Privacy Policy
Toven AI · Version 1.0 · Last updated 25 September 2026
1. Who we are
Toven AI is a trading name of Meridien Inc., a company incorporated in the State of Delaware whose principal office is at 2 N 6th St, Brooklyn, NY 11249 ("Toven", "we", "us"). We provide compliance surveillance software to financial services firms.
This policy explains how we handle personal data in these situations:
- you visit toven.ai;
- you contact us or book a demo;
- you deal with us on behalf of a customer; or
- you use the Toven AI service at compliance.toven.ai (the "Service") as a user at one of our customers.
The Service is hosted in the European Union. We handle personal data in line with the EU General Data Protection Regulation (GDPR) and, where it applies, the UK GDPR.
Questions about this policy: sam@toven.ai
2. Our two roles
When we are the controller. We decide how and why personal data is used for:
- visitors to our website;
- people who contact us;
- our customers' business contacts; and
- users of the Service, meaning their account details and the logs of their activity.
This policy covers that data.
When we are a processor. Our customers load their own records into the Service, such as electronic communications, voice-call transcripts, trade and order records and personnel rosters. These records contain personal data about the customer's employees, clients and counterparties. We call this data "Customer Data". We process Customer Data only to provide the Service, on the customer's instructions and under our agreement with them. The customer is the controller. It is responsible for telling those individuals how their data is used.
If your data is in a customer's records and you want to exercise your rights, please contact that organisation. If you contact us instead, we will pass your request on to them. Section 10 summarises how we handle Customer Data.
3. Personal data we collect as controller
| Category | What it includes | Where it comes from |
|---|---|---|
| Website usage | Pages you view, the page that referred you, approximate location based on your IP address, browser and device type, and Google Analytics cookie identifiers | Your browser, through Google Analytics |
| Network and security data | IP address, request details and timestamps | Your device, through Cloudflare and our hosting provider |
| Enquiries and demo bookings | Name, email address, organisation, role, your message and appointment details | You, by email or through our Google Calendar booking page |
| Account data | Name, work email address, Microsoft Entra ID identifiers, organisation, and roles or group memberships | Your organisation, and Microsoft Entra ID when you sign in |
| Service activity and security logs | Sign-in events, IP address, browser type, and the actions you take and features you use in the Service, with timestamps | Created when you use the Service |
| Customer relationship data | Names and contact details of billing, contract and security contacts, our correspondence with them, and contract and invoicing records | You or your organisation |
We do not seek to collect special categories of personal data, such as health data, as controller.
4. Why we use it and our legal bases
| Purpose | Data used | Legal basis |
|---|---|---|
| Providing the Service and managing user accounts, including sign-in and roles | Account data; Service activity and security logs | Our legitimate interest in providing the Service our customer has contracted for. Where you are personally our customer, performance of our contract with you |
| Protecting the Service and our website, detecting and investigating security incidents, and keeping audit records | Network and security data; Service activity and security logs | Our legitimate interest in keeping our systems and our customers' data secure. Legal obligation where the law requires us to keep records |
| Responding to enquiries and arranging demos | Enquiries and demo bookings | Our legitimate interest in responding to business enquiries. Steps you ask us to take before entering a contract |
| Managing customer relationships: contracts, invoicing, support, and notices about the Service, security and policy changes | Customer relationship data; account data | Performance of a contract. Our legitimate interest in managing the relationship. Legal obligation for tax and accounting records |
| Understanding how our website is used so that we can improve it | Website usage | Your consent where the law requires consent for analytics cookies, as in the EEA and the UK. Elsewhere, our legitimate interest in understanding how our website is used |
| Improving the Service | Service activity logs, but not the content of Customer Data | Our legitimate interest in improving the Service |
| Meeting legal obligations, and establishing, exercising or defending legal claims | Any of the data above, as needed | Legal obligation. Our legitimate interest in protecting our legal position |
We do not sell personal data. We do not use Customer Data to train or fine-tune AI models.
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects on you. Within the Service, AI output supports decisions but does not make them: our customers' reviewers make every decision.
5. Cookies
- toven.ai uses Google Analytics cookies, such as
_ga, to measure visits. You can block or delete cookies in your browser settings. You can also install Google's opt-out browser add-on from tools.google.com/dlpage/gaoptout. - The Service uses cookies that are strictly necessary to keep you signed in and to protect your session.
- Cloudflare may set cookies that are strictly necessary for security.
6. Who we share personal data with
We share personal data only with the following recipients.
