Privacy policy
Last updated: 4 August 2026
1. Who we are
Portavi is a PMO portfolio dashboard operated by Smadi for technical solutions, An Naba’ah St, Al Zahiyah, 9, Abu Dhabi, 22210, United Arab Emirates ("Portavi", "we", "us"). The product runs at app.portavipmo.com; this website is portavipmo.com. For anything in this policy, contact support@portavipmo.com.
For data synced into Portavi from tools your organization connects (your projects, tasks, and communication signals), your organization is the data controller and Portavi processes that data on its behalf. For your Portavi account data and this website, Portavi is the controller.
2. We never store message content
This is the most important fact in this policy, so it comes first. When your organization connects a communication tool (Slack, Microsoft Teams, or Google Chat), Portavi reads only the channels your admins explicitly map to projects, and it scans those messages for delivery signals: blockers, delays, urgency, issues, and progress.
Message bodies are read in memory during a sync, solely to run that detection, and are never written to our database or any other storage. What Portavi stores is signal metadata only: the signal type, a timestamp, the sender’s name, the channel, and a deep link to the original message in the source tool.
Notification emails describe a signal without quoting the message. Following a deep link is subject to your own permissions in the source tool — Portavi never becomes a way to read a message you could not otherwise access.
3. Information we collect
Account information. When you create an account: your name, email address, and authentication method (email/password, Google, or Microsoft). Passwords are handled by our authentication provider and are never visible to us in plain text.
Project data from connected PM tools. When your organization connects a project management tool (Jira, Asana, Monday.com, Azure DevOps, or ClickUp), Portavi syncs — read-only — projects and boards, tasks and subtasks, assignees, due dates, status and completion, and sprints and phases. Portavi cannot modify anything in the source tool.
Communication signals. As described in section 2: signal metadata only, never message content.
Usage and device data. Product analytics (via PostHog) about how the app is used, which you can turn off entirely in Settings → Privacy — the opt-out is honoured on both the client and the server.
This website. The marketing website (portavipmo.com) uses cookieless, privacy-preserving analytics (via PostHog) to count page visits and measure which pages lead to sign-ups. It sets no cookies, stores no identifiers in your browser, and honours your browser’s "Do Not Track" setting.
Billing information. Payments are processed by Stripe. Portavi never stores your card number; we retain only the subscription and invoicing records Stripe provides.
4. How we use information
- To provide the service: portfolio dashboards, project health, flagged blockers, notifications, and reports
- To operate accounts, workspaces, and billing
- To send transactional email such as invitations, verification, and signal notifications
- To secure the service: rate limiting, bot protection, and abuse prevention
- To improve the product, using analytics you can opt out of
We do not sell personal data, and we do not use customer data to train machine-learning models.
5. Sub-processors
Portavi uses the following service providers to operate the product:
- Supabase — database, authentication, file storage
- Vercel — application hosting
- Stripe — payments and subscription billing
- Resend — transactional email (invitations, notifications, verification)
- PostHog — product analytics (user-controllable opt-out)
- Cloudflare — bot protection (Turnstile), WAF and CDN
- Upstash — rate-limit counters
In addition, data flows into Portavi from the integration providers your organization itself chooses to connect (Atlassian, Asana, Monday.com, Microsoft, Google, Slack, ClickUp). Each connection is explicitly authorized by your organization and can be disconnected at any time.
6. Retention and deletion
- Message content: never stored (see section 2)
- Signal metadata: retained until the project or workspace it belongs to is deleted, then deleted with it
- In-app notifications: automatically deleted after 30 days
- Account data: deleted when you delete your account
Account deletion is self-service and complete. Deleting your account removes your user record, your workspace memberships, and your authentication identity. If you are the only member of a workspace, the workspace is deleted with you; if you are its only PMO Manager, you are asked to promote a replacement first so you cannot orphan your team’s data by accident.
7. Your rights
Portavi is operated from Abu Dhabi, and the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) applies to our processing. If you are in the European Economic Area or the United Kingdom, the GDPR or UK GDPR also applies to you.
Under these laws you can request access to your personal data, correction, deletion, restriction of processing, a portable copy, or object to processing. Many of these you can exercise directly in the product — including full account deletion and the analytics opt-out — and for anything else, email support@portavipmo.com. We respond within the timelines the applicable law requires. If you are unsatisfied with our response, you may lodge a complaint with the UAE Data Office or your local supervisory authority.
8. International transfers
Our sub-processors operate infrastructure in multiple regions, so data may be processed outside your country, including outside the UAE and the EEA. Where required, we rely on appropriate safeguards for such transfers, such as contractual protections with our sub-processors.
9. Security
Every workspace-scoped table enforces Row-Level Security for tenant isolation; integration OAuth tokens are stored server-side only and never returned to the browser; sign-up and sign-in are protected by Cloudflare Turnstile; all API endpoints are rate-limited; data is encrypted in transit with TLS and backups are encrypted at rest. Our security page describes these controls in more detail.
10. Children
Portavi is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18.
11. Changes to this policy
If we make material changes to this policy, we will update the date at the top and notify workspace administrators by email before the changes take effect.
12. Contact
Smadi for technical solutions, An Naba’ah St, Al Zahiyah, 9, Abu Dhabi, 22210, United Arab Emirates. Email: support@portavipmo.com.