Legal

Privacy policy.

Effective: 18 July 2026

Last updated: 18 July 2026

This policy explains how Eraivo processes personal data when you visit our website, communicate with us, or use our products, dashboards, APIs, SDKs, and related services.

01

Scope and controller

This policy applies to personal data processed by Eraivo in connection with the services described above. It does not govern independent third parties, protocols, wallets, networks, or websites that publish their own privacy notices.

Eraivo is the controller for website, business-contact, and account-administration data it determines how to use. When an organization uses Eraivo to process data in its own workflow, that organization may be the controller and Eraivo may act as its processor under the applicable agreement.

02

Data we process

Depending on how you interact with Eraivo, we may process:

  • Account and contact data: name, work email, organization, role, account identifiers, and communication preferences.
  • Authentication data: wallet addresses, signed authentication messages, session identifiers, access logs, and security events.
  • Product and workflow data: agent and operator identifiers, intents, policies, approval records, transaction references, evidence metadata, webhook configuration, and support material you submit.
  • Technical data: IP address, device and browser information, timestamps, request identifiers, diagnostic logs, and usage events.
  • Business communications: messages, meeting notes, product feedback, billing contacts, and records needed to manage a relationship.
  • Public blockchain data: addresses, transactions, contract events, balances, and other information available from public networks.

Please do not submit sensitive personal data in transaction memos, evidence URIs, webhook payloads, or other fields unless it is necessary and your organization has established a lawful basis and appropriate safeguards.

03

Where data comes from

We receive data directly from you or your organization, automatically from your use of the services, from systems you connect to Eraivo, and from public blockchain networks.

We may also receive business-contact or security information from service providers, integration partners, event organizers, public sources, and people who refer you to us.

04

How we use data

We process personal data to:

  • provide, maintain, and secure the services;
  • authenticate users and administer accounts;
  • process intents, policies, approvals, and workflow records;
  • deliver support and respond to enquiries;
  • monitor reliability, prevent abuse, and investigate incidents;
  • improve product performance and usability;
  • manage billing, contracts, and business relationships;
  • meet legal obligations and enforce our agreements.

We do not sell personal data. We do not use personal data for third-party cross-context behavioural advertising.

06

How we share data

We may disclose personal data to:

  • vendors that provide hosting, storage, monitoring, authentication, communications, analytics, security, customer support, and professional services;
  • blockchain networks, RPC providers, wallet or signing providers, and other rails required to carry out an action you or your organization requested;
  • your organization, its authorized administrators, and counterparties included in a workflow;
  • authorities or other parties when required by law, needed to protect rights and safety, or necessary to investigate fraud or security incidents; and
  • a successor or adviser in connection with financing, due diligence, reorganization, merger, acquisition, or sale, subject to appropriate safeguards.

Service providers may process data only for the contracted purpose and under confidentiality and data-protection obligations appropriate to their role.

07

Public blockchain data

Public blockchains are designed to be transparent and persistent. Transactions may reveal wallet addresses, assets, amounts, timestamps, contract interactions, and other metadata to anyone. Eraivo cannot erase or change information that has been written to a public blockchain.

Avoid placing names, email addresses, documents, secrets, or other personal data directly on-chain. Where a workflow needs evidence, use an appropriate off-chain storage and access-control design and place only the minimum necessary reference or hash on-chain.

08

Retention

We retain personal data only as long as reasonably necessary for the purpose for which it was collected, including service delivery, security, dispute resolution, audit, accounting, and legal obligations. The period depends on the data type, account status, contractual requirements, risk of harm, and applicable law.

We may delete, aggregate, or de-identify data when it is no longer needed. Backup copies may remain for a limited period until they are overwritten. Public blockchain records remain subject to the network’s design rather than Eraivo’s deletion process.

09

Security

We use administrative, technical, and organizational safeguards intended to protect personal data, including access controls, authentication, encryption where appropriate, logging, dependency and vulnerability management, and incident-response procedures.

No system can guarantee absolute security. You are responsible for protecting your credentials, wallet keys, integration secrets, devices, and the access you grant to your agents and users.

10

International transfers

Eraivo and its service providers may process data in countries other than the one where you live. Where law requires, we use an approved transfer mechanism, such as adequacy decisions or contractual safeguards, and apply supplementary measures as appropriate.

11

Your choices and rights

Depending on your location and the context, you may have the right to request access, correction, deletion, restriction, portability, or an objection to certain processing. You may withdraw consent without affecting processing that was lawful before withdrawal.

Send a request to privacy@eraivo.com. We may need to verify your identity and authority. If Eraivo processes the data on behalf of your organization, we may direct the request to that organization. You may also complain to the data-protection authority in your country.

12

Children

Eraivo is a business and developer service not directed to children. You must be at least 18, or the age of legal majority where you live, to create an account. If you believe a child has provided personal data to us, contact us so we can investigate.

13

Changes to this policy

We may update this policy as our services, providers, or legal obligations change. We will post the revised version here and change the “last updated” date. If a change materially affects your rights, we will provide additional notice when required.

14

Contact

Questions or requests about privacy can be sent to privacy@eraivo.com. Security reports should be sent separately to security@eraivo.com.