Privacy noticeLast updated 2026-08-24

AYVES Privacy Notice

Draft v1.0 — for AYVES BV review and adoption. Effective date: [date of adoption] · Version: 1.0 · Last updated: 24 August 2026

This is a working draft prepared by the company for its own review and adoption. It has not been reviewed by external counsel. Placeholders in [square brackets] mark facts to be confirmed before publication.

This notice explains how AYVES BV processes personal data in connection with the AYVES platform. It is written to serve two audiences at once:

  1. Customers and their users — the institutional investors, asset managers, pension funds and stewardship teams who hold accounts on AYVES; and
  2. Individuals recorded in the company-research database — company directors and officers whose professional roles are recorded from public filings and public registers, and individuals whose names appear in public sanctions lists, the ICIJ offshore-leaks database, or public litigation records, where these have been matched to a company we analyse.

If you are in the second group and did not give us your data directly, Section 5 (How we handle data about company directors and officers) is written specifically for you and explains the legal basis on which we hold it, how to object, and how to ask for correction.


1. Who we are (the controller)

AYVES BV ("we", "us", "AYVES BV") operates the AYVES platform and is the data controller for the processing described in this notice.

Legal entity AYVES BV
Registered office [AYVES BV registered office address, Eindhoven, Netherlands]
Chamber of Commerce (KvK) number [AYVES BV KvK registration number]
Product/brand AYVES
Privacy contact [privacy contact email — e.g. privacy@ayves.example]
Postal contact for privacy matters [AYVES BV privacy postal address]

AYVES BV has not appointed a statutory Data Protection Officer under Article 37 GDPR at this stage. Our assessment is that our core activities do not, at present, meet the Article 37(1) triggers (they do not consist of large-scale systematic monitoring, and special-category processing is not our core activity). We keep this assessment under review as the platform grows. All privacy queries reach a named internal owner at the contact above. [Confirm DPO assessment on adoption; appoint and name a DPO here if the position changes.]

Where we act as a processor rather than a controller — that is, when we process your own account and account-content data on your documented instructions under a customer agreement — the terms of our Data Processing Agreement apply, and this notice describes that processing for transparency. The distinction between where we are a controller and where we are a processor is set out in Section 4.


2. What AYVES is (so the processing makes sense)

AYVES is a research platform: an evidence-grade record of companies' tax-risk, read from publicly filed corporate disclosures — principally public Country-by-Country Reports (CbCR) — through versioned, published methodologies. Every figure is cited to its source document, and every rating is a deterministic arithmetic function of the published data, not a subjective judgement and not the output of an AI model.

AYVES is a reading of public disclosures. It is not tax advice, legal advice, investment advice, or an allegation of wrongdoing about any company or person.

Understanding this matters for privacy because it explains why we hold the two very different categories of personal data described above, and why the data about company officers is held at the level of their professional role rather than as a personal profile.


3. The personal data we process, and where it comes from

We group the personal data we process into two streams.

3.1 Customer account and usage data (you gave this to us, or it arises from your use)

Category Examples Source
Identity and contact Name, email address, optional profile image You, at sign-up (magic-link)
Organisation and role Employer/organisation, team membership, invitation email of colleagues you invite You / your organisation's administrator
Account and security Account status, session records, sign-in events, coarse device/user-agent string, a salted hash of your IP address (sha256(ip + daily salt)), session epoch Generated by the service when you use it
Usage and content you create Portfolios and holdings you upload (ISIN/LEI/ticker + optional weights), watchlists, entity notes, monitor and notification rules, briefings, saved threshold profiles, engagement cases and dialogue logs you author, corrections and coverage requests you submit, filings you upload You, through use of the platform
AI usage counters Daily analysis quota counters, per-analysis cost accounting Generated by the service
Bring-your-own-key credentials Encrypted third-party AI provider API keys (AES-256-GCM at rest) You, if you choose BYOK
Billing Tier, paid-until date, payment records (amount, currency, method, payment reference), a payment-provider customer identifier, signup country You + our payment processor (Section 6)

We do not collect your card number. Card data is entered directly into our payment processor's hosted payment surface and never reaches AYVES servers (Section 6).

3.2 Company-research data, including personal data about company officers and named individuals

To build the company-research record, we process, at the level of the company entity and the professional role, the following personal data drawn from public sources:

Category Examples Source
Officer/director records Full name, function label, city and country of the role, the entity and role held, and the period held Public corporate filings and public company registers
Role timeline Dated professional events (appointment, resignation) with the public source noted Public registers / filings
Public-list name matches Matches of an officer's or entity's name against public sanctions lists, the ICIJ offshore-leaks database, and public litigation dockets (court, docket number, parties) The public lists and public court records named

This data is deliberately narrow. We do not hold home addresses, personal telephone numbers, personal email addresses, dates of birth, political opinions, social-media feeds, or any personal-dossier field about these individuals. We do not score individuals. Every screen that shows a named individual carries a fixed banner making clear the record is a professional, entity-level substance signal and not a personal dossier.

