Privacy Policy

Last updated: 5 October 2026

Governax is a product of Clouvy Labs, Inc. (“Governax,” “we,” “us,” or “our”). This Privacy Policy describes how we collect, use, disclose, and safeguard information when you visit governax.ai or use the Governax platform.

1. Our Role

We play two different roles depending on the data:

  • As a controller for information about our own visitors, account holders, and billing contacts, which we use to run and sell the service.
  • As a processor for the data our customers bring into Governax by connecting their tools (“Customer Data”). The customer organisation decides what to connect and is the controller of that data. If your employer uses Governax and you have questions about records concerning you, please contact your employer first; we will assist them in responding.

2. Information We Collect

Information you provide

  • Account information - name, email address, password (stored only as a one-way hash), organisation name, and the country your organisation is registered in.
  • Sign-in with a third party - if you sign in with Google, Microsoft, or GitHub, we receive your name, email address, and profile identifier from that provider. We do not receive your password for that provider.
  • Security information - two-factor authentication settings, authenticator secrets and backup codes (stored in protected form), and one-time codes we email to you.
  • Organisation and team data - entities you create, members you invite, their roles, and changes to membership, including deactivation.
  • Billing information - billing contact, plan, billing currency, subscription status, and invoice history. Card and other payment details are entered directly with our payment processor, Razorpay, and are never stored on our servers.
  • Communication data - messages you send through our contact form, by email, or to support.

Customer Data from connected tools

When an organisation connects a tool, Governax reads that tool’s audit and membership records and stores them in the organisation’s governance ledger. Depending on what is connected, this can include:

  • Slack - workspace membership, user and channel identifiers, names and email addresses, and access requests and decisions made through the Governax Slack app.
  • GitHub and GitLab - organisation or group membership, repository and project access changes, and the related audit events.
  • Okta, Google Workspace, and Microsoft Entra ID - directory and administrative audit events, such as user, group, role, application, and sign-in policy changes.
  • AWS - CloudTrail management events, such as identity and access changes.

These records typically identify the people involved (name, email address, user identifier) and may include IP addresses, user agents, and timestamps. We collect only what the connected tool exposes to the read access the customer grants, and only to build the ledger.

Information collected automatically

  • Session and security data - IP address, browser user agent, and sign-in times, used to keep your account secure and to record security-relevant events.
  • Website analytics - on our public website only, and only after you accept the cookie banner, we use Google Analytics and Microsoft Clarity (see section 4).
  • Cookies and similar technologies - see our Cookie Policy for details.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Governax platform, including building and verifying each organisation’s governance ledger.
  • Authenticate users, enforce roles and permissions, and protect accounts.
  • Process subscriptions, payments, and invoices.
  • Send service emails, such as verification codes, invitations, password resets, billing notices, and security alerts.
  • Respond to enquiries and support requests.
  • Understand how visitors use our public website so we can improve it.
  • Comply with legal, tax, and accounting obligations, and enforce our Terms of Service.

We do not sell personal information, we do not use Customer Data for advertising, and we do not use Customer Data to train machine learning models.

Legal bases

Where the law requires a legal basis for processing, we rely on performance of our contract with you or your organisation, our legitimate interests in running a secure and reliable service, compliance with legal obligations, and your consent (for example, for analytics cookies, which you can withdraw at any time).

4. Website Analytics

On our public website we use Google Tag Manager to load Google Analytics 4 and Microsoft Clarity. Clarity captures behavioural metrics, heatmaps, and session replay so we can see how visitors use the site and improve it. None of these tools load until you accept the cookie banner, and none of them load inside the signed-in platform. Data is processed by Google and Microsoft under the Google Privacy Policy and the Microsoft Privacy Statement. You can change your choice at any time on our Cookie Policy page.

5. Service Providers

We share information with service providers only as needed to run Governax, under contracts that require them to protect it:

  • Hostinger - cloud servers that host the platform and its databases.
  • Cloudflare - content delivery and network security.
  • Razorpay - payment processing and subscription billing.
  • Resend - delivery of transactional emails and contact form messages.
  • Google and Microsoft - website analytics (with consent) and, if you choose them, sign-in.

We may also disclose information when required by law, subpoena, or governmental request, to protect the rights, safety, and property of Governax, our users, or others, or in connection with a merger, acquisition, or sale of assets, with notice to affected customers.

6. Data Security

We protect data with encryption in transit, role-based access controls, and optional two-factor authentication. Credentials that customers give us for connected tools (such as Slack and GitLab access tokens) are encrypted at rest with AES-256-GCM. Where a tool supports it, we use access that the customer grants to Governax and can revoke at any time (for example, an AWS role with an external ID, or Microsoft admin consent), so no customer password or long-lived key is stored. The governance ledger is hash-chained so that any alteration of past records can be detected. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Data Retention

  • Governance ledger - ledger records are kept for as long as the entity they belong to exists. Because the ledger is a tamper-evident record, individual entries are not edited or deleted. An organisation owner can delete an entity together with its ledger history, which is permanent.
  • Organisation membership - when someone is removed from an organisation, their membership is deactivated rather than erased, so the organisation keeps an accurate record of who had access and when.
  • Account data - kept while your account is active and deleted or anonymised on request, except where it forms part of a ledger or membership record above, or where we must keep it.
  • Billing records - kept for as long as tax and accounting laws require.
  • Disconnected tools - when a tool is disconnected, its stored credential is deleted and no further data is collected. Records already in the ledger remain.

8. Your Rights

Depending on where you live, you may have the right to:

  • Access, correct, or delete your personal information.
  • Object to or restrict certain processing activities.
  • Request data portability.
  • Withdraw consent where processing is based on consent.
  • Nominate another person to exercise your rights in the event of death or incapacity, and raise a grievance with us.
  • Complain to your local data protection authority.

Requests about Customer Data are handled through the customer organisation that controls it, as described in section 1. Deletion requests are subject to the ledger and membership records described in section 7. To exercise these rights, contact us at [email protected].

9. International Data Transfers

We and our service providers operate in several countries, including the United States and India, so your information may be processed outside the country where you live. Where required, we use standard contractual clauses or equivalent safeguards to protect it.

10. Children’s Privacy

Governax is a business service and is not directed at individuals under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will take steps to delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on our website. Continued use of the platform after changes take effect constitutes acceptance of the updated policy.

12. Contact and Grievance Officer

For questions about this Privacy Policy, to exercise your rights, or to raise a grievance, contact our Grievance Officer:

Clouvy Labs, Inc.
136 Madison Avenue, New York, NY 10016, United States
Email: [email protected]