1. Scope and Roles
1.1 Controller. Unless a separate enterprise agreement states otherwise, the controller responsible for processing consumer personal information is SZ SYLVOL Technology Co., Ltd., located at Room 1014B, Building 10A, Shenzhen Bay Science and Technology Ecological Park, No. 10 Gaoxin South 9th Road, High-Tech Zone Community, Yuehai Subdistrict, Nanshan District, Shenzhen, China. Where a regional representative must be appointed, see Section 14.
1.2 Scope. This Policy applies to our consumer apps, web experiences, connected devices, account services, AI processing, subscriptions, and customer support. Separate notices may apply to applicants, employees, enterprise customers, or testing programs.
1.3 Enterprise Use. If an organization provides your account and acts as the controller, we may process data as its processor or service provider under a separate agreement. In that case, the organization's privacy notice may govern certain rights and instructions.
2. Information We Collect
We collect information you provide, information generated as you use the Services, and limited information from third parties. Depending on the features you use, categories may include:
- Account and profile information: email address, account identifiers, authentication records, nickname, avatar, and selected country, region, and language.
- Device and binding information: device model, serial number or device identifier, firmware version, battery condition, storage status, Bluetooth or network status, binding history, and diagnostic identifiers.
- Audio and imported files: recordings created using AIVIZA Note or AIVIZA, files you import, and associated timestamps or file metadata.
- Transcripts, summaries, and AI interactions: transcript text, speaker labels, summaries, notes, prompts, template selections, AI chat inputs, and generated outputs.
- Subscription information: plan type, Pro or Advanced status, purchase channel, entitlement status, renewal status, start and end dates, redemption codes, transaction identifiers, and limited billing metadata. App stores generally process full payment-card details themselves.
- Support information: communications with customer support, troubleshooting details, order or device information, files you choose to submit for diagnosis, and disclosed recordings of phone or chat support interactions.
- Usage and diagnostic information: feature interactions, timestamps, app version, crash logs, performance metrics, IP address, approximate region inferred from IP, operating system, and device type.
- Website and commercial information: website activity, cookie identifiers, order and shipping details, product reviews, preferences, and marketing interactions where applicable.
- Permission-based data: access to the microphone, local files, photos or camera, contacts, calendar, notifications, Bluetooth, nearby devices, or other device permissions only where needed for a requested feature and controlled by the operating system.
We do not intentionally request government identification, financial-account credentials, health records, or other highly sensitive data in ordinary consumer use. Recordings and transcripts may, however, contain sensitive or personal information spoken by participants. You control what you record and upload.
3. How We Use Information
- provide, synchronize, and maintain the Services and your account;
- pair and manage AIVIZA Note, deliver firmware, and troubleshoot device issues;
- transcribe audio and generate summaries and other requested AI outputs;
- manage Pro and Advanced plans, entitlements, trials, redemptions, and renewals;
- verify users, prevent abuse, detect fraud, and protect account and service security;
- provide customer support and investigate issues reported by users;
- measure reliability, diagnose crashes, and improve product performance;
- meet legal obligations, enforce our terms, and respond to valid legal process; and
- send product updates or marketing communications that you can opt out of, where we have consent or the law otherwise permits.
4. Legal Bases for Processing
In regions where the GDPR, UK GDPR, or similar laws require a legal basis for processing, we generally rely on performance of a contract to provide requested Services; legitimate interests such as security, fraud prevention, and service improvement where those interests are not overridden; consent for optional permissions or marketing where required; and compliance with legal obligations. Processing sensitive data may require additional lawful conditions depending on the content and jurisdiction.
5. Audio, Transcription, and AI Processing
5.1 Local and Cloud Processing. Recordings may initially be stored on AIVIZA Note, your mobile device, or both. When you request cloud synchronization, transcription, summarization, or other online AI features, relevant content may be securely transmitted to our cloud infrastructure and approved third-party service providers to fulfill the request. Optional end-to-end protection applies to Content stored on our servers; it does not mean that requested cloud AI processing can occur while Content remains encrypted throughout processing.
