Privacy

Not yet reviewedThis page was drafted by the engineering team, not by a lawyer. It describes what this website actually does, accurately and in plain language, but it has not been reviewed by a qualified adviser and it is not legal advice. Anything still marked below needs a real answer before this goes live. Remove this note once the page has been reviewed.

What this site collects, and what happens to it.

Three things on this site collect information: the assistant, the message form and the booking flow. This page describes each one specifically — what is stored, where it goes, who can read it and what you can ask us to do about it.

Draft last edited 3 August 2026Applies to this website only

Who we are

AivoraLabs is an engineering studio. This policy covers this website — aivoralabs.tech — and nothing else.

It does not cover software we build for clients. Those systems are operated by the client under the client's own policies, and are governed by the agreement for that engagement.

The legal entity responsible for this site is To fill: registered company name, registration number and registered address. For anything on this page, write to info@aivoralabs.tech.

To fill: whether a data protection officer or a named privacy contact is required in your jurisdiction, and who it is

The assistant

The assistant is the single largest collector of information on this site, so it is described first and in the most detail. It is an automated chat window; it is not a person, and it is not monitored live.

What is stored when you use it

The conversation
Every message, yours and the assistant's, is stored on our servers in full and can be read afterwards by studio staff.
A session id
A random identifier that links your messages together. It is kept in your browser so a reload does not lose the conversation — see Cookies and local storage.
Context about the visit
The page you started the conversation from, the page that referred you here, your browser's user-agent string, your browser's time-zone name, and a hashed form of your IP address.
Details you volunteer
Your name, email address and company, whether you type them into the small form the assistant sometimes shows or simply mention them mid-conversation.

Your messages are sent to a third-party AI provider

To produce a reply, we send your message, the recent turns of the same conversation, our own instructions to the assistant and passages from our published pages to a third-party AI provider over the internet. That provider processes this on our behalf. We do not send it your email address, your hashed IP or your CRM record — but if you type personal details into the chat, those details are part of the message and are transmitted with it.

So: please do not put anything confidential, sensitive, or belonging to somebody else into the assistant. If you need to discuss something under NDA, email info@aivoralabs.tech or book a call instead.

To fill: the provider's own retention and training terms, once the account plan is confirmed — state here whether conversations are retained by them and for how long

The assistant reads your replies for contact details

You do not have to fill in a form for us to record who you are. Our software scans the messages you send for a name, an email address and a company name, and writes what it finds to the record described below. If you give a work email address, the company may be inferred from its domain; personal mailbox domains are ignored. We store the phrase that triggered each match, so a human can check the record against what you actually said.

We also derive a simple interest score from behaviour — whether an email was given, whether a company is known, which service you asked about, how long the conversation ran, and whether a call was booked. It is used internally to decide who to follow up with first. It has no legal or contractual effect, and no decision about you is made automatically without a person involved.

The message form and the booking flow

Sending a message

The message form on the contact page asks for your name, your email address and your message; company and topic are optional. There is also a hidden field no human can see — it exists to catch automated spam, and submissions that fill it in are kept and flagged rather than deleted, so the filter can be tuned.

Along with what you type, we store the page you sent it from, the page that referred you, your browser's user-agent string, your browser's time-zone name and a hashed form of your IP address. Your message is emailed to the studio, and you may receive an automatic acknowledgement at the address you gave.

Booking a call

Booking asks for your name, your email address, and optionally your company and a note about what you want to discuss. We also store the meeting type and time you chose, your browser's time-zone name so we can show times in your local zone, and a hashed form of your IP address. If you started in the assistant, the booking is linked to that conversation.

The booking form carries the same hidden anti-spam field as the message form, with the same consequence: a submission that fills it in is kept and flagged rather than deleted.

You get a confirmation email containing a cancellation link. That link carries a secret token which stays valid until the booking is over, and anyone holding it can cancel the booking — so treat the email as private.

What we do not collect

This site has no analytics, no advertising tags, no social media pixels and no third-party trackers. Simply reading these pages does not create a record of you.

We record technical details of a visit only when you send something — a chat message, a form submission, a booking. There is no background collection otherwise.

This site also sets no cookies of its own. The full detail, including the two browser storage keys the assistant does use, is on the Cookies and local storage page.

How we handle IP addresses

We never store your IP address. When you submit something, the address is combined with a secret value and put through a one-way hash, and only that hash is written to the database. It lets us recognise repeat submissions from the same source and enforce rate limits without keeping the address itself.

