Skip to content
TRIVANALABS

Legal

Privacy policy

How Trivana Labs, LLC handles information collected through this website and data processed inside the Trivana platform.

Last updated
Entity
Trivana Labs, LLC, a Massachusetts limited liability company

1Scope

This policy describes how Trivana Labs, LLC (“Trivana,” “we,” “us,” or “our”) handles information in two distinct contexts:

(a) This website. Information you provide when you submit a contact, demo, or newsletter form on trivanalabs.com, and the limited, aggregate analytics we collect about site usage. Sections 2 and 3 cover this.

(b) The Trivana platform. Customer Data that our customers and their Authorized Users submit to or generate through the Services. Sections 4 through 8 cover this, and our handling of that data is governed by our Terms of Service and our Data Processing Addendum (the “DPA”), which is incorporated into those Terms by reference. Where this policy and those documents differ, those documents control.

2Information from this website

2.1 What we collect. When you submit a contact, demo, or newsletter form, you provide us with information such as your name, work email, company, role, and message. We don’t collect this information from any other source.

2.2 How we use it. Form submissions are emailed to a Trivana Labs inbox so a team member can respond. We do not sell, rent, or share this information with third parties. We don’t persist it to a separate database - it lives in our email system only.

2.3 Email confirmations. When you request a demo, we send a confirmation email to the address you provide. You will not be added to any marketing list without your consent.

2.4 Newsletter. If you subscribe to occasional product updates, you can unsubscribe at any time by replying to any email we send you.

3Cookies and analytics

3.1 Analytics. We use a privacy-respecting analytics service (Plausible) that does not use cookies and does not track individuals across sites. We do not use advertising cookies. The only cookies we set are those that may be required for routing or session continuity in your browser.

3.2 Bot protection. We may use Cloudflare Turnstile on forms to distinguish legitimate submissions from automated abuse. Turnstile is used for security and spam prevention, not advertising or cross-site tracking.

4Customer data in the platform

4.1 Definition. “Customer Data” means any data, files, financial information, business information, or other content that a customer or its Authorized Users submit to or generate through the Services.

4.2 Ownership and use. As between the parties, the customer owns and retains all right, title, and interest in and to Customer Data. The customer grants Trivana a non-exclusive, worldwide, royalty-free license to host, copy, transmit, display, and process Customer Data solely as necessary to provide, maintain, support, and secure the Services and as otherwise permitted by the Terms and the DPA.

4.3 Customer responsibilities. Customers are responsible for the accuracy, quality, and legality of Customer Data; the means by which they acquired it; obtaining all necessary rights, consents, and authorizations to provide it to us; and their Authorized Users’ compliance with the Terms.

4.4 Data Processing Addendum. Our processing of Customer Data is further governed by the DPA, which includes our commitments regarding security, breach notification, subprocessors, and data return and deletion. Customers and prospective customers can request a copy at legal@trivanalabs.com.

5Security and subprocessors

5.1 Safeguards. We maintain a written, risk-based security program with appropriate administrative, technical, and physical safeguards designed to protect the security, confidentiality, and integrity of Customer Data, as described in the DPA. All website form submissions are transmitted over HTTPS.

5.2 Subprocessors. We use subprocessors to provide the Services, currently Railway (application hosting), Amazon Web Services (cloud hosting, where used for a deployment), and OpenAI and Anthropic (AI features, when enabled). The DPA lists them with their purposes and location limits, and the current list is available on request. Provider certifications and attestations cover only the provider’s own services; we do not represent that Trivana itself holds SOC 2, ISO, or similar certifications.

5.3 Confidentiality. Customer Data is treated as the customer’s Confidential Information under Section 6 of our Terms of Service.

6Aggregated data and AI training

6.1 AI and model training. We do not use Customer Data, customer Confidential Information, or de-identified copies derived from Customer Data to train artificial intelligence or machine learning models, and we do not opt that data into any AI provider’s model-improvement, feedback-sharing, or training program. Any exception requires a separate signed amendment. Ordinary use of AI features, including inference, retrieval, and related retention, is governed by the DPA.

6.2 Aggregated data. We may use properly aggregated or de-identified information about the operation, support, and use of the Services (“Aggregated Data”) to operate, secure, and improve the Services and our business, provided that Aggregated Data does not identify a customer, its Authorized Users, or any individual, and meets applicable legal de-identification requirements. We will take reasonable measures against re-identification, will not sell or license Aggregated Data as a standalone product, and will not use de-identified copies of Customer Data to train AI models.

7Retention and deletion

7.1 Website inquiries. We retain information submitted through this site for as long as needed to respond to your inquiry and for a reasonable period thereafter, consistent with our records-management practices. You can request deletion of your information at any time by emailing legal@trivanalabs.com.

7.2 Customer Data. Return and deletion of Customer Data following termination of a subscription is governed by the DPA.

8Where we operate

The Services are intended for US business customers and Authorized Users located in the United States. We store primary application data in a US region. Some processing, such as AI inference by our AI providers, support access, logs, and backups, may take place in other disclosed provider locations, as described in the DPA. Customers shall not access or use the Services from outside the United States without our prior written consent.

9Your choices

9.1 Website information. You may request access to, correction of, or deletion of information you submitted through this site by emailing legal@trivanalabs.com.

9.2 Platform data. Where Trivana processes Customer Data on a customer’s behalf, requests from that customer’s Authorized Users should be directed to the customer, who controls that data. We will support our customers in responding to such requests as described in the DPA.

10Changes to this policy

We may update this policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. Material changes to our Terms of Service are subject to the notice requirements in Section 13.7 of those Terms.

Running a security or procurement review? Email legal@trivanalabs.com for the current DPA and security documentation, or get in touch.