Section 5 explains the legal basis for this stream in full, because most of these individuals did not give us their data directly.

3.3 What we do not do

  • We do not sell personal data.
  • We do not use personal data for behavioural advertising.
  • We do not build personal profiles of company officers, and we do not rate individuals.
  • We do not carry out automated decision-making that produces legal or similarly significant effects on any person (Section 11).

4. Purposes and lawful bases

The table below sets out, for each purpose, the lawful basis under Article 6 GDPR and whether we act as controller or processor.

Purpose Personal data used Lawful basis (Art 6 GDPR) Our role
Create and operate your account; authenticate you (magic-link) Identity, contact, account/security 6(1)(b) performance of a contract Controller (of account data)
Provide the research features you use (analyses, portfolios, watchlists, monitors, engagement workspace, exports) Usage and content you create 6(1)(b) performance of a contract Processor, on your instructions (see DPA); controller for account-level records
Take payment and keep financial records Billing, payment records 6(1)(b) contract; 6(1)(c) legal obligation (fiscal record-keeping) Controller
Secure the service, prevent abuse, enforce rate limits Account/security, IP hash, usage counters 6(1)(f) legitimate interests (security and integrity of the service) Controller
Send service and transactional email (sign-in, corrections status, alerts, digests you configured) Contact, the content of the message 6(1)(b) contract; 6(1)(a) consent for optional digests Controller / Processor as applicable
Build and maintain the company-research record from public disclosures Officer/role records, public-list matches 6(1)(f) legitimate interests (Section 5) Controller
Maintain an audit trail and reproducibility record of every analysis Analysis records, agent-invocation and model-call logs 6(1)(f) legitimate interests (evidential integrity, defensibility, corrections) Controller
Cookie/consent record-keeping Consent events 6(1)(c) legal obligation (ePrivacy/PECR record) Controller
Optional analytics and error tracking See Section 6 and our cookie notice 6(1)(a) consent Controller

The key distinction: for the company-research database (public-company and officer data), AYVES BV is an independent controller — we decide the purposes and means, and customers cannot instruct us to change the shared record. For your own account and the content you create in it, AYVES BV acts largely as a processor on your documented instructions, governed by the DPA.


5. How we handle data about company directors and officers (Article 14)

Most individuals recorded in the company-research database did not give us their data directly. GDPR Article 14 applies. This section is our Article 14 disclosure to those individuals.

What we hold and where it comes from. As set out in Section 3.2: your name, professional function, the entity and role you hold or held, the city/country of the role, a dated role timeline, and any match of your name against public sanctions lists, the ICIJ offshore-leaks database, or public litigation records. The sources are public corporate filings, public company registers, the public lists named, and public court records. We do not obtain this data from you and we do not enrich it with private or contact information.

The purpose. We record this data so that institutional investors and their stewardship teams can understand the tax-governance profile of the companies they own or research. Company officers hold their roles in a public, professional capacity in large multinational groups; the identity and continuity of who holds which role is a substance-and-governance signal about the company, not a comment about the individual.

The lawful basis: legitimate interests, Article 6(1)(f). Our legitimate interest, and the legitimate interests of our institutional customers, is enabling responsible-investment, stewardship and tax-governance analysis of large listed companies using information those individuals hold in a professional and already-public capacity.

Legitimate-interests balancing (summary of our LIA). We have weighed our interest against your rights and freedoms and consider the balance is met, for these reasons:

  • Public and professional in nature. The data concerns your professional role and is already published in official registers and filings. It is not private-life data.
  • Data minimisation. We hold role-level fields only — no home address, no personal contact details, no date of birth, no profiling of you as an individual. Public-list matches are held as neutral annotations, hedged, and are never used to rate you.
  • No decision about you. We do not score individuals and we take no automated decision about you. The signal is about the company entity.
  • Framing and safeguards. Every surface showing a named individual carries a governance banner stating the record is entity-level and not a personal dossier. Narrative language is hedged and passes an accusatory-language filter.
  • Limited retention. Officer/role and public-list data are retained on a rolling basis and removed when no longer refreshed from the source (Section 8).
  • Your controls. You can object and ask for correction or erasure (below and Section 9).

A fuller internal Legitimate Interests Assessment is maintained per source. You may request a summary at the privacy contact in Section 1. [Confirm the LIA registers at docs/public/legal/lia-person-data.md and per-source LIAs are complete before publication.]

