TRUST
Privacy policy
Privacy policy
Privacy policy
Last updated: August 1, 2026
Last updated: August 1, 2026
Effective Date: August 6, 2026
This Privacy Policy explains how Alvin Technologies, Ltd. (“Alvin,” “we,” “us” or “our”) collects, uses, shares, stores and protects personal information when you access or use our websites, portals, applications, communications and related services, including alvin.finance, portal.alvin.finance, Alvin Envoy, Alvin Travel and Alvin Protocol. AlvinOS is our operating system used to support the delivery of these services.
This Privacy Policy applies when you visit our websites, access an Alvin workspace, submit information to us, communicate with us or participate in a travel, delegation, protocol or operational program supported by Alvin.
1. Who we are
Alvin Technologies, Ltd. is a Delaware company with its registered address at 251 Little Falls Drive, Wilmington, Delaware 19808, United States.
For privacy questions, requests or concerns, contact us at hello@alvin.finance.
2. Services covered by this Privacy Policy
This Privacy Policy applies to personal information processed through or in connection with alvin.finance, portal.alvin.finance, Alvin Envoy, Alvin Travel, Alvin Protocol and any related customer, organization, delegate, traveler, partner, supplier or administrator workspace.
It also applies to information processed through forms, uploads, bookings, requests, approvals, communications, managed delegation services, travel services, protocol services, operational coordination, payment and prepayment workflows, supplier-payment activities, customer support, implementation and account administration.
This Privacy Policy does not apply to third-party websites, applications or services that Alvin does not control. Those third parties may process information under their own terms and privacy policies.
3. Our role in processing personal information
Depending on the service and circumstances, Alvin may act as either a controller or a processor of personal information.
Alvin generally acts as a controller where we determine why and how information is processed. This may include processing for website operation, account administration, customer and supplier relationship management, billing and invoicing, security, fraud prevention, support, service communications, legal compliance and internal business administration.
Where an organization uses Alvin to manage information about its delegates, travelers, employees, representatives or other participants, Alvin may process that information on the organization’s instructions. In those circumstances, the organization may determine which individuals are included, what information is submitted, who may access it, how it is used within the relevant workflow and how long it should be retained.
Additional data-processing terms may apply under the relevant customer agreement.
4. Information we collect
The information we collect depends on the services used, the relevant engagement and your role within that engagement.
We may collect information directly from you or receive it from your organization, employer, delegation coordinator, head of delegation, travel manager, supplier, partner, guardian or another authorized representative.
4.1 Account and contact information
We may collect your name, email address, phone number, job title, organization name, department, team, user role, permissions, account credentials, authentication information, account status, workspace activity, support requests and account-related communications.
4.2 Organization and business information
We may collect information about your company, government body, institution or organization, including its name, address, billing details, tax information, invoice information and authorized representatives. We may also collect project, program, delegation and workflow information, together with contracts, quotes, service orders, invoices, payment status, supplier records, fulfilment records, requests, approvals and operational actions.
4.3 Delegation, traveler and participant information
Where necessary to provide Alvin Envoy, Alvin Travel, Alvin Protocol or related services, we may collect a participant’s full name, title, position, organization, delegation, country represented, nationality, citizenship information, date of birth, passport details, passport copies, visa documents, government-issued identification, accreditation information, invitation letters and emergency contact details. We may also collect information about delegate or traveler status, document readiness, approvals, participation and operational communications.
4.4 Travel and accommodation information
We may collect travel dates, flight details, booking references, ticket information, baggage information, accommodation and rooming information, arrival and departure details, transfer requirements, ground-transportation details, driver information, vehicle information, itineraries and supplier confirmations.
Where voluntarily provided or required for a booking, we may also collect travel preferences, loyalty-program information, rebooking information and records relating to disruptions or changes.
4.5 Protocol, event and movement information
We may collect event and meeting schedules, delegation programs, venue information, protocol requirements, executive, VIP or diplomatic movement information, airport and venue movement details, driver and vehicle assignments, access instructions, pavilion or programming information, responsible contacts, operational incidents, escalations and completion records.
4.6 Sensitive information
Where reasonably necessary for accessibility, safety, travel, accommodation, protocol or service delivery, we may collect limited sensitive information.
