Privacy Policy

Kaarvi Privacy Policy PRIVACY POLICY Effective Date: July 5, 2026 Last Updated: July 5, 2026 This Privacy Policy describes how Kaarvi, Inc. (“Kaarvi,” “we,” “us,” or “our”) collects, uses, discloses, stores, and otherwise processes personal data in connection with our website, platform, software, APIs, documentation, and related services (collectively, the “Services”). Kaarvi is a business-to-business enterprise platform. The Services are designed for business, commercial, institutional, and professional use and are made available to organizations and their personnel. The Services are not offered for personal, family, household, or consumer use. This Privacy Policy applies to personal data that Kaarvi collects and processes for its own business purposes, including personal data relating to website visitors, prospective customers, customer representatives, administrators, Authorized Users, billing contacts, and business partners who interact with Kaarvi in a business or professional capacity. It also applies to personal data collected automatically through use of the Services, including through cookies, logs, session data, and similar technologies, to the extent Kaarvi processes such data for its own operational, security, and administrative purposes. Controller and Processor Roles. This Privacy Policy describes Kaarvi’s privacy practices where Kaarvi acts for its own business purposes. Kaarvi’s platform enables customers to submit, upload, connect, and process data through the Services, including datasets, records, files, queries, prompts, and other content (“Customer Data,” as defined in the Terms of Service). Kaarvi processes Customer Data on behalf of and under the instructions of the applicable customer, acting as a processor or service provider under the applicable customer contract, Order Form, and Data Processing Addendum (“DPA”). The categories of Customer Data processed, the nature and purpose of such processing, and the applicable data-protection obligations are described in the DPA, not in this Privacy Policy. Customers are responsible for determining the purposes and means of processing Customer Data, for providing required notices, and for obtaining any necessary rights, consents, or lawful bases in connection with the Customer Data they submit to the Services. This Privacy Policy should be read together with, and not as a replacement for, the applicable DPA or other data-processing terms between Kaarvi and its customers. Kaarvi may update this Privacy Policy from time to time. If Kaarvi makes a material change, Kaarvi will provide notice as appropriate under the circumstances, which may include posting the updated Privacy Policy on our website or through the Services. The “Effective Date” and “Last Updated” dates above indicate when this Privacy Policy became effective and was most recently revised. 1. PERSONAL DATA COLLECTED Kaarvi collects and processes the following categories of personal data for its own business purposes. These categories relate to individuals who interact with Kaarvi or the Services in a business or professional capacity, and do not describe Customer Data that customers or Authorized Users submit to, connect to, or process through the Services, which is governed by the applicable DPA. Identity and Account Data. First name, last name, username, email address, avatar, and similar account-level identifiers collected during registration or account management. Professional and Organizational Data. Company or organization name, organization domain, job title, company size, primary use case, referral source, and other business-related information provided during registration or account setup. Authentication and Credential Data. Password hashes, authentication type (e.g., local, SSO, OpenID), multi-factor authentication status, encrypted MFA secrets, hashed backup codes, password reset tokens, and related authentication artifacts. Where third-party identity providers are used, Kaarvi may receive external user identifiers, email addresses, display names, profile attributes, provider type, and login counts. Billing and Financial Contact Data. Billing contact email, billing account identifiers, subscription tier, currency, payment method metadata (such as type and last four digits), transaction records, and usage-based billing data. Full payment card or bank account details are processed by third-party payment processors and are not stored by Kaarvi. Technical and Session Data. IP address, browser type, device characteristics, user agent string, browser fingerprint, session identifiers, and session timestamps (creation, expiration, and last activity), collected automatically in connection with access to the Services. Authentication and Security Event Data. Login attempts (successful and unsuccessful), authentication methods used, failure reasons, account lock status, IP addresses, user agents, and timestamps, collected and retained by Kaarvi for platform security, fraud prevention, and abuse detection. 