Privacy Policy
Last updated: August 27, 2026
This Privacy Policy explains how [Legal entity name]("Receviona," "we," "us") collects, uses, and protects personal data in connection with the Receviona platform (the "Service"). It covers two kinds of personal data: data about the people who use Receviona on behalf of a customer organization, and personal data that may appear within the accounts receivable data (customer contacts, invoices, payments) that a customer uploads or connects to the Service.
1. Who we are
For data protection purposes, [Legal entity name], registered at [registered address], acts as the data controller for account and billing information, and as a data processor acting on the instructions of the customer organization for the receivables data (including any personal data of debtor contacts) that organization uploads to the Service.
2. Data we collect
We collect:
- Account data — name, work email, and organization, provided when you sign up or are invited to a workspace;
- Receivables data — customer records, invoices, payments, and related contact details that your organization imports or enters into the Service;
- Usage and log data — sign-in timestamps, IP address, and actions taken in the product, recorded for security and in the audit log described below;
- Support data — anything you send us when you contact support.
We do not collect payment-card or bank-account credentials directly; billing is handled by a third-party payment processor.
3. How we use data
We use this data to:
- Provide the Service — compute aging, risk scores, and collection priority, and generate draft recommendations and communications for your review;
- Secure the Service — authenticate users, enforce role-based permissions, and maintain the audit log;
- Communicate with you about your account, and, where you have agreed to receive them, product updates;
- Improve the Service, using aggregated or de-identified data wherever practical.
We do not use one customer's receivables data to train models shared with other customers, and every organization's data is isolated from every other organization's at the data layer.
4. AI processing
Some product features (risk explanations, collection recommendations, draft communications) send relevant account data to an AI model provider to generate a response, which is then shown to you for review — never sent or acted on automatically. Financial totals, aging, and scores are always computed by deterministic application code, not by the AI model, and are not derived from or altered by AI output.
5. Sharing and sub-processors
We share personal data with the infrastructure, database, email-delivery, and AI-model providers that operate the Service on our behalf, each bound by a data-processing agreement, and never sell personal data. We may disclose data if required by law or to protect the rights, safety, or property of Receviona or others.
6. Data retention
We retain account and receivables data for as long as your organization maintains an active subscription, plus a reasonable period after termination to allow data export, then delete it unless a longer period is required by law or by an unresolved dispute. Audit log entries are retained separately for security and compliance purposes.
7. Security
Data is encrypted in transit and at rest. Access within the product is governed by role-based permissions scoped to your organization, every tenant-owned record is isolated to its own organization, and security-relevant actions are recorded in an append-only audit log. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
8. International transfers
Where personal data is transferred across borders, we rely on [transfer mechanism, e.g. Standard Contractual Clauses] or another legally recognized safeguard.
9. Your rights
Depending on where you are located, you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing. Account users should direct these requests to their organization's administrator, who controls the underlying data; organizations and administrators can contact us directly at [privacy contact email].
10. Cookies
The Service uses a single session cookie required to keep you signed in. We do not use third-party advertising or tracking cookies within the product.
11. Children
The Service is intended for business use and is not directed at children.
12. Changes to this policy
We may update this Privacy Policy from time to time. For material changes, we will provide notice before the change takes effect.
13. Contact
Questions about this policy or requests concerning your personal data can be sent to [privacy contact email].
This page is a template describing how the Service is designed to handle data and does not constitute legal advice. It should be reviewed by qualified counsel, with the bracketed details completed, before being relied on as a binding policy.