This Privacy Policy explains how Aivance Technologies, Inc. (“Aivance”, “we”, “our”, or “us”), a company incorporated in Delaware, United States, handles personal information.
It applies to our website at aivancetechnologies.com, including demo.aivancetechnologies.com where the demonstrations are published, and to the products and features we make available from time to time, which currently include Trevano, Zocia and Meherya (together, the “Services”). Some products described on our website are still in development; this Policy applies to each product from the point at which it is made available to you.
If you do not agree with this Policy, please do not use the Services.
Where the products stand today. Aivance is pre-launch. Trevano ERP is server software under active development and is not yet open to customers; Zocia and Meherya are designs, not running services. What you can open on this website are demonstrations that run inside your own browser tab — they hold no account, send nothing to a server and keep nothing after you close the tab. This Policy is written to cover the Services as they will operate, so that it is in place before anyone’s data is held rather than after. What is built and what is not is set out on the status page.
01Who we are and what this covers
Aivance Technologies, Inc. is the controller of the personal information described in this Policy, except where we act as a processor on behalf of a business customer (see Section 4).
Different products collect different information. Where a specific product collects information not described here, we will tell you at the point of collection or in a product-specific notice, which forms part of this Policy.
02Information we collect
2.1 Information you give us
- Account details such as name, email address, phone number, organisation name and role
- Billing information. Card and bank details will be collected and processed by our payment provider; we do not store full payment card numbers on our systems, and we will not begin collecting billing information at all until there is something to bill for
- Content and records you enter into or upload to the Services
- Messages you send us, including support requests, emails and chat messages
- Any other information you choose to provide, for example in a profile or a form
- Information about other people that you choose to add — for example a reference written by a friend, or a family member you invite to see a match. Please add this only where you have that person’s permission, and only what they are content for you to share
One thing on this website works differently, and it is worth saying plainly. The enquiry form on our home page — the one behind the pricing buttons — does not send anything to a server of ours. Pressing Send it opens your own email application with the message already written, and nothing reaches us until you press send there. Until that moment, what you typed has not left your device. If you close the message instead, we never see it.
The WhatsApp buttons on this website work the same way. Pressing one opens WhatsApp with the message already written, and nothing reaches us until you send it there. WhatsApp is run by Meta, not by us. Once you are inside it, Meta’s terms and privacy policy govern what happens to the message, not ours.
2.2 Information collected automatically
- IP address, approximate location derived from it, browser and device type, operating system and device identifiers
- Log data: pages viewed, features used, dates and times, referring pages and error reports
- Cookies and similar technologies, as described in Section 8
- Precise location data, only where a feature requires it and only after you grant permission through your device. You can withdraw that permission at any time in your device settings
2.3 Information from other sources
- Data from platforms you choose to connect to the Services, limited to what that connection requires
- Information from our payment, analytics and fraud-prevention providers
- Publicly available business information, used to verify an organisation
- Information provided by an administrator of an organisation that has given you an account
Several of the sources above describe the Services as they will operate. Today there is no payment provider, no analytics provider and no fraud-prevention provider connected to anything of ours, because nothing of ours is live yet.
2.4 Sensitive information
As a rule we do not ask for sensitive personal information such as health information, or information revealing racial or ethnic origin or sexual orientation. Two features are the exception, and we set them out here rather than leave them to a general clause:
- Identity verification. Where a product offers a verified badge, we ask you to show a government identity document and, if you choose the face check, to record a short liveness video. We use these once, to confirm you are a real person and that the document is yours. We do not show either to other users, we do not use them to identify you anywhere else, and we do not sell or share them. Neither the document image nor the video is retained after the check completes; the Meherya screens say the same thing in the same words, and this Policy is not the weaker of the two.
- Religion and language in Meherya. A matrimony service cannot match on values without them, so Meherya asks for religion and language preference. These are used only to produce your match scores and to filter what you are shown.
Both are optional. Where the law treats this information as a special category — including under the EU and UK GDPR — we rely on your explicit consent, we explain the purpose at the point we ask, and you may withdraw consent or delete the information at any time using the contact details in Section 15. Where a product later asks for sensitive information not described here, we will explain the purpose and ask before collecting it.
03How and why we use information
We use personal information for the purposes set out below. Where the law requires a legal basis for processing (for example under the EU or UK GDPR), the relevant basis is shown alongside each purpose.
| Purpose | Legal basis |
|---|---|
| Providing the Services — creating accounts, delivering features, processing transactions | Performance of a contract |
| Support and administration — answering requests, sending service notices | Performance of a contract; legitimate interests |
| Improving the Services — diagnostics, analytics, testing, aggregate reporting | Legitimate interests |
| Security and fraud prevention — detecting misuse, protecting accounts and systems | Legitimate interests; legal obligation |
| Marketing — sending updates about our products | Consent, or legitimate interests where permitted |
| Legal compliance — tax, accounting, responding to lawful requests | Legal obligation |
| Automated features — recommendations, forecasting, summaries and similar functions within a product | Performance of a contract; legitimate interests |
3.1 Automated processing
Some features use automated processing to produce suggestions, forecasts, summaries or rankings. These outputs are intended to assist decisions, not to replace them. We do not make decisions producing legal or similarly significant effects about you based solely on automated processing without a lawful basis and appropriate safeguards. Where you are in a jurisdiction that grants a right to human review of such a decision, you may request it using the contact details in Section 15.
