical identifier, subject line, sender and date received. Message bodies, previews and attachments are neither requested nor retained. Only messages containing an explicit date in the subject generate a proposal. Potential data subjects in future real documents include users, creators, counterparties, representatives, signatories, collaborators and named persons. Data comes from the user, authorised members and, only after the relevant gates have been opened, uploaded documents.

Special categories of personal data, data relating to criminal convictions and offences, and minors' data are permanently excluded from the service. No plan or exemption permits their upload, storage or analysis. A user declaration, generic consent or DPA does not make their processing admissible within Owevaro.

Purposes and candidate legal bases

Purposes and candidate legal bases
PurposeRoleOperational basisStatus
Account, access and requested functionscontrollerArticle 6(1)(b), limited to the contracting userin_review
Security, abuse prevention and defence of claimscontrollerArticle 6(1)(f), with necessity/balancing test still to be completedin_review
Tax obligations and lawful requestscontrollerArticle 6(1)(c), where applicablefuture
Business customer contentprocessorinstructions and legal basis of the customer acting as controllerCLOSED
Third-party data in the consumer flowpossible controllerlegal basis and Article 14 position not finalBLOCKED
Email and calendar in the allowlisted private testcontrollerArticle 6(1)(b) for the function requested by the controller; separate and revocable OAuth authorisationPRIVATE_TEST_ONLY
Future payments through Stripe Managed Paymentscontroller for the account/user relationship; Stripe roles by purpose to be validatedcontract and legal obligations, only after the gate is openedPREPARED_CLOSED
Email and calendar for public users, external AI and Usage Watchto be classified by purposeno current authorisationCLOSED

OAuth authorisation is a technical permission and is not the same as a GDPR legal basis. Google uses the restricted gmail.metadata scope; Microsoft uses the delegated Mail.ReadBasic permission. Both exclude message bodies, previews and attachments from the requested scope. Calendar scopes technically permit event management, but Owevaro uses only the creation of an event selected and confirmed by the user; it does not import the calendar and does not create events automatically.

Cookies, local storage and PWA

No advertising cookies, profiling, fingerprinting or optional analytics are active on the Owevaro domain. The browser stores only necessary technical items: the preference recording dismissal of the notice, the Supabase session after login, a temporary timestamp used to recover from loading errors, and static PWA resources through the Service Worker and Cache Storage. The PWA cache is not designed to store contracts or workspace records. The inventory, keys and durations are described in COOKIE-STORAGE-POLICY.md.

If the user chooses Google, Microsoft or Apple, the provider's external pages may use their own technologies under their respective notices. Server and provider logs, which may include IP address, user agent, time, route and response code, are distinct from data stored in the browser. The Owevaro notice is informational and closing it does not express consent.

Optional service feedback

The user may voluntarily submit a category and text to help improve Owevaro. These are associated with the account identifier and date. The purpose is service improvement, with a candidate basis under Article 6(1)(f) GDPR and a balancing test still in_review. The interface warns users not to enter contracts, customer data, special-category data or other third-party personal data. The proposed maximum retention period is 12 months; the data is also deleted with the account.

Providers and locations

The repository documents Supabase Free for identity/database/storage in eu-west-2 (London), with DPA Version 1 and Supabase Pte. Ltd., and two Hostinger KVM 4 VPSs in Frankfurt for frontend, API, file controls and technical logs, covered by the DPA for VPS Services. Vercel is not part of the current production flow and is retained temporarily only as an inactive rollback. Google, Apple and Microsoft may take part in login where configured; Gmail, Google Calendar, Outlook and Microsoft Calendar take part only in the authorised private test. Stripe live and Managed Payments are prepared, but SALES_ENABLED=false prevents all checkout activity; for future enabled transactions, Stripe states that it acts as merchant of record and processes the data needed for orders, payments, taxes, receipts, refunds, disputes and fraud prevention under its terms. Vertex AI and Resend remain blocked or future. Subprocessor lists and SCCs are documented; onward access, an updated Supabase TIA and Hostinger's geographical matrix remain subject to provider responses and professional review before real data is processed.

The United Kingdom is covered by the current EU adequacy decision identified in LEGAL-SOURCES.md. Any other transfers require an applicable safeguard, verification of actual access and supplementary measures. A primary region does not prove the absence of access from outside that region.

Retention, deletion and restoration

Periods are defined by system in RETENTION-POLICY.md. In the prepared local flow, the uploaded original remains in quarantine only for antivirus scanning, reconstruction, OCR and extraction, and is deleted on completion; it is not promoted to durable document storage or included in the self-managed backup. Minimized upload metadata, evidence of the policy applied, structured data and user-confirmed citations remain. Active deletion does not amount to a general promise concerning providers' internal backups, which remains subject to professional review. Real documents remain blocked until the gate is opened.

Rights and complaints

Requests may be sent to the contact details above. Where applicable, Owevaro handles access, rectification, erasure, restriction, portability and objection. The standard GDPR time limit is one month and may be extended in the circumstances provided by law, subject to informing the data subject. Verification of the requester's identity, scope, system searches, response and evidence are governed by DSAR-PROCEDURE.md. A complaint may be lodged with the Italian Data Protection Authority (Garante per la protezione dei dati personali).

Security, breaches, automation and minors

The code contains controls for TLS, RLS, private buckets, quarantine and file analysis; their effectiveness in external environments remains at the evidentiary level stated in the evidence register. The personal data breach runbook is documented but not operational. No solely automated decisions producing legal or similarly significant effects are envisaged. The service is restricted to adults; the age declaration is not strong identity or age verification.

Status in_review: the document is not represented as signed or effective. The real-data, sales, external-AI, OAuth and Usage Watch gates remain closed.
All legal documentsLegal contacts
OOwevaro

Know what you’re owed.
The control room for protecting creators’ work and revenue.

Service in development. Analyses are informational, require human review and do not replace legal, tax or accounting advice.

ProductHow Owevaro worksFor UGC creatorsPricingOpen the workspace
ResourcesAll resourcesUGC usage rightsCreator paymentsRights-expiry calculatorPayment due-date calculator
Legal and supportLegal centerPrivacy noticeCookies and storageConsumer termsLegal contactsWithdrawal, cancellation and account

© 2026 Owevaro · All rights reserved

Service owner: Alin Daniel Epure · P. IVA 17835711007 · Italy

/