LEGAL • PRIVACY & DATA GOVERNANCE
POLICY CORE
Privacy Policy

Privacy, data protection, and human-governed AI.

This Privacy Policy explains how innovAIT SE, LLC collects, uses, protects, retains, and discloses information across its websites, applications, platforms, AI-enabled services, professional services, and related systems.

Effective: June 16, 2025 Last Updated: August 27, 2026
Overview

Plain-English commitments

These commitments summarize our operating posture. The detailed sections below govern how those commitments are applied.

No sale of personal information.

innovAIT does not sell personal information or customer confidential information.

No cross-context behavioral advertising.

We do not disclose personal information for third-party cross-context behavioral advertising.

Customer data is not a general-purpose training pool.

We do not use customer confidential information or identifiable customer content to train general-purpose models for unrelated customers without explicit authorization.

Human governance remains part of consequential operations.

Access, automation, and AI-enabled actions are designed around scoped authority, accountability, and human review where consequences warrant it.

1 • Scope

Where this policy applies

This Privacy Policy applies to innovAIT SE, LLC websites, applications, platforms, AI-enabled products, professional services, support channels, and related backend systems that reference or link to this policy.

Contract-specific, regulated, government, enterprise, or white-label services may include additional privacy, security, retention, or data-handling terms. Where a written agreement imposes stronger protections, those stronger terms control.

2 • Data

Information we collect

Account & contact information

Name, email address, organization, account identifiers, support communications, notification preferences, and related account information.

Service & transaction information

Subscription or service records, billing status, entitlement information, and payment-related metadata. Payment card details are handled by authorized payment processors rather than stored as full card numbers by innovAIT.

Customer-provided content

Information, documents, images, audio, video, measurements, descriptions, operational inputs, or other materials intentionally submitted for analysis, valuation, diagnostics, research, or service delivery.

Security & technical information

IP address, user agent, device/browser information, authentication events, request metadata, error information, and security/audit events used to protect systems, investigate abuse, and maintain service integrity.

3 • Use

How we use information

  • Provide, operate, maintain, secure, and improve innovAIT services.
  • Authenticate users and enforce access, entitlement, and authorization rules.
  • Generate requested analyses, valuations, diagnostics, reports, and other service outputs.
  • Detect fraud, abuse, unauthorized access, anomalous behavior, and security threats.
  • Provide support, service notices, operational communications, and account administration.
  • Meet legal, contractual, audit, compliance, and recordkeeping obligations.
  • Improve system quality using data that has been appropriately minimized, de-identified, aggregated, or otherwise governed for the applicable use case.
4 • AI Governance

AI and model data governance

Capability does not automatically equal authority.

innovAIT designs AI-enabled systems around bounded access, scoped permissions, auditable activity, defined operational limits, and human governance for consequential actions.

Customer confidential information and identifiable customer content are used to perform the service requested and for other purposes authorized by the customer, contract, or applicable law.

innovAIT does not treat customer confidential information as an unrestricted general-purpose training corpus. Where de-identified or aggregated data is used to improve a product or service, controls are applied to reduce linkage to an identifiable individual or customer.

Intellectual-property ownership, licensing, report rights, and commercial-use restrictions are governed by the applicable Terms of Use, order form, statement of work, license, or other written agreement—not by this Privacy Policy.

5 • Protection

Security and protective measures

Security is treated as an operating requirement. Protective measures are layered so that compromise of a single control does not automatically provide unrestricted access to systems or data.

Access control

Access is limited by role, entitlement, and operational need. Sensitive functions are subject to additional authorization and logging.

Authentication & session controls

Authentication protections, session controls, and account-security measures are used to reduce unauthorized access and credential misuse.

Encryption

Encrypted transport is used for data in transit. Sensitive stored information is protected using platform and infrastructure controls appropriate to the data.

Network & application boundaries

Public exposure is minimized, privileged interfaces are restricted, and application services are segmented or scoped according to operational purpose.

Auditability & monitoring

Security-relevant events are logged and reviewed to support anomaly detection, investigation, accountability, incident response, and compliance.

Backups & resilience

Backup and recovery controls are maintained to support restoration, continuity, and protection against destructive events. Recovery procedures are periodically reviewed.

Data minimization

innovAIT seeks to limit collection, access, retention, and disclosure to what is reasonably necessary for the authorized purpose.

Human governance

Consequential actions are not intended to rely solely on model capability. Human authorization, interruption, denial, and review remain available where appropriate.

No security architecture can guarantee absolute security.

innovAIT continuously evaluates controls, reduces unnecessary attack surface, and updates safeguards as systems, threats, and operational requirements evolve.

6 • Disclosure

Sharing and disclosure

innovAIT does not sell personal information.

Information may be disclosed only when reasonably necessary to:

  • Use infrastructure, hosting, payment, communications, security, or support providers acting on our behalf.
  • Comply with valid legal process, law, regulation, or enforceable governmental request.
  • Protect users, innovAIT, systems, property, rights, safety, or service integrity.
  • Complete an authorized corporate transaction subject to appropriate confidentiality and legal safeguards.
  • Perform cross-service functionality requested or authorized by the customer.

Service providers are expected to process information only for authorized purposes and subject to appropriate confidentiality, security, and contractual restrictions.

7 • Retention

Retention and deletion

Information is retained only for as long as reasonably necessary for service delivery, customer access, security, fraud prevention, dispute resolution, legal obligations, backup integrity, and other legitimate operational purposes.

Retention periods may vary by data category, service, contract, regulatory requirement, or security need. De-identified or aggregated information that no longer reasonably identifies an individual may be retained for legitimate analytical or system-improvement purposes.

8 • Rights

Your privacy rights

Depending on applicable law and jurisdiction, you may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or information about certain disclosures or processing activities.

Requests are subject to identity verification, legal exceptions, security requirements, and obligations that may require innovAIT to retain particular records.

9 • Children

Children’s privacy

innovAIT services are not directed to children under 13, or a higher minimum age where required by applicable law. We do not knowingly collect personal information from children in violation of applicable law.

10 • Processing

International processing

Information may be processed in the United States or other locations where innovAIT or authorized service providers operate. Where required, appropriate contractual, organizational, or legal safeguards are used for cross-border processing.

11 • Response

Security incidents

Suspected security events are evaluated according to their nature and potential impact. innovAIT may contain affected systems, preserve evidence, restrict access, rotate credentials, investigate activity, restore from protected backups, notify affected parties, and coordinate with customers, service providers, insurers, regulators, or law enforcement where appropriate.

12 • Updates

Changes to this policy

This policy may be updated as services, laws, security practices, or operational requirements change. Material changes will be reflected by an updated revision date and additional notice where required.

13 • Contact

Privacy and security inquiries

For privacy requests, data-governance questions, or concerns regarding this policy, contact innovAIT at:

contact@getinnovait.com