Privacy Policy
Last updated:
This policy explains how Alvisa AI collects, uses, stores and shares personal data when you visit alvisa.ai, contact us, or use the Alvisa application, and how we handle information about the business professionals our customers reach through it.
1. Who we are
Alvisa AI is provided by Alvisa AI Co., Ltd. (艾維薩智能科技股份有限公司, “Alvisa”, “we” or “us”). This policy covers our website at alvisa.ai and the Alvisa application at app.alvisa.ai (the “Service”). You can reach us about privacy at jarvis@alvisa.ai.
2. Our role
Where we decide how data is used, we are responsible for it as the controller (a non-government agency collecting personal data, under Taiwan’s Personal Data Protection Act). This covers visitors to our website, people who contact us, the account information of people who use the Service, and the business contact information we obtain from third-party sources (see “Information about business professionals”).
Where we process data for our customers, we act on their behalf as a processor. This covers the data a customer adds to the Service or syncs from accounts it connects, such as its contact records, messages and campaigns (“Customer Data”, as defined in our Terms of Service). The customer decides how that data is used and is responsible for having a lawful basis to use it. If you are a person whose data a customer manages in Alvisa, please contact that customer first. We will help it respond to you, and you can also contact us.
3. Information we collect
When you visit our website
Our hosting provider processes technical data, such as your IP address, browser type and the pages you request, to deliver and protect the website. We use no analytics or advertising tools on alvisa.ai.
When you contact us
If you write to us, by email or through the contact form on our website, we receive what you send, such as your name, company, email address, phone number (if you give it), topic and message. The contact form prepares an email in your own email app; it sends nothing until you send that email.
When you use the Service
- Account information: your name, work email address, job title, role, and optionally a profile photo, time zone and email signature. Sign-in is handled by our authentication provider, Auth0. We also keep invitations to join a workspace.
- Workspace information: your organization’s name, website, time zone and postal address. The postal address appears in the footer of outreach email, as anti-spam laws require.
- Technical and security data: such as IP addresses and browser information, which we record for some account events (for example, when an invitation is accepted) and in system logs.
- Customer Data: the contacts and companies you add or import (for example names, business email addresses, phone numbers, job titles, LinkedIn profile URLs, employers and locations), lists, notes, campaigns and sequences, the answers you give during onboarding, the knowledge you upload, and the content the Service generates for you, such as company summaries, prospect qualification and sales stage.
- Connected accounts: when you connect an email account (such as Gmail) or a LinkedIn account, we receive the account’s email address, display name and profile URL, and the Service syncs its messages and conversations, including senders, recipients, subjects, message content, dates and attachments. The sync covers conversations with anyone, not only people in your contacts, so that the Unibox can show them. See “Google user data” for Google accounts.
- Email engagement: sends, bounces, replies and unsubscribe requests for outreach sent through the Service. Some outreach email contains a small image that records that the email was opened; we store only that it was opened and how many times.
4. Information about business professionals
The Service helps customers find and research business prospects. To do this, we obtain information about business professionals from third-party sources:
- Business data providers, such as Apollo.io, which provide company information and professional contact information.
- LinkedIn, where a customer has connected a LinkedIn account: profile information and recent public activity that the account can see.
This information can include your name, job title, employer and work history, business email address and, where available, business phone number, LinkedIn profile URL, location, snippets of your public posts, and information about your company. We use it only to provide the Service’s prospecting features: to help customers identify relevant prospects, prepare relevant outreach, and prioritize their work. It is shown only to customers who use those features, inside their own workspace.
If you are a business professional and do not want your information used this way, write to us at jarvis@alvisa.ai. You can ask us what we hold about you, ask us to correct or delete it, or object to its use. When we delete your information at your request, we keep a minimal record of your email address so that we can honor your request.
5. How we use information
We use personal data to:
- provide the Service: manage contacts and campaigns, research prospects, draft outreach, send the messages and invitations that users set up, sync conversations, detect replies and stop sequences when a contact replies;
- provide the AI features described below;
- keep the Service and its users secure, and prevent spam, fraud and abuse;
- provide support, and tell customers about their account and changes to the Service;
- respond to inquiries and send the information people ask us for;
- understand how the Service is used, in aggregated or de-identified form, so that we can operate and improve it; and
- comply with the law and enforce our agreements.
