Roviean ("Roviean," "we," "us," or "our") respects your privacy and is committed to protecting personal information. This Privacy Policy ("Policy") explains how we collect, use, disclose, retain, and safeguard information when you visit https://roviean.com, use our websites, applications, portals, APIs, or engage our AI, SaaS, software development, automation, consulting, web development, mobile application, and digital transformation services (collectively, the "Services").
This Policy applies to visitors, prospective clients, clients, authorized users, and other individuals who interact with Roviean worldwide. It should be read together with our Terms of Service, Cookie Policy, AI Disclaimer, and any executed data processing agreement or statement of work.
By accessing or using the Services, you acknowledge that you have read this Policy. Where required by law, we will obtain your consent before processing personal information for specific purposes.
1. Scope of Policy
This Policy describes Roviean's practices when we act as a data controller — for example, when you submit an inquiry, place an order, create an account on our platforms, or communicate with us directly.
When we process personal data solely on behalf of a business client, we generally act as a data processor and the client remains the controller. In those cases, the client's privacy notice and data processing agreement govern, and this Policy applies only to the extent we determine purposes and means of processing.
This Policy does not apply to third-party websites, applications, or services linked from our Services. Those providers process information under their own privacy policies.
2. Information We Collect
We collect information in three broad ways: (a) information you provide directly; (b) information collected automatically through your use of the Services; and (c) information we receive from third parties such as service providers, payment processors, or publicly available sources where permitted by law.
The categories of information we collect depend on how you interact with Roviean and which Services you use.
3. Information Provided by Users
You may provide us with:
- Identity and contact information (name, email address, telephone number, company name, job title, postal address);
- Account and authentication information (username, password, security questions, access credentials);
- Project and order information (briefs, specifications, messages, files, designs, technical requirements);
- Billing and commercial information (billing contact, purchase order references, tax identifiers where applicable);
- Communications (emails, support tickets, meeting notes, feedback, survey responses);
- Recruitment information if you apply for roles with Roviean;
- Any other information you choose to submit through forms, portals, or direct correspondence.
4. Automatically Collected Information
When you access the Services, we and our service providers may automatically collect technical and usage information through cookies, pixels, server logs, SDKs, and similar technologies.
This may include information about how you navigate pages, interact with features, respond to communications, and use AI-enabled tools made available through our platforms.
5. Device Information
We may collect device-related information such as device type, operating system, browser type and version, language settings, screen resolution, mobile network information, and unique device or advertising identifiers where permitted by law and your device settings.
6. Log Data
Our servers and infrastructure providers may automatically record log data, including IP address, access timestamps, referring URLs, pages viewed, crash reports, diagnostic data, and security event information.
We use log data to operate, secure, troubleshoot, and improve the Services.
8. Analytics Technologies
We may use analytics tools to understand traffic, usage patterns, feature adoption, and service performance. Analytics providers may collect pseudonymous identifiers, event data, and technical information.
We configure analytics to minimize unnecessary collection where practicable and use analytics for legitimate business purposes such as security, product improvement, and measuring engagement.
9. Marketing Technologies
Where permitted by law and, where required, with your consent, we may use marketing pixels, campaign tracking, and similar technologies to measure advertising effectiveness and deliver relevant communications.
You may opt out of marketing communications as described in Section 31 (Marketing Preferences).
10. Use of Information
We use personal information to:
- Provide, operate, maintain, and deliver the Services;
- Respond to inquiries, orders, proposals, and support requests;
- Create and administer accounts, projects, and client engagements;
- Process payments, invoices, and contractual obligations;
- Communicate about Services, updates, security notices, and administrative matters;
- Improve, test, monitor, and develop our websites, products, and AI-enabled features;
- Detect, prevent, and investigate fraud, abuse, and security incidents;
- Comply with legal obligations and enforce our terms and policies;
- Protect the rights, property, and safety of Roviean, our users, and others.
11. Legal Bases for Processing
Where the EU General Data Protection Regulation ("GDPR"), UK GDPR, or similar laws apply, we process personal data only where we have a valid legal basis.
Depending on context, our legal bases include:
- Contract: processing necessary to perform a contract with you or take steps at your request before entering a contract;
- Legitimate interests: operating, securing, and improving our business, communicating with prospects and clients, and preventing fraud, balanced against your rights;
- Consent: where required for non-essential Cookies, certain marketing communications, or other processing for which consent is the appropriate basis;
- Legal obligation: compliance with applicable laws, regulatory requests, tax, and accounting requirements;
- Vital interests or public interest: only where applicable and permitted by law.
Withdrawal of Consent
Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal. Withdrawal may limit certain features or communications.
12. AI Service Data Processing
Roviean develops and integrates artificial intelligence, machine learning, large language models, automation workflows, and related technologies. You understand that AI systems may process content you submit — including text, files, prompts, and operational data — to provide, improve, secure, and support the Services.
