Built secure from the ground up
Chavid is a UK-built platform designed with security and privacy at its core — not bolted on as an afterthought. Every call is encrypted, every byte of data stays in the UK.
Every call is encrypted
Chavid uses industry-standard encryption protocols to protect every video call, audio call, and message — in transit and at rest.
DTLS-SRTP for video & audio
All video and audio streams are encrypted using DTLS-SRTP (Datagram Transport Layer Security — Secure Real-time Transport Protocol), the same standard used by WebRTC across the industry. Keys are negotiated per-session and never reused.
TLS 1.3 for signalling & messaging
All signalling traffic, API calls, and messages travel over TLS 1.3 — the latest and most secure version of the Transport Layer Security protocol. Older, weaker TLS versions are rejected.
AES-256 at rest
Stored data — messages, call metadata, user records — is encrypted at rest using AES-256. Encryption keys are managed separately from the data they protect.
Ephemeral session keys
Encryption keys for calls are generated fresh for each session and discarded when the call ends. There are no long-lived keys that could be compromised to decrypt past calls.
Your data never leaves the UK
Unlike US-headquartered platforms, Chavid is a UK company. All data is stored and processed on UK infrastructure — never transferred to the United States or any third country.
UK servers only
All user data, call metadata, and messages are stored on servers physically located in the United Kingdom.
No US transfers
Chavid does not transfer personal data to the United States or any country outside the UK/EEA. No Schrems II risk.
No third-party data sharing
We do not sell, share, or license your data to advertisers, data brokers, or any third party.
Right to erasure
Users can request deletion of their account and all associated data at any time, in accordance with UK GDPR Article 17.
UK only
Every byte of Chavid data is stored and processed on servers in the United Kingdom. No exceptions.
Compliance built in
Chavid was designed to meet the requirements of UK GDPR, the Data Protection Act 2018, and the security expectations of regulated sectors.
UK GDPR
Chavid operates under UK GDPR and the Data Protection Act 2018. We maintain a lawful basis for all processing, publish a full privacy policy, and honour all data subject rights including access, rectification, restriction, and erasure.
Data Protection Act 2018
As a UK-based data controller, Chavid complies with the DPA 2018. We are in the process of registering with the Information Commissioner's Office (ICO) as required for organisations that process personal data.
No advertising model
Chavid's business model is subscription-based. We have no advertising revenue and no incentive to harvest, profile, or monetise user data. Your data is never the product.
Minimal data collection
We collect only what is necessary to provide the service: name, email, and call metadata. We do not collect biometric data, location data, or behavioural profiles.
Designed for regulated sectors
Chavid's security architecture makes it suitable for use in healthcare, education, and public sector environments where data protection is non-negotiable.
NHS & Healthcare
- All calls encrypted with DTLS-SRTP — no unencrypted audio or video
- UK data residency — patient data never leaves UK jurisdiction
- No data sharing with third parties or advertisers
- Guest join by link — no patient account or app download required
- Waiting room feature — clinician controls who enters the call
- Call recording available for clinical documentation (host-controlled)
- GDPR-compliant data handling with right to erasure
Chavid is not currently certified to NHS DSP Toolkit or ISO 27001. Organisations with formal certification requirements should assess suitability against their own governance frameworks.
Schools & Education
- Waiting room — teacher admits pupils individually, no uninvited access
- Host-controlled breakout rooms for group work
- No advertising or data profiling of any user
- Guest join — pupils join by link, no account or app needed
- UK data storage — compliant with UK GDPR and DPA 2018
- Screen sharing for presentations and collaborative work
- Up to 500 participants per call on Individual plan
Schools should conduct their own Data Protection Impact Assessment (DPIA) before deploying any video calling platform. Chavid can provide data processing information to support this process.
Universities & Higher Education
- Up to 1,000 participants per call on Team plan — suitable for large lectures
- Live captions for accessibility compliance
- Polls and Q&A for interactive teaching
- Recording for lecture capture and review
- UK GDPR compliant — suitable for student data processing
- No US data transfers — avoids Schrems II complications
- Guest access — external speakers join without an account
Universities should review Chavid's data processing terms and conduct a DPIA as part of procurement. We are happy to provide a Data Processing Agreement (DPA) on request.
Infrastructure & access controls
UK-hosted infrastructure
All Chavid services run on UK-based cloud infrastructure. No data is routed through or stored in the United States or other third countries.
Encrypted database
The Chavid database is encrypted at rest using AES-256. Database access is restricted to application services only — no direct public access.
HTTPS everywhere
All web traffic is served over HTTPS with TLS 1.3. HTTP connections are automatically redirected. HSTS is enforced.
Authentication security
Passwords are hashed using bcrypt with a high work factor. Session tokens are cryptographically random and expire automatically. Email verification is required on signup.
Rate limiting & abuse prevention
API endpoints are rate-limited to prevent brute-force attacks and abuse. Suspicious activity triggers automatic lockout.
Dependency management
Third-party dependencies are regularly reviewed and updated. We use automated tooling to flag known vulnerabilities in our supply chain.
Security questions answered
Common questions from procurement teams, IT leads, and data protection officers.
Questions about security or compliance?
We're happy to provide documentation, answer procurement questions, or discuss your organisation's specific requirements.