Where the GDPR or similar laws apply, we rely on these legal bases: performing our contract with you or your organization; our legitimate interests in providing, securing and improving the Service and in helping customers reach relevant business prospects, which we balance against your rights; compliance with legal obligations; and your consent, where the law requires it.
We do not sell personal data, and we do not use it for advertising.
6. AI processing
The Service uses AI models provided by OpenAI. To provide its AI features, it sends OpenAI the information each feature needs:
- onboarding answers and uploaded knowledge, to build the knowledge that AI features draw on;
- contact, company and prospect information, including LinkedIn profile and activity information, to summarize companies, qualify prospects and draft outreach; and
- the subject and content of messages exchanged with people in your contacts, to qualify those contacts, keep their sales stage and history up to date, and suggest replies.
We store the text extracted from uploaded knowledge, together with numerical representations (embeddings) of it, so that AI features can find the relevant parts.
We do not use Customer Data to train AI models. OpenAI processes this information as our service provider. Under OpenAI’s terms for its API, it does not use the data we send to train or improve its models, and it may keep that data for up to 30 days to detect abuse, unless the law requires it to keep it longer.
AI output can be inaccurate. The Service presents qualification and scoring to help sales teams prioritize their work; it does not make decisions that have legal or similarly significant effects on anyone.
7. Google user data
This section explains how the Service handles information it receives from Google APIs (“Google user data”) when a user connects a Gmail or Google Workspace account. Accounts are connected through our service provider Unipile, using Google’s own sign-in and consent screen.
What we access, and why
- Email messages and their metadata, such as senders, recipients, subject, date, thread and content. We use them to show your conversations in the Unibox, to recognize replies to outreach sent through Alvisa, and to stop a sequence when a contact replies.
- Sending email on your behalf: the outreach in campaigns and sequences that you set up, and the messages you send from the Unibox.
- Your account’s email address and name, to identify the connected account in the Service.
How we use it
We use Google user data only to provide and improve the user-facing features described above. We do not sell it, use it for advertising, or use it to create, train or improve AI or machine learning models. As described in “AI processing”, the subject and content of messages exchanged with people in your contacts are sent to OpenAI to qualify those contacts, update their sales stage and suggest replies; OpenAI does not use them to train its models.
Who we share it with
We share Google user data only with the service providers that help us provide these features (Unipile, Amazon Web Services and OpenAI), for security purposes such as investigating abuse, when necessary to comply with the law, or as part of a merger, acquisition or sale of assets, and then only after obtaining your explicit prior consent. We do not transfer it to anyone else.
Human access
Our staff do not read Google user data unless you give us permission for specific messages (for example, to help with a support request), it is necessary for security purposes such as investigating abuse, it is required by law, or it has been aggregated and anonymized for internal operations.
Storage, protection and deletion
Synced messages are stored in our AWS environment in Tokyo, Japan, and encrypted at rest. Unipile holds the access tokens for accounts connected through it; we store only a reference to the account. Where we store access tokens ourselves, we encrypt them with keys managed in AWS Key Management Service.
You can disconnect a connected account at any time in the Service’s settings, or remove Alvisa’s access from your Google Account permissions. Disconnecting stops new data from being synced. To have the data already synced from a Google account deleted, write to us at jarvis@alvisa.ai. When a customer’s subscription ends, we delete this data as described in “Data retention”.
Limited Use
Alvisa AI’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The use of information received from Google Workspace scopes will adhere to the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.
9. International data transfers
We are based in Taiwan. The Service is hosted by Amazon Web Services in Tokyo, Japan. Our service providers may process personal data in other countries, including the United States and member states of the European Union. Where the law requires it, we put safeguards in place for these transfers, such as contractual commitments from our providers, and we comply with any restrictions on international transfers set by Taiwan’s authorities.
10. Data retention
We keep personal data only as long as we need it:
- Customer Data and account information is kept while the customer’s subscription is active, and customers can delete records in the Service at any time. We delete it within 90 days after the subscription ends.