This may include dietary requirements, allergy information, accessibility requirements, mobility needs, medical or health-related travel requirements, emergency-assistance information and religious or cultural requirements relevant to meals, travel, accommodation or protocol.
We may also process citizenship, immigration or minor-related information where required for the relevant service.
We seek to limit sensitive information to what is reasonably necessary. Where required by applicable law, Alvin or the organization responsible for the relevant engagement will obtain consent or establish another lawful basis before processing the information.
4.7 Payment and program information
Where applicable, we may collect quotes, invoices, receipts, prepayments, program balances, amounts committed to suppliers, payment status, supplier-payment status, settlement status, refund requests, booking records, expense records, billing contact information, payer information, payment-method metadata, transaction references and reconciliation information.
Alvin may receive or administer prepayments and program funds in connection with contracted travel, delegation, protocol and operational services.
Banking, payment, foreign-exchange, settlement and other regulated services may be provided through appropriately licensed third parties. Alvin does not provide banking or regulated financial-advisory services.
4.8 Communications and uploaded documents
We may collect emails, messages, notes, meeting notes, call notes, forms, uploaded files, contracts, letters, confirmations, travel documents, supplier documents, quotes, invoices, payment records, operational plans, schedules and other documents required to provide the services.
4.9 Website and usage information
When you use our websites or applications, we may automatically collect information such as your IP address, browser type, device type, operating system, referring page, pages viewed, date and time of access, session information, authentication events, workspace activity, security events, error information, performance data and cookie information.
5. Information received from other sources
We may receive information from employers, customer organizations, government bodies, delegation secretariats, heads of delegation, travel coordinators, program coordinators, event organizers, embassies, diplomatic missions, parents, guardians, travel-management providers, airlines, ticketing providers, hotels, accommodation providers, transport operators, visa providers, document providers, banks, payment providers, suppliers and service partners.
Information received from these sources may include booking details, itinerary information, participation status, document status, payment status, supplier confirmations and operational updates.
6. How we use personal information
We use personal information to provide and operate our services, create and manage accounts, authenticate users, manage access permissions and configure organization workspaces.
We may use information to coordinate delegations, travel, accommodation, protocol and operational programs. This may include processing requests, bookings, approvals, documents and communications, managing delegate and traveler readiness, arranging services with suppliers, preparing schedules, manifests, rooming lists and movement plans and issuing operational reminders and updates. We may also use information to provide customer and participant support, manage invoices, prepayments, supplier commitments, balances and refunds, maintain service and payment records, identify pending or at-risk actions and manage incidents or escalations.
In addition, we may process information to monitor service performance, maintain security, prevent fraud or misuse, protect participants, comply with contracts and legal obligations, resolve disputes, enforce agreements, administer our business and send service or marketing communications where permitted by law.
7. Legal bases for processing
Where applicable law requires a lawful basis, we may process personal information where necessary to perform a contract, take steps before entering into a contract, pursue legitimate business interests, comply with legal obligations, protect vital interests or act with consent.
Our legitimate interests may include operating and securing our services, coordinating customer workflows, maintaining records, preventing fraud, supporting customers, improving reliability and protecting Alvin, our customers and participants.
Where we process sensitive or special-category information, we rely on an additional condition permitted by applicable law. This may include explicit consent, protection of vital interests, compliance with legal obligations, the establishment or defense of legal claims, substantial public interest supported by law or another lawful condition available in the circumstances.
8. How we share personal information
We may share personal information where reasonably necessary to provide services, operate our business, comply with law or protect legitimate interests.
8.1 With your organization
If your access or participation is managed by an organization, we may share relevant information with that organization. This may include account information, participation status, workflow status, document status, travel and accommodation status, booking status, approvals, communications, invoices, payment status, incidents, escalations and outstanding actions.
8.2 With authorized users
We may share relevant information with authorized delegates, travelers, heads of delegation, administrators, coordinators, operations teams, program managers, customer representatives and other approved workspace participants.
Access may depend on role-based permissions and organization settings.
8.3 With suppliers and service providers
We may share information with suppliers and service providers needed to deliver the relevant service.
