Privacy Policy
Effective date: 1 May 2026 · Asveon Group Ltd.
Relivv ("we", "us", or "our") is a platform operated by Asveon Group Ltd., a company registered in Bulgaria, European Union (VAT No. BG204351931). We are committed to protecting your personal information and being transparent about how we collect and use it. This Privacy Policy explains what data we collect, why we collect it, how we store it, and what rights you have.
If you have any questions, contact us at [email protected]. By using Relivv, you agree to this Policy. If you do not agree, please do not use our Services.
1. Who We Are (Controller)
The data controller responsible for your personal data is:
- Company: Asveon Group Ltd.
- Address: Rikkardo Vakkarini 8, 1404, Sofia, Bulgaria
- VAT Number: BG204351931
- Email: [email protected]
- Phone: +359 877 747 479
2. What Data We Collect
Data you provide directly
- Account data: name, email address, and password (hashed) when you register
- Profile data: profile picture (optional)
- Event data: event name, date, type, and configuration settings you set up
- Media: photos and videos uploaded by you (as organiser) or your guests via a shared event link
- Guest data: guest name or email if provided voluntarily when uploading to an event
- Billing data: name, billing address, and VAT number collected by Stripe at checkout; we store a reference to the payment but not your full card details
- Support data: messages you send to our support team
Data collected automatically
- IP address, browser type, and device information
- Pages visited and actions taken within the platform
- Session tokens (stored in cookies and local storage for authentication)
3. Why We Collect Your Data (Legal Basis)
| Purpose | Legal Basis (GDPR) |
|---|---|
| Create and manage your account | Contract performance (Art. 6(1)(b)) |
| Provide the event media sharing service | Contract performance (Art. 6(1)(b)) |
| Process payments and issue invoices | Legal obligation + Contract (Art. 6(1)(b)(c)) |
| Send transactional emails (invoices, password reset) | Contract performance (Art. 6(1)(b)) |
| AI content moderation (detect inappropriate media) | Legitimate interest (Art. 6(1)(f)) |
| Retain accounting records | Legal obligation — Bulgarian tax law (Art. 6(1)(c)) |
| Respond to support requests | Legitimate interest (Art. 6(1)(f)) |
4. Data Retention
How long we keep your event media depends on your plan:
- Free plan: media is retained for 7 days after the event date
- PLUS plan: media is retained for 90 days
- PRO plan: media is retained for 365 days
You will receive an email notification at least 30 days before your media is scheduled for deletion, giving you the opportunity to download it.
Account data is retained for as long as your account is active. If you request account deletion, we will delete your personal data within 30 days, except where we are legally required to retain it (e.g. accounting records, which we retain for 5 years under Bulgarian tax law).
Invoice and payment records are retained for 5 years in compliance with Bulgarian accounting legislation.
5. Subprocessors (Who We Share Data With)
We use the following third-party services to operate Relivv. All are bound by data protection agreements and are GDPR-compliant or covered by appropriate transfer mechanisms.
| Service | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS Lightsail) | Server hosting — application and database | EU (Frankfurt, Germany) |
| Amazon Web Services (AWS S3) | Media storage — photos and videos uploaded to events | EU (Stockholm, Sweden — eu-north-1) |
| Stripe | Payment processing and invoicing | US (with EU Standard Contractual Clauses) |
| Resend | Transactional email delivery (invoices, welcome emails, notifications) | US (with EU Standard Contractual Clauses) |
| Anthropic | AI-powered content moderation (detecting inappropriate uploaded media) | US (with EU Standard Contractual Clauses) |
We do not sell your personal data to any third party.
6. International Data Transfers
Asveon Group Ltd. is based in the European Union. Some of our subprocessors (Stripe, Resend, Anthropic) are located in the United States. When transferring data outside the EU/EEA, we ensure appropriate safeguards are in place, including EU Standard Contractual Clauses (SCCs) as required by GDPR Chapter V. Your media files are stored exclusively on AWS S3 in the EU (Stockholm, Sweden) and your application data on AWS servers in the EU (Frankfurt, Germany).
7. Your Rights (GDPR)
As a resident of the European Union or European Economic Area, you have the following rights regarding your personal data:
- Right of access: you may request a copy of the personal data we hold about you
- Right to rectification: you may correct inaccurate or incomplete data at any time via your account settings
- Right to erasure ("right to be forgotten"): you may request deletion of your data, subject to legal retention obligations
- Right to restrict processing: you may ask us to limit how we use your data
- Right to data portability: you may request your data in a structured, machine-readable format
- Right to object: you may object to processing based on legitimate interests
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time
- Right to lodge a complaint: you have the right to complain to the Bulgarian Commission for Personal Data Protection (CPDP) at www.cpdp.bg, or to the supervisory authority in your EU country of residence
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
8. Data Security
We implement industry-standard security measures to protect your data:
- All data in transit is encrypted using TLS/HTTPS
- Passwords are hashed using bcrypt — we never store plain-text passwords
- Media files are stored on Amazon S3 with access controls — files are not publicly guessable
- Database access is restricted to the application server only, with no public exposure
- Daily encrypted database backups are stored on Amazon S3
- Authentication tokens expire and are rotated regularly
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected users without undue delay.
9. Children's Privacy
Relivv is intended for users who are at least 18 years of age. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us at [email protected] and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make significant changes, we will notify you by email or by a prominent notice on our website before the changes take effect. Continued use of Relivv after the effective date constitutes acceptance of the updated policy.
11. Contact
For any privacy-related questions or requests:
- Asveon Group Ltd.
- Rikkardo Vakkarini 8, 1404, Sofia, Bulgaria
- Email: [email protected]
- Phone: +359 877 747 479