Legal
Privacy Policy
Effective Date: October 2, 2026
1. Introduction
Malva ("Malva," "we," "our," or "us") respects your privacy and is committed to protecting personal information.
This Privacy Policy explains how we collect, use, disclose, process, retain, and safeguard information when you use the Malva platform, website, applications, integrations, and related services (collectively, the "Service").
This Policy also describes how Malva handles data received through connected third-party services, including Google Workspace and Microsoft 365.
2. Information We Collect
2.1 Account Information
- Name
- Email address
- Job title
- Company name
- Profile information
- Authentication and account information
2.2 CRM and Business Data
- Contact and company records
- Opportunity, deal, and pipeline data
- Activities and engagement data
- Tasks and meetings
- Forecasting information
- CRM metadata
- Sales performance metrics
2.3 Google Workspace Data
- Gmail messages and thread content that the user authorizes Malva to access
- Gmail metadata such as sender, recipients, subject, timestamps, and thread identifiers
- Google Calendar event information required to create, update, reschedule, or cancel user-initiated meetings
- Google Calendar free/busy information used to calculate available meeting times
2.4 Microsoft 365 Data
- Outlook email messages and conversation content that the user authorizes Malva to access
- Outlook mail metadata such as sender, recipients, subject, timestamps, and conversation identifiers
- Microsoft 365 / Outlook Calendar event information required to create, update, reschedule, or cancel user-initiated meetings
- Calendar availability information used to calculate available meeting times
- Basic Microsoft account identity information required to authenticate the user and connect the authorized account
2.5 Usage and Technical Data
- Device and browser information
- IP address
- Operating system
- Usage patterns and feature interactions
- Log and diagnostic information
2.6 AI Processing Data
- CRM records and sales activities
- Selected email or conversation context
- Meeting summaries or transcripts where applicable
- Notes and communications metadata
- User instructions and interactions with the Service
3. How We Use Information
- Provide, operate, maintain, and secure the Service
- Authenticate users and maintain authorized integrations
- Display email conversations related to user-selected CRM contacts or deals
- Send emails or replies only after an explicit user action
- Calculate meeting availability using authorized calendar information
- Create, update, reschedule, and cancel user-initiated calendar events
- Provide user-facing AI-assisted drafts, summaries, insights, recommendations, and analytics
- Monitor performance and reliability
- Detect fraud, abuse, and security incidents
- Communicate with users
- Comply with legal obligations
4. Legal Basis for Processing
Where applicable under laws such as the GDPR, Malva processes personal data based on one or more of the following legal bases: performance of a contract, legitimate business interests, user consent, and compliance with legal obligations.
5. AI Features and AI Service Providers
Malva uses artificial intelligence technologies to provide user-facing features such as editable email drafts, summaries, recommendations, classifications, forecasts, and related productivity functionality.
Malva currently uses the OpenAI API directly for certain AI-powered features. Data is sent to the AI service only when necessary to perform a user-requested feature and only to the extent needed for that feature.
For example, an email-drafting request may include selected email or conversation context, recipient information, the user's requested goal, and relevant CRM context so that Malva can generate an editable draft.
AI-generated outputs may contain inaccuracies. Users are responsible for reviewing generated content and making final business decisions.
AI services do not independently send emails, create or modify calendar events, or delete connected-service data. External actions are performed through separate authenticated application operations and require an explicit user action.
Malva does not use Google Workspace or Microsoft 365 user data, including raw, derived, aggregated, or anonymized data, to develop, train, fine-tune, or improve generalized or non-personalized AI or machine-learning models.
6. Data Sharing and Service Providers
Malva does not sell personal information.
Service Providers
- Malva may share information with service providers that help operate the Service, including cloud infrastructure providers, authentication providers, analytics providers, customer support providers, and AI service providers.
- Where Google Workspace or Microsoft 365 data is transferred to a service provider, the transfer is limited to what is necessary to provide, maintain, secure, or support the specific user-facing functionality requested by the user.
- Connected-account data is not transferred for advertising, data brokerage, creditworthiness assessment, generalized AI/ML model training, or unrelated secondary purposes.
- Malva currently uses OpenAI as a direct AI service provider for certain user-facing AI features. Malva does not use an AI aggregator, gateway, or model hub for this integration.
Legal Requirements
- Malva may disclose information if required by law, court order, government request, or regulatory obligation.
If Malva participates in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction subject to applicable law and contractual obligations.
7. Google Workspace and Google API Services User Data
Malva accesses Google Workspace data only after the user grants the relevant permissions through Google OAuth.
