Privacy Policy
Last updated September 27, 2026
1. Information we collect
We collect information you provide directly — such as your name, email address, and organization details when you create an account or contact us.
We also collect information automatically when you use Roiva, including usage data, log data (IP address, browser type, pages visited), and cookies necessary for the service to function.
When you connect third-party integrations (e.g. HubSpot, Salesforce, Zendesk, Xero), we store OAuth credentials and sync data from those platforms on your behalf. We do not access that data for any purpose other than providing the service to you.
A chat integration works the other way around. When you connect Slack or Microsoft 365, we store the workspace or tenant name, the channel you choose and the webhook address for it, and we post notifications to that channel. We do not read your messages, list your channels, or see who is in your workspace.
When your team attaches documents to an initiative (for example a business case, a review deck, a statement of work or a contract), we store each file on your behalf, or, for a document kept elsewhere, its link and title. These documents may contain personal information about your staff or about the people and companies named in them. We do not read, analyze or share a document attached this way; a file you upload to create an initiative from its contents is the one exception, described in section 5.
2. How we use your information
We use the information we collect to:
- Provide, operate, and improve Roiva
- Authenticate your account and keep it secure
- Send transactional emails (invitations, notifications, receipts)
- Respond to support requests
- Comply with legal obligations
We do not sell your personal information to third parties. We do not use your data to train AI models.
3. Data storage and security
Your data is stored on servers in the United States (AWS). We use encryption in transit (TLS) and at rest. Sensitive credentials — integration tokens, API keys, OAuth client secrets, and SAML signing keys — are encrypted at the field level using AES-256.
External auditor access links are stored as a one-way SHA-256 digest, never as the original token. The full URL is shown to your administrator once at creation and cannot be retrieved again afterwards. If an auditor loses their link, your administrator regenerates a new one.
MCP access tokens, which let an AI assistant your administrator connects (such as Claude Code or Cursor) read your account, are stored the same way: as a one-way SHA-256 digest, shown once. The assistant can read your data but not change it. The answers Roiva returns to it are processed by that assistant's provider under your organization's own agreement with them; that provider is not one of our sub-processors.
Documents attached to an initiative are stored in Amazon S3 in the United States and encrypted at rest. A file is served only to a signed-in member of your account who is allowed to see it, through a link that expires after five minutes. Statements of work and contracts are visible only to your account's owners and admins, and to the people named as approvers on that initiative. Each uploaded file is scanned for malware by Amazon Web Services when it arrives, in the same United States region where it is stored, and a file found to contain malware is never delivered to anyone.
No method of transmission or storage is 100% secure. We take reasonable measures to protect your information but cannot guarantee absolute security.
4. Data retention and deletion
We retain your account data for as long as your account is active. You can delete your data at any time using the in-app controls:
- Delete your user. Profile → Security → Delete account. This permanently removes your sign-in credentials, two-factor secret, assistant chat history, notifications, and personal activity, and removes you from every account you're a member of.
- Delete a workspace account (Owner only). Settings → Account → Delete account. This permanently removes the workspace and every initiative, value entry, integration, document, and report it contained.
Removing a document from an initiative deletes the stored file. Deleting an initiative deletes every document attached to it.
Both flows are irreversible. We recommend exporting any reports or data you want to keep before initiating either deletion.
Some records are deleted on a schedule rather than waiting for you to ask, because we shouldn't hold them longer than we need them:
- Audit logs: two years. The record of who did what inside your workspace. Two years so a SOC 2 audit can examine the period under test and the one before it.
- Product analytics and in-app notifications: 13 months.
- Assessment responses that never became an account: two years from your last activity. If you took our public AI-readiness assessment and never signed up, your answers and contact details are deleted after two years. A copy may remain in our CRM under its own settings; email us and we'll remove that too.
Everything else in your workspace is kept while your account is active and deleted when you delete it. We don't age out your own records.
When you delete an account or user, we retain a single audit-log entry recording that the deletion happened — the date, an aggregate count of what was destroyed, and (for user deletions) a one-way SHA-256 hash of the email address so support can answer a future "did this person ever have an account" query without storing the email itself. No other personal information is retained. This entry exists so the deletion itself stays auditable.
Financial records inside your workspace — accounting periods, journal entries, allocation rules — are deleted with the rest of the account data. We rely on your prior export of those records to satisfy your own tax and audit retention duties, in line with GDPR Article 17(3)'s recognition that erasure rights and financial-records obligations can coexist provided the data subject has been given the opportunity to preserve their own copy. Our own books (revenue from you, in our accounting system and Stripe) are retained separately under the retention period required by applicable tax law.
