Chavid

Built secure from the ground up

Chavid is a UK-built platform designed with security and privacy at its core — not bolted on as an afterthought. Every call is encrypted, every byte of data stays in the UK.

End-to-end encrypted callsUK data storage onlyUK GDPR compliantNo US data transfersNo advertising or data selling30-day free trial — no card needed

Every call is encrypted

Chavid uses industry-standard encryption protocols to protect every video call, audio call, and message — in transit and at rest.

DTLS-SRTP for video & audio

All video and audio streams are encrypted using DTLS-SRTP (Datagram Transport Layer Security — Secure Real-time Transport Protocol), the same standard used by WebRTC across the industry. Keys are negotiated per-session and never reused.

TLS 1.3 for signalling & messaging

All signalling traffic, API calls, and messages travel over TLS 1.3 — the latest and most secure version of the Transport Layer Security protocol. Older, weaker TLS versions are rejected.

AES-256 at rest

Stored data — messages, call metadata, user records — is encrypted at rest using AES-256. Encryption keys are managed separately from the data they protect.

Ephemeral session keys

Encryption keys for calls are generated fresh for each session and discarded when the call ends. There are no long-lived keys that could be compromised to decrypt past calls.

Your data never leaves the UK

Unlike US-headquartered platforms, Chavid is a UK company. All data is stored and processed on UK infrastructure — never transferred to the United States or any third country.

UK servers only

All user data, call metadata, and messages are stored on servers physically located in the United Kingdom.

No US transfers

Chavid does not transfer personal data to the United States or any country outside the UK/EEA. No Schrems II risk.

No third-party data sharing

We do not sell, share, or license your data to advertisers, data brokers, or any third party.

Right to erasure

Users can request deletion of their account and all associated data at any time, in accordance with UK GDPR Article 17.

🇬🇧

UK only

Every byte of Chavid data is stored and processed on servers in the United Kingdom. No exceptions.

No US transfers
No EU transfers
No third-country transfers

Compliance built in

Chavid was designed to meet the requirements of UK GDPR, the Data Protection Act 2018, and the security expectations of regulated sectors.

UK GDPR

Chavid operates under UK GDPR and the Data Protection Act 2018. We maintain a lawful basis for all processing, publish a full privacy policy, and honour all data subject rights including access, rectification, restriction, and erasure.

Data Protection Act 2018

As a UK-based data controller, Chavid complies with the DPA 2018. We are in the process of registering with the Information Commissioner's Office (ICO) as required for organisations that process personal data.

No advertising model

Chavid's business model is subscription-based. We have no advertising revenue and no incentive to harvest, profile, or monetise user data. Your data is never the product.

Minimal data collection

We collect only what is necessary to provide the service: name, email, and call metadata. We do not collect biometric data, location data, or behavioural profiles.

Designed for regulated sectors

Chavid's security architecture makes it suitable for use in healthcare, education, and public sector environments where data protection is non-negotiable.

NHS & Healthcare

  • All calls encrypted with DTLS-SRTP — no unencrypted audio or video
  • UK data residency — patient data never leaves UK jurisdiction
  • No data sharing with third parties or advertisers
  • Guest join by link — no patient account or app download required
  • Waiting room feature — clinician controls who enters the call
  • Call recording available for clinical documentation (host-controlled)
  • GDPR-compliant data handling with right to erasure

Chavid is not currently certified to NHS DSP Toolkit or ISO 27001. Organisations with formal certification requirements should assess suitability against their own governance frameworks.

Schools & Education

  • Waiting room — teacher admits pupils individually, no uninvited access
  • Host-controlled breakout rooms for group work
  • No advertising or data profiling of any user
  • Guest join — pupils join by link, no account or app needed
  • UK data storage — compliant with UK GDPR and DPA 2018
  • Screen sharing for presentations and collaborative work
  • Up to 500 participants per call on Individual plan

Schools should conduct their own Data Protection Impact Assessment (DPIA) before deploying any video calling platform. Chavid can provide data processing information to support this process.

Universities & Higher Education

  • Up to 1,000 participants per call on Team plan — suitable for large lectures
  • Live captions for accessibility compliance
  • Polls and Q&A for interactive teaching
  • Recording for lecture capture and review
  • UK GDPR compliant — suitable for student data processing
  • No US data transfers — avoids Schrems II complications
  • Guest access — external speakers join without an account

Universities should review Chavid's data processing terms and conduct a DPIA as part of procurement. We are happy to provide a Data Processing Agreement (DPA) on request.

Infrastructure & access controls

UK-hosted infrastructure

All Chavid services run on UK-based cloud infrastructure. No data is routed through or stored in the United States or other third countries.

Encrypted database

The Chavid database is encrypted at rest using AES-256. Database access is restricted to application services only — no direct public access.

HTTPS everywhere

All web traffic is served over HTTPS with TLS 1.3. HTTP connections are automatically redirected. HSTS is enforced.

Authentication security

Passwords are hashed using bcrypt with a high work factor. Session tokens are cryptographically random and expire automatically. Email verification is required on signup.

Rate limiting & abuse prevention

API endpoints are rate-limited to prevent brute-force attacks and abuse. Suspicious activity triggers automatic lockout.

Dependency management

Third-party dependencies are regularly reviewed and updated. We use automated tooling to flag known vulnerabilities in our supply chain.

Security questions answered

Common questions from procurement teams, IT leads, and data protection officers.

Video and audio calls use DTLS-SRTP encryption, which is the WebRTC industry standard. This encrypts media in transit between participants and the Chavid media server. Chavid uses LiveKit as its media infrastructure, which operates on UK-based servers. Messages are encrypted in transit using TLS 1.3 and at rest using AES-256.

All Chavid data — user accounts, messages, call metadata, and recordings — is stored on servers physically located in the United Kingdom. We do not transfer data to the United States or any country outside the UK/EEA.

Chavid's encryption, UK data residency, and GDPR compliance make it technically suitable for many healthcare communication use cases. However, Chavid is not currently certified to NHS DSP Toolkit or ISO 27001. Healthcare organisations should conduct their own risk assessment and DPIA before deployment. We are happy to provide data processing documentation to support this.

Yes. Chavid stores all data in the UK, complies with UK GDPR and the DPA 2018, has no advertising model, and includes a waiting room feature so teachers control who enters a call. Schools should conduct a DPIA as part of their procurement process. We can provide a Data Processing Agreement on request.

No. Chavid's revenue comes entirely from subscriptions. We do not sell, share, or license user data to advertisers, data brokers, or any third party. We collect only the data necessary to provide the service.

Chavid is in the process of registering with the Information Commissioner's Office (ICO) as required under the Data Protection Act 2018. ICO registration will be confirmed here once complete.

Yes. If your organisation requires a formal Data Processing Agreement — for example as part of a school or NHS procurement process — please contact us at [email protected] and we will provide one.

Questions about security or compliance?

We're happy to provide documentation, answer procurement questions, or discuss your organisation's specific requirements.