These may include airlines, ticketing partners, hotels, accommodation providers, transport operators, vehicle operators, drivers, protocol providers, event organizers, venue operators, visa providers, logistics providers, banks, payment providers, foreign-exchange providers, settlement providers, application infrastructure providers, communications providers, authentication providers, analytics providers, security providers, support providers, professional advisers, implementation partners and business partners.
We seek to share only the information reasonably necessary for the relevant purpose.
8.4 For legal, safety and compliance purposes
We may disclose information where reasonably necessary to comply with law, regulation, a court order or a lawful government request.
We may also disclose information to enforce agreements, investigate fraud, address abuse or security incidents, protect health or safety, respond to legal claims or comply with sanctions and other legal obligations.
8.5 Business transfers
If Alvin is involved in a merger, acquisition, financing, restructuring, sale of assets or similar transaction, personal information may be disclosed or transferred as part of that transaction, subject to applicable legal and confidentiality requirements.
9. Third-party services
Our services may involve third parties such as travel suppliers, accommodation providers, transport operators, payment providers, banks, infrastructure providers and communications providers.
Some of these providers process information on Alvin’s behalf. Others may independently determine how they process information and may operate under their own privacy policies.
Alvin is not responsible for the independent privacy practices of third parties that we do not control.
10. International processing and transfers
Alvin uses third-party application, infrastructure, communication and service providers to operate its services.
Personal information may be processed in the United States, Europe, Africa or other jurisdictions where Alvin, our customers, suppliers, partners or service providers operate.
Data-protection laws may differ among jurisdictions. Where required by law, Alvin uses appropriate safeguards for international transfers. These may include contractual protections, data-processing agreements, recognized transfer mechanisms, access controls, encryption, data minimization and organizational security measures.
11. Data security
Alvin uses reasonable administrative, technical and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, disclosure or destruction.
These safeguards may include role-based access controls, organization-scoped permissions, authentication controls, access logging, secure application infrastructure, encryption in transit, encryption at rest where supported and appropriate, restricted internal access, vendor controls, monitoring, backups and incident-response procedures.
AlvinOS is built on SOC 2 Type II and ISO 27001-certified infrastructure and is designed to support GDPR-aligned data handling. These infrastructure certifications relate to the audited systems and controls of Alvin’s underlying infrastructure providers. Alvin remains responsible for the configuration, operation and governance of its own services. No system is completely secure. We cannot guarantee that unauthorized access, loss, misuse or disclosure will never occur.
12. Data retention
We retain personal information for as long as reasonably necessary to provide and complete the services, maintain user and organization accounts, complete travel and operational workflows, maintain business and payment records, reconcile supplier and customer records, resolve disputes, enforce agreements, comply with legal obligations and protect legitimate business and security interests.
Retention periods may depend on the type of information, customer instructions, the duration of the customer relationship, completion of the relevant workflow, supplier requirements, contractual obligations, tax and accounting requirements, audit needs, dispute requirements and security considerations.
Where Alvin processes information on behalf of an organization, retention and deletion may be governed by that organization’s instructions and the relevant customer agreement.
When information is no longer required, we may delete it, anonymize it or restrict access until deletion is practical.
13. Your rights and choices
Depending on your location and applicable law, you may have the right to ask whether we process your personal information, access it, correct inaccurate information, request deletion, restrict or object to processing, request portability or withdraw consent.
You may also have the right to appeal a decision concerning a privacy request, complain to a data-protection authority and exercise your rights without unlawful discrimination.
Alvin does not sell personal information for monetary consideration and does not use personal information for cross-context behavioral advertising.
To exercise a privacy right, contact hello@alvin.finance.
We may need to verify your identity, authority or relationship with the relevant organization before responding. Where your information is controlled by an Alvin customer, we may refer your request to that organization or coordinate with it.
We may retain information where retention is required or permitted by law, including for tax, accounting, security, contractual or legal-claim purposes.
14. Organization-controlled information
In many cases, Alvin processes information on behalf of a customer, organization or administrator. The organization may control who is included in a workspace, what information is submitted, who may access it, user roles and permissions, operational instructions, communications, approvals and retention or deletion decisions.
