MAVIORB

MAVIORB shared account

MAVIORB Privacy Policy

How MAVIORB handles personal data for the shared MAVIORB account, identity, authentication, account-security, and platform gateway.

Effective: 22 August 2026 Version: 1.0
Theodoros Mavrosavvas (Θεόδωρος Μαυρόσαββας), trading as MAVIORB
MAVIORB is a registered business name in Cyprus and is currently operated as a personal trading name rather than a separate incorporated company.
hello@maviorb.com

1. Who we are

The controller for the shared MAVIORB account and platform layer is Theodoros Mavrosavvas (Θεόδωρος Μαυρόσαββας), trading as MAVIORB.

MAVIORB is a registered business name in Cyprus and is currently operated as a personal trading name rather than a separate incorporated company.

For privacy questions or requests, contact hello@maviorb.com.

2. What this policy covers

This policy covers the shared MAVIORB account, identity, authentication, account-security, and platform gateway. It does not replace product-specific terms or privacy information for individual MAVIORB product lines.

For example, LunaloQ remains a separate product experience with its own product-specific Terms and privacy information for matters such as readings, profiles, birth data, Moondrops, subscriptions, and other LunaloQ processing.

3. Personal data we process for a MAVIORB account

Depending on how you create and use your account, MAVIORB may process the following categories of personal data:

  • Account details such as your name, email address, password hash, and email-verification status.
  • Authentication and session information needed to keep you signed in, protect your session, and complete account-security actions such as email verification or password reset.
  • External identity information when you choose a supported sign-in provider, including the provider, issuer, provider subject identifier, email and email-verification snapshots where supplied, display-name snapshot where supplied, and timestamps recording when the identity was linked or last authenticated.
  • Transactional account-security information needed to send or record verification and password-reset activity.

4. Google Sign-In data

If you choose Google Sign-In, your browser or application sends a Google identity credential to MAVIORB. MAVIORB verifies that credential using Google authentication libraries and validates the issuer, audience, and unique Google subject identifier before accepting the identity.

Google may also provide your email address, whether Google has verified that email address, and your display name. MAVIORB uses this information only to authenticate you, create or link the correct MAVIORB account, and protect the account-linking process.

The shared MAVIORB identity layer stores the external identity key using provider, issuer, and subject, together with limited email, verification, and display-name snapshots and link or authentication timestamps.

The current shared-account identity implementation does not persist a raw Google ID token, Google access token, or Google refresh token as identity data. Temporary external-identity claims are encrypted, time-limited, and used only to complete the relevant account flow.

Google processes information under Google's own terms and privacy policy when you use Google Sign-In. MAVIORB does not treat your Google email address alone as sufficient proof for silently linking a different account.

5. Why we process this data

We process shared-account data only for purposes connected with providing and protecting the MAVIORB account and platform layer.

  • To create, administer, and authenticate your MAVIORB account.
  • To verify your email address and help you recover access when you request a password reset.
  • To link an external identity securely when you choose a supported sign-in provider.
  • To protect users, accounts, and MAVIORB services against misuse, fraud, unauthorized access, and security incidents.
  • To maintain essential service records and comply with applicable legal obligations.

6. Legal bases

Depending on the specific purpose, MAVIORB relies on the legal basis appropriate to that processing. This may include taking steps at your request or performing the account service, legitimate interests in operating and securing MAVIORB, compliance with legal obligations, and consent where a separate optional activity specifically requires it.

Optional marketing, tracking, or product-specific permissions are not treated as part of shared-account acceptance merely because you create a MAVIORB account. Where those activities require a separate choice, they are governed and recorded separately.

7. Who may receive personal data

MAVIORB may use service providers that are necessary to operate hosting, authentication, security, transactional email, and related technical infrastructure. They receive only the information reasonably needed for their role and remain subject to applicable contractual and legal safeguards.

When you choose Google Sign-In, Google is also involved in the authentication interaction under its own terms and privacy policy.

Personal data may also be disclosed where required by law, a lawful authority, or where reasonably necessary to establish, exercise, or defend legal claims.

8. International processing

Some technology providers may process data in countries outside Cyprus or the European Economic Area. Where data-protection law requires safeguards for an international transfer, MAVIORB will use the applicable transfer mechanism or other lawful safeguard appropriate to the provider and processing.

You can contact hello@maviorb.com if you need information about safeguards relevant to your personal data.

9. How long we keep data

MAVIORB keeps shared-account information only for as long as it is needed for the account, security, legal, and operational purposes described in this policy.

External identity records are tied to the MAVIORB account and the current shared identity schema deletes those identity rows when the associated user account is deleted. Temporary external-identity claims currently expire after ten minutes.

Session, verification, password-reset, security, communications, and other operational records follow their applicable technical lifecycle and may have different retention needs. Product-specific records may also have separate retention rules described by the relevant product privacy information.

Where a record must be retained after account closure for a legal, security, fraud-prevention, accounting, or dispute purpose, MAVIORB will limit that retention to what is necessary for that purpose.

10. Account deletion and privacy rights

Authenticated users can use the available MAVIORB account controls to delete the core account. Product-specific deletion or rights processes may also apply where a product maintains additional data under the same MAVIORB controller.

Depending on applicable law and the circumstances, you may have rights to access, correct, erase, restrict, or receive a copy of your personal data, and to object to certain processing. Where processing is based on consent, you may withdraw that consent without affecting processing that was lawful before withdrawal.

To exercise a privacy right or ask a question, contact hello@maviorb.com. We may need to verify your identity before acting on a request.

11. Cookies and session storage

The shared MAVIORB account uses session technology and cookies needed to authenticate users, maintain secure browser sessions, and protect state-changing requests. Optional analytics, advertising, or tracking technologies, if introduced, must be governed separately and are not implied by this policy merely because the account service uses necessary session storage.

12. Security

MAVIORB uses technical and organizational controls intended to protect personal data, including server-side authentication checks, secure password hashing, encrypted temporary identity claims, session protections, and controlled external-identity linking.

No internet service can guarantee absolute security. If you believe your MAVIORB account or personal data may have been compromised, contact hello@maviorb.com promptly.

13. Complaints

You may contact MAVIORB first so we can try to address your concern. You also have the right to lodge a complaint with the competent data-protection supervisory authority. In Cyprus, this is the Office of the Commissioner for Personal Data Protection.

14. Changes to this policy

MAVIORB may update this policy when the shared account, identity architecture, providers, legal requirements, or data practices change. The current version and effective date are shown on this page. Material changes will be handled with the notice or renewed interaction required by applicable law and the affected service.

MAVIORB provides the shared account and platform layer. Individual MAVIORB product lines may have separate product-specific terms and privacy information for their own services and data processing.