Raven CX Privacy Notice
Effective date: 2026-10-04 · Last updated: 2026-10-04 · Version: 1.0
Raven CX provides the customer support system (chat, frequently asked questions and support history) that online platforms use to serve their customers. If you opened a platform's support page and saw “Powered by Raven CX”, this notice explains which personal data is processed, why, who it is shared with, how long it is kept and how you can exercise your rights.
In this notice, “platform” means the company whose support you are using (its name appears at the top of the support page), and “we” means Raven CX.
1. Who is responsible for your data
- The platform is the controller. It decides why and how your data is used for support (for example, which data to ask for and how long to keep conversations), as defined in Brazil's General Data Protection Law (LGPD, Law No. 13,709/2018) and similar laws.
- Raven CX is the processor (operator). We process the data on the platform's behalf and according to its instructions, so that the support system works securely.
- For any request about your data, you can contact the platform itself or write to us at [email protected]. When the decision belongs to the platform, we forward your request to it and help it answer.
2. What data we process
2.1 Support account
To chat with an agent, you create an account:
- E-mail address — used to sign in and to receive the verification code and the other service e-mails (section 6).
- Password — we only store an irreversible code derived from it (a hash); we never store the password itself.
- Nickname — created automatically from the part of your e-mail before the “@” (or from the name on your Google account). It is the name the agent sees.
- Language — the language of the page when you registered, used to write e-mails in your language.
- Google sign-in (only if you choose it and it is available) — we receive from Google your account identifier, e-mail address, confirmation that the e-mail is verified, and your name. We do not receive your Google password and we do not store your photo.
One account (the same e-mail) works on all platforms of the same company that use Raven CX. That company's staff may see that you have also been helped on another of its platforms; the details are only visible to staff with a specific permission.
2.2 Platform identification
- Your user number or username on the platform, when you enter it in the form before the chat (if the platform asks for it). If the platform allows it, an agent can also add or deactivate this identifier for you.
2.3 Conversations
- The topic you choose, the text messages, images and (if the platform allows) videos you send, and the staff's replies;
- the date and time of messages, the conversation status (queued, in progress, closed) and which agents took part;
- automatic translations of the messages (section 4);
- your rating of the support (a score from 1 to 5 and, if you wish, tags and a comment);
- “was this helpful?” votes on the FAQ, which are not linked to your account.
Please do not send passwords, full card numbers or other sensitive data in the chat unless it is needed to solve your case. If that happens, tell the support team or write to us (section 15).
2.4 Records made by the support team
To organise support and protect its staff, the platform may record about you or your conversation: internal notes, tags, category and priority, a VIP flag, abuse reports, records of messages that match content rules set by the platform and, where applicable, an account block. You do not see these records. Blocking (banning) an account is always decided by a person on the team, never by the system.
2.5 Technical and security data
- Login session record: when you sign in, we store the date, your IP address and your browser identification (user-agent). This protects your account — for example, it lets us detect the use of a stolen session.
- Attempt limits: counters per IP address and per e-mail that stop excessive attempts (such as sign-in, registration and password recovery).
- Bot check: at registration, at password recovery and after several failed sign-in attempts, a Cloudflare Turnstile check may appear; it analyses technical signals from your browser. To validate it, we send Cloudflare the check result and your IP address.
- As with any website, our network and hosting provider (Cloudflare) processes your IP address to deliver the pages and protect the service against attacks.
2.6 What we do not do
- We do not record your country or location, and we do not store your IP address in your profile or in conversations — it only appears in the login session record and the attempt limits described above.
- We do not use advertising, analytics or tracking cookies, or third-party trackers, on the support page.
- We do not sell your data and do not use it for advertising.
- The system does not make automated decisions about you (such as blocking your account or profiling you). The automatic security protections (attempt limits and the bot check) only stop new attempts for a limited time.
3. Why we use the data
- To help you: open and keep the conversation, route it to an agent, show the history and answer your questions and complaints;
- to create and protect your account (sign-in, verification code, password recovery);
- to identify you on the platform, linking the conversation to your identifier and to previous conversations;
- to translate messages when you and the agent use different languages (section 4);
- to send the service e-mails (section 6);
- to keep the service secure and prevent unauthorised access, abuse, fraud and attacks;
- to produce support statistics for the platform (conversation volume, response times, ratings);
- to comply with legal obligations and answer requests from authorities when the law requires;
- to handle your requests as a data subject (section 14).
