Privacy policy
How Aiva handles your data
Aiva is provided by VERLOX Ltd, a company registered in England and Wales ("VERLOX", "we", "us"). This policy explains what personal data we collect when you use Aiva, why we collect it, who we share it with, and the choices and rights you have, including when you connect a Google or Microsoft account.
Last updated: 11 September 2026.
1. Who this applies to
This policy covers the Aiva product at hireaiva.co.uk and admin.hireaiva.co.uk:
the marketing site, the workspace dashboard, and the underlying AI worker platform. If your
organisation uses Aiva as its "data controller" employer/customer, your employer's own privacy
notice may also apply to how they use Aiva internally; this policy describes what VERLOX
itself does with data as the platform provider.
2. Data we collect
- Account data: name, email address, and password hash (or Google/Microsoft sign-in identifier) when you register a workspace.
- Billing data: plan, invoices, and payment status. Card details are collected and stored by Stripe directly; VERLOX never sees or stores full card numbers.
- Workspace content: the messages, documents, contacts, and other content you or your AI workers create, upload, or process inside Aiva, so the product can do the job you hired it to do.
- Usage and diagnostic data: log-in activity, feature usage, and error/audit logs, used to keep the service secure, reliable, and improving.
- Data from connected accounts: only if you choose to connect one (Google, Microsoft, or another integration); see section 3.
3. Google user data specifically
Aiva offers "Sign in with Google" and an optional "Connect Google" feature. They are separate:
- Sign in with Google requests only your Google account's basic profile (name, email address, profile photo) to create or log in to your Aiva account. We do not read your Gmail, Calendar, Drive, or Contacts to let you sign in.
- Connect Google is a separate, explicit opt-in from inside your workspace. Once connected, Aiva accesses only the specific Google service(s) you authorised (for example Calendar events, Drive files, or Contacts) to perform the feature you asked for: booking a meeting, importing a document, or enriching a contact record. Each scope is requested and shown to you individually on Google's own consent screen before anything is granted.
Aiva's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- Google user data is used only to provide or improve the specific, user-facing Aiva feature you connected it for, never for serving advertisements, and never sold, rented, or transferred to third parties for their own independent use.
- Google user data is not used to train general-purpose or generalised AI/ML models. Where an AI model call is needed to summarise or act on content you connected (for example drafting a reply to an email you asked Aiva to handle), the request is made in service of that specific action you requested, not to build a model.
- Human access to Google user data is limited to what is strictly necessary for security investigations, legal compliance, or with your explicit consent (for example, when you ask support for help troubleshooting a connection).
You can disconnect a Google connection at any time from Settings → Connections inside your workspace, or by revoking Aiva's access directly from your Google Account permissions page. Disconnecting stops future access; see section 6 for how to request deletion of data already imported.
4. Other integrations and sub-processors
We use the following categories of third-party providers to operate Aiva. Each only receives the data it needs to perform its specific role:
- Payments: Stripe, for billing and subscription management.
- AI model providers: the language model providers configured for your workspace, to process the requests and content you send to your AI workers.
- Outbound email delivery: a transactional email provider, for account, billing, and notification emails Aiva sends on your behalf.
- Microsoft (optional): if you connect Outlook/Microsoft 365, the same principles in section 3 apply: access is limited to what you authorised, for the feature you connected it to.
- Cloud hosting and infrastructure: to run the application and store your data securely.
5. Why we process your data
- To provide the Aiva service you signed up for (performance of a contract).
- To keep the platform secure, prevent abuse, and meet legal obligations.
- With your consent, for optional connections (Google, Microsoft, and similar integrations) and optional communications.
- Our legitimate interests in operating, supporting, and improving Aiva, balanced against your rights.
6. Data retention and deletion
We keep workspace and account data for as long as your workspace is active, plus a limited period afterwards to meet legal, billing, and dispute-resolution obligations. You can request deletion of your account and workspace data at any time from Settings inside Aiva, or by emailing [email protected]. Deletion requests are queued and processed; some data may be retained briefly afterwards where the law requires it (for example completed invoices).
7. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion ("right to be forgotten")
- Object to or restrict certain processing
- Request a portable export of your data
- Withdraw consent for anything based on consent, at any time
To exercise any of these rights, email [email protected]. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
8. Security
We apply encryption in transit, access controls, and audit logging to protect your data. See our security page for the current published summary, or email [email protected] to report a vulnerability.
9. International transfers
Some of our sub-processors operate outside the UK/EEA. Where that happens, we rely on appropriate safeguards (such as Standard Contractual Clauses or an equivalent adequacy mechanism) to protect your data.
10. Cookies
Aiva uses essential cookies to keep you signed in and to remember basic preferences. We do not use third-party advertising or cross-site tracking cookies.
11. Children's privacy
Aiva is a business product and is not directed at, or knowingly used to collect data from, children under 16.
12. Changes to this policy
We may update this policy as Aiva changes. Material changes will be reflected by updating the "Last updated" date above; where required by law, we will notify you directly.
13. Contact us
VERLOX Ltd · Email [email protected] · Security reports: [email protected]