Malva uses Gmail data to provide user-facing email functionality, including displaying authorized conversations and sending user-confirmed messages or replies.
Malva uses Google Calendar data to provide user-facing scheduling functionality, including availability checks and the creation, update, rescheduling, and cancellation of user-initiated meetings.
The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
Google Workspace user data is not used to create, train, fine-tune, or improve generalized, foundational, or non-personalized AI/ML models.
Google Workspace user data is not sold, used for advertising, or transferred to third parties except as necessary to provide or improve the user-facing functionality requested by the user and as permitted by the Google User Data Policy.
Users can revoke Malva's Google access through their Google Account permissions. Revoking access may disable the corresponding Gmail or Google Calendar functionality in Malva.
8. Microsoft 365 and Microsoft Graph Data
Malva accesses Microsoft 365 data only after the user or, where applicable, the user's organization grants the relevant permissions through the Microsoft identity platform.
Malva may use Microsoft Graph to provide user-facing Outlook Mail and Calendar functionality, including displaying authorized email conversations, sending user-confirmed emails or replies, checking calendar availability, and creating, updating, rescheduling, or cancelling user-initiated meetings.
Malva requests only the permissions required for enabled functionality and is designed to follow the principle of least privilege.
Microsoft 365 data is processed only for the user-facing functionality requested by the authenticated user and for the operation, security, and support of that functionality.
Microsoft 365 data is not sold, used for advertising, or used to create, train, fine-tune, or improve generalized or non-personalized AI/ML models.
Users or tenant administrators may revoke Malva's Microsoft permissions through the applicable Microsoft account or Microsoft Entra administration controls. Revoking access may disable the corresponding Outlook Mail or Calendar functionality in Malva.
9. Data Retention
Malva retains information only for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, enforce agreements, and satisfy legitimate security and operational requirements.
Malva minimizes retention of Google Workspace and Microsoft 365 data to what is necessary for the enabled user-facing functionality and operational requirements of the Service.
For AI requests made through the OpenAI Responses API, Malva configures requests with store:false where supported by the implemented workflow. This application-level setting is separate from any provider-level retention or Zero Data Retention controls.
Upon account deletion, Malva will delete or anonymize information within a commercially reasonable period unless retention is required by law or necessary for legitimate security, fraud-prevention, or dispute-resolution purposes.
10. Data Security
Malva implements reasonable administrative, technical, and organizational safeguards designed to protect information. Measures may include encryption in transit, access controls, authentication controls, monitoring and logging, and infrastructure security practices.
No security system can guarantee absolute protection.
11. International Data Transfers
Malva operates globally. Information may be processed and stored in countries other than the user's country of residence, including the United States.
Where required, Malva implements appropriate safeguards for international transfers of personal data.
12. Your Rights
Depending on your location, you may have rights regarding your personal data, including access, correction, deletion, restriction of processing, data portability, and objection to processing.
To exercise these rights, contact Malva using the information below.
13. California Privacy Rights
If you are a California resident, you may have rights under applicable California privacy laws, including rights to request access to certain personal information and information regarding Malva's data practices.
Malva does not sell personal information.
14. European Economic Area, Switzerland, and United Kingdom
If you are located in the EEA, Switzerland, or the United Kingdom, you may have rights under applicable data protection laws, including GDPR and related regulations.
You may also have the right to lodge a complaint with a supervisory authority.
15. Cookies and Similar Technologies
Malva may use cookies, local storage, session identifiers, and analytics technologies to maintain sessions, improve performance, understand usage, and enhance security.
Users may control cookies through browser settings, subject to functionality that requires essential cookies or equivalent technologies.
16. Third-Party Services
The Service may integrate with third-party platforms, including CRM systems, Google Workspace, Microsoft 365, communication tools, productivity software, cloud providers, and AI service providers.
This Privacy Policy describes Malva's handling of information received through those integrations. A user's direct use of a third-party service remains subject to that third party's own privacy policy and terms.
17. Children's Privacy
The Service is not intended for individuals under the age of 18. Malva does not knowingly collect personal information from children.
If Malva becomes aware that personal information has been collected from a child, Malva will take appropriate steps to remove it.
18. Changes to This Privacy Policy
Malva may update this Privacy Policy from time to time. Updated versions become effective when published on the Service unless applicable law requires a different notice or effective date.
19. Contact Us
Malva
Email:: team@getmalva.com
For privacy-related questions, requests, or concerns, please contact us using the email above.