Cevanos

Privacy Policy

What personal data Cevanos handles, why, and on whose instructions. It covers three different groups of people, and which one you are changes what we can do for you — so that is where it starts.

1.Who this covers, and our role for each

Data protection law turns on who decides why data is processed. We are in a different position for each group below, so find yourself here first.

If you are…Our roleWhat that means
A visitor to cevanos.aiControllerWe decide what this site collects. Ask us directly.
A member of a Cevanos workspaceControllerYour account, billing and support records are ours to answer for. Ask us directly.
Someone who messaged a Cevanos-powered agentProcessorThe business running that agent decides what is collected and kept. Ask them; we act on their instructions and will pass your request on.

If you found us because a company you buy from uses Cevanos for support, that company is who your rights run against. We will help them answer you, and we will not act on your data without their instruction — including deleting it. Where our customer is itself a processor acting for someone else, we act as their sub-processor on the same terms.

2.What we collect

2.1From this website

What you submit to a sign-up, contact or demo form — name, work email, company, and anything you write in a message field. Plus technical data: IP address, browser and device type, referring page and pages viewed, used for security, aggregate analytics and keeping the site working.

2.2From workspace members

  • Account data. Name, work email, password hash or identity-provider identifier, role, workspace membership.
  • Workspace settings. Region, timezone, currency, and the configuration you create — agents, policies, ceilings, approval rules, connected integrations.
  • Billing data. Plan, subscription status, invoices, payment history. Card numbers are held by our payment processor and never enter Cevanos.
  • Usage data. Features used, credit and decision consumption, error and performance telemetry, and the audit trail of privileged actions such as changing a spend ceiling.
  • Support data. What you send us when you ask for help, and our replies.

2.3From the agents you run

  • Knowledge sources. Website crawls, uploaded documents and connected content you designate as a source. Personal data in those files is in the agent’s knowledge.
  • Conversations. Messages between your customers and your agent across chat, email, WhatsApp, social and voice, including attachments, call audio and transcripts.
  • Data from connected systems. What the agent reads on your behalf — an order, a shipment, a subscription, an account record — through the credentials and scopes you granted.
  • Decision records. What the agent did or refused to do, under which policy, on what facts, with what spend, and whether it could be reversed.

We do not ask for special-category data and the service is not offered for it by default. Do not put health, biometric, government-identifier or financial-account data into a workspace unless we have agreed to it in writing.

2.4Cookies

  • Essential cookies keep you signed in, hold your session and protect against cross-site request forgery. The site does not work without them.
  • Preference cookies remember choices such as theme.
  • Analytics cookies tell us in aggregate which pages are read and where things break. Set only where you have consented, if consent is required where you are.
  • Advertising cookies are not used. We run no third-party ad trackers on this site.

You can clear or block cookies in your browser; blocking the essential ones will sign you out. The chat widget you embed on your own site sets what it needs to hold a conversation — telling your visitors about that, in your own privacy notice, is part of running the agent.

3.Why we process it

PurposeLegal basis (UK/EU GDPR)
Running agents — answering, acting, recording decisionsContract; for end-user data, our customer’s instructions as processor
Accounts, authentication and workspace accessContract
Billing, invoicing, tax and collectionsContract; legal obligation
Support, service notices and operational emailContract; legitimate interests in running the service
Security, abuse prevention, rate limiting and audit loggingLegitimate interests in protecting the service and its users
Product analytics and reliability, aggregated or de-identifiedLegitimate interests in improving the service
Marketing email to business contactsConsent where required, otherwise legitimate interests — with an unsubscribe link in every message
Legal, tax and regulatory obligations, and defending claimsLegal obligation; legitimate interests

We do not use workspace content for automated decision-making about the individuals in it. The agent’s decisions are about transactions — a refund, a return, an account change — under policies our customer wrote, and our customer answers for those under their own privacy notice.

4.AI models and your content

Running an agent means sending relevant content — the question, the matched knowledge, the conversation so far, the facts fetched from your systems — to a large language model. Some of those models are third-party, and that is a processing step worth being explicit about.

  • We do not train our own general-purpose models on your workspace content.
  • Model providers act as sub-processors under contract with us, to produce the output your agent needs and for nothing else.
  • Provider retention and training terms are documented on request. We publish a written statement of the terms applying to your workspace rather than a summary here, because a summary goes stale. Ask privacy@cevanos.ai.
  • You can reduce what is sent. Scope your knowledge sources and narrow the integration permissions you grant, and the agent has less to send.

If a zero-retention or no-training commitment is a condition of your buying decision, ask for it in writing before you sign. We would rather answer that with a document than with a sentence on a web page.

5.Who we share it with

We do not sell personal data and we do not share it for cross-context behavioural advertising. We disclose it in four situations only.

