PINAVIAAI governance and execution
Back to Pinavia

Enterprise data processing

Data Processing Addendum

This addendum governs Pinavia's processing of personal data on a customer's behalf. It forms part of the pilot terms and applies whenever a customer connects or uploads material containing personal data.

Effective 2026-08-13Draft — under legal review

This is a complete draft prepared for legal review, not an executed agreement. It describes the processing Pinavia performs today and the controls in place. For a pilot that requires signed data-processing terms, request the counter-signable version at hello@pinavia.io before uploading regulated or personal data.

Roles of the parties

The customer is the controller — or the equivalent role under their applicable law — and determines the purposes and means of processing. Pinavia is the processor and acts only on the customer's documented instructions, which are given through the product's own configuration: the evidence sources connected, the workspace scope set, and the workflows enabled.

Where a customer's own client data is involved, for example an advisory firm operating under the partner channel, the customer remains controller toward that client and Pinavia remains processor throughout. Pinavia does not enter into a controller relationship with a customer's clients.

Scope and purpose of processing

Processing is limited to delivering the workspace the customer has configured. Pinavia does not sell customer data, does not use it for advertising, and does not use customer content to train models.

  • Subject matter: documents, communications, and business context the customer connects or uploads as evidence.
  • Nature of processing: ingestion, text extraction, classification, embedding and indexing, retrieval, synthesis, recommendation drafting, approval routing, audit logging, and export generation.
  • Categories of data subject: the customer's personnel and any individuals named in the evidence the customer supplies.
  • Duration: for the term of the pilot or subscription, plus the deletion window in the retention section below.

Model providers and training

Evidence content is sent to model providers only to generate an output the customer has requested. Pinavia's agreements with those providers exclude customer content from provider model training, and Pinavia does not train its own models on customer content.

Deployments that require content never to leave customer-controlled infrastructure are on our roadmap and are not available today. Where that changes, the product will state plainly which processing runs locally rather than implying full local processing.

Subprocessors

Pinavia uses subprocessors for hosting and compute, managed database storage, object storage, identity and authentication, model inference, transactional email, billing, error monitoring, and cookieless analytics on public pages. Customers are notified before a new subprocessor is added, and may object on reasonable data-protection grounds.

  • A full subprocessor list is provided with our data processing agreement on request.

Security controls

Controls are described in full in the security document. In summary, access is authenticated and scoped to the customer's workspace, data is encrypted in transit and at rest by the underlying platforms, and consequential actions are recorded in an audit trail, with the identity of the human who approved them, that the customer can export at any time.

Retention and deletion

Customer content is retained for the term of the agreement. On termination, the customer may export their evidence, decisions, approvals, and audit trail before deletion.

On written deletion request, Pinavia deletes workspace records from the production database within 30 days. Original files are held in object storage under a fixed retention lock and are removed when that period ends. Backup copies are never edited by Pinavia and are retained under the backup bucket's retention settings. Audit records required to evidence that a deletion occurred are retained in a minimised form that contains no customer content.

Incident notification

Pinavia notifies the customer without undue delay, and in any event within 72 hours of becoming aware, of any breach affecting the customer's personal data. Notification includes what is known about the nature of the incident, the categories and approximate volume of data involved, the likely consequences, and the measures taken or proposed.

Hosting locations and audit

Hosting locations are listed with the subprocessor list, which is provided with our data processing agreement on request. Pinavia makes available the information necessary to demonstrate compliance with this addendum and will contribute to audits on reasonable notice, including through completed security questionnaires.

Data Processing Addendum | Pinavia