Legal
Privacy Policy
Al-Lami Ventures s.r.o., doing business as Piwot (“Piwot”, “we”, “us”). This policy explains how we process personal data when you use PIWOT℗ and related services.
Last updated: 19 July 2026. English controls. Product mark PIWOT℗; legal name Piwot where used in contracts.
1. Introduction and who we are
Al-Lami Ventures s.r.o. is a company registered in the Slovak Republic. We operate the PIWOT℗ design subscription platform at https://app.piwot.co, marketing properties at https://www.piwot.co, and the optional PIWOT℗ Slack application (the “Service”).
This Privacy Policy is designed for business customers, enterprise procurement, and Slack Marketplace review. It describes real product behavior: multi-tenant workspaces, request boards, billing, electronic contracts, notifications, and Slack. It is not marketing copy.
Privacy contact: support@piwot.co. Operational and contract email: onboarding@piwot.co. Related: Terms of Service.
If you disagree with this policy, do not use the Service or connect Slack. Continued use after the “Last updated” date constitutes acceptance where permitted by law, except where a separate consent is required.
2. Definitions
- Personal Data: information relating to an identified or identifiable natural person.
- Customer: the company or organization that holds a Piwot workspace or subscription.
- User: a natural person who accesses the Service (admin, teammate, agency staff).
- Customer Content: requests, briefs, files, comments, brand kits, and similar materials submitted to a workspace.
- Platform Data: account, billing, security, and operational data we need to run Piwot as a service provider.
- Slack Workspace: a Slack team connected via OAuth to at most one Piwot organization.
- Subprocessor: a vendor that processes Personal Data on our behalf to deliver the Service.
3. Scope of this policy
This policy applies to Personal Data processed in connection with:
- Accounts, authentication, and workspace membership on app.piwot.co
- Onboarding, Service Agreements, e-signatures, and billing
- Request boards, files, comments, notifications, and support chat
- The PIWOT℗ Slack app (install, channels, commands, interactive messages, events)
- Emails and in-product messages we send about the Service
- Public legal pages and marketing site forms we operate
It does not control Slack Technologies, LLC / Salesforce, Whop, Cal.com, or other third-party sites that have their own policies. When you leave our Service, their terms apply.
4. Controller and processor roles
4.1 We as controller
We determine purposes and means for Platform Data: account creation, authentication, security, billing records, product analytics needed to run the platform, Slack connection metadata for our install records, and communications about the Service. For those activities we are a data controller under the GDPR (where applicable).
4.2 We as processor (Customer Content)
For Customer Content stored in a Customer workspace (briefs, files, comments, board configuration), the Customer is typically the controller and we act as a processor: we process that content only to provide the Service, on documented instructions (use of the product features), with confidentiality, security, and subprocessor restrictions described here. We do not use Customer Content to sell advertising or to train general-purpose AI models for third parties.
4.3 Instructions and assistance
Customers may issue instructions through product settings, support requests, or written agreement. We will assist with reasonable data subject requests that relate to Customer Content when the Customer cannot fulfill them alone, and with security and DPIA cooperation where legally required and commercially reasonable.
5. Categories of data we process
5.1 Identity and account
- Name, work email address, password (stored hashed by our authentication provider; we do not store plaintext passwords)
- Profile photo if uploaded
- Role and membership in one or more organizations (client or agency)
- Preferences (for example notification toggles, calendar week start)
5.2 Workspace and commercial
- Company name, website, plan, seat limits, firm configuration
- Invite records (email invites and share links)
- Billing status, cancellation timing, commercial fields on agreements
- Payment processor identifiers and status (not full card numbers)
5.3 Customer Content (design work)
- Request titles, types, priorities, statuses, assignments
- Briefs and rich text, mentions, links
- File attachments, cover images, annotation pins
- Comments and activity history
- Brand kit materials and firm notes the Customer stores
- Designer match suggestions and related metadata
5.4 Support
- Support conversation threads, message bodies, and attachment metadata
- Agency-facing support labels (for example PIWOT Support branding)
5.5 Contracts and e-signature audit trail
- Typed legal name, drawn signature image, method (draw or type)
- Consent checkbox and acceptance timestamps
- Document ID (Service Agreement identifier)
- IP address and user agent at signing
- Copy of terms version accepted
5.6 Slack (only if connected)
- Slack team id and team name
- Selected notification channel id and name
- Bot OAuth token and, if granted, user OAuth token for private-channel invite
- Bot user id, installer Slack user id, scopes granted
- Slack user ids and display names of people who use commands or buttons
- Email from Slack users.info only when scope users:read.email is granted and needed to map identity
- Message text and file metadata deliberately pushed to a request (for example @mention of the bot in a request thread)
- Message timestamps used to map Slack posts to requests for thread features
5.7 Technical and security logs
- IP address, approximate location derived from IP, browser and device type
- Request logs, error logs, and rate-limit or abuse signals
- Delivery status for notifications (in-app, email, Slack)
6. How we collect data
- Directly from Users (signup, settings, requests, support)
- From the Customer’s admins (invites, firm settings, Slack connect)
- Automatically via cookies, local storage, and server logs
- From Slack via OAuth and Events/Interactivity APIs after install
- From payment and scheduling providers (Whop, Cal.com) as configured
- From AI providers only when designer matching is invoked for a request
7. Purposes and legal bases (GDPR)
Where the GDPR or UK GDPR applies, we rely on the bases below. Multiple bases may apply to the same processing.