AI processing may involve classification, summarization, generation, retrieval, recommendation, or automated workflow execution. Outputs may be inaccurate or incomplete and must be reviewed by you before reliance, as described in our AI Disclaimer.
Unless otherwise agreed in writing, we do not use Client confidential materials submitted for bespoke project delivery to train public third-party foundation models without explicit consent. We may use de-identified or aggregated insights to improve our internal systems and service quality.
Where AI features rely on third-party model providers, those providers process information under their own terms and privacy policies, as further described in Section 15.
13. Business Purposes for Processing
For purposes of laws such as the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), we collect and process personal information for business and commercial purposes including service delivery, customer support, analytics, security, product development, advertising where permitted, auditing, and compliance.
We do not sell personal information for monetary consideration. We do not share personal information for cross-context behavioral advertising in a manner that constitutes "sharing" under CPRA unless disclosed and, where required, permitted through appropriate choices.
15. Service Providers
We engage trusted third-party service providers to perform functions on our behalf. These providers may process personal information according to our instructions and their own privacy policies, contracts, and security obligations.
Third-party providers may process information in jurisdictions other than your own. We require appropriate contractual protections where required by law.
16. Cloud Infrastructure Providers
We use cloud infrastructure and hosting providers — which may include providers such as Vercel, Supabase, and other reputable platforms — to host websites, applications, databases, files, and operational systems.
These providers may process IP addresses, log data, account metadata, uploaded content, and configuration data necessary to deliver hosting, content delivery, database, storage, and security services.
17. Payment Processors
Payments for software packages and professional services are typically settled via invoice and offline bank transfer or other methods agreed with our sales team. We do not embed a third-party card checkout on this website. Billing contact details and transaction records may be stored to fulfill orders and for accounting.
We do not store full payment card numbers on our own systems where a certified payment processor handles card data. Payment processing is subject to the processor's privacy policy and PCI-DSS obligations.
18. Analytics Providers
We may use analytics providers to measure website and product performance. These providers may set Cookies or collect pseudonymous usage data, event metadata, and technical diagnostics.
Analytics data is used to understand engagement, diagnose errors, improve performance, and enhance user experience.
19. Government and Legal Requests
We may disclose information where we believe disclosure is required or permitted by applicable law, regulation, legal process, subpoena, court order, or governmental request.
We may also disclose information to protect the rights, property, or safety of Roviean, our users, clients, or the public, and to detect, prevent, or address fraud, security, or technical issues, subject to applicable law.
20. Business Transfers
If Roviean is involved in a merger, acquisition, financing, reorganization, insolvency, or sale of assets, personal information may be transferred as part of that transaction subject to standard confidentiality arrangements.
We will provide notice where required by law if your information becomes subject to a materially different privacy practice.
21. International Data Transfers
Roviean serves users and clients worldwide. We may transfer, store, and process personal information in countries other than the country where you reside, including Ireland, the European Economic Area, the United Kingdom, the United States, and other jurisdictions where we or our service providers operate.
Where required by GDPR, UK GDPR, or similar laws, we implement appropriate safeguards such as Standard Contractual Clauses, UK International Data Transfer Agreements, supplementary measures, or reliance on adequacy decisions where applicable.
By using the Services, you understand that your information may be processed internationally subject to this Policy and applicable safeguards.
22. Data Retention
We retain personal information only for as long as reasonably necessary to fulfill the purposes described in this Policy, including providing Services, maintaining business records, resolving disputes, enforcing agreements, and meeting legal, contractual, operational, and regulatory obligations.
Retention periods vary depending on data category, sensitivity, applicable limitation periods, and whether an ongoing client relationship exists. When information is no longer required, we delete, anonymize, or securely isolate it in accordance with our retention practices.
23. Security Measures
We implement commercially reasonable technical and organizational security measures designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure.
These measures may include access controls, encryption in transit for modern deployments, secure development practices, logging and monitoring, vendor review, and incident response procedures.
No method of internet transmission or electronic storage can be guaranteed 100% secure. Accordingly, while we strive to protect your information, we cannot guarantee absolute security.
You are responsible for maintaining the confidentiality of your account credentials, access tokens, API keys, and authentication factors, and for all activities occurring under your account except where caused by our failure to implement reasonable security measures.
24. User Rights
Depending on your location, you may have statutory rights regarding your personal information. Rights may include those listed in Sections 25–30 and California-specific rights in Section 37.
We will not discriminate against you for exercising privacy rights where prohibited by law.
25. Access Rights
You may have the right to request confirmation of whether we process your personal information and to obtain a copy of certain personal information we hold about you, subject to applicable exceptions and verification requirements.
26. Correction Rights
You may have the right to request correction of inaccurate personal information or completion of incomplete information, subject to verification and legal limitations.
