Privacy Policy
This policy explains how BIVANEX ("BIVANEX", "we", "us") handles information when an organization or an authorized user uses our business operations, inspection and automation services, including BIVANEX Inspect and Hermes.
1. Information we handle
- Account and organization data: name, business contact details, tenant membership, roles, authentication and security events.
- Operational and inspection data: customer, site and equipment references; inspection identifiers; notes; photos; documents; findings; drafts; approvals and audit history supplied by authorized users.
- Connected-service data: authorization metadata, provider identifiers and tokens needed to operate a connection. Tokens are not displayed to end users and are protected in server-side storage.
- Google Workspace data: only the files a user explicitly selects, opens or creates for BIVANEX under the Google Drive
drive.filepermission, together with the minimum metadata and content needed for the user-requested workflow. - WhatsApp Business data: messages, message and delivery identifiers, sender/business identifiers, timestamps and media sent to a BIVANEX-managed business number, when that channel is enabled for the relevant tenant.
- Technical data: device/browser information, IP-derived security information, request logs, error data and service telemetry used for security and reliability.
2. How we use information
We use information to authenticate users; provide tenant-scoped business and inspection workflows; resolve authorized records; process user-selected documents; route messages and evidence; prepare drafts; support human review; maintain auditability; prevent abuse; troubleshoot; and meet contractual or legal obligations.
Automation and AI-assisted features support the user-requested workflow. They do not grant professional authority and do not make final inspection, certification or safety decisions.
3. Google API data and Limited Use
BIVANEX requests the narrowest Google permissions needed for a feature. Drive access uses drive.file; BIVANEX does not scan a user’s entire Drive through that permission. Google user data is used only to provide or improve prominent user-facing features requested by the user.
BIVANEX’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, use it for advertising, use it to determine creditworthiness, or use it to train shared or generalized AI/ML models.
4. Sharing and service providers
We do not sell personal information. We may disclose information to the customer organization that controls the relevant tenant; to authorized users within that tenant; to infrastructure, security, communication and AI service providers acting for BIVANEX; or when required by law, security or the protection of rights. Providers receive only the information needed for their contracted function.
5. Tenant isolation and security
BIVANEX uses tenant-scoped authorization, least-privilege connections, access controls, transport encryption, protected credential storage, audit records and operational monitoring. No system is completely secure; users must protect credentials and promptly report suspected misuse.
6. Retention and deletion
We retain data only for as long as needed to deliver the contracted service, follow the customer’s instructions, secure the service, resolve disputes and meet legal obligations. Retention can vary by data type and customer agreement. Backups are removed through their normal rotation. When a connection is removed, we stop new access and revoke or delete stored connection credentials where supported.
Users can request access, correction or deletion as described on our Data Deletion page. Some records may be retained where required for legal, security, fraud-prevention or contractual audit purposes.
7. Choices and disconnection
Authorized users can remove supported connections in BIVANEX and can revoke provider access directly in Google or Meta account settings. Revocation stops future access but does not automatically delete information already processed for a legitimate workflow; submit a deletion request for that step.
8. International processing and children
Service providers may process data in countries other than the user’s country, subject to contractual and technical safeguards. BIVANEX is a business service and is not directed to children.
9. Changes and contact
We may update this policy when services or legal requirements change. Material changes will be presented through an appropriate notice. Privacy and data requests may be sent to benyamin@bivanex.com.