2. SOURCE OF PERSONAL DATA Kaarvi collects personal data for its own business purposes directly from individuals who interact with Kaarvi or the Services, from customer organizations that create or administer accounts for their personnel, from third-party identity and access-management providers used in connection with the Services, and automatically through the operation, security, and administration of the Services, including by means of logs, session tools, cookies, local storage, and similar technologies. Kaarvi may also receive personal data from service providers and business partners to the extent necessary to support account administration, billing, authentication, security, and service delivery. 3. USE OF PERSONAL DATA Kaarvi uses personal data collected for its own business purposes to administer accounts and organizational environments; authenticate users and manage access controls; provide support and respond to inquiries; administer subscriptions, billing, and related financial operations; protect the security, integrity, and availability of the Services; maintain, monitor, and improve the performance and reliability of the Services; generate internal operational, security, and service-performance analytics based on Usage Data, system telemetry, aggregated information, or de-identified information; and comply with applicable law, contractual obligations, audit requirements, and legal process. Customer Data processed by Kaarvi on behalf of customers in connection with the Services is governed by the applicable customer agreement and Data Processing Addendum and is not governed comprehensively by this Privacy Policy. 4. DISCLOSURE OF PERSONAL DATA Kaarvi may disclose personal data collected for its own business purposes to service providers and advisors that support the operation, security, administration, and delivery of the Services, including hosting and infrastructure providers, identity and access-management providers, payment and billing providers, communication and notification vendors, security and fraud-prevention providers, and legal, audit, insurance, and other professional advisors. Kaarvi may also disclose such personal data where required or permitted by applicable law or legal process, where reasonably necessary to protect rights, property, safety, or the Services, or in connection with an actual or proposed corporate transaction subject to customary confidentiality protections. Kaarvi does not disclose personal data for unrelated third-party marketing, advertising, or data-broker purposes. 5. NO SALE; NO TARGETED ADVERTISING Kaarvi does not sell personal data. Kaarvi does not disclose personal data to third parties for monetary or other valuable consideration in a manner intended to constitute a “sale” under applicable U.S. state privacy laws. Kaarvi does not share personal data for cross-context behavioral advertising. Kaarvi does not use personal data collected through the Services to deliver behavioral advertising, does not use advertising cookies or marketing pixels for cross-context ad targeting, and does not monetize personal data through advertising-based profiling. Any disclosure of personal data by Kaarvi is limited to the recipients described in Section 4 and is made solely for business, operational, security, compliance, support, payment, infrastructure, or service-delivery purposes. To the extent applicable U.S. state privacy laws require disclosure on these points, Kaarvi does not sell personal data, does not share personal data for cross-context behavioral advertising, and does not engage in targeted advertising. 6. COOKIES AND SIMILAR TECHNOLOGIES 6.1 Kaarvi uses cookies, local storage, session storage, and similar technologies to support the operation of the Services. These technologies are used to enable authentication, maintain session state, store application and configuration data, preserve onboarding and workflow state, support security controls, and ensure proper platform functionality. These technologies are used for service operation and are not used for third-party advertising or cross-context behavioral advertising. 6.2 Kaarvi does not use third-party advertising cookies, tracking pixels, or similar technologies for marketing or advertising purposes within platform interfaces. Any performance monitoring or operational metrics are generated internally and used solely to operate, secure, and improve the Services. 6.3 Most web browsers allow users to control cookies and local storage through browser settings, including the ability to block or delete stored data. Disabling or restricting cookies or similar technologies may affect the availability or functionality of certain features of the Services, including authentication and session management. 