Privacy
Privacy and Customer Data
Pinavia is built around customer-owned evidence. The material you connect stays yours, is scoped to your workspace, and is processed only to produce the outputs you ask for.
This notice is a complete draft prepared for legal review. It describes how the product behaves today. If your procurement process requires a counsel-approved privacy notice before onboarding, request the reviewed version at hello@pinavia.io.
What we process, and why
Two categories of data pass through Pinavia. Account data identifies the people using the workspace: name, work email, organisation membership, and role. It exists so access can be scoped and so an approval can be attributed to a named person, which the product's governance model depends on.
Workspace content is the evidence you connect or upload — documents, communications, and business context — together with what the product derives from it: extracted text, classifications, embeddings, citations, drafted recommendations, approval records, and audit events. It is processed to deliver the workspace you configured, and for no other purpose.
What we do not do
Pinavia does not sell customer data, does not use it for advertising, and does not use workspace content to train models — neither its own nor a provider's. Model providers operate under agreements that exclude customer content from training. Public marketing pages use cookieless analytics that record no workspace content and set no advertising cookies.
Where your evidence goes
Evidence is stored in your workspace and retrieved to answer your questions. When generating an answer, the relevant passages are sent to a model provider so that a response can be produced, then returned and stored with the citations attached.
Deployments where content never leaves infrastructure you control, with retrieval and generation on a local model endpoint, are on our roadmap and are not available today. The product states where processing happens rather than implying otherwise; overstating that boundary would be the most damaging thing a governance product could do.
Access and scoping
Access is authenticated through a managed identity provider and scoped to your organisation's workspace. Members see only what their workspace and role permit, restricted evidence stays restricted rather than silently reappearing in a summary, and agent access is issued as revocable scoped tokens. Pinavia staff do not access workspace content except where you request support and grant access for that purpose, and such access is logged.
Retention and deletion
Workspace content is kept for the term of your agreement so that decisions remain defensible over time — an audit trail that expires is not an audit trail. You can export evidence, decisions, approvals, and the audit trail at any point. On a written deletion request, workspace records are removed from the production database within 30 days; original files are held under a fixed retention lock in object storage and removed when it ends; backup copies are never edited by Pinavia and are retained under the backup bucket's retention settings.
Your rights
Where individuals named in your evidence exercise rights of access, correction, or erasure, you direct that request as the controller and Pinavia assists as processor. Requests reach us at hello@pinavia.io and we respond within 30 days. A full subprocessor list is provided with our data processing agreement on request, and the notification commitments that apply if data is ever exposed are set out in the data processing addendum.