| Purpose | Examples | Primary legal base |
|---|---|---|
| Provide the Service | Accounts, board, files, Slack posts, support | Contract (Art. 6(1)(b)) |
| Billing and contracts | Plans, invoices, e-sign, refunds | Contract; Legal obligation (tax) |
| Security and abuse prevention | Auth, signatures, fraud, rate limits | Legitimate interests (Art. 6(1)(f)); Contract |
| Product improvement | Aggregated reliability metrics | Legitimate interests |
| Service communications | Security notices, feature changes affecting use | Contract; Legitimate interests |
| Optional marketing | Only if separately offered and allowed | Consent or soft opt-in where lawful |
| Slack integration | OAuth, channel posts, commands | Contract; Legitimate interests |
| Designer matching | Suggest designer for a request | Contract; Legitimate interests |
| Legal claims and compliance | Disputes, law enforcement requests | Legal obligation; Legitimate interests |
Legitimate interests include securing multi-tenant systems, preventing fraud, improving reliability, and B2B account management. You may object where the right applies (see Section 15).
8. Slack application annex
Connecting Slack is optional. It is designed for trust-sensitive corporate customers.
8.1 How install works
- OAuth starts only when a signed-in Piwot admin opens Connect in Settings or onboarding (signed state binds user id and organization id).
- Tokens are stored only for that organization. Marketplace install alone does not attach tokens to a random org or grant board access.
- One Slack team_id maps to at most one Piwot organization. A workspace already linked elsewhere is rejected.
- Unknown or unlinked Slack teams receive no board data from slash commands or interactive actions.
8.2 What we post
Lifecycle and activity notifications (for example new request, status change, comments, support) are posted to the notification channel the Customer selects for that install. We may send ephemeral (private to the acting user) messages for errors, tips, or acknowledgements. We do not sell ad inventory in Customer channels or inject third-party ads.
8.3 Bot and user scopes (purpose limitation)
| Scope | Purpose |
|---|---|
| chat:write, chat:write.public | Post request cards and status updates |
| channels:read, groups:read | Channel picker for admins |
| channels:history, groups:history | Optional thread replies to comments |
| channels:join | Join public channels the admin selects |
| commands | /new and /piwot slash commands |
| users:read, users:read.email | Attribute actions to real names when possible |
| team:read | Workspace name on install |
| files:read | File notes when user opts in with @mention |
| links:read, links:write | Unfurl app.piwot.co request links |
| User channels:write, groups:write | Invite bot into private channels the admin picks |
8.4 Thread and file rules
Plain thread replies in Slack stay in Slack by default so teams can coordinate privately. Content is pushed to the request only when a User mentions the bot, uses an explicit “Add to request” shortcut, or otherwise uses a product path designed for that purpose. File notes store names and links accessible to the bot; we do not silently copy entire channel history.
8.5 Disconnect and uninstall
Admins can disconnect Slack in Settings → Connections. That removes the install record and tokens for the organization. Uninstalling the app in Slack ends bot access for that workspace. Residual backups may persist for a limited period under Section 13.
8.6 What we do not do with Slack
- Read or write board data for Slack teams with no valid install
- Treat an unmapped Slack user id as a dashboard superuser
- Use Slack content to train foundation models for sale to others
- Post Customer notifications outside the linked channel except user-visible ephemerals
9. Artificial intelligence and designer matching
When designer matching is enabled, request fields (for example type, brief, service category) may be sent to an AI model provider (such as xAI or OpenAI, depending on configuration) solely to suggest a designer persona for that request. Outputs may be stored on the request as match metadata. This is an assistive feature for routing work, not a legal or credit decision about a person.