Legal bases. The platform, as controller, defines the legal basis for each processing activity. As a rule, support relies on the performance of a contract or of preliminary steps at your request (LGPD art. 7, V); security, fraud and abuse prevention and support statistics rely on legitimate interests (art. 7, IX); and keeping records required by law relies on compliance with a legal or regulatory obligation (art. 7, II) and on the regular exercise of rights (art. 7, VI).
4. Automatic translation
When you and the agent use different languages, messages may be translated automatically by artificial intelligence so that you understand each other:
- Translation is performed by OpenAI (United States) through Raven CX's servers. We only send the text to be translated (and, if any, the platform's glossary of terms) — we do not send your e-mail address, nickname or account identifiers.
- You receive the translation of the agent's replies; the agent sees your original message and its translation.
- The translation is stored with the message and deleted together with it.
- Platform translation memory: to avoid translating the same sentence twice, sentences and their translations may be kept in a temporary cache (up to 7 days) and in the platform’s own translation library. From your messages, only sentences without any number, e-mail address or link are kept; replies from the support team may be kept in full.
- Shared library: Raven CX keeps an encrypted translation library used by all platforms. Only sentences without any number, e-mail address or link — whether written by you or by the support team — go into it (for example, “Good morning, I need help”). This rule is applied before sending and checked again by Raven CX before storing, and the sentences go through an automatic review (also performed with OpenAI) before other platforms can use them.
- None of these entries records who wrote the sentence or in which conversation. In the libraries they are deleted automatically after 180 days without use (those rejected in the shared library’s review within 30 days), and they are not deleted together with your conversation.
- Automatic translations may contain mistakes. If something looks odd, ask the agent to explain it another way.
5. Conversation history
- Your conversations are kept so that support can continue: when you come back, you and the agent see the history that is still within the retention period (section 10).
- The platform's staff use the history to understand previous cases, handle complaints and disputes and assess the quality of support.
- If the platform allows it, authorised staff can export a conversation; every export is logged.
- When the period ends, the conversation, its messages, images, translations and the records linked to it are deleted automatically.
6. E-mails we send
We only send service e-mails, through the provider Resend:
- the registration verification code;
- password reset and the notice that your password was changed;
- a notice that an agent replied while you were away (without the content of the message);
- the result of a request about your data (for example, the link to download it).
We do not send marketing e-mails.
7. Who has access
- The platform's staff: each person has a role with defined permissions and only sees the platforms they are authorised for. The full e-mail address is masked for anyone without a specific permission, and viewing personal data, exports and important changes are recorded in audit logs.
- Raven CX: our team accesses data only when needed to operate, maintain and protect the service or to handle data subject requests, through a console protected by a password and two-step verification.
8. Who we share data with
We do not sell your data. To provide the service, we use the providers below, which process data only to perform the contracted service:
- Cloudflare (United States, global network): hosting, database, storage of images and videos, page delivery and the bot check (Turnstile).
- OpenAI (United States): automatic translation of messages (section 4).
- Resend (United States): sending the service e-mails (section 6).
- Backblaze (United States; copies stored in its European Union region): encrypted backups (section 10).
- Google (United States): only if you choose to sign in with your Google account.
We may also share data with public, judicial or regulatory authorities when the law requires it, and with legal advisers when necessary to exercise or defend rights.
9. International data transfers
Raven CX is based in the United States, and the providers above are in the United States or operate global networks; backups are stored in the European Union. Your data is therefore processed outside Brazil (or your own country). We use providers that offer contractual data-protection commitments and, where the law requires, we adopt the transfer mechanisms provided for by applicable law — in Brazil, those of LGPD art. 33, such as standard contractual clauses.
10. How long we keep data
The periods below are Raven CX’s standard configuration; the platform may configure different periods.
- Messages: deleted automatically 7 days after they are sent.
- Closed conversations (with the rating, notes, tags, reports and other records linked to them): deleted 7 days after closing.
- Images and videos sent in the chat: deleted 3 days after upload.
- Translations: together with the message.
- Internal transfer records (which agent the conversation was passed from and to, with an optional staff note): deleted together with the conversation and in any case after 180 days.
- Login session record (IP and browser): each record is deleted when the session expires, about 30 days after it is created.
- Staff audit logs (who viewed or changed data, without storing the values): 7 days.
- Attempt limits (IP or e-mail): about 2 days.
- Account (e-mail, nickname, password hash, language), platform identifiers and notes linked to your account: while the account exists, or until you ask for deletion. An identifier deactivated by staff is deleted after 7 days.
- Account block record (encrypted e-mail address and reason): kept as moderation history, even after the block is lifted; on a deletion request the e-mail address is erased and only its irreversible code (hash), described in section 14, is kept in its place.