7. CHILDREN’S PRIVACY The Services are designed for business, commercial, institutional, and professional use and are not directed to children or general consumer use. Account creation is intended for authorized representatives of business or organizational customers and requires business-related registration information, such as company name, company size, and job title. Kaarvi does not knowingly collect personal data directly from children through its website, registration processes, or platform accounts. In certain circumstances, customers may upload or process datasets through the Services that contain personal data relating to children. In such cases, Kaarvi processes that data solely on behalf of and under the instructions of the applicable customer, in accordance with the applicable contractual terms and DPA. Customers are responsible for determining whether their use of the Services involves children’s data and for complying with applicable law relating to such data. If Kaarvi becomes aware that it has collected personal data directly from a child in a manner inconsistent with this Section, Kaarvi will take appropriate steps to delete such information in accordance with applicable law. 8. DATA RETENTION 8.1 Kaarvi retains personal data collected for its own business purposes for as long as reasonably necessary to fulfill the purposes for which the data was collected, including for account administration, authentication, access control, security monitoring, fraud prevention, support, billing, legal compliance, contractual performance, dispute resolution, and ordinary business and operational needs. 8.2 Certain categories of personal data expire or are deleted automatically based on system configuration or operational workflows. Examples include session credentials, access tokens, refresh tokens, verification tokens, password-reset tokens, temporary caches, and similar short-lived security or technical data. Other categories, including authentication logs, security event records, and audit trails, may be retained for longer periods where justified by security, legal, evidentiary, governance, contractual, or operational needs. 8.3 In some cases, Kaarvi may retain certain logs, audit records, or deactivated-account records without a fixed deletion schedule where necessary for security, fraud prevention, evidentiary preservation, compliance, governance, dispute resolution, or service administration, unless and until such data is deleted, anonymized, or otherwise processed in accordance with Kaarvi’s internal retention practices. 8.4 Where personal data is associated with customer accounts, Kaarvi may retain such data for the duration of the customer relationship and for a reasonable period thereafter as necessary to support post-termination retrieval, deletion workflows, legal compliance, dispute resolution, financial reconciliation, audit requirements, and backup cycling. Certain data may also persist in backup systems, disaster recovery media, or archival systems for a limited period following deletion from active systems, subject to applicable security and confidentiality protections. 8.5 Kaarvi may de-identify, anonymize, or aggregate personal data rather than delete it, where permitted by applicable law and where such information is no longer capable of being associated with an identified or identifiable individual. Kaarvi may retain and use such information for lawful business purposes. 9. SECURITY 9.1 Kaarvi implements and maintains reasonable administrative, technical, and organizational measures designed to protect personal data against unauthorized access, acquisition, use, disclosure, alteration, or destruction. These safeguards include, as appropriate: a. access controls designed to restrict access to personal data to authorized personnel and systems on a need-to-know basis, including role-based access restrictions and multi-tenant data isolation; b. authentication mechanisms, including support for multi-factor authentication and identity federation; c. encryption and comparable protective measures for personal data in transit and at rest; d. logging, monitoring, and auditing capabilities designed to detect unauthorized access, misuse, anomalies, and security events; e. risk-based access controls, including real-time risk scoring and anomaly detection; and f. incident response procedures designed to identify, investigate, contain, and remediate security incidents, and business continuity, backup, and recovery processes. 9.2 NO SYSTEM, SERVICE, OR METHOD OF TRANSMISSION OR STORAGE IS COMPLETELY SECURE. KAARVI DOES NOT GUARANTEE THAT THE SERVICES WILL BE IMMUNE FROM ALL SECURITY INCIDENTS, VULNERABILITIES, OR DISRUPTIONS. CUSTOMERS AND USERS ARE RESPONSIBLE FOR USING THE SECURITY FEATURES MADE AVAILABLE THROUGH THE SERVICES IN A MANNER APPROPRIATE TO THEIR ENVIRONMENT, INCLUDING MAINTAINING CREDENTIAL SECURITY AND CONFIGURING ACCESS CONTROLS. 10. INTERNATIONAL TRANSFERS 10.1 Kaarvi operates as a cloud-based service and may process personal data in the United States and in other jurisdictions where Kaarvi, its affiliates, service providers, or subprocessors operate or maintain infrastructure. Personal data may be transferred to, stored in, or accessed from jurisdictions outside of the individual’s country of residence where necessary to provide, operate, maintain, secure, and support the Services. 10.2 Where required by applicable law, Kaarvi implements appropriate safeguards designed to protect personal data in connection with cross-border transfers, which may include contractual protections, data processing agreements, and other legally recognized transfer mechanisms. 