3.2 Marketing choices
You can opt out of marketing emails at any time using the unsubscribe link in the message or by contacting us. We will still send you administrative and service messages relating to your account.
04Customer Data and our role
When an organisation uses a product such as Trevano to manage its own records, that organisation decides what information to enter and why. In relation to that information (“Customer Data”), the organisation is the controller and we act as a processor, handling the data on its documented instructions and under the data processing agreement we enter into with it. No organisation is using the Services yet, so no such agreement is in place today.
If you are an individual whose information appears in Customer Data — for example an employee or a customer of that organisation — you should direct requests about your information to that organisation in the first instance. We will assist them in responding, and we will refer your request to them where appropriate.
Where we act as a processor, this Policy applies to our own handling of the data, and that agreement governs the rest.
4.1 Staff location and attendance features
Trevano offers features that record where a member of staff or a delivery rider is while they are working. Where an organisation switches these on, that organisation decides to do so and is the controller of the resulting data; we provide the tool and hold the records on its instructions.
We build these features on the following basis, and we say so to every organisation that buys them:
- Location is collected only during working hours and only while the person is signed in to a work account. It is not collected outside those hours
- The person being located must be told, in plain language, before it starts. Location tracking that a member of staff has not been told about is a misuse of the product
- The organisation is responsible for meeting the employment and data protection law that applies to it, including any assessment, notice or consultation its jurisdiction requires before monitoring staff
- We do not use staff location data for our own purposes, and we do not sell or share it
If you are a member of staff and you believe you are being tracked without having been told, contact your employer first. You may also write to us using the details in Section 15 and we will raise it with them.
4.2 Location across our Services
Location is part of how our Services work. It is not an extra switched on afterwards. In the consumer products it is there to work out distance and nothing else; where an employer switches on the staff and rider features, watching is openly the purpose, and Section 4.1 sets out the rules that go with that rather than dressing it up as something softer.
Where a feature is built around distance — showing you what is near enough to reach, ranking a match by how far away it is, or recording where work was carried out — that feature asks your browser or device for your location and needs one in order to run. A distance worked out from a position we had guessed at would not be worth showing you, so rather than show you something inaccurate, we ask. Where you do not grant it, the feature says so and does not run. It does not substitute a made-up position.
We ask at the moment the feature needs it and not before, and the screen tells you what it is for before your browser does.
What we do with it
- We work out distance, and we place you in the right area. That is the whole of it
- The position your device gives us is a precise one, and we say so rather than asking for a blurred reading and calling that a protection. What protects you is not how rough the reading is, it is the three lines above and below this one: what we do with it, who is shown it, and how long it stays
- Whether a position is kept, and for how long, depends on which feature asked for it. The staff and rider features in Section 4.1 record positions and keep them as the employing organisation’s records — proving that a delivery happened is the point of them, and we will not describe them as though it were not. Outside those features no position of yours is stored anywhere at all today, because Zocia and Meherya have no server behind them
- Nobody is shown your address or your coordinates. Other people see a rounded distance and nothing else, and it is designed that way so that no one can work backwards from it to where you live
What stays in your hands
- The permission belongs to your browser or device, not to us. You can withdraw it at any time in your settings, and we neither prevent that nor try to
- If you withdraw it, the features that depend on it pause until you grant it again. Your account and everything that does not depend on distance carries on as normal
- We will not ask for a position for any purpose beyond the ones set out above without telling you first and updating this Policy, as described in Section 14
Section 4.1 above sets out the additional rules that apply where an organisation switches on location for its own staff, which is a different situation with its own protections.
05How we share information
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
We disclose information only as described below:
- Service providers — companies that provide hosting, storage, payment processing, communications, analytics, error monitoring and customer support tooling on our behalf. They may access personal information only to perform those services for us and are bound by contractual confidentiality and security obligations. Today the only ones engaged are for hosting this website and for our email; the rest are named here because they will be engaged as the Services go live, not because they already are
- Integrations you enable — where you connect a third-party platform, the information required by that connection is shared with it, and the third party's own terms and privacy policy then apply
- Your organisation — if your account was created by or is administered by an organisation, its administrators may access account and usage information
- Professional advisers — lawyers, accountants and auditors, where necessary and subject to confidentiality
- Legal and safety — where we reasonably believe disclosure is required by law or legal process, or is necessary to protect the rights, property or safety of Aivance, our users or the public. Where we are permitted to do so, we will notify the affected user
- Corporate transactions — in connection with a merger, acquisition, financing or sale of assets, subject to the recipient continuing to protect the information in a manner consistent with this Policy
We may also publish aggregated or de-identified information that cannot reasonably be used to identify you. We will not attempt to re-identify such information.
