Privacy Policy

Last updated:

This policy explains what data Tavnit collects, how it is used, and the controls you have over it. It covers the marketing site at tavnit.io and the Tavnit application. For anything not answered here, contact support@tavnit.io.

What Tavnit does with your documents

Tavnit is a document pipeline. You define a flow describing the fields you want, send a document to it, and receive structured data back. Along the way the platform can clean and enrich the results, split combined PDFs, route documents to the right flow, pause for human review, store results, and hand data to an AI browser agent to act on.

Every one of those steps operates on the content of the documents you send. That content is processed to produce the output you asked for, and to operate the features your organisation has configured — nothing else.

What we collect

Account information. Your name, email address, organisation, and the credentials used to sign in.

Document content. The files you upload, email to a flow address, or send through the API, together with the structured data extracted from them. Documents such as invoices, contracts, receipts, resumes and customs paperwork routinely contain personal data, so we treat all document content as sensitive by default.

Processing records. Runs, credit consumption, review decisions, and the append-only audit trail that Human-in-the-Loop review produces — which records who viewed, edited, approved or rejected each run.

Technical data. Standard log data generated when you use the site or the application.

Processing by third-party providers

Extraction, optical character recognition, enrichment and browser automation are performed with the help of third-party service providers. This means document content is transmitted to those providers in order to be processed, under contractual terms that restrict them to processing it on our behalf.

We do not publish the identity of individual providers here, because that list changes as the platform evolves. If you need to review our current subprocessors — for example to complete a vendor assessment or a data protection impact assessment — request the list from support@tavnit.io and we will provide it.

If you process regulated, confidential or otherwise high-risk documents, contact us before sending them so we can confirm in writing whether our current arrangements meet your requirements.

How we use your data

  • Run the extraction, cleaning, splitting, routing, review and agent workflows you configure
  • Store results in Buckets and deliver them by API, webhook or email as you direct
  • Operate Human-in-the-Loop review and maintain its audit trail
  • Meter credit usage and process billing
  • Provide support, and detect and prevent abuse or security incidents

We do not sell your data. We do not use the content of your documents for advertising.

Your data, your control

You own the documents you send and the data extracted from them. You grant us only the licence needed to process, store and deliver that content in order to run the service for you.

Where your documents contain personal data about other people, you remain responsible for that data and for having a lawful basis to process it. In that arrangement you are the controller and we act on your instructions.

Extracted results and Bucket data remain available to your organisation until you delete them or close your account. Audit trail entries are append-only by design, so they cannot be edited after the fact — that is what makes them useful as a record.

Where your data goes when you tell it to

Several Tavnit features send data outward at your instruction. A webhook posts results to an endpoint you specify. An email output sends them to an address you choose. An AI browser agent visits a URL you provide and interacts with that site. The MCP connector lets an AI assistant you have authorised query your flows and Buckets.

In each case you are choosing the destination, and that destination is outside our control. Review those configurations before sending sensitive data through them.

Access control and security

Access to the application requires authentication. API access requires a secret key, and the MCP connector uses a generated connector URL. Both are credentials: a connector URL grants access to your organisation’s data, and refreshing one immediately invalidates the previous URL so any client still using it stops working. Rotate either at any time if you believe it has been exposed.

Within an organisation, Owner, Admin and Member roles determine what each person can do. Buckets add a second layer on top of that: each bucket is either visible to the whole organisation or private to its owner and explicitly granted users, and each user can be granted Viewer or Editor access to a specific bucket independently of their organisation role.

These controls only work if you use them. Review role assignments and bucket access when people join or leave your team.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict how it is processed, and to complain to a data protection authority. We do not sell personal data.

To exercise any of these, email support@tavnit.io. If your request concerns personal data inside a document that another organisation sent through Tavnit, we will direct you to that organisation, since they control that data rather than us.

Cookies

The marketing site uses only what is necessary to serve the page. The application uses cookies required for signing in and keeping you signed in.

Changes to this policy

We will update this policy as the platform changes and will revise the date at the top. Where a change materially affects how your data is handled, we will tell account holders rather than relying on you to notice.

Contact

Questions about this policy, your data, or our current subprocessors: support@tavnit.io. See also our Terms of Service.