Privacy Policy
This policy explains how DataVonix Private Limited ("we") handles personal data in My GoHighLevel MCP. It is written to meet the GDPR and India's Digital Personal Data Protection Act, 2023 (DPDP).
Roles
- For your account data (you and your team), we are the controller (DPDP: data fiduciary).
- For data in your HighLevel sub-accounts (your contacts and customers), you are the controller and we act as your processor under the DPA.
What we collect
- Account data: name, email, password hash, two-factor settings, role, sign-in times.
- Billing data: billing email and phone, and a record of your payments. Card details are handled by Cashfree, not us.
- Connection data: encrypted GoHighLevel sessions (never your GoHighLevel password), hashed Claude connection tokens, the name of the Claude client and when it was last used.
- Activity log: each tool call's time, user, sub-account, tool, result and record count. Message content is not stored; email addresses and phone numbers in arguments are masked.
- Website analytics: only if you accept analytics cookies (see below).
We do not store copies of your HighLevel contacts, conversations or pipelines. Results pass through to Claude.
Why we use it (legal bases)
Providing the service (contract), security and fraud prevention (legitimate interests), billing and tax records (legal obligation), and analytics (consent).
Sharing
Sub-processors: Contabo (hosting; servers in Mumbai, India), Cashfree (payments), Google Workspace (email), and HighLevel and Anthropic when you use the connector. We do not sell personal data.
International transfers
Where data leaves the EEA/UK or India, we use appropriate safeguards (e.g. Standard Contractual Clauses).
Retention
Account data for the life of the account. Activity logs for as long as your organisation exists. Payment records as long as tax law requires. When you delete your organisation, your GoHighLevel sessions and Claude connections are removed at once and the rest of its data is deleted 30 days later, except where the law requires us to keep it.
Your rights
Access, correction, deletion, portability, objection, withdrawing consent and (DPDP) nominating a representative. Use Settings → Download my data or Delete account, or contact hello@datavonix.com. You may complain to your data protection authority or, in India, the Data Protection Board.
Security
Encryption in transit (TLS) and at rest for GoHighLevel sessions, hashed passwords and tokens, role-based access, audit logs, and tenant isolation tested on every build. See Security & data handling.
Cookies
- Essential: a session cookie to keep you signed in, and a local setting remembering your theme and cookie choice.
- Analytics (optional): privacy-friendly page analytics, loaded only after you accept. Change your choice by clearing site data in your browser.
Changes
We will post updates here and notify account owners of material changes.
Contact
DataVonix Private Limited, India. Grievance officer (DPDP): hello@datavonix.com.