LEGAL

Privacy policy

What personal data Trivena handles, why we handle it, and what you can ask us to do with it. Written to be read rather than to be impressive.

Effective 1 July 2026

1. Who we are

Trivena builds and hosts business applications, operated in connection with Tynktech in the Netherlands. Where this policy refers to “we” or “Trivena”, it means that operating entity. You can reach us at cloud@tynktech.nl.

2. Two different roles

It matters which hat we are wearing, because it changes who decides what happens to data.

  • As a controller for this website and our own business relationship with you: enquiries, access requests, correspondence, and account administration.
  • As a processorfor the business data inside a customer's Trivena Cloud Site. That data belongs to the customer, who decides what is stored and why. We process it on their instructions in order to run the service. See the data processing agreement for that relationship.

3. What we collect as controller

  • Contact and enquiry data: name, work email, company, team size, and the message you send us through the contact form or by email.
  • Account data: the details needed to create and administer your Trivena Cloud account and Sites, including the identity of administrators.
  • Correspondence: emails and support conversations, so we have context the next time you write.
  • Technical and usage data: aggregate website analytics, plus server and security logs such as IP address, request time, and user agent.

4. Why we use it

  • To reply to your enquiry and provide the information or access you asked for.
  • To create, administer, support, and bill for your Trivena Cloud account and Sites.
  • To keep the platform secure, diagnose faults, and investigate abuse.
  • To meet legal, accounting, and tax obligations.
  • To understand, in aggregate, which pages help people evaluate Trivena.

We rely on performance of a contract for account and service data, legitimate interests for security, fault diagnosis, and responding to business enquiries, and legal obligation where a law requires retention. Where consent is required, we ask for it and you can withdraw it.

5. What we do not do

  • We do not sell personal data.
  • We do not use customer business data to train shared AI models across customers.
  • We do not add you to a marketing newsletter because you sent us a question.

6. Trivena AI and your data

AI capabilities inside Trivena applications operate within a single customer Site and in the context of the requesting user's permissions. AI cannot read or surface records that user is not allowed to access. Where a capability depends on an external AI provider, it is used to process the request in question, not to build a shared model of your business. See safety and permissions for detail.

7. Service providers

We use a limited number of providers to operate Trivena, for example infrastructure and hosting providers, transactional email delivery, website analytics, and AI providers for specific features. They act on our instructions under contract, and we share the minimum needed for them to do their job. A current list of subprocessors is available on request and referenced in the DPA.

8. International transfers

Trivena is operated from the Netherlands and we prefer providers in the European Economic Area. Where a provider processes data outside the EEA, we rely on an appropriate transfer mechanism, such as the European Commission's standard contractual clauses.

9. How long we keep it

  • Enquiries and correspondence: while there is an active conversation, and a reasonable period after.
  • Account and billing records: for the life of the relationship plus the statutory retention period.
  • Security and server logs: a short rolling window, unless needed for an ongoing investigation.
  • Customer Site data: for the term of the customer's agreement, then deleted per that agreement.

10. Security

Each customer runs in an isolated Site with its own database. Traffic is encrypted in transit, access is governed by the platform's permission system, administrative access to infrastructure is restricted to the people who operate it, and backups and monitoring are automated. Our security page describes this in more detail.

11. Your rights

Subject to applicable law you can ask us for access to your personal data, correction of inaccurate data, deletion, restriction of processing, portability, or to object to processing based on legitimate interests. Email cloud@tynktech.nl and we will respond within the period required by law.

If your data sits inside a customer's Site, for example because you are that company's employee or customer, please contact that company first, as they decide what is stored. We will support them in responding.

You also have the right to lodge a complaint with a supervisory authority. In the Netherlands that is the Autoriteit Persoonsgegevens.

12. Cookies and analytics

This website uses aggregate analytics to understand which pages are useful. We do not run advertising trackers on it. Trivena Cloud uses cookies that are strictly necessary to keep you signed in to your Site.

13. Changes

If we change this policy we will update the effective date above. Material changes affecting customers are communicated directly rather than left for you to discover.

Questions

For privacy questions, data subject requests, or a copy of our subprocessor list, contact cloud@tynktech.nl