Service providers. These providers process personal data for us under written terms:
| Provider | What it does for us |
|---|---|
| Microsoft (Microsoft Azure, including Microsoft Entra ID) | Hosts the Service and our website, handles sign-in, and stores data |
| Cloudflare | Provides DNS for our domains, and network security and delivery for the Service |
| Provides business email and calendar (Google Workspace), demo bookings, and website analytics (Google Analytics) |
Other providers that support our security and compliance operations may process limited personal data, such as user account details, for those purposes.
Your organisation. If you use the Service, your organisation can see your account details and your activity in the Service, such as the reviews and decisions you record.
Professional advisers, such as lawyers, accountants and auditors, who are bound by confidentiality.
Authorities, courts or regulators, where the law requires it or where we need to protect our legal rights.
A buyer or successor, if our business is merged, acquired or sold. This policy continues to apply to your data.
The Subprocessors that process Customer Data for our customers are listed in section 10.
7. International transfers
The Service and its data are hosted in the EU, in Microsoft Azure's Sweden Central region. Some of our providers are based in, or process data in, other countries, including the United States. Cloudflare runs a global network, and Google provides our email, calendar and website analytics. Our personnel may also access personal data from outside the European Economic Area (EEA).
When we transfer personal data outside the EEA or the UK, we use one of these safeguards:
- an adequacy decision, including the EU–U.S. Data Privacy Framework and its UK Extension, where the recipient is certified under it; or
- the European Commission's Standard Contractual Clauses, with the UK Addendum where relevant.
To get a copy of the relevant safeguards, contact sam@toven.ai.
8. How long we keep personal data
- Account data: while your user account is active. When our customer's subscription ends, we delete it with the customer's Customer Data, on the timeline described in section 10.
- Service activity and security logs: as long as we need them for security monitoring, incident investigation and audit obligations. We then delete them.
- Enquiries and demo bookings: as long as we need them to deal with your enquiry and any follow-up. If you become a customer, we keep them as customer relationship data.
- Customer relationship data: for the length of the relationship. After it ends, we keep this data as long as legal, tax and accounting requirements demand, and as long as we need it to deal with any claims.
- Website usage: Google Analytics keeps event-level data for no longer than 14 months. Aggregated reports that do not identify you may be kept for longer.
9. How we protect personal data
The Security Commitments section of our Terms of Service (toven.ai/terms) describes how we protect personal data. The measures include:
- encryption in transit and at rest;
- databases and storage that cannot be reached from the public internet;
- access limited to named personnel who use multi-factor authentication;
- logging and monitoring; and
- vulnerability management.
If a personal data breach affects data we control, we will notify the relevant supervisory authority and the affected individuals where the GDPR requires it.
10. Customer Data we process for our customers
- We process Customer Data only to provide the Service to the customer, on the customer's documented instructions.
- We do not use Customer Data to train or fine-tune AI models. We do not sell it or share it with other customers.
- Customer Data is hosted in the EU, in Microsoft Azure's Sweden Central region.
- Our Subprocessors for Customer Data are:
- Microsoft (Microsoft Azure, including Azure AI Foundry and Azure Databricks), for hosting, storage, AI model inference and data processing; and
- Cloudflare, for DNS, TLS termination and proxying of traffic to the Service.
- If we become aware of a security incident affecting Customer Data, we notify the customer without undue delay.
- We keep Customer Data while the customer's account is active. After the subscription ends, we keep it for 30 days so that the customer can reinstate the account or have the data returned. We then delete it within a further 30 days.
- A customer can ask us to delete Customer Data at any time. We delete it within 30 days of the request, unless the law requires us to keep it.
- Individuals should send requests about Customer Data to the relevant customer. We pass on any such requests we receive.
11. Your rights
Under the GDPR and the UK GDPR, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict how we use your data;
- receive your data in a portable format;
- object to our use of your data where we rely on legitimate interests; and
- withdraw your consent at any time, where we rely on consent. Withdrawing consent does not affect processing that took place before you withdrew it.
To exercise these rights, email sam@toven.ai. We may need to verify your identity. We respond within one month. For complex requests, the law allows us to extend this by two further months, and we will tell you if we do. These rights have legal limits, and we will explain if one applies to your request.
You can also complain to a data protection supervisory authority. In the EU, this can be the authority in the country where you live or work, or where you believe the infringement took place. In the UK, it is the Information Commissioner's Office. We would appreciate the chance to address your concern first.
For personal data in Customer Data, please contact the relevant customer (see section 2).
12. Children
Our website and Service are for business use and are not directed at children. We do not knowingly collect personal data from children.
13. Changes to this policy
We publish the current version of this policy at toven.ai/privacy with its version number and date. Before a material change takes effect, we will email our customers' account contacts about it.
14. Contact
Meridien Inc., 2 N 6th St, Brooklyn, NY 11249
Email: sam@toven.ai