Privacy Policy
Last updated: October 6, 2026
Passo Advisory, LLC operates Svetta (“Svetta,” “we,” “us,” or “our”), a business technology product that provides artificial intelligence, automation, integration, and customer operations technology to businesses.
This Privacy Policy explains how Svetta may collect, receive, use, process, disclose, retain, and protect personal information in connection with our websites, applications, platform, integrations, and services (collectively, the “Services”).
It also explains how information may be processed when an individual communicates or interacts with a business that uses Svetta.
1. Our Role
Svetta provides technology that businesses may use to communicate with customers, manage customer interactions, automate workflows, connect existing business systems, and perform authorized business operations.
Depending on the circumstances and applicable law, a business using Svetta may determine the purposes and means for which its customer information is processed, while Svetta may process that information on the business's behalf to provide the Services.
Svetta may separately process limited information for purposes necessary to operate and administer its own business and Services, including account administration, security, fraud and abuse prevention, service reliability, legal compliance, and technical support.
The respective privacy obligations of Svetta and its business customers may vary depending on the applicable jurisdiction, the Services being used, and the nature of the processing.
2. Information We May Process
The information Svetta processes depends on how a business configures and uses the Services.
We may process categories of information including:
- Names and other identifiers.
- Telephone numbers, email addresses, and other contact information.
- Messages, inquiries, and other communications exchanged with a business, including images, audio, attachments, and transcriptions when supported and used.
- Information voluntarily provided during a customer interaction.
- Lead and prospective customer information.
- Appointment, reservation, service request, and customer support information.
- Estimate details, measurements, project information, drafts, revisions, approval decisions, and delivery records when relevant to an enabled workflow.
- Transaction or order-related information when relevant to an enabled business workflow.
- Account, organization membership, language preference, and authorization information.
- Browser push subscription identifiers and notification preferences when a user enables notifications.
- Information received from systems or services connected to Svetta by an authorized business.
- Communication metadata and technical identifiers.
- Device, browser, log, diagnostic, security, and other technical information reasonably necessary to operate and protect the Services.
Svetta does not necessarily collect or process every category listed above for every business or individual.
Information sources
We receive information from individuals who contact a business, authorized business users, connected communication channels and business systems, and technical events generated when the Services are used. The information available through an integration depends on its permissions and capabilities; Svetta does not automatically read a business owner's personal phone address book.
3. How We Use Information
Depending on the Services enabled by a business, Svetta may process information to:
- Receive, understand, route, and respond to customer inquiries.
- Assist businesses with customer communications and customer service.
- Create, update, or manage leads and customer requests.
- Assist with appointments, reservations, scheduling, and related services.
- Perform business workflows and actions authorized by the business.
- Retrieve information from authorized business systems.
- Transfer or escalate conversations to human representatives.
- Support transitions between automated and human-assisted service.
- Generate and facilitate transactional, operational, service, or other authorized communications.
- Provide artificial intelligence and automation functionality.
- Prepare and revise estimates and record approvals, cancellations, and delivery status.
- Send operational browser notifications to users who enable them and associate those subscriptions with the relevant business.
- Authenticate users and protect accounts and systems.
- Detect, prevent, investigate, and address security incidents, fraud, misuse, or technical problems.
- Maintain, troubleshoot, support, and improve the reliability and performance of the Services.
- Comply with applicable legal, regulatory, contractual, and enforcement requirements.
Where an action depends on an external service or third-party provider, Svetta may transmit the information necessary to request that action. The external service or provider may independently determine whether the requested action can be completed.
4. Artificial Intelligence and Automated Processing
Svetta uses or may use artificial intelligence and automated systems as part of the Services.
Depending on the configuration selected by a business, these systems may process information to understand customer requests, classify or route interactions, retrieve relevant business information, generate responses, assist with workflows, or determine which authorized tools or processes may be appropriate.
Information may be processed by third-party artificial intelligence or technology providers where necessary to provide enabled functionality.
Svetta does not sell personal information.
Svetta does not make one business customer's private customer conversations or private customer data available to another business customer.
Svetta does not use one business customer's private conversations to create a shared customer database accessible by other business customers.