Rotating the secret makes every stored hash permanently unlinkable to any address, by design.

The record we keep about you

Conversations, messages and bookings all resolve to one record per person, so the studio sees a single history rather than three disconnected fragments. Where the same email address comes back through a different route, the older record is merged into it.

That record can hold:

  • Identity — name, email address, company and, if you provide one, a phone number.
  • Context — how you first reached us, which service you asked about, what kind of engagement you were considering, and your time zone.
  • History — a timeline of your conversations, messages and bookings, with the full transcript of each conversation attached.
  • Internal working notes — a follow-up stage, tags, the interest score described above, and notes written by studio staff. These are never shown to you on the site.
  • Marketing consent — off unless you actively tick it. The tick box is separate from giving us your email, and is never pre-ticked.

Studio staff can export a summary of these records — name, email, company, stage, source, owner, interest, score, tags and dates — to a spreadsheet file for internal work. Transcripts, messages and internal notes are not part of that export.

Who can see it

Studio staff. Authorised people at AivoraLabs, through a password-protected admin application with separate read-only and full-access roles. Notifications about new messages and bookings are also emailed to studio addresses, and those emails contain what you sent.

Service providers acting for us. The third-party AI provider that generates the assistant's replies, the service that delivers our email, and the infrastructure the site and database run on. Loading this site also requests a web font from a third-party font service, which necessarily sees your IP address and browser — that request sets no cookie.

Nobody else. We do not sell your information, we do not rent it, and we do not share it for anyone else's advertising. We would disclose it if a valid legal obligation required us to.

To fill before publishing — sub-processor listList every third party that processes visitor data here before publishing, with what each one does, where it processes data, and the link to its own terms. At minimum that means: the AI provider behind the assistant, the email delivery service, the hosting and database provider, and the web-font service. Also record whether data leaves your visitors' region and on what basis.

How long we keep it

Honestly: nothing on this site deletes itself yet. There is no automatic expiry job. Conversations, messages, bookings and the record described above are kept until someone at the studio deletes them, or until you ask us to.

The one exception is in your own browser: the copy of the conversation kept there is ignored after twelve hours, and clearing it is described on the Cookies and local storage page.

We would rather state that plainly than publish a retention period the software does not actually enforce.

To fill before publishing — retention scheduleDecide how long each kind of record should be kept — chat transcripts, contact messages, bookings, prospect records, outbound email logs — and state the periods here. Then have the schedule implemented so the page describes what the system does rather than what someone intends.

Your choices

You can ask us to:

  • Show you what we hold — a copy of your record, including any chat transcripts linked to it.
  • Correct it — particularly useful if the assistant read a name or company out of a message and got it wrong.
  • Delete it — the record, the messages and the transcripts, unless we have to keep something to meet a legal obligation.
  • Stop contacting you — including withdrawing marketing consent, which you can do at any time and which does not affect anything sent before.

Email info@aivoralabs.tech. So we can find the right record, please write from the address you used, or quote the reference number from your confirmation email.

You can also simply avoid the collection: the assistant is optional, and you can reach a person directly by email or on WhatsApp (+92 334 521 1879) without using it.

To fill before publishing — statutory rights and complaintsDepending on where your visitors are, they may have specific legal rights and a right to complain to a supervisory authority. Once the operating jurisdiction is confirmed, name the applicable law here, state the lawful basis relied on for each purpose above, name the relevant authority and give the response deadline you commit to. Do not claim compliance with any regime until that has been checked.

How it is protected

What is in place today, stated as fact rather than as reassurance:

  • Traffic to this site and its API travels over HTTPS, so what you send is encrypted in transit. That one rests on how the site is deployed rather than on the code, and it is the only item in this list that does.
  • IP addresses are hashed before storage and never written down raw.
  • The admin application requires a login, separates read-only from full access, and keeps its session credential out of reach of page scripts.
  • Public submission endpoints are rate-limited, and spam submissions are flagged rather than silently accepted.
  • The credentials for the AI provider live only in server configuration; they are not stored in the database and are never rendered by any screen.

No system is perfectly secure, and we make no claim to hold any security certification. If you believe you have found a vulnerability, email info@aivoralabs.tech and we will respond.

Children

This is a business-to-business site. It is not directed at children, and we do not knowingly collect information from anyone under 16. If you believe a child has sent us something, email info@aivoralabs.tech and we will delete it.

Changes to this page

When what the site collects changes, this page changes with it, and the date at the top is updated. There is no version history here yet.

To fill: decide whether material changes will be notified to people already in the CRM, and how