27. Deletion Rights
You may have the right to request deletion of personal information we hold about you, subject to exceptions such as ongoing contractual performance, legal retention obligations, security needs, or establishment, exercise, or defense of legal claims.
28. Portability Rights
Where applicable, you may have the right to receive personal information you provided to us in a structured, commonly used, machine-readable format and to request transmission to another controller where technically feasible.
29. Objection Rights
Where processing is based on legitimate interests or direct marketing, you may have the right to object to certain processing. We will assess objections in accordance with applicable law and may continue processing where we have compelling legitimate grounds or legal requirements.
30. Restriction Rights
You may have the right to request restriction of processing in certain circumstances, such as while we verify accuracy of information or assess an objection request.
31. Marketing Preferences
You may opt out of promotional emails by using the unsubscribe link in a message or contacting us at contact@roviean.com with subject line "Marketing Opt-Out."
Even if you opt out of marketing, we may still send service-related, transactional, security, and legal notices necessary to administer your relationship with Roviean.
32. Children's Privacy
The Services are not directed to children under eighteen (18) years of age, and we do not knowingly collect personal information from children.
If you believe a child has provided personal information to us, please contact us and we will take appropriate steps to delete such information where required by law.
34. Data Breach Procedures
We maintain procedures designed to detect, investigate, and respond to suspected personal data breaches.
Where we are required by applicable law, we will notify affected individuals and relevant supervisory authorities of a personal data breach without undue delay and, where feasible, within statutory timeframes, describing the nature of the breach, likely consequences, and measures taken or proposed.
35. Automated Decision-Making Notice
Roviean may use automated processing, including AI-assisted classification, scoring, routing, or recommendations, to support service delivery and internal operations.
We do not make solely automated decisions producing legal or similarly significant effects about individuals unless permitted by law, disclosed in advance, and subject to appropriate safeguards and human review where required.
36. Third-Party Websites Disclaimer
The Services may contain links to third-party websites, plugins, integrations, or applications. Third-party providers process information according to their own privacy policies and practices, which we do not control.
Your interactions with third-party services are governed by those providers' terms and privacy notices.
37. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you may have additional rights under the CCPA/CPRA, including:
- The right to know categories and specific pieces of personal information collected, sources, business purposes, and categories of recipients;
- The right to delete personal information, subject to exceptions;
- The right to correct inaccurate personal information;
- The right to opt out of sale or sharing of personal information where applicable;
- The right to limit use and disclosure of sensitive personal information where applicable;
- The right to non-discrimination for exercising privacy rights.
Categories Collected (Last 12 Months)
In the preceding twelve (12) months, we may have collected the following categories of personal information:
- Identifiers (name, email, phone, IP address, account ID);
- Customer records information (billing contact, commercial details);
- Commercial information (project orders, engagement history);
- Internet or network activity (usage, logs, Cookies);
- Professional or employment-related information (company, role);
- Inferences drawn from the above to improve Services, where permitted.
Authorized Agents
California residents may designate an authorized agent to submit requests on their behalf. We may require verification of the agent's authority and your identity.
38. Data Subject Requests and Response Timelines
To exercise privacy rights, contact us at contact@roviean.com with subject line "Privacy Request" and include:
- Your full name and contact email;
- The right you wish to exercise;
- Sufficient information to verify your identity and locate relevant records;
- If applicable, your relationship to Roviean (visitor, client, authorized user).
Response Timelines
We respond to verified requests within the timeframe required by applicable law. Under GDPR and UK GDPR, we generally respond within one (1) month, which may be extended by two (2) further months for complex requests where permitted, with explanation.
Under CCPA/CPRA, we generally respond within forty-five (45) days, with a permitted extension of an additional forty-five (45) days where reasonably necessary and notified to you.
If we cannot fulfill a request, we will explain the reason and any applicable appeal or complaint options.
Supervisory Authorities
If you are in the EEA or UK, you may lodge a complaint with your local data protection supervisory authority. In Ireland, the Data Protection Commission (www.dataprotection.ie) is the supervisory authority for matters within its competence.
39. Changes to Policy
We may update this Policy from time to time to reflect changes in law, technology, or our practices. The "Last updated" date at the top indicates when this Policy was most recently revised.
Material changes will be posted on the Website. Where required by law, we will provide additional notice or obtain consent before changes take effect.
Continued use of the Services after the effective date of an updated Policy constitutes acknowledgment of the revised Policy, except where prohibited by law.
40. Contact Information
For privacy questions, data subject requests, security concerns, or complaints, contact:
Roviean
Email: contact@roviean.com
Website: https://roviean.com
Privacy requests: contact@roviean.com (subject line "Privacy Request")
For client engagements where Roviean acts as processor, please also contact the relevant client controller where appropriate.