If you can't sign in and need help exercising your deletion right, contact us at hello@roiva.ai .
5. Third-party services
We use the following sub-processors to operate the service:
- AWS — cloud infrastructure, storage and email delivery. Roiva runs in a single US region (us-east-1): application data in Amazon RDS for PostgreSQL, uploaded files in Amazon S3, the background job queue in Amazon ElastiCache, and transactional email through Amazon SES, which receives the recipient's address and the message we send them.
- Stripe — payment processing
- Sentry — error monitoring
- Anthropic — large-language-model inference for the in-app assistant and for AI-generated initiative estimates and document analysis. Content you send to the assistant, and initiative and document text we analyze on your behalf, are processed by Anthropic's API. Anthropic does not use this content to train its models. See Anthropic's privacy policy for details.
- PostHog — product and usage analytics across both our marketing pages and the signed-in application. In-browser tracking only loads after you accept the analytics cookie banner; a limited set of account events (described in Section 6) is also sent from our servers. See PostHog's privacy policy for details.
- HubSpot — demo scheduling and sales contact records. If you book a demo, the name, email address and meeting details you enter are submitted to HubSpot. The booking widget is an embedded HubSpot page; it does not set cookies or other storage on our own site. Separately, if you complete the AI ROI Exposure Assessment and give us an email address, we create a contact in our own HubSpot from what you entered — your email, company and role, and the answers the assessment scored — so that we can follow up. See HubSpot's privacy policy for details.
- Google Analytics 4 — usage analytics (only loaded after you accept the analytics cookie banner). See Google's privacy policy for details.
Each sub-processor is contractually required to handle data in accordance with applicable privacy law.
6. Cookies and analytics
Roiva uses two kinds of cookies and similar storage:
- Functional (always on). Session cookies for authentication, account context, and security, plus two that remember how to show pages to you: your color mode and your time zone. These are required for Roiva to work and are not optional.
- Analytics (opt-in). On our marketing pages and inside the signed-in application we use PostHog and Google Analytics 4 (GA4) to understand how people find and use Roiva. Neither tool loads in your browser until you click Accept on our cookie banner.
PostHog stores its identifier in both your browser's local storage and a first-party cookie. Once loaded it records pageviews, and — because autocapture is enabled — it also records interactions such as clicks on buttons and links, along with the element that was interacted with. PostHog only builds a stored person profile for users we have identified (in practice, signed-in users); visitors who are not signed in are counted without a persistent profile being created. We have configured our PostHog project to discard client IP addresses, so your IP address is not stored alongside these events; an approximate location is derived from it before it is discarded.
Google Analytics 4 sets its own cookies and records pageviews, on-site events, approximate location, and an anonymized IP address (IP anonymization is enabled in our configuration). We do not use GA4's advertising features, audiences, or remarketing.
Separately from the banner, when you are signed in our servers send a small, fixed set of product events to PostHog — such as completing signup or requesting an invite — together with your email address, account identifier, and account name. This is server-side processing we carry out to operate and improve the service; it does not involve cookies or storage in your browser, and it is not affected by your cookie banner choice.
You can decline analytics at any time by clicking Decline on the banner — your choice is stored in your browser's local storage. Because that storage is per-site, our marketing pages and the signed-in application ask separately, and declining on one does not carry over to the other. To change a previous choice, click Cookie preferences in the footer of any marketing page, or on your Profile page inside the application; the banner will reappear and you can choose again.
We do not use advertising, retargeting, or third-party tracking cookies.
7. Your rights
Depending on your jurisdiction, you may have the right to access, correct, or delete your personal data, or to object to or restrict certain processing.
The fastest way to exercise your erasure right (GDPR Article 17 and equivalents) is the in-app self-service flow described in Section 4 . For access, correction, objection, restriction, or any request you can't complete in-app, email us at hello@roiva.ai and we will respond within the timeframes required by applicable law.
8. Children
Roiva is a service for businesses and the people who work in them. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, email hello@roiva.ai and we will delete it.
9. Changes to this policy
We may update this policy from time to time. We will notify you of material changes by email or by posting a notice in the application. Continued use of Roiva after changes take effect constitutes acceptance of the updated policy.
10. Contact
Questions about this policy? Email us at hello@roiva.ai .