Anvax
Why AnvaxIndustriesDeploymentSecurityBlog
Book a demo→

Legal

Privacy Policy

Effective: 1 September 2026Last updated: 1 September 2026

On this page

  • Overview
  • What we collect
  • How we use it
  • Customer data
  • Sharing & sub-processors
  • Data residency
  • Retention
  • Your rights
  • Security
  • Contact & DPA

Overview

This Privacy Policy describes how Anvax Technologies Private Limited (“Anvax”) handles personal data when you visit our website, use our platform, or interact with us. It also explains the distinctions between data we collect as a data controller (visitor and contact data) and data our customers bring to the platform (where we act as a data processor).

Anvax is committed to data minimisation. We collect what we need to operate and improve the service; we do not sell personal data to third parties.

What we collect

Website visitors

  • Page views and referrer (anonymised, used only for aggregate analytics)
  • IP address (truncated for analytics; retained in server logs for 30 days for security purposes)
  • Browser type and device class (aggregated, no fingerprinting)

Contact and sales enquiries

  • Name and work email you provide via the contact form
  • Company name and role if provided
  • Contents of your message
  • Follow-up correspondence

Platform accounts

  • Email address and display name
  • Organisation and role within the platform
  • Authentication events (login, MFA, session creation/destruction)
  • Usage metadata (feature use, connector configuration) for billing and support, not document content

How we use it

We use the data we collect to:

  • Respond to your enquiries and provide support
  • Operate, maintain, and improve the platform
  • Send security notifications, service updates, and product communications (you can opt out of marketing at any time)
  • Comply with our legal obligations
  • Detect and prevent fraud, abuse, and security incidents

We do not use personal data for automated decision-making that produces legal or similarly significant effects.

Customer data (platform)

When you use the Anvax platform, you bring in your organisation’s documents, records, and content (“Customer Data”). Anvax acts as a data processor for Customer Data; you remain the data controller.

For self-hosted tiers (Private Cloud, Sovereign Cloud, On-premises), Customer Data never transits Anvax systems. We have no standing access to it. Any support access is time-bounded, requires your explicit authorisation, and is logged in your audit trail.

We do not use Customer Data to train any model. There is no shared model across tenants. AI processing occurs within your own infrastructure using models you choose.

Sharing and sub-processors

We do not sell personal data. We share data only with:

  • Sub-processors: a small set of vendors who support our website and operations (listed on the sub-processors page). Each is bound by a data processing agreement.
  • Law enforcement or regulators: only where required by applicable law, and we will notify you to the extent legally permitted.
  • Business transfers: in the event of a merger or acquisition, under confidentiality obligations and with notice to affected parties.

For self-hosted tiers, the sub-processor list is minimal because Customer Data does not leave your infrastructure.

Data residency

Customer Data is processed in the region you choose. We offer:

  • Private Cloud: your own AWS, Azure, or GCP account, any region you select
  • Sovereign Cloud: in-country partners for India, EU, Gulf (UAE/KSA), and Singapore
  • On-premises: your own data centre, no network egress required

Data residency is enforced at the infrastructure layer, not a configuration flag.

Website visitor data (analytics, contact form) is processed by sub-processors that may be located outside your jurisdiction. See the sub-processors page for details.

Retention

  • Contact and sales enquiry data: retained while the relationship is active, deleted on request, automatically reviewed after 3 years of inactivity.
  • Platform account data: retained for the duration of the contract plus 90 days for offboarding, then deleted or returned.
  • Anonymised analytics: retained indefinitely (cannot be linked to an individual).
  • Security logs (website): 30 days.

Customer Data retention on self-hosted tiers is governed by your own policies; Anvax does not control it.

Your rights

Depending on your jurisdiction, you may have the right to access, correct, delete, or port the personal data we hold about you, to object to or restrict certain processing, and to withdraw consent where processing is based on consent.

To exercise these rights, contact us at privacy@anvax.in or via the contact form. We will respond within 30 days (or the statutory period if shorter).

If you believe we have not addressed your concern, you have the right to lodge a complaint with your local data protection authority.

Security

We apply technical and organisational measures proportionate to the risk, including TLS 1.3 in transit, encryption at rest, access controls, audit logging, and regular security reviews. Full details are on the Security & Architecture page.

In the event of a personal data breach, we will notify affected parties and relevant authorities within the timeframes required by applicable law.

Contact and DPA

For privacy enquiries, data subject rights requests, or to request a Data Processing Agreement:

Data Protection Contact

Anvax Technologies Private Limited

Bengaluru, Karnataka, India

Email: privacy@anvax.in

Or use the contact form.

Anvax

The self-hosted, governed AI workspace for enterprises that cannot use public AI.

Product

  • Overview
  • Search
  • Chat
  • Agents
  • Governance
  • Deployment

Solutions

  • Financial services
  • Healthcare
  • Legal
  • Public sector
  • All industries

Company

  • About
  • Security
  • Blog
  • Careers
  • Contact
  • Book a demo
© 2026 Anvax Technologies Pvt. Ltd.DocumentationTermsPrivacySOC 2ISO 27001GDPR-ready