If your participation is managed by an organization, you may contact that organization regarding access, correction, deletion, authorization or workspace permissions. You may also contact Alvin and we will help route the request where appropriate.
15. Children and minors
Our services are intended for business, government, institutional and organizational use.
Individuals under 18 may be included in travel, delegation, educational, event or protocol workflows where participation is submitted or authorized by a parent, guardian, school, organization, government body or another responsible representative.
We do not knowingly permit minors to create independent accounts without appropriate authorization.
Organizations submitting information about minors are responsible for ensuring that they have the necessary authority and have provided any legally required notices or obtained any required consent.
16. Cookies and analytics
We may use cookies and similar technologies to operate our websites and services, authenticate users, maintain secure sessions, remember preferences, analyze usage and performance and detect fraud, abuse or security threats.
Some cookies are necessary for the operation and security of the service.
Where required by law, we will request consent before using non-essential analytics or similar technologies. You may also be able to manage cookies through your browser settings. Some features may not work properly if cookies are disabled.
17. Marketing communications
We may send business, product or service communications where permitted by law. You may opt out of marketing emails by using the unsubscribe instructions in the email or contacting us.
We may still send non-marketing communications relating to your account, security, service delivery, bookings, payments, operational workflows, support or legal notices.
18. Artificial intelligence and automated tools
Alvin may use automated tools to support reminders, workflow routing, document-status tracking, operational summaries, data extraction, prioritization and communication drafting.
Alvin does not use customer confidential information, passport information, health information or other personal information submitted through customer workspaces to train general-purpose artificial intelligence models without the customer’s express authorization.
Unless expressly disclosed otherwise, Alvin does not use solely automated decision-making to make decisions that produce legal or similarly significant effects concerning individuals.
19. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our services, business, applicable laws, providers or privacy and security practices.
The updated version will state its effective date.
If we make material changes, we may notify affected users through our website, an Alvin workspace, email or another appropriate
communication method.
20. Contact
For privacy questions, requests or concerns, contact:
Alvin Technologies, Ltd.
251 Little Falls Drive
Wilmington, Delaware 19808
United States
Email: hello@alvin.finance
Effective Date: August 6, 2026
This Privacy Policy explains how Alvin Technologies, Ltd. (“Alvin,” “we,” “us” or “our”) collects, uses, shares, stores and protects personal information when you access or use our websites, portals, applications, communications and related services, including alvin.finance, portal.alvin.finance, Alvin Envoy, Alvin Travel and Alvin Protocol. AlvinOS is our operating system used to support the delivery of these services.
This Privacy Policy applies when you visit our websites, access an Alvin workspace, submit information to us, communicate with us or participate in a travel, delegation, protocol or operational program supported by Alvin.
1. Who we are
Alvin Technologies, Ltd. is a Delaware company with its registered address at 251 Little Falls Drive, Wilmington, Delaware 19808, United States.
For privacy questions, requests or concerns, contact us at hello@alvin.finance.
2. Services covered by this Privacy Policy
This Privacy Policy applies to personal information processed through or in connection with alvin.finance, portal.alvin.finance, Alvin Envoy, Alvin Travel, Alvin Protocol and any related customer, organization, delegate, traveler, partner, supplier or administrator workspace.
It also applies to information processed through forms, uploads, bookings, requests, approvals, communications, managed delegation services, travel services, protocol services, operational coordination, payment and prepayment workflows, supplier-payment activities, customer support, implementation and account administration.
This Privacy Policy does not apply to third-party websites, applications or services that Alvin does not control. Those third parties may process information under their own terms and privacy policies.
3. Our role in processing personal information
Depending on the service and circumstances, Alvin may act as either a controller or a processor of personal information.
Alvin generally acts as a controller where we determine why and how information is processed. This may include processing for website operation, account administration, customer and supplier relationship management, billing and invoicing, security, fraud prevention, support, service communications, legal compliance and internal business administration.
Where an organization uses Alvin to manage information about its delegates, travelers, employees, representatives or other participants, Alvin may process that information on the organization’s instructions. In those circumstances, the organization may determine which individuals are included, what information is submitted, who may access it, how it is used within the relevant workflow and how long it should be retained.