Where any data relates to sanctions, offences or litigation. Matches to public sanctions lists, the ICIJ offshore-leaks database, and public litigation dockets are drawn only from information already made public by the relevant authority, publisher or court. We hold them as neutral, hedged context that annotates the company record; they never drive a rating. [Where any such data amounts to personal data relating to criminal convictions or offences (Article 10 GDPR), confirm the Member-State legal basis relied on before publication — see the regulatory-position memo, Section (c).]

Your rights, and how to exercise them. You have the right to object to this processing on grounds relating to your particular situation (Article 21), and the rights of access, rectification, erasure and restriction (Section 9). Because our processing rests on legitimate interests, if you object we will stop unless we can show compelling legitimate grounds that override your interests, rights and freedoms. For a correction to a professional record, our corrections process (Section 9.3) is usually the fastest route. Contact us at the privacy contact in Section 1.

Article 14 timing and the "disproportionate effort" position. We cannot practically contact every officer named in public filings individually, and doing so would in most cases be impossible or involve disproportionate effort within the meaning of Article 14(5)(b). We therefore rely on this published notice as our Article 14 disclosure, keep the data minimised and public-sourced, and make the objection and correction routes easy to use.


6. Recipients and sub-processors

We share personal data with a small set of service providers ("sub-processors") who process it on our behalf, and with the parties below. Our current sub-processor register is published and version-controlled; it is the authoritative, up-to-date list and includes each provider's purpose, the personal-data scope, the processing region, and the transfer mechanism where relevant.

Authoritative register: the AYVES sub-processor register (maintained in the product and published on the sub-processor page; source of record src/data/subprocessors.ts). We update it in the same change as any addition, removal or region change, and publish a change-log entry.

At the date of this draft, the register includes:

Provider Role Region
Scaleway Cloud hosting of the application, database and workers Amsterdam, Netherlands (EU)
PostgreSQL (self-hosted on Scaleway) Primary database, inside our own VM Amsterdam, Netherlands (EU)
MiniMax AI provider A — figure extraction and narrative generation People's Republic of China
Zhipu GLM AI provider B — standby/divergence-check extraction and narrative People's Republic of China
Mollie Payment processing Amsterdam, Netherlands (EU)
Resend Transactional email EU (Frankfurt)
Sentry Error tracking (consent-gated) EU (Frankfurt)
Umami Cookieless page analytics (consent-gated) EU (self-hosted candidate)
Uptime Kuma Uptime monitoring EU

We also disclose personal data to professional advisers, auditors, and authorities where we are legally required to do so. We do not otherwise disclose personal data to third parties, and we do not sell it.


7. International transfers

Our infrastructure, database, payment processing and email are located in the EU/EEA.

The exception is our AI providers. AYVES uses large-language-model providers to extract figures from filing PDFs and to draft narrative. At the date of this draft, the active and standby AI providers (MiniMax and Zhipu GLM) are established in the People's Republic of China, a country without an EU adequacy decision. This means a transfer to a third country under Chapter V GDPR takes place for that processing.

We handle this transfer as follows, factually:

  • What is transferred. Only the plain text extracted from the uploaded filing PDF is sent to the AI provider. The raw PDF bytes are never sent. Filings are public corporate disclosures. Customer account data, billing data and the officer/person database are not sent to the AI providers.
  • Transfer mechanism. We rely on the European Commission's Standard Contractual Clauses with the provider, together with our own technical and organisational measures.
  • Operational control. The active AI provider can be switched at runtime from our admin panel without redeploying the service, which lets us respond quickly if transfer risk changes.
  • Planned move. We intend to move AI inference to EU-hosted or self-hosted infrastructure. An EU-hosted adapter is on our roadmap as the standing fallback and would remove this third-country transfer for the AI stage when adopted.

You may request a copy of the relevant transfer safeguards at the privacy contact in Section 1.


8. How long we keep personal data (retention)

Our full retention schedule is maintained internally (data-management strategy, INFRA-01). The principal periods are:

Data Retention
Uploaded PDF bytes Held in memory only during extraction; unlinked within seconds of processing (never stored)
Your account and the content you create (portfolios, watchlists, notes, monitors, briefings, engagement records, analyses) For the life of your account; deleted on account closure, subject to the deliberate retentions below
Anonymous mini-analyses 7 days from creation, then hard-deleted
Anonymous rate-limit counters (IP hash) 30 days; the IP salt rotates daily
Analysis audit + reproducibility records (analysis records, model-call and agent-invocation logs) Retained for evidential integrity and reproducibility; per-call logs are kept for 24 months, then aggregated to monthly totals
Payment records 7 years, to meet Dutch fiscal record-keeping obligations
Cookie/consent records 24 months, rolling
Company-research officer/role records and role timeline 24 months rolling from when the record was last refreshed from its public source
Public-list matches, news/signal annotations, litigation records 24 months, rolling
Encrypted backups Rotating: 30 daily, 12 monthly, 5 yearly. Deleted data can persist in backups until the relevant backup expires