10.3 The locations in which personal data is processed may depend on factors such as the customer’s configuration of the Services, the geographic location of the customer’s infrastructure, the use of third-party providers, and the operational architecture of the Services. Kaarvi does not limit processing to a single geographic region unless expressly agreed in writing. 11. U.S. STATE PRIVACY RIGHTS 11.1 Depending on the individual’s state of residence, the nature of the relationship with Kaarvi, and the processing context, certain rights may be available under applicable U.S. state privacy laws, including the laws of California, Colorado, Connecticut, Virginia, and other states with comprehensive privacy legislation. These rights are subject to exceptions, limitations, and verification requirements, and may not apply to all categories of personal data or all processing activities. Subject to applicable law and any relevant exceptions, an individual may have the right to: a. confirm whether Kaarvi processes the individual’s personal data and request access to such data; b. correct inaccuracies in personal data; c. request deletion of personal data; d. obtain a copy of certain personal data in a portable format; and e. opt out of the sale of personal data, sharing of personal data for cross-context behavioral advertising, targeted advertising, or certain profiling activities, to the extent applicable. 11.2 As described in Section 5, Kaarvi does not sell personal data, does not share personal data for cross-context behavioral advertising, and does not engage in targeted advertising. To the extent an applicable opt-out right is limited to those activities, Kaarvi does not currently engage in the processing that would trigger such rights. 11.3 Where required by applicable law, if Kaarvi declines to take action on a privacy-rights request, the requester may appeal that decision by contacting Kaarvi using the contact methods in Section 13 and stating that the submission is an appeal. Kaarvi will review and respond to any such appeal in accordance with applicable law. Certain state laws require that, if an appeal is denied, the individual be informed of how to contact the relevant state regulator. 11.4 Where Kaarvi processes personal data as part of Customer Data on behalf of a customer, Kaarvi generally acts as a service provider or processor and may direct the requester to the relevant customer, or otherwise respond in accordance with the customer’s instructions, applicable contractual terms, and applicable law. 12. INDIVIDUAL RIGHTS AND CHOICES 12.1 Kaarvi provides the following controls and mechanisms for personal data that Kaarvi processes for its own business purposes, subject to applicable law, contractual limitations, and Kaarvi’s role in the relevant processing activity: a. users may access and update certain personal data associated with their account through the account settings and profile management features of the Services; b. organizational administrators may update certain user information and account attributes within their organization; c. individuals may request deletion of personal data associated with their account, subject to applicable law, contractual requirements, and Kaarvi’s retention obligations, either through account management features or by contacting Kaarvi as described in Section 13; d. users may manage communications preferences through the Services, including notification settings, alert configurations, and communication frequency; e. users may review and manage active sessions, update passwords, enable or disable multi-factor authentication, and revoke or regenerate API keys or tokens; and f. individuals may submit requests to withdraw consent where consent is the applicable legal basis, in accordance with the mechanisms provided through the Services or by contacting Kaarvi. 12.2 Kaarvi may take reasonable steps to verify the identity and authority of any individual submitting a request, including confirming that the requester is the individual to whom the request relates or is authorized to act on that individual’s behalf. Authorized agents or representatives may submit requests on behalf of an individual where permitted by applicable law, subject to verification of the agent’s authority. Kaarvi will respond within the timeframes and in the manner required by applicable law. 12.3 Where an individual’s request relates to personal data contained in Customer Data, Kaarvi may direct the requester to the applicable customer or act in accordance with the customer’s instructions under the DPA. 13. CONTACT INFORMATION Privacy-related inquiries, requests, complaints, appeals, and other privacy-rights submissions may be directed to: Email: legal@kaarvi.ai Mail: Kaarvi, Inc., 12320 Barker Cypress Rd, Ste 600 – 1023, Cypress, TX 77429-8323, United States Where required by applicable law, Kaarvi will review and respond to verified requests and appeals in accordance with applicable legal requirements.