Additional data-processing terms may apply under the relevant customer agreement.
4. Information we collect
The information we collect depends on the services used, the relevant engagement and your role within that engagement.
We may collect information directly from you or receive it from your organization, employer, delegation coordinator, head of delegation, travel manager, supplier, partner, guardian or another authorized representative.
4.1 Account and contact information
We may collect your name, email address, phone number, job title, organization name, department, team, user role, permissions, account credentials, authentication information, account status, workspace activity, support requests and account-related communications.
4.2 Organization and business information
We may collect information about your company, government body, institution or organization, including its name, address, billing details, tax information, invoice information and authorized representatives. We may also collect project, program, delegation and workflow information, together with contracts, quotes, service orders, invoices, payment status, supplier records, fulfilment records, requests, approvals and operational actions.
4.3 Delegation, traveler and participant information
Where necessary to provide Alvin Envoy, Alvin Travel, Alvin Protocol or related services, we may collect a participant’s full name, title, position, organization, delegation, country represented, nationality, citizenship information, date of birth, passport details, passport copies, visa documents, government-issued identification, accreditation information, invitation letters and emergency contact details. We may also collect information about delegate or traveler status, document readiness, approvals, participation and operational communications.
4.4 Travel and accommodation information
We may collect travel dates, flight details, booking references, ticket information, baggage information, accommodation and rooming information, arrival and departure details, transfer requirements, ground-transportation details, driver information, vehicle information, itineraries and supplier confirmations.
Where voluntarily provided or required for a booking, we may also collect travel preferences, loyalty-program information, rebooking information and records relating to disruptions or changes.
4.5 Protocol, event and movement information
We may collect event and meeting schedules, delegation programs, venue information, protocol requirements, executive, VIP or diplomatic movement information, airport and venue movement details, driver and vehicle assignments, access instructions, pavilion or programming information, responsible contacts, operational incidents, escalations and completion records.
4.6 Sensitive information
Where reasonably necessary for accessibility, safety, travel, accommodation, protocol or service delivery, we may collect limited sensitive information.
This may include dietary requirements, allergy information, accessibility requirements, mobility needs, medical or health-related travel requirements, emergency-assistance information and religious or cultural requirements relevant to meals, travel, accommodation or protocol.
We may also process citizenship, immigration or minor-related information where required for the relevant service.
We seek to limit sensitive information to what is reasonably necessary. Where required by applicable law, Alvin or the organization responsible for the relevant engagement will obtain consent or establish another lawful basis before processing the information.
4.7 Payment and program information
Where applicable, we may collect quotes, invoices, receipts, prepayments, program balances, amounts committed to suppliers, payment status, supplier-payment status, settlement status, refund requests, booking records, expense records, billing contact information, payer information, payment-method metadata, transaction references and reconciliation information.
Alvin may receive or administer prepayments and program funds in connection with contracted travel, delegation, protocol and operational services.
Banking, payment, foreign-exchange, settlement and other regulated services may be provided through appropriately licensed third parties. Alvin does not provide banking or regulated financial-advisory services.
4.8 Communications and uploaded documents
We may collect emails, messages, notes, meeting notes, call notes, forms, uploaded files, contracts, letters, confirmations, travel documents, supplier documents, quotes, invoices, payment records, operational plans, schedules and other documents required to provide the services.
4.9 Website and usage information
When you use our websites or applications, we may automatically collect information such as your IP address, browser type, device type, operating system, referring page, pages viewed, date and time of access, session information, authentication events, workspace activity, security events, error information, performance data and cookie information.
5. Information received from other sources
We may receive information from employers, customer organizations, government bodies, delegation secretariats, heads of delegation, travel coordinators, program coordinators, event organizers, embassies, diplomatic missions, parents, guardians, travel-management providers, airlines, ticketing providers, hotels, accommodation providers, transport operators, visa providers, document providers, banks, payment providers, suppliers and service partners.
Information received from these sources may include booking details, itinerary information, participation status, document status, payment status, supplier confirmations and operational updates.
6. How we use personal information
We use personal information to provide and operate our services, create and manage accounts, authenticate users, manage access permissions and configure organization workspaces.
