Scope and responsibility
Sivela, Inc. (“Sivela,” “we,” “us,” or “our”) provides the Sivela AI website and related business services. This Privacy Notice explains how we handle personal information for our own purposes, including website operation, business inquiries, customer administration, and support.
Where we process personal information contained in a customer’s images, annotations, datasets, or inference inputs solely on that customer’s instructions, the customer generally determines the purposes of processing. That processing is governed by the applicable service agreement and data processing agreement. If your information was supplied by a customer, contact that organization first to exercise rights concerning its dataset. We assist customers as required by the applicable agreement and law.
Our contact details are [Legal and privacy contact email] and Sivela, Inc., [Company mailing address].
Information entered into the website demonstration
The public website contains illustrative product views and a contact form. When you submit the form, its fields are sent to our Cloudflare Worker, verified using Turnstile, and delivered by email to our designated inbox. The fields can include a name, company, work email, project description, and intended technology stack. The form does not create an account or booking or write its values to cookies or browser storage.
The demonstration does not upload images, train a model, process live inference inputs, or collect payment details. Your browser may independently provide autofill, caching, or history features under its own settings. A separately selected email or external booking link, where available, also transmits information that you choose to provide.
Business contact information
When you communicate with us through an active email address, scheduling service, support channel, or a business relationship, we may receive your name, work email, employer, job role, contact preferences, meeting details, message content, and related correspondence. We may also receive the information necessary to follow up on a referral or introduction.
Please limit information to what is relevant to your inquiry. A description of your use case and environment is usually sufficient for an initial discussion; do not send confidential production datasets or sensitive personal information through a general contact channel.
Account, contract, and transaction records
If you enter into a service relationship with us, we may process authorized-user and administrator details, account identifiers, authentication and access records, contracts, order information, billing contacts, invoices, payment status, and relevant tax or business-registration information. The exact information depends on the services purchased and the features provided.
Payment information is handled through the payment arrangements agreed for the engagement. We do not request or collect payment-card details through the current public website form. Any payment provider has its own obligations and privacy information for the functions it performs independently.
Technical information and service activity
Delivering a website or hosted service requires processing technical information, which can include IP addresses, requested URLs, timestamps, browser or device characteristics, response status, diagnostic events, and security records. A hosting or network provider may process such information to deliver requests, troubleshoot errors, prevent abuse, and protect its infrastructure.
For an active hosted-service engagement, relevant usage records may also include account and workspace identifiers, feature activity, API requests, compute usage, or error metadata, depending on the agreed service and configuration. The current marketing-site code does not include an analytics SDK. Incorporation in Delaware does not by itself establish the location of hosting or technical logs.
Customer datasets, model artifacts, and self-hosted inference
Customer datasets can contain personal information when an image, annotation, identifier, or associated metadata relates to an identifiable person. Where we receive such information for a customer project, we process it within the agreed instructions and scope. An image is not automatically biometric identification data; its use and processing determine the applicable requirements. Customers must assess sensitive or regulated uses before providing data.
A delivered deployment package does not inherently give Sivela access to its host or to the inputs and predictions processed there. Customer-controlled deployment, remote support, diagnostics, and telemetry depend on the architecture and configuration agreed for the project. Any collection of runtime information by Sivela must be specified in the relevant documentation and agreements. This notice does not promise that every self-hosted arrangement is offline or has identical data flows.
Where information comes from
We receive information directly from people who contact us, from customer administrators or colleagues who authorize or invite users, from activity on services we operate, and from providers involved in agreed hosting, support, scheduling, or payment arrangements. We may also use business information from a referral or publicly available professional source to understand and respond to a relevant inquiry.
We receive contact-form fields only after you submit the form. We do not claim access to information held only within a customer’s independently operated infrastructure.
How we use personal information
We use relevant information to respond to inquiries; arrange demonstrations; understand requirements; prepare and administer agreements; provide authorized access, support, and services; manage billing; maintain business records; diagnose problems; secure systems; prevent misuse; and comply with legal obligations. Where permitted, we may use business contact details to follow up on a requested conversation or provide relevant service updates.