5.2 Cloud and AI Providers. Production uses Amazon Web Services (AWS) infrastructure and Amazon S3 for cloud hosting and object storage, Amazon Transcribe / Amazon Bedrock for ASR and related speech processing, and OpenAI for LLM features. We send only the data necessary to provide the function you request.
5.2.1 App Stores. If you purchase or manage a subscription through the Apple App Store, Apple processes app distribution, purchase, subscription, transaction-identifier, and billing-related information under its own terms and privacy policy. Recordings, transcripts, summaries, prompts, and other User Content are not provided to Apple as a result of an App Store purchase.
5.3 Provider Management. AWS has passed our vendor qualification, security, and privacy review and is subject to applicable contractual and data-protection arrangements. The current production environment does not use another cloud, transcription, model-routing, or generative-AI content processor. See the public service-provider list for specific services and processing locations.
5.4 Provider Retention, Deletion, and Training. We do not use User Content to train AIVIZA's own general-purpose models and do not permit production processors to use User Content to train general-purpose models. AWS Amazon Transcribe / Amazon Bedrock provide ASR and related speech processing; OpenAI is used only for LLM features. We do not use User Content to train AIVIZA's own general-purpose models. Deletion follows the 90-day and up-to-30-additional-day periods in Section 8 and is transmitted to AWS or OpenAI where applicable.
5.5 Personnel Access. Personnel should not routinely listen to or read User Content. Authorized personnel may access limited data only where needed for support you request, security or incident investigations, legal compliance, or other documented operational purposes, subject to access controls and logging.
5.6 Speaker Labels and Self Voiceprint. Ordinary speaker separation creates anonymous labels only within one recording and does not create a cross-recording voiceprint database. The optional Self Voiceprint feature is off by default and is limited to identifying the account holder. Voice samples, features, and matching indexes are extracted, verified, stored, and deleted only on the device and are not uploaded to the cloud. Disabling the feature, withdrawing permission, or deleting the last sample deletes the local voiceprint data.
6. Sharing and Subprocessors
We do not sell your recordings or transcripts as ordinary commercial inventory. We may disclose personal information to the following categories of recipients only where reasonably necessary and subject to appropriate safeguards:
- cloud hosting, storage, and infrastructure providers;
- speech-to-text, language-model, model-routing, and other AI providers used to deliver requested features;
- analytics, crash-reporting, security, communications, and customer-support providers;
- payment processors, Apple App Store, Google Play, and other commercial service providers;
- professional advisers, auditors, insurers, and corporate service providers subject to confidentiality obligations;
- affiliates or successor entities in connection with a merger, financing, acquisition, reorganization, or asset transfer, as permitted by applicable law; and
- law enforcement, courts, regulators, or other parties where disclosure is legally required or reasonably necessary to protect rights and safety.
See the current service-provider and processing-location list
7. International Transfers and Data Residency
7.1 Data Residency. Our production data is primarily processed and stored in the United States. Processing locations and retention rules for backups, logs, disaster recovery, and entrusted service providers may vary by feature, region, and configuration.
7.2 Cross-Border Transfers. Personal information may be processed outside your country of residence. Where required by law, we use recognized transfer mechanisms such as adequacy decisions, standard contractual clauses, the UK international data-transfer addendum, or other legally valid safeguards.
7.3 Regional Routing. If region-specific storage is offered, such as for the European Union, United States, Asia-Pacific, or Japan, exact routing and exceptions will be stated here only after the infrastructure has been verified.
8. Data Retention and Deletion
8.1 General Rule. We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including providing the Services, maintaining security, resolving disputes, and meeting legal obligations. User Content is retained for 90 days by default. After expiration or deletion, copies may remain in deletion queues and backups for up to 30 additional days.