We may use information to coordinate delegations, travel, accommodation, protocol and operational programs. This may include processing requests, bookings, approvals, documents and communications, managing delegate and traveler readiness, arranging services with suppliers, preparing schedules, manifests, rooming lists and movement plans and issuing operational reminders and updates. We may also use information to provide customer and participant support, manage invoices, prepayments, supplier commitments, balances and refunds, maintain service and payment records, identify pending or at-risk actions and manage incidents or escalations.
In addition, we may process information to monitor service performance, maintain security, prevent fraud or misuse, protect participants, comply with contracts and legal obligations, resolve disputes, enforce agreements, administer our business and send service or marketing communications where permitted by law.
7. Legal bases for processing
Where applicable law requires a lawful basis, we may process personal information where necessary to perform a contract, take steps before entering into a contract, pursue legitimate business interests, comply with legal obligations, protect vital interests or act with consent.
Our legitimate interests may include operating and securing our services, coordinating customer workflows, maintaining records, preventing fraud, supporting customers, improving reliability and protecting Alvin, our customers and participants.
Where we process sensitive or special-category information, we rely on an additional condition permitted by applicable law. This may include explicit consent, protection of vital interests, compliance with legal obligations, the establishment or defense of legal claims, substantial public interest supported by law or another lawful condition available in the circumstances.
8. How we share personal information
We may share personal information where reasonably necessary to provide services, operate our business, comply with law or protect legitimate interests.
8.1 With your organization
If your access or participation is managed by an organization, we may share relevant information with that organization. This may include account information, participation status, workflow status, document status, travel and accommodation status, booking status, approvals, communications, invoices, payment status, incidents, escalations and outstanding actions.
8.2 With authorized users
We may share relevant information with authorized delegates, travelers, heads of delegation, administrators, coordinators, operations teams, program managers, customer representatives and other approved workspace participants.
Access may depend on role-based permissions and organization settings.
8.3 With suppliers and service providers
We may share information with suppliers and service providers needed to deliver the relevant service.
These may include airlines, ticketing partners, hotels, accommodation providers, transport operators, vehicle operators, drivers, protocol providers, event organizers, venue operators, visa providers, logistics providers, banks, payment providers, foreign-exchange providers, settlement providers, application infrastructure providers, communications providers, authentication providers, analytics providers, security providers, support providers, professional advisers, implementation partners and business partners.
We seek to share only the information reasonably necessary for the relevant purpose.
8.4 For legal, safety and compliance purposes
We may disclose information where reasonably necessary to comply with law, regulation, a court order or a lawful government request.
We may also disclose information to enforce agreements, investigate fraud, address abuse or security incidents, protect health or safety, respond to legal claims or comply with sanctions and other legal obligations.
8.5 Business transfers
If Alvin is involved in a merger, acquisition, financing, restructuring, sale of assets or similar transaction, personal information may be disclosed or transferred as part of that transaction, subject to applicable legal and confidentiality requirements.
9. Third-party services
Our services may involve third parties such as travel suppliers, accommodation providers, transport operators, payment providers, banks, infrastructure providers and communications providers.
Some of these providers process information on Alvin’s behalf. Others may independently determine how they process information and may operate under their own privacy policies.
Alvin is not responsible for the independent privacy practices of third parties that we do not control.
10. International processing and transfers
Alvin uses third-party application, infrastructure, communication and service providers to operate its services.
Personal information may be processed in the United States, Europe, Africa or other jurisdictions where Alvin, our customers, suppliers, partners or service providers operate.
Data-protection laws may differ among jurisdictions. Where required by law, Alvin uses appropriate safeguards for international transfers. These may include contractual protections, data-processing agreements, recognized transfer mechanisms, access controls, encryption, data minimization and organizational security measures.
11. Data security
Alvin uses reasonable administrative, technical and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, disclosure or destruction.
These safeguards may include role-based access controls, organization-scoped permissions, authentication controls, access logging, secure application infrastructure, encryption in transit, encryption at rest where supported and appropriate, restricted internal access, vendor controls, monitoring, backups and incident-response procedures.