Any future use of aggregated, de-identified, or otherwise privacy-protected information for cross-customer analytics or service improvement will be subject to applicable law, contractual requirements, and appropriate safeguards.
AI-generated content can be incomplete or inaccurate. Businesses should review information and proposed actions as appropriate. Estimate approval and other human review requirements depend on the workflow enabled for the business.
This policy does not represent that every AI provider has the same training, retention, or processing settings. Processing also depends on the provider service and applicable contractual configuration.
5. Communications and Messaging Services
Businesses may connect Svetta to communication services such as WhatsApp Business Platform or other supported messaging, voice, web, social, or communication channels.
When an individual communicates through a third-party communication service, that service provider may independently collect and process information according to its own terms and privacy policies.
When authorized by a business, Svetta may receive, process, generate, route, and transmit communications on behalf of that business.
Use of a communication channel through Svetta remains subject to applicable laws and to the terms, policies, permissions, and technical requirements of the applicable communication provider.
6. Transactional, Operational, and Marketing Communications
Svetta may enable businesses to send communications relating to inquiries, appointments, reservations, services, transactions, customer support, account activity, or other business operations.
Marketing or promotional communications are outside the current pilot workflows. Any future enabled marketing functionality must have appropriate notices, authorizations, and provider-policy controls before use.
Businesses using Svetta are responsible for providing required notices and obtaining and maintaining any consent, opt-in, or other authorization required for communications they initiate or direct.
Svetta also implements or may implement platform controls designed to support compliance with applicable provider requirements and communication preferences.
Where a communication provider requires approved templates, message classifications, consent, opt-in, opt-out mechanisms, or other conditions, communications sent through that provider must comply with those requirements.
Recipients may withdraw consent or opt out of communications as permitted by applicable law and the relevant communication channel. Svetta and businesses using Svetta may process such requests as necessary to honor applicable communication preferences and legal obligations.
7. Service Providers, Subprocessors, and Integrations
Svetta may engage third-party service providers and connect with third-party platforms to operate and provide the Services.
Depending on the Services and integrations enabled by a business, these third parties may provide services such as:
- Messaging and communications.
- Artificial intelligence and automated processing.
- Cloud infrastructure, hosting, and data storage.
- Appointment and scheduling services.
- Customer relationship management.
- Payment and transaction services.
- Business management and enterprise systems.
- Authentication and security.
- Monitoring, diagnostics, analytics, and technical support.
Svetta may disclose or transmit information to such providers when reasonably necessary to provide requested functionality, maintain or secure the Services, comply with applicable requirements, or otherwise process information as described in this Privacy Policy.
Current providers include Meta/WhatsApp for messaging, OpenAI for AI processing, Railway for application hosting, Neon for database services, and Clerk for authentication. Setmore is used where a business enables scheduling. Cloudflare supports domain/network services where configured, and browser/device push services deliver enabled notifications. Providers receive information relevant to their role; not every provider receives every category of information or serves every business workflow.
Third-party platforms may process information under their own terms and privacy policies when they act independently from Svetta.
8. Separation of Business Customer Data
Svetta is designed to support multiple business customers.
Svetta uses technical and organizational measures designed to segregate information associated with different business customers and to prevent unauthorized access between customer environments.
Access to customer information is intended to be limited according to the applicable business, user authorization, system, integration, and functionality.
No security architecture can eliminate every risk, but Svetta designs its Services with customer data separation as a core requirement.
9. Data Retention
Svetta retains personal information for no longer than reasonably necessary for the purposes for which it is processed, subject to applicable legal, contractual, security, dispute-resolution, and operational requirements.
Retention periods may differ depending on:
- The type and sensitivity of the information.
- The Services being used.
- Instructions or contractual requirements of the applicable business customer.
- Security and fraud-prevention requirements.
- Applicable statutes of limitation.
- Legal, accounting, regulatory, or other recordkeeping requirements.
There is currently no single automatic deletion period covering all pilot conversation and estimate records. Retention depends on the enabled workflow, business instructions, operational needs, and applicable legal or contractual requirements. A retention schedule and deletion automation are separate operational controls; this notice does not claim that they have been implemented for every record category.
