Privacy policy.
Effective: 18 July 2026
Last updated: 18 July 2026
This policy explains how Eraivo processes personal data when you visit our website, communicate with us, or use our products, dashboards, APIs, SDKs, and related services.
Scope and controller
This policy applies to personal data processed by Eraivo in connection with the services described above. It does not govern independent third parties, protocols, wallets, networks, or websites that publish their own privacy notices.
Eraivo is the controller for website, business-contact, and account-administration data it determines how to use. When an organization uses Eraivo to process data in its own workflow, that organization may be the controller and Eraivo may act as its processor under the applicable agreement.
Data we process
Depending on how you interact with Eraivo, we may process:
- Account and contact data: name, work email, organization, role, account identifiers, and communication preferences.
- Authentication data: wallet addresses, signed authentication messages, session identifiers, access logs, and security events.
- Product and workflow data: agent and operator identifiers, intents, policies, approval records, transaction references, evidence metadata, webhook configuration, and support material you submit.
- Technical data: IP address, device and browser information, timestamps, request identifiers, diagnostic logs, and usage events.
- Business communications: messages, meeting notes, product feedback, billing contacts, and records needed to manage a relationship.
- Public blockchain data: addresses, transactions, contract events, balances, and other information available from public networks.
Please do not submit sensitive personal data in transaction memos, evidence URIs, webhook payloads, or other fields unless it is necessary and your organization has established a lawful basis and appropriate safeguards.
Where data comes from
We receive data directly from you or your organization, automatically from your use of the services, from systems you connect to Eraivo, and from public blockchain networks.
We may also receive business-contact or security information from service providers, integration partners, event organizers, public sources, and people who refer you to us.
How we use data
We process personal data to:
- provide, maintain, and secure the services;
- authenticate users and administer accounts;
- process intents, policies, approvals, and workflow records;
- deliver support and respond to enquiries;
- monitor reliability, prevent abuse, and investigate incidents;
- improve product performance and usability;
- manage billing, contracts, and business relationships;
- meet legal obligations and enforce our agreements.
We do not sell personal data. We do not use personal data for third-party cross-context behavioural advertising.
Legal bases
Where the GDPR, UK GDPR, or similar law applies, our legal basis depends on the context. We may process data to perform a contract or take steps at your request, comply with law, pursue legitimate interests such as service security and product improvement, or act on your consent where consent is required.
When we rely on legitimate interests, we consider the purpose, necessity, and impact on the people concerned. You may object to this processing as described below.
Public blockchain data
Public blockchains are designed to be transparent and persistent. Transactions may reveal wallet addresses, assets, amounts, timestamps, contract interactions, and other metadata to anyone. Eraivo cannot erase or change information that has been written to a public blockchain.
Avoid placing names, email addresses, documents, secrets, or other personal data directly on-chain. Where a workflow needs evidence, use an appropriate off-chain storage and access-control design and place only the minimum necessary reference or hash on-chain.
Retention
We retain personal data only as long as reasonably necessary for the purpose for which it was collected, including service delivery, security, dispute resolution, audit, accounting, and legal obligations. The period depends on the data type, account status, contractual requirements, risk of harm, and applicable law.
We may delete, aggregate, or de-identify data when it is no longer needed. Backup copies may remain for a limited period until they are overwritten. Public blockchain records remain subject to the network’s design rather than Eraivo’s deletion process.
Security
We use administrative, technical, and organizational safeguards intended to protect personal data, including access controls, authentication, encryption where appropriate, logging, dependency and vulnerability management, and incident-response procedures.
No system can guarantee absolute security. You are responsible for protecting your credentials, wallet keys, integration secrets, devices, and the access you grant to your agents and users.
International transfers
Eraivo and its service providers may process data in countries other than the one where you live. Where law requires, we use an approved transfer mechanism, such as adequacy decisions or contractual safeguards, and apply supplementary measures as appropriate.
Your choices and rights
Depending on your location and the context, you may have the right to request access, correction, deletion, restriction, portability, or an objection to certain processing. You may withdraw consent without affecting processing that was lawful before withdrawal.
Send a request to privacy@eraivo.com. We may need to verify your identity and authority. If Eraivo processes the data on behalf of your organization, we may direct the request to that organization. You may also complain to the data-protection authority in your country.
Children
Eraivo is a business and developer service not directed to children. You must be at least 18, or the age of legal majority where you live, to create an account. If you believe a child has provided personal data to us, contact us so we can investigate.
Changes to this policy
We may update this policy as our services, providers, or legal obligations change. We will post the revised version here and change the “last updated” date. If a change materially affects your rights, we will provide additional notice when required.
Contact
Questions or requests about privacy can be sent to privacy@eraivo.com. Security reports should be sent separately to security@eraivo.com.