Deliberate retentions after account erasure. When you close your account and ask us to erase your data (Section 9), we hard-delete or de-identify your personal data, but we deliberately retain, with a documented basis:

  • Analysis, model-call, agent-invocation and analysis-audit records — for the integrity, reproducibility and auditability of analyses (Article 6(1)(f)); these are de-linked from your identity where possible.
  • Payment records — for the statutory Dutch fiscal-retention period (Article 6(1)(c)).

These retentions are implemented in our erasure routine and are the only categories that survive an erasure request.


9. Your rights and how to exercise them

Under the GDPR you have the rights to access, rectification, erasure, restriction, data portability, and to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time without affecting prior processing.

9.1 Self-service tools for account holders

For your own account, AYVES provides in-app tools:

  • Export — download a machine-readable copy of your account data and the content you have created (portability, Article 20).
  • Delete my account — a self-service erasure flow that runs our erasure routine (otus_delete_user_data). It hard-deletes or de-identifies your personal data across the platform (including your bring-your-own-key credentials, notes, portfolios, watchlists, monitors, briefings, engagement content, private annotations, and live share links), detaches your identity from any shared-record entries that survive, and scrubs your identity fields from the account record. The deliberate retentions in Section 8 apply.

9.2 Requests you make to us directly

For any right, or if you cannot use the self-service tools, contact the privacy contact in Section 1. We respond within one month (extendable by two further months for complex requests, with notice). We may need to verify your identity first.

9.3 Corrections to the company-research record (including officer data)

If you are a company officer, or a company acting through a verified representative, and you believe a professional record about you or your company is inaccurate, our corrections process is the route:

  • Corrections are submitted through the corrections channel [in-app corrections channel / corrections contact email].
  • We verify the requester's identity (for a company issuer, via corporate-domain match and call-back) before the response clock starts.
  • Our target response time is 10 business days. This is a service target, not a contractual guarantee.
  • Corrections are audit-trailed, and outcomes to a published record are reflected in the record.

This process sits alongside your statutory rights of rectification and objection; using it does not waive them.

9.4 The right to complain

If you have a concern we have not resolved, you may lodge a complaint with the Dutch supervisory authority:

Autoriteit Persoonsgegevens (AP) — Postbus 93374, 2509 AJ Den Haag, Netherlands — autoriteitpersoonsgegevens.nl.

You may also complain to the supervisory authority in your country of residence or work. We would, of course, prefer the chance to resolve it first.


10. How we protect personal data

Our technical and organisational measures include: encryption of data at rest and in transit; envelope-encryption of secrets and bring-your-own-key credentials (AES-256-GCM); role-based access control with a restricted, IP-allowlisted, fresh-session-gated admin surface; an append-only administrative audit log; salted hashing of IP addresses; isolation of PDF extraction in a network-isolated subprocess; nightly encrypted backups with a weekly restore-verification drill; and cross-provider checks that hold uncertain analyses for human review rather than releasing them. These measures are described further in our Data Processing Agreement, Schedule 2.


11. Automated decision-making and AI

We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you (Article 22 GDPR).

To be precise about the role of AI in AYVES:

  • Figure extraction is AI-assisted but human-gated. Large-language models help structure the figures in a filing, but every figure is cross-validated against the source text at the character-span level, and a human confirms the figures in an editable review table before any analysis runs. The model never has the last word on a number.
  • Ratings are deterministic arithmetic, not AI. Company ratings are pure, published, deterministic functions of the confirmed figures. They are not model outputs and do not vary between runs.
  • News classification only suggests; a human grades. An AI news-classifier may suggest a marker for a public news item, but nothing becomes visible on a customer surface until a human operator grades it. The suggestion is provenance-stamped and never touches the rating path.
  • AI-assisted artifacts are labelled. Where AYVES presents AI-generated narrative, it carries an EU AI Act Article 50 transparency label indicating it is AI-generated and reviewed under the stated methodology version.

Because ratings are deterministic and every AI-assisted step is gated by a human, no output of AYVES is a solely-automated decision with legal or similarly significant effect on an individual.


12. Changes to this notice

We may update this notice as the platform and our processing change. We will change the version number and the "last updated" date, and, for material changes, take reasonable steps to bring the change to the attention of account holders. The sub-processor register carries its own change-log.


AYVES BV · AYVES · Privacy Notice · Draft v1.0 · 24 August 2026.