Removing a contact from a directory, marking assistance as handled, disabling notifications, or deleting a conversation in a separate messaging application does not by itself delete all related records held by Svetta. Requests to delete personal information are handled separately as described below.
When information is no longer required, it should be deleted, anonymized, or otherwise disposed of, subject to applicable requirements. Backups, audit records, and third-party records may have separate retention cycles.
10. Data Security
Svetta uses administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, acquisition, disclosure, alteration, loss, misuse, or destruction.
Depending on the systems involved, these measures may include access controls, authentication, customer data separation, credential and secret management, logging, monitoring, encryption provided by underlying infrastructure, and other security practices.
Access to personal information is intended to be limited to persons and systems that require such access for authorized purposes.
No method of electronic transmission, processing, or storage can be guaranteed to be completely secure.
11. International Data Processing and Transfers
Svetta is based in the United States and may use service providers located in the United States and other countries.
As a result, personal information may be processed in a country other than the country where the individual or business is located.
Where applicable law requires safeguards for international transfers of personal information, Svetta will use appropriate mechanisms or safeguards as required for the relevant processing.
Business customers using Svetta are also responsible for assessing international data transfer requirements applicable to their own processing activities and use of connected services.
Legal bases where applicable
For information we process for our own purposes, relevant legal bases may include providing an agreed service, legitimate interests in administering and securing the Services, complying with legal obligations, and consent where required. When we process customer information on a business's behalf, that business determines the applicable basis for its processing. Enabling a device permission is not a substitute for every consent or notice that may be required.
12. Privacy Rights and Requests
Depending on applicable law and where an individual resides, an individual may have certain rights regarding personal information, which may include rights to request access, correction, deletion, restriction, portability, objection, or other rights provided by applicable law.
The availability and scope of these rights vary by jurisdiction and circumstances.
When Svetta processes information on behalf of a business customer, the applicable business may be the appropriate organization to receive and respond to a privacy request. Svetta may assist the business with a request where required by applicable law or contractual obligations.
Individuals may also contact Svetta using the contact information below.
A request should provide sufficient information to allow us to understand the request and, where relevant, identify the business or interaction involved.
We may request reasonable information necessary to verify identity, authority, or the validity of a request before acting on it.
We may retain information or decline or limit a request where permitted or required by applicable law.
13. Data Deletion Requests
Individuals may request deletion of personal information by contacting Svetta at the email address listed below.
Where the information was processed on behalf of a business using Svetta, we may refer the request to that business or coordinate with that business as appropriate.
Deletion requests should include sufficient information to identify the relevant account, business, communication, or interaction without unnecessarily providing sensitive information.
We may need to verify the identity or authority of the person making the request.
Certain information may be retained when necessary or permitted for legal compliance, security, fraud prevention, dispute resolution, establishment or defense of legal claims, contractual obligations, or other lawful purposes.
For practical request instructions, see Data deletion instructions.
14. Children's Privacy
Svetta provides technology services to businesses and does not intentionally design or market its Services directly to children.
Businesses using Svetta are responsible for determining whether their services involve children or minors and for complying with applicable requirements concerning age, parental consent, and processing of children's information.
If Svetta becomes aware of personal information processed in circumstances requiring deletion, restriction, or other action under applicable law, Svetta will take appropriate action consistent with its role and legal obligations.
15. Legal Requirements and Protection of Rights
Svetta may preserve, use, or disclose information when reasonably necessary to comply with applicable law, regulation, legal process, or valid governmental request, or to establish, exercise, or defend legal claims.
We may also process information when reasonably necessary to investigate or address fraud, security incidents, misuse of the Services, threats to safety, or violations of applicable agreements or policies, subject to applicable law.
16. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our Services, technology, business practices, legal requirements, or privacy practices.
When we make changes, we will update the “Last Updated” date at the top of this Privacy Policy.
Where required by applicable law, we will provide additional notice regarding material changes.
17. Contact Us
Questions, privacy requests, and data deletion requests may be directed to:
Passo Advisory, LLC 18800 NE 29th Ave, Apt 408, Aventura, FL 33180, United States Email: [email protected]