- Translation memory: cache of up to 7 days; in the libraries, deleted after 180 days without use (section 4).
- File with your data (when you request access): kept for up to 7 days and then deleted.
- Backups: made daily and encrypted; deleted automatically within about 60 days. Data already deleted from the system may remain in these copies until they expire, and they are only used to restore the service.
- Record of your data subject requests (what was requested, when and how it was handled): kept to demonstrate compliance with the LGPD.
Periods may be longer when there is a legal obligation, an order from an authority or a need to preserve data for legal proceedings; in those cases the data is preserved only for that purpose until the situation ends. If in doubt about the periods your platform uses, ask the platform or us.
11. Cookies and browser storage
On the support page:
- One essential sign-in cookie, protected (page scripts cannot read it and it is only sent with sign-in requests), valid for up to 30 days, so you do not have to sign in on every visit.
- Browser session storage (sessionStorage), cleared when you close the tab: it remembers which conversation you were in (so you return to it if you reload the page), how far messages have been synchronised, and a temporary security code for Google sign-in.
- The bot check (Cloudflare Turnstile), when it appears, is loaded from Cloudflare and follows that provider's rules.
On this website (ravencx.app): this website does not set cookies; it only stores your theme choice (light or dark) in your browser's local storage.
Because we only use essential technologies, we do not ask for cookie consent. You can delete cookies and site data in your browser; after that you will need to sign in again.
12. Security
- Connections are always encrypted (HTTPS).
- Passwords and sign-in tokens are stored only as hashes; e-mail addresses of blocked accounts and the shared translation library are stored encrypted; backups are encrypted (AES-256) and stored outside Cloudflare.
- Each client company has its own database and storage, separate from those of other companies.
- Role- and permission-based access, masked e-mail addresses and audit logs.
- Two-step verification is mandatory for each platform's super-administrator accounts and for the Raven CX console; the platform may require it for more agent accounts.
- Attempt limits and bot checks.
No system is completely secure. If a security incident occurs that may cause you relevant risk or harm, the platform and Raven CX will take the measures required by law, including notifying the ANPD and the affected people when required.
13. Children and teenagers
Support is not directed at children or teenagers. If the platform you are contacting only accepts adults, that rule also applies to its support. If you learn that a child or teenager has sent us personal data without the necessary authorisation, contact us (section 15) so that, together with the platform, we can take appropriate action.
14. Your rights
Under the LGPD (art. 18), you may request:
- confirmation that we process your data, and access to it;
- correction of incomplete, inaccurate or outdated data;
- anonymisation, blocking or deletion of unnecessary or excessive data, or of data processed in breach of the law;
- data portability, as set out in regulations;
- deletion of data processed on the basis of your consent, and withdrawal of consent;
- information about the entities with which your data is shared (section 8);
- information about the possibility of not giving consent and the consequences of refusing;
- objection to processing carried out in breach of the law;
- review of decisions made solely on the basis of automated processing (art. 20) — as explained in section 2.6, the system does not make this kind of decision.
Outside Brazil, you may have similar rights under the law of your country.
How to make a request. Write to [email protected], preferably from your account's e-mail address, telling us which platform it concerns and what you would like. You can also ask the platform itself. To protect you, we may ask you to confirm your identity before handing over or deleting data. Anything that depends on the platform's decision is forwarded to it.
Deadlines. Requests for confirmation or for full access are answered within 15 days, as provided in LGPD art. 19; other requests within the periods set by law and regulation. Handling your requests is free of charge.
About deletion. Deletion applies to your whole account, including conversations on all platforms of the same company. We may keep the minimum needed for security and to comply with the law: the record of the request itself; records of reports and moderation related to abuse; and, if the account has been blocked, an irreversible code (hash) of the e-mail address so that the block remains effective. Data under legal preservation is only deleted when the preservation ends, and backups expire on their own (section 10).
Complaints. You may lodge a complaint with Brazil's National Data Protection Authority (ANPD) — www.gov.br/anpd — or with the data protection authority of your country.
15. Contact
For questions about this notice or your data, or to make a request:
Privacy contact: Raven CX Privacy Team
E-mail: [email protected]
Company: Raven CX
Registered address: 1729 Maryland Avenue, Feather Sound, Florida 33762, United States
Website: https://ravencx.app
16. Changes to this notice
We may update this notice when the service, providers, retention periods or the law change. The version in force is always on this page, with the date of the last update at the top. When a change is significant and the law requires it, we will also let you know through the platform or the support page.