← Trust Centre

Privacy and data governance

Know what data enters, why it is used and when it leaves.

Privacy is handled through explicit data roles, documented purpose, minimisation, retention and controlled disclosure across the website, evaluation and production service.

Assurance position

Tenvia will not use a generic privacy statement to blur the difference between website visitors, business contacts, users and clinical study data.

Control register

What buyers need to know.

Statuses distinguish product direction from commitments and evidence for a specific deployment. They are not certification labels.

Control domainCurrent statusPublic position
01Data rolesDefined per deployment

Controller and processor responsibilities are mapped to the service, study context and customer instructions.

02Purpose and minimisationDesign principle

Only data needed for the agreed service purpose should be collected. Fixture data or data with identifying details removed is preferred during evaluation.

03Retention and deletionContractual control

Retention periods, return, deletion and backup treatment are documented in the DPA and service schedule.

04SubprocessorsContractual disclosure

The applicable provider list, processing purpose, location and change process are disclosed before production.

05International transfersContractual control

Applicable EU SCCs, UK Addendum or IDTA and supporting transfer measures are included where required.

06Rights and cooperationContractual control

Assistance with rights requests, incidents, assessments and regulator enquiries is defined in the DPA.

Prospect FAQ

Direct answers for due diligence.

These answers describe the current public boundary. Contracted controls and evidence must match the actual deployment.

Request deeper evidence

The current forms do not submit information to a Tenvia database. They prepare an email draft in the visitor’s email application, and the visitor chooses whether to send it.

Evidence room preview

Review sensitive assurance under controlled access.

The index below shows the material a diligence review can request. Scope and availability are confirmed item by item before access is granted.

01Processing overviewAvailability confirmed in diligenceControlled

02Data flow mapAvailability confirmed in diligenceControlled

03DPA and transfer packageAvailability confirmed in diligenceControlled

04Subprocessor registerAvailability confirmed in diligenceControlled

05Retention and deletion scheduleAvailability confirmed in diligenceControlled

Security and diligence

Request the right level of access.

Start with a public product review. Add confidentiality when the discussion includes sensitive study or security information.

How access works
01Explore publiclyReview the product using fixture data. No NDA is required.02Discuss confidentiallyPut a mutual NDA in place before sharing study material.03Review evidenceReceive controlled access to the relevant assurance material.

Access is granted only after Tenvia confirms the request, confidentiality route and available evidence.

Diligence requestWhat would you like to review?
Nothing is saved
Selected reviewNDA and controlled access

Request sensitive security, privacy, quality or architecture evidence.

Your details

This prepares an email for your review. Tenvia receives nothing until you choose to send it.
Continue the assurance reviewAI governance