Privacy Statement
Maatvia LLC respects the confidentiality of the data our customers entrust to us. This statement explains what personal data we process as a controller for our own website and account administration, and how we handle the data our customers load into the console as a processor on their behalf.
1. Who we are
Maatvia LLC, a limited liability company organised under the laws of the State of Delaware, United States, is the controller for personal data relating to our website visitors, prospects, account owners and users. Privacy contact: privacy@maatvia.com.
Where our customers upload trade data that contains personal data — for example counterparty contacts or screening subjects — the customer is the controller and we act as processor under the Data Processing Addendum.
2. What we collect
- Account data
- Name, work email, organisation, role, password hash (managed by our authentication provider), account and seat status.
- Billing data
- Plan, seat count, billing cadence, subscription status, invoices and payment-processor identifiers. Full card numbers never reach our systems.
- Customer content
- Company records, product and classification data, regulatory measures, mitigation notes, uploaded or connected workbooks, and exported reports.
- Integration data
- Where you connect Microsoft OneDrive or SharePoint: the identifiers of the folders and files you select, file names, and encrypted access tokens issued by Microsoft.
- Usage and technical data
- Sign-in events, feature and page usage, sync and audit-log entries, IP address, browser and device information, and error diagnostics.
- Support and communications
- Messages you send us and the correspondence history.
We do not knowingly collect data from children and the service is not intended for consumers.
3. Why we process it and on what legal basis
- Providing the service, accounts and seats
- Performance of our contract with you.
- Billing, collections and tax records
- Contract performance and legal obligation.
- Support, service communications and incident notices
- Contract performance and legitimate interests.
- Security, abuse prevention, audit logging and fraud detection
- Legitimate interests and legal obligation.
- Product improvement using aggregated or de-identified usage data
- Legitimate interests.
- Marketing emails to business contacts
- Consent where required, otherwise legitimate interests — you can opt out in any message.
- Complying with law and responding to lawful requests
- Legal obligation.
We do not sell personal data, do not share it for cross-context behavioural advertising, and do not use identifiable customer content to train third-party AI models.
4. AI processing
Some features send text to AI providers to translate, summarise or explain trade content. We send only what is needed for the request, providers are bound by contract to process it solely for that request, and output is AI-generated and may be wrong — see the AI & Automated Content Disclosure.
The console does not make automated decisions with legal effect about individuals.
6. International transfers
We are based in the United States and our providers may process data in the United States and the European Union. Where data leaves the EEA, the UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable) together with appropriate technical measures such as encryption in transit and at rest.
7. Retention
- Account and customer content: for the life of the subscription and up to 30 days after termination, after which it is deleted or irreversibly anonymised, unless you ask us to delete sooner.
- Backups: rolling backups are overwritten within 35 days.
- Billing and tax records: up to 7 years, as required by law.
- Security, sync and admin audit logs: up to 24 months.
- Support correspondence: up to 24 months after the case closes.
8. Security
We use encryption in transit and at rest, row-level authorisation so each account can only read its own records, role-based restrictions on administrative functions such as regulatory-tracker uploads, encrypted storage of third-party access tokens, least-privilege access for staff, and audit logging of privileged actions. See the Security Policy for detail and for how to report a vulnerability.
9. Your rights
Depending on where you live you may have the right to access, correct, delete, port, restrict or object to processing of your personal data, to withdraw consent, and not to be discriminated against for exercising these rights.
To exercise a right, email privacy@maatvia.com from the address on your account. We respond within 30 days and may ask for information to verify your identity. If the data was uploaded by a customer, we refer the request to that customer as controller.
You may also lodge a complaint with your supervisory authority, or with the relevant state Attorney General in the United States.
11. Changes to this statement
We update this statement as the service evolves. The version and date at the top change with it, and we notify account owners of material changes by email or in the console.