8.2 User Content. Audio, transcripts, summaries, and notes are generally retained for 90 days from creation or upload; you may delete them sooner. After deletion, backups and technical deletion queues may retain copies for up to 30 days, except where retention is legally required. Where applicable, we will transmit deletion requests to providers that process the relevant User Content; residual copies subject to a provider's technical process and applicable law will be deleted or isolated under the applicable data-processing arrangement.
8.3 Account Deletion. After receiving a valid account-deletion request, we aim to complete deletion within 30 days, except where retention is required by law or necessary for fraud prevention, security, dispute resolution, or another lawful purpose. Account deletion does not itself withdraw processing instructions made by an enterprise customer acting as controller; deletion, return, and retention for enterprise accounts are governed by the applicable enterprise agreement or data-processing agreement.
8.4 De-identification. Where permitted by law, we may retain information that has been irreversibly anonymized so that it can no longer identify an individual.
9. Security
We implement technical and organizational safeguards appropriate to the nature and risk of the data. These may include encryption in transit and at rest, access controls, least-privilege administration, logging, secure-development practices, monitoring, vulnerability management, backups, and incident-response procedures. Public statements about actual security measures must match verified implementation.
No system can guarantee absolute security. You are responsible for protecting account credentials, keeping devices secure, and promptly reporting suspected compromise to support@aiviza.ai.
10. Your Privacy Rights
Depending on where you live, you may have the right to request access, correction, deletion, portability, restriction of or objection to processing; withdraw consent; opt out of certain targeted advertising or sale or sharing concepts where applicable; and appeal certain privacy decisions. You may submit a request at support@aiviza.ai. We do not currently provide a separate participant notice webpage; a recorded participant without an account may also use this email to make a request concerning their personal information.
We may need to verify your identity before processing a request. An authorized agent may act for you where the law permits and required proof is provided. We will not discriminate against you for exercising applicable privacy rights.
11. Account Deletion and Withdrawal of Consent
You may request account deletion by emailing support@aiviza.ai. You may also use in-app controls, where provided, to delete recordings, revoke device permissions, disable optional synchronization, or close your account. Revoking operating-system permissions may prevent related features from working. Withdrawing consent does not affect processing that was lawful before the withdrawal.
12. Children's Privacy
The consumer Services are intended for users aged 13 or older. Children under 13 may not register for or use them. Users who are at least 13 but below the digital-consent age where they live also need lawful authorization from a parent or legal guardian. If you believe we collected information from a child who does not meet these requirements, contact support@aiviza.ai. We will stop processing and delete the information as required by law.
13. Cookies and Similar Technologies
Our website may use cookies, pixels, local storage, and similar technologies for essential functions, preferences, analytics, security, and, where permitted, advertising or measurement. Where consent is required, non-essential technologies will be controlled through an appropriate consent mechanism.
14. Region-Specific Disclosures
14.1 United States. Depending on state law and our processing activities, residents may have rights relating to access, deletion, correction, portability, targeted advertising, sale or sharing, sensitive-data processing, or profiling.
14.2 European Economic Area and United Kingdom. The controller is SZ SYLVOL Technology Co., Ltd. You may lodge a complaint with the competent data-protection authority.
15. Policy Updates
We may update this Policy to reflect changes in law, technology, service providers, or the Services. The updated Policy will show its new effective and last-updated dates. If a change is material, we will provide notice through the app, website, email, push notification, or another legally appropriate method. Where consent is required for a new processing purpose, we will obtain it before that processing begins.
16. Contact Us
SZ SYLVOL Technology Co., Ltd. Room 1014B, Building 10A, Shenzhen Bay Science and Technology Ecological Park, No. 10 Gaoxin South 9th Road, High-Tech Zone Community, Yuehai Subdistrict, Nanshan District, Shenzhen, China Website: www.aiviza.ai Support: support@aiviza.ai