AlvinOS is built on SOC 2 Type II and ISO 27001-certified infrastructure and is designed to support GDPR-aligned data handling. These infrastructure certifications relate to the audited systems and controls of Alvin’s underlying infrastructure providers. Alvin remains responsible for the configuration, operation and governance of its own services. No system is completely secure. We cannot guarantee that unauthorized access, loss, misuse or disclosure will never occur.
12. Data retention
We retain personal information for as long as reasonably necessary to provide and complete the services, maintain user and organization accounts, complete travel and operational workflows, maintain business and payment records, reconcile supplier and customer records, resolve disputes, enforce agreements, comply with legal obligations and protect legitimate business and security interests.
Retention periods may depend on the type of information, customer instructions, the duration of the customer relationship, completion of the relevant workflow, supplier requirements, contractual obligations, tax and accounting requirements, audit needs, dispute requirements and security considerations.
Where Alvin processes information on behalf of an organization, retention and deletion may be governed by that organization’s instructions and the relevant customer agreement.
When information is no longer required, we may delete it, anonymize it or restrict access until deletion is practical.
13. Your rights and choices
Depending on your location and applicable law, you may have the right to ask whether we process your personal information, access it, correct inaccurate information, request deletion, restrict or object to processing, request portability or withdraw consent.
You may also have the right to appeal a decision concerning a privacy request, complain to a data-protection authority and exercise your rights without unlawful discrimination.
Alvin does not sell personal information for monetary consideration and does not use personal information for cross-context behavioral advertising.
To exercise a privacy right, contact hello@alvin.finance.
We may need to verify your identity, authority or relationship with the relevant organization before responding. Where your information is controlled by an Alvin customer, we may refer your request to that organization or coordinate with it.
We may retain information where retention is required or permitted by law, including for tax, accounting, security, contractual or legal-claim purposes.
14. Organization-controlled information
In many cases, Alvin processes information on behalf of a customer, organization or administrator. The organization may control who is included in a workspace, what information is submitted, who may access it, user roles and permissions, operational instructions, communications, approvals and retention or deletion decisions.
If your participation is managed by an organization, you may contact that organization regarding access, correction, deletion, authorization or workspace permissions. You may also contact Alvin and we will help route the request where appropriate.
15. Children and minors
Our services are intended for business, government, institutional and organizational use.
Individuals under 18 may be included in travel, delegation, educational, event or protocol workflows where participation is submitted or authorized by a parent, guardian, school, organization, government body or another responsible representative.
We do not knowingly permit minors to create independent accounts without appropriate authorization.
Organizations submitting information about minors are responsible for ensuring that they have the necessary authority and have provided any legally required notices or obtained any required consent.
16. Cookies and analytics
We may use cookies and similar technologies to operate our websites and services, authenticate users, maintain secure sessions, remember preferences, analyze usage and performance and detect fraud, abuse or security threats.
Some cookies are necessary for the operation and security of the service.
Where required by law, we will request consent before using non-essential analytics or similar technologies. You may also be able to manage cookies through your browser settings. Some features may not work properly if cookies are disabled.
17. Marketing communications
We may send business, product or service communications where permitted by law. You may opt out of marketing emails by using the unsubscribe instructions in the email or contacting us.
We may still send non-marketing communications relating to your account, security, service delivery, bookings, payments, operational workflows, support or legal notices.
18. Artificial intelligence and automated tools
Alvin may use automated tools to support reminders, workflow routing, document-status tracking, operational summaries, data extraction, prioritization and communication drafting.
Alvin does not use customer confidential information, passport information, health information or other personal information submitted through customer workspaces to train general-purpose artificial intelligence models without the customer’s express authorization.
Unless expressly disclosed otherwise, Alvin does not use solely automated decision-making to make decisions that produce legal or similarly significant effects concerning individuals.
19. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our services, business, applicable laws, providers or privacy and security practices.
The updated version will state its effective date.
If we make material changes, we may notify affected users through our website, an Alvin workspace, email or another appropriate
communication method.
20. Contact
For privacy questions, requests or concerns, contact:
Alvin Technologies, Ltd.
251 Little Falls Drive
Wilmington, Delaware 19808
United States
Email: hello@alvin.finance