5.1Sub-processors

Service providers who process data on our behalf, under contract, for purposes we set. By category: cloud hosting and infrastructure; AI model providers; payment processing; email and messaging delivery; voice and telephony infrastructure; error, performance and product analytics; and customer support tooling.

The current named list, with locations and safeguards, is available on request as part of a data processing agreement — write to privacy@cevanos.ai. We give workspace owners at least 14 days’ notice before a new sub-processor starts handling customer data, and you may object in that window on reasonable data-protection grounds; if we cannot resolve the objection you may terminate the affected part of the service and we refund the unused, prepaid part of the period. Every sub-processor is under a written contract binding it to at least the protections in this policy, and we stay responsible to you for what it does.

5.2Systems you connect

When you connect a store, a helpdesk, a payment system or a messaging channel, data moves between Cevanos and that system because you told it to. Those providers are not our sub-processors — they are yours, under your agreement with them, and their privacy policy governs what they do with it.

5.3Legal, safety and corporate transactions

Where we are legally required to, or where disclosure is genuinely necessary to investigate fraud or a security incident or to defend legal claims. We check that a request is valid, give it the narrowest reading we can, and tell the affected customer unless prohibited. If we are involved in a merger or sale of assets, data may transfer as part of it; the buyer stays bound by this policy and you will be told before anything material changes.

6.International transfers

Our infrastructure and sub-processors are not all in one country, so personal data may be processed outside the country you are in, including outside the UK and EEA. Where it is, we rely on an adequacy decision where one applies, and otherwise on Standard Contractual Clauses or the UK equivalent, with the additional measures those clauses require us to assess.

Data residency for a specific region is confirmed per workspace rather than promised here, because what can be offered depends on the region and the sub-processors involved. Ask which regions can be offered for your workspace, and what residency would actually cover, before you rely on it.

7.How long we keep it

DataRetention
Workspace content — sources, conversations, decision recordsWhile the workspace is active, plus the windows below. Shorter periods can be configured where the plan supports it.
Account and workspace recordsWhile the workspace is active, then deleted or anonymised
Invoices and financial recordsAs long as tax and company law require, typically six to seven years
Security and audit logsUp to 12 months, longer where an active investigation needs it
Website analytics and form submissionsUp to 24 months
BackupsAged out on their ordinary rotation after a deletion, rather than edited in place

After termination, Customer Data is available for export for 30 days and is then deleted or irreversibly anonymised within 90 days, except where a legal obligation requires us to keep a record.

8.Security

  • Encryption. Connections encrypted in transit, data encrypted at rest, secrets held in a managed key store.
  • Access control. Roles and permissions scope what each member can reach. Changing a limit or an approval rule is privileged and recorded with who did it and when.
  • Scoped knowledge and actions. Sources are scoped per agent, and each action carries the permissions, limits and approval requirements you assign.
  • Decision records. Every decision and refusal is recorded and reviewable in the console.
  • Least privilege internally. Staff access to customer environments is limited to what a task needs, and logged.

What we will not claim: we do not publish an audit or certification status here, and will not state one until an assessor’s report supports it. Ask for the current status in writing and you will get an accurate answer rather than a badge.

No system is perfectly secure. If you believe you have found a vulnerability, or that an account is compromised, write to security@cevanos.ai. Where a breach affecting personal data occurs, we notify affected customers and regulators within the timeframes the law requires.

9.Your rights

Depending on where you are, you have some or all of these rights over personal data we hold about you as controller: access, correction, deletion where no legal obligation requires us to keep it, portability, objection to processing based on legitimate interests, restriction while a dispute is resolved, withdrawal of consent at any time, and marketing opt-out. Exercising any of them never changes the price or quality of the service you receive.

Write to privacy@cevanos.ai. We answer within 30 days and will tell you if a request is genuinely complex enough to need longer. We may need to verify your identity first, which is a protection for you rather than an obstacle.

If you talked to an agent run by one of our customers, send your request to that business — we are their processor, and we will forward anything that reaches us and help them answer it. You can also complain to your data protection authority: in the UK the Information Commissioner’s Office, in the EEA your national authority. We would rather you came to us first, and we will not hold it against you either way.

Children. Cevanos is a business product. It is not directed at children, we do not knowingly collect data from anyone under 13, and workspaces must not be configured to process it. If you believe a child’s data has reached us, write to privacy@cevanos.ai and we will delete it.

10.Changes and contact

We update this policy as the product and the law change; the date at the top always reflects the current version. Where a change materially affects how we handle personal data, we give at least 30 days’ notice by email to workspace owners or in the product before it takes effect.

Privacy questions, data requests and data processing agreements: privacy@cevanos.ai. Security reports: security@cevanos.ai.

Cevanos (legal entity name to be confirmed), Registered office address to be confirmed. See also the Terms of Service and the Refund Policy.