Customers who do not want AI matching should avoid enabling or invoking match features and may contact support@piwot.co for workspace-level questions. We do not claim that AI providers never retain data under their own terms; we configure providers for product use and purpose limitation to the extent the product and contracts allow.
10. Subprocessors
We use specialized providers. Categories and typical vendors include (names may change; material changes will be reflected in this policy):
| Provider / category | Function | Notes |
|---|---|---|
| Vercel | Application hosting, edge delivery | EU/US depending on project |
| Supabase | Database, auth, file storage | Project region as configured |
| Resend (or email provider) | Transactional email | Invite, auth, notices |
| Whop | Payments and memberships | Card data on Whop, not our servers |
| Slack / Salesforce | Optional workspace integration | Only if Customer connects |
| Cal.com | Scheduling embeds | Kick-off / discovery when used |
| AI model APIs | Designer matching | When match is invoked |
Subprocessors are bound by contracts that require confidentiality and data protection measures appropriate to their role. A current list may be requested at support@piwot.co.
12. International transfers
We and our subprocessors may process data in the European Economic Area, the United States, and other countries. Where a transfer from the EEA/UK requires a safeguard, we use appropriate mechanisms such as the European Commission’s Standard Contractual Clauses (and UK addenda where applicable), or rely on adequacy decisions.
13. Retention
| Category | Typical retention |
|---|---|
| Account and membership | Life of account + reasonable wind-down |
| Customer Content | Life of workspace unless deleted sooner by Customer or us on request |
| Contracts, e-sign, billing | As required by tax/commercial law (often multi-year) |
| Slack tokens and install row | Until disconnect/uninstall |
| Security and application logs | Short operational windows unless needed for investigations |
| Agreement share drafts | Limited TTL as product-configured |
| Support messages | Life of conversation + reasonable archive |
After retention ends, we delete or irreversibly anonymize data, subject to backup cycles and legal holds.
14. Security
We implement technical and organizational measures appropriate to risk, including:
- TLS encryption in transit for the web application
- Access controls and least-privilege service credentials
- Password hashing via our authentication provider
- Slack request signature verification on Events, Interactivity, and Commands
- Tenant isolation rules for Slack (signed-in install, one team per org, request-level checks)
- Monitoring and logging for abuse and reliability
No method of transmission or storage is perfectly secure. Users must protect credentials, use strong passwords, and limit admin access. If we become aware of a personal data breach affecting you, we will notify as required by applicable law and without undue delay where notification is mandatory.
15. Your privacy rights
Depending on your location, you may have rights to access, rectify, erase, restrict, port, or object to certain processing, and to withdraw consent where processing is consent-based. To exercise rights, email support@piwot.co from your account email (or with enough detail to verify identity). We may need to confirm identity before acting.
If we process Customer Content as a processor, we may redirect you to the Customer (your company admin) when they are the controller.
You may lodge a complaint with a supervisory authority. For the EU, that is typically the authority in your Member State of residence. In Slovakia, the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov SR) is relevant for the controller’s establishment.
16. Additional US state privacy disclosures
For California residents and similar US state laws (including CCPA as amended by CPRA): we process categories listed in Section 5 for the business purposes in Section 7. We do not sell Personal Information or share it for cross-context behavioral advertising. We do not use sensitive personal information to infer characteristics beyond what is needed to provide the Service. You may request know, delete, and correct rights via support@piwot.co. Authorized agents may submit requests with proof of authority. We will not discriminate for exercising rights.
17. Children
The Service is for business use by adults. We do not knowingly collect Personal Data from children under 16. If you believe a child provided data, contact support@piwot.co and we will delete it.
19. Automated decision-making
Designer matching and similar automations may use algorithms to suggest routing. They do not produce legal or similarly significant effects solely by automated means without human involvement in delivery of design services. Seat limits and plan entitlements are rule-based product configuration, not profiling of consumers for credit or employment.
20. Changes to this policy
We may update this policy to reflect product, legal, or subprocessor changes. We will post the new version at this URL with a revised “Last updated” date. For material adverse changes to rights, we will provide additional notice where required (for example email or in-product notice). Continued use after the effective date constitutes acceptance where permitted; if you do not agree, disconnect Slack and stop using the Service.
21. Contact
Al-Lami Ventures s.r.o.
Doing business as Piwot / product mark PIWOT℗
Privacy: support@piwot.co
Platform: https://app.piwot.co
Marketing: https://www.piwot.co
Terms: https://app.piwot.co/terms
This policy is provided in English. Translations, if any, are for convenience; English controls unless mandatory local law requires otherwise.
Related: Terms of Service · support@piwot.co