06Security
We take reasonable and appropriate technical and organisational measures designed to protect personal information against loss, misuse and unauthorised access, disclosure, alteration and destruction. Depending on the Service, these measures include encryption of data in transit, encryption of stored data as each product goes live, access controls limiting who can reach production systems, authentication controls, logging, and backups.
The specific measures applied vary by product and evolve over time. Features that are still in development may not yet include the full set of controls that will apply at general availability. Two of the measures above are being built rather than finished: two-factor authentication for administrator accounts, and encryption of stored data. We would rather name them here than list them as though the work were done. What is built and what is not is set out on the status page.
No service, product or method of transmission over the internet is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your credentials confidential and for the security of the devices you use to access the Services.
07How long we keep information
We keep personal information for as long as needed for the purposes described in this Policy, and then delete or de-identify it. In practice this means:
- Account and Customer Data — for as long as the account is active, and for a limited period afterwards to allow export and recovery from error
- Billing and tax records — for the period required by applicable law
- Support correspondence — for as long as needed to handle the matter and to improve support quality
- Logs and security records — for a limited period appropriate to their purpose
We may retain information for longer where we are required to do so by law, or where it is necessary to establish, exercise or defend legal claims. Backup copies are deleted on our ordinary backup cycle.
08Cookies and similar technologies
We use cookies and similar technologies to keep you signed in, remember your preferences, keep the Services secure, and understand how the Services are used so we can improve them. That describes the Services once they are live. The website you are reading now sets no cookies at all, and the demonstrations on it keep nothing after you close the tab — not in a cookie, and not anywhere else.
We do not use cookies for cross-site behavioural advertising. Where required by applicable law, we ask for your consent before setting non-essential cookies, and you can change your choice at any time. You can also control cookies through your browser settings, though disabling them may affect how the Services work.
09Your privacy rights
Subject to the law that applies to you, you may have the right to:
- Access the personal information we hold about you, and receive a copy
- Correct information that is inaccurate or incomplete
- Delete your personal information
- Port your information to another provider in a structured, commonly used, machine-readable format
- Restrict or object to certain processing, including processing based on legitimate interests and processing for direct marketing
- Withdraw consent at any time where processing is based on consent. This does not affect processing carried out before withdrawal
- Opt out of the sale or sharing of personal information. As stated in Section 5, we do not sell or share personal information as those terms are defined under United States state privacy laws
To exercise these rights, contact us using the details in Section 15. We will respond within the time required by applicable law. We may need to verify your identity before acting, and we may decline a request where the law permits, in which case we will explain why.
We will not discriminate against you for exercising a privacy right. You may use an authorised agent to submit a request where the law allows.
If you are in the European Economic Area or the United Kingdom, you have the right to lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concern before you do so.
10Children
The Services are intended for people aged 18 and over and are not directed at children. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected such information, we will delete it. If you believe a minor has provided us with personal information, please contact us and we will act promptly.
11International transfers
Aivance Technologies, Inc. is incorporated in the United States. The work of building and running the company, including access to the systems described in this Policy, is done from Dhaka, Bangladesh, and we work with service providers in several countries. Your information may therefore be transferred to, stored in and processed in countries other than your own — including the United States and Bangladesh — where data protection laws may differ from those in your country. We set this out plainly rather than leaving it to be discovered, because where the people who can reach your data sit is something you are entitled to know before you hand any over.
Where we transfer personal information out of the European Economic Area, the United Kingdom or another jurisdiction with transfer restrictions, we will rely on a lawful transfer mechanism — the European Commission's Standard Contractual Clauses and the UK Addendum, together with additional safeguards where appropriate — and it will be in place before the transfer begins, not after. To be exact about today: no such transfer is happening, because there are no customers and no live Service. You may request further information about these safeguards using the contact details below.
12Security incidents
If we become aware of a security incident affecting your personal information, we will investigate promptly, take reasonable steps to contain and remedy it, and notify you and any relevant regulator where required by applicable law and within the timeframes that law sets. Where we act as a processor for an organisation, we will notify that organisation without undue delay so that it can meet its own obligations.
13Third-party services and links
The Services may link to, or interoperate with, websites, applications and services we do not control. We are not responsible for their content or their privacy practices. We encourage you to read their privacy policies before providing information to them.
14Changes to this Policy
We may update this Policy as our products, our practices or the law change. When we do, we will revise the “Last updated” date at the top of this page. If a change is material, we will provide additional notice, such as an email or a notice within the Services, before it takes effect. Continued use of the Services after a change takes effect means you accept the updated Policy.
We keep a dated copy of each version of this Policy from this one onward, and will send you an earlier version on request so that you can see what has changed.
15How to contact us
For any question about this Policy, or to exercise a privacy right, contact us at:
- Company
- Aivance Technologies, Inc.
- Address
- 131 Continental Drive, Suite 301
Newark, DE 19713, USA - support@aivancetechnologies.com
Please include enough detail for us to understand and verify your request. If you contact us on behalf of an organisation, please say so.