- Information about business professionals from third-party sources is kept while it is needed for the prospecting features, and deleted when you ask us to.
- Raw notifications from connected-account providers are deleted after 30 days.
- Backups expire automatically within 35 days, so deleted data may remain in a backup until it expires.
- Messages sent to us are kept as long as needed to respond and to maintain our business relationship, and deleted on request.
- Suppression records (an email address that must not be contacted) are kept for as long as they are needed to honor the request.
We keep data longer only where the law requires it, for example for tax and accounting records, or to resolve disputes and enforce our agreements.
11. Security
We protect personal data with technical and organizational measures, including:
- TLS encryption for connections between your browser and the Service, and for database connections;
- encryption at rest for our main database and file storage;
- encryption of stored access tokens with keys managed in AWS Key Management Service;
- separation of each customer’s data, enforced in the database for every request a user makes;
- role-based permissions inside each workspace;
- secrets kept in a managed secrets service, and restricted access to production systems.
No system is perfectly secure. If a security incident affects your personal data, we will notify you and the authorities as the law requires.
12. Your rights and choices
Under Taiwan’s Personal Data Protection Act, you may ask us to let you review your personal data, give you a copy of it, supplement or correct it, stop collecting, processing or using it, or delete it. Where the GDPR or similar laws apply, you also have the rights to object to processing, to restrict it, to data portability, and to withdraw consent at any time. You may also complain to your data protection authority.
To make a request, write to us at jarvis@alvisa.ai. We may need to verify your identity first. We respond within the time limits set by law: generally 15 days for review and copy requests and 30 days for other requests, extendable once by the same period, with notice and reasons. If your request concerns Customer Data, we will pass it to the customer concerned and help it respond.
Users of the Service can update most of their account information in the Service. To delete an account, write to us at jarvis@alvisa.ai.
Unsubscribing from outreach
If you receive outreach sent through Alvisa and do not want more, use the unsubscribe option in the email, reply to the sender, or write to us at jarvis@alvisa.ai. We will pass your request to the customer that contacted you and add your email address to that customer’s suppression list, so that the Service does not send you further outreach on its behalf.
14. Children
The Service is for businesses and is not directed at children. Users must be at least 18 years old. We do not knowingly collect personal data from children; if you believe a child has given us personal data, write to us and we will delete it.
15. Notice under Taiwan’s Personal Data Protection Act
This section sets out the information that Articles 8 and 9 of Taiwan’s Personal Data Protection Act require. It applies to the personal data for which we are responsible as described in “Our role”.
- Collector: Alvisa AI Co., Ltd. (艾維薩智能科技股份有限公司).
- Purposes (with the codes of the specific purposes published under the Act): marketing (040); contract, quasi-contract and other legal relationship matters (069); consumer and customer management and services (090); information and communication services (135); information and database management (136); information security and management (137); surveys, statistics and research analysis (157); and other business within our registered business scope (181).
- Categories: identifying information (C001), current employment (C061), work experience (C064), and the content of messages and files (C132), as described in “Information we collect” and “Information about business professionals”.
- Sources: you; the customers and users of the Service; the accounts users connect; and the third-party sources named in “Information about business professionals”.
- Period: as long as the purposes require, as set out in “Data retention”.
- Area: Taiwan, Japan, and the countries where our service providers operate, as set out in “International data transfers”.
- Recipients: Alvisa, the service providers and customers named in “How we share information”, and authorities where the law requires it.
- Methods: automated and manual processing, including the AI processing described above.
- Your rights: the rights under Article 3 of the Act, exercised as described in “Your rights and choices”.
- If you do not provide data: you may choose not to give us personal data. Without account information we cannot create an account or provide the Service, and without contact details we may not be able to answer your inquiry.
16. Changes to this policy
We may update this policy from time to time. We will post the updated version on this page and change the date at the top. If a change is material, we will notify customers’ administrators by email or in the Service before it takes effect.
17. Contact us
Questions and requests about this policy or your personal data can be sent to Alvisa AI Co., Ltd. at jarvis@alvisa.ai.