Customer Data used for a fine-tuning project is processed to deliver that project under the agreed instructions. These arrangements do not give us a blanket right to reuse private customer images or messages to train shared models. Any separate shared-model training use requires an appropriate agreement or other valid authorization. We do not use this website to make solely automated decisions producing legal or similarly significant effects about visitors.
Legal bases where required
Where applicable law requires a legal basis, we process information as necessary to perform a contract with you or take requested steps before entering into one; for legitimate interests such as responding to business inquiries, supporting customers, administering business relationships, and protecting systems, after considering relevant rights and interests; to comply with legal obligations; or on the basis of consent where required.
When our contract is with your employer rather than with you individually, legitimate interests may support handling your business contact details. If we rely on consent, you may withdraw it at any time for future processing without affecting the lawfulness of processing already carried out. Customer-directed processing follows the applicable data processing agreement and the customer’s lawful instructions.
Cookies, analytics, and similar technologies
The marketing-site code does not set advertising or analytics cookies, deploy advertising pixels, embed a third-party scheduling widget, or persist form values in local storage. Site fonts and images are served as local assets. The contact form uses Cloudflare Turnstile for abuse prevention; its script and verification request are handled by Cloudflare. The fact that our application code does not set cookies does not prevent your browser from caching files or a hosting/security layer from processing request information.
If additional functionality introduces cookies or similar storage, its purposes and applicable controls must be disclosed when enabled. Where consent is legally required for non-essential technologies, those technologies must not be activated before the required consent. You can manage browser storage through browser settings, though blocking strictly necessary functions may affect a service that relies on them.
Service providers and other recipients
Contact-form submissions include the name, company, email address, and any optional project and deployment details you enter. Cloudflare processes the form and Turnstile verification. Resend sends the resulting email to our Zoho inbox. The website does not keep a separate database of those submissions. Personal information may also be processed by providers that perform services for us, such as hosting, network protection, email, scheduling, support, or billing, to the extent those services are actually used. Access should be limited to the relevant purpose and subject to appropriate obligations. Customer-data subprocessors and any applicable change-notification mechanism are addressed through the relevant data processing agreement or associated documentation.
An organization’s account administrators may access information needed to administer its users and service relationship. We may disclose information to professional advisers or authorities when reasonably necessary to comply with law, establish or defend legal claims, or protect rights and security. Information may also be transferred as part of a merger, financing, reorganization, or sale of assets, subject to applicable protections and required notices.
We do not sell personal information or share it for cross-context behavioral advertising through this website.
International transfers
Sivela is organized in the United States, and information may be processed in the United States or other countries depending on the service, customer arrangements, and providers used. Those countries may have different data-protection rules from your location. A customer’s hosting or regional requirements must be expressly reflected in the agreed service scope.
Where European, UK, Swiss, or other applicable law restricts an international transfer, an appropriate transfer mechanism or lawful exception is required. Depending on the circumstances, this may include an adequacy decision, approved contractual safeguards, and supplementary measures where necessary. We do not claim certification under a transfer framework or a specific regional hosting commitment in the absence of an applicable verified arrangement. You may contact us for information about safeguards relevant to your information.
Retention and deletion
We retain personal information for as long as reasonably necessary for the purpose for which it was collected, taking account of the nature and sensitivity of the information, the duration of the relationship, required business records, applicable limitation periods, legal obligations, and potential disputes. Inquiry records, invoices, security logs, and customer datasets may require different retention periods; there is no single retention period for all categories.
Where information is no longer needed, it should be deleted or de-identified in accordance with applicable requirements. Backup copies may remain until overwritten under the relevant retention cycle and should not be used for unrelated purposes. A lawful preservation requirement may delay deletion. Return and deletion of customer-controlled data are addressed in the service agreement and data processing agreement. Contact-form submissions are retained in the designated email inbox under the applicable email retention practices.
