TovenAI

Privacy Policy

Toven AI · Version 1.0 · Last updated 25 September 2026

1. Who we are

Toven AI is a trading name of Meridien Inc., a company incorporated in the State of Delaware whose principal office is at 2 N 6th St, Brooklyn, NY 11249 ("Toven", "we", "us"). We provide compliance surveillance software to financial services firms.

This policy explains how we handle personal data in these situations:

The Service is hosted in the European Union. We handle personal data in line with the EU General Data Protection Regulation (GDPR) and, where it applies, the UK GDPR.

Questions about this policy: sam@toven.ai

2. Our two roles

When we are the controller. We decide how and why personal data is used for:

This policy covers that data.

When we are a processor. Our customers load their own records into the Service, such as electronic communications, voice-call transcripts, trade and order records and personnel rosters. These records contain personal data about the customer's employees, clients and counterparties. We call this data "Customer Data". We process Customer Data only to provide the Service, on the customer's instructions and under our agreement with them. The customer is the controller. It is responsible for telling those individuals how their data is used.

If your data is in a customer's records and you want to exercise your rights, please contact that organisation. If you contact us instead, we will pass your request on to them. Section 10 summarises how we handle Customer Data.

3. Personal data we collect as controller

CategoryWhat it includesWhere it comes from
Website usagePages you view, the page that referred you, approximate location based on your IP address, browser and device type, and Google Analytics cookie identifiersYour browser, through Google Analytics
Network and security dataIP address, request details and timestampsYour device, through Cloudflare and our hosting provider
Enquiries and demo bookingsName, email address, organisation, role, your message and appointment detailsYou, by email or through our Google Calendar booking page
Account dataName, work email address, Microsoft Entra ID identifiers, organisation, and roles or group membershipsYour organisation, and Microsoft Entra ID when you sign in
Service activity and security logsSign-in events, IP address, browser type, and the actions you take and features you use in the Service, with timestampsCreated when you use the Service
Customer relationship dataNames and contact details of billing, contract and security contacts, our correspondence with them, and contract and invoicing recordsYou or your organisation

We do not seek to collect special categories of personal data, such as health data, as controller.

4. Why we use it and our legal bases

PurposeData usedLegal basis
Providing the Service and managing user accounts, including sign-in and rolesAccount data; Service activity and security logsOur legitimate interest in providing the Service our customer has contracted for. Where you are personally our customer, performance of our contract with you
Protecting the Service and our website, detecting and investigating security incidents, and keeping audit recordsNetwork and security data; Service activity and security logsOur legitimate interest in keeping our systems and our customers' data secure. Legal obligation where the law requires us to keep records
Responding to enquiries and arranging demosEnquiries and demo bookingsOur legitimate interest in responding to business enquiries. Steps you ask us to take before entering a contract
Managing customer relationships: contracts, invoicing, support, and notices about the Service, security and policy changesCustomer relationship data; account dataPerformance of a contract. Our legitimate interest in managing the relationship. Legal obligation for tax and accounting records
Understanding how our website is used so that we can improve itWebsite usageYour consent where the law requires consent for analytics cookies, as in the EEA and the UK. Elsewhere, our legitimate interest in understanding how our website is used
Improving the ServiceService activity logs, but not the content of Customer DataOur legitimate interest in improving the Service
Meeting legal obligations, and establishing, exercising or defending legal claimsAny of the data above, as neededLegal obligation. Our legitimate interest in protecting our legal position

We do not sell personal data. We do not use Customer Data to train or fine-tune AI models.

We do not make decisions about you based solely on automated processing that have legal or similarly significant effects on you. Within the Service, AI output supports decisions but does not make them: our customers' reviewers make every decision.

5. Cookies

6. Who we share personal data with

We share personal data only with the following recipients.

Service providers. These providers process personal data for us under written terms:

ProviderWhat it does for us
Microsoft (Microsoft Azure, including Microsoft Entra ID)Hosts the Service and our website, handles sign-in, and stores data
CloudflareProvides DNS for our domains, and network security and delivery for the Service
GoogleProvides business email and calendar (Google Workspace), demo bookings, and website analytics (Google Analytics)

Other providers that support our security and compliance operations may process limited personal data, such as user account details, for those purposes.

Your organisation. If you use the Service, your organisation can see your account details and your activity in the Service, such as the reviews and decisions you record.

Professional advisers, such as lawyers, accountants and auditors, who are bound by confidentiality.

Authorities, courts or regulators, where the law requires it or where we need to protect our legal rights.

A buyer or successor, if our business is merged, acquired or sold. This policy continues to apply to your data.

The Subprocessors that process Customer Data for our customers are listed in section 10.

7. International transfers

The Service and its data are hosted in the EU, in Microsoft Azure's Sweden Central region. Some of our providers are based in, or process data in, other countries, including the United States. Cloudflare runs a global network, and Google provides our email, calendar and website analytics. Our personnel may also access personal data from outside the European Economic Area (EEA).

When we transfer personal data outside the EEA or the UK, we use one of these safeguards:

To get a copy of the relevant safeguards, contact sam@toven.ai.

8. How long we keep personal data

9. How we protect personal data

The Security Commitments section of our Terms of Service (toven.ai/terms) describes how we protect personal data. The measures include:

If a personal data breach affects data we control, we will notify the relevant supervisory authority and the affected individuals where the GDPR requires it.

10. Customer Data we process for our customers

11. Your rights

Under the GDPR and the UK GDPR, you have the right to:

To exercise these rights, email sam@toven.ai. We may need to verify your identity. We respond within one month. For complex requests, the law allows us to extend this by two further months, and we will tell you if we do. These rights have legal limits, and we will explain if one applies to your request.

You can also complain to a data protection supervisory authority. In the EU, this can be the authority in the country where you live or work, or where you believe the infringement took place. In the UK, it is the Information Commissioner's Office. We would appreciate the chance to address your concern first.

For personal data in Customer Data, please contact the relevant customer (see section 2).

12. Children

Our website and Service are for business use and are not directed at children. We do not knowingly collect personal data from children.

13. Changes to this policy

We publish the current version of this policy at toven.ai/privacy with its version number and date. Before a material change takes effect, we will email our customers' account contacts about it.

14. Contact

Meridien Inc., 2 N 6th St, Brooklyn, NY 11249

Email: sam@toven.ai

We use optional analytics cookies to understand how this site is used. Read our Privacy Policy.