Security measures and incidents
We seek to protect information with measures appropriate to the risks and the services involved, including appropriate access restrictions and operational safeguards. Detailed commitments for a customer deployment belong in its service and data processing agreements. This general notice is not a claim of a particular certification, independently audited control set, or guaranteed level of protection.
No transmission or storage system is completely secure. Customers and users should protect credentials, limit access, and configure their own infrastructure appropriately. If an incident triggers notification obligations, we will act in accordance with applicable law and contractual responsibilities. Where we act on a customer’s instructions, the customer may be responsible for notices to affected individuals, with our assistance as required.
Privacy rights and requests
Depending on your location, the applicable law, and our role, you may have rights to confirm whether information is processed; obtain access or a copy; request correction or deletion; restrict processing; object to certain processing; receive portable information; withdraw consent; or obtain information about disclosures. These rights are subject to applicable exceptions, including legal retention requirements and the rights of others.
Send requests to [Legal and privacy contact email] with enough information to identify the relevant relationship and request. Do not send unnecessary identity documents. We may request proportionate verification or evidence of an authorized agent’s authority where appropriate. We will respond within the period required by applicable law and explain any lawful extension or refusal. Where permitted by law, an appeal may be sent to the same contact with the original request and the reasons for reconsideration.
If an organization controls the dataset or account concerned, we may refer your request to that organization and assist it under the applicable agreement. We will not unlawfully discriminate or retaliate against a person for exercising applicable privacy rights.
Additional regional information
For individuals in the European Economic Area, United Kingdom, or Switzerland, applicable rights can include objection to processing based on legitimate interests and the right to complain to the relevant supervisory authority. Where a legally required local representative or additional contact is appointed, the relevant details must be provided to affected individuals. No representative or data protection officer appointment is asserted by this notice.
Where US state privacy laws apply to our processing, eligible residents may have access, correction, deletion, portability, appeal, and opt-out rights, including for sale, targeted advertising, or certain profiling. Our current website does not sell information, share it for cross-context behavioral advertising, or conduct qualifying profiling. Consequently there is no corresponding website advertising activity to disable through an opt-out preference signal. If practices change, applicable recognized preference signals and opt-out requirements must be implemented. Statutory applicability and exemptions depend on the circumstances, not solely on Delaware incorporation.
Communications and your choices
You can tell us that you no longer want optional promotional communications, or use an unsubscribe mechanism where one is included. Administrative messages about an active contract, security, billing, or a request you initiated may still be necessary. A request for product information does not automatically enroll you in an undisclosed marketing program.
You may choose not to supply optional information. Where information is necessary to respond to a request or provide a purchased service, we may be unable to carry out that activity without it. Your browser settings control features such as autofill, cache, and locally stored data.
Children and third-party websites
The Services are intended for businesses and are not directed to children under 13. We do not knowingly seek personal information from children through the website. If you believe a child has provided information through an active contact channel, contact us so we can investigate and take appropriate steps.
Links to external websites, email services, or scheduling providers lead to services whose privacy practices may differ from ours. Review their notices before sharing information. Linking to a service does not mean that we control all processing performed by that provider.
Changes to this notice
We may update this Privacy Notice to reflect changes to our services, data practices, or legal requirements. The date on this page identifies the latest revision. Where a change requires direct notice, consent, or another action under applicable law, updating this page alone does not replace that requirement.
Before enabling additional tracking, account features, or new customer-data processing, the corresponding practices and notices must be aligned with what is actually implemented. A new notice does not authorize incompatible reuse of previously collected information without a lawful basis.
Contact us
For questions about this Privacy Notice, to exercise applicable rights, or to raise a concern about how information is handled, contact [Legal and privacy contact email].
Postal correspondence: Sivela, Inc., [Company mailing address].
If your request concerns information processed on behalf of your employer or another customer, identify that organization so it can be routed appropriately.