Privacy Policy

Introduction

This Privacy Policy explains how Diva AI (“Diva AI,” “we,” “us,” or “our”) collects, uses, shares, and protects personal data when you use our platform. This policy is designed to support compliance with Indonesia’s Personal Data Protection Law (UU PDP No. 27 of 2022) and, for customers operating in the EU/UK, the General Data Protection Regulation (GDPR).

By using Diva AI, you agree to the practices described in this policy. If you do not agree, please do not use our services.


1. Information We Collect

We collect the following categories of personal data:

1.1 Account and Workspace Data

  • Name, work email address, phone number, and role of each team member you invite to your workspace
  • Company name, business address, and tax identification number (for invoicing)
  • Login credentials (passwords are hashed and never stored in plain text)
  • Workspace settings and preferences

1.2 Connected Marketplace Data

When you connect your marketplace accounts (Shopee, TikTok Shop, Lazada, Tokopedia, etc.), we access and process:

  • Store profile information (shop name, seller ID, rating)
  • Product catalog (titles, descriptions, images, SKUs, pricing, inventory levels)
  • Order data (order IDs, amounts, timestamps, fulfillment status)
  • Advertising performance metrics (impressions, clicks, spend, conversions)
  • End-customer data (buyer names, shipping addresses, phone numbers, order contents) as necessary to fulfill the services you request

This data is accessed via official marketplace APIs under the permissions (scopes) you explicitly grant during connection.

1.3 Payment and Billing Data

  • Billing address and tax information
  • Payment method details: We store only the card brand (e.g., Visa) and last 4 digits for display purposes. Full card numbers, CVV codes, and expiration dates are handled exclusively by our PCI DSS Level 1 compliant payment processor and are never stored on our servers.
  • Transaction history and invoices

1.4 Usage and Analytics Data

  • Pages visited, features accessed, and time spent in the platform
  • AI agent actions and decisions (e.g., campaigns created, alerts triggered, drafts generated)
  • Device information (browser type, operating system, IP address)
  • Log files and error reports for debugging and security monitoring

1.5 Communications

  • Customer support tickets, chat messages, and email correspondence with our team
  • Feedback and survey responses

1.6 Cookies and Tracking Technologies

See Section 3 below for details on cookies and similar technologies.


2. Data Processing Roles: Controller vs. Processor

Diva AI operates in two distinct capacities depending on the type of data:

2.1 Diva AI as Data Controller

For your workspace data (account information, billing details, usage analytics, and team member data), Diva AI acts as the data controller. We determine how and why this data is processed, and we are responsible for its protection under this Privacy Policy.

2.2 Diva AI as Data Processor

For your end-customer data (marketplace buyer information such as names, addresses, and order details accessed via connected APIs), Diva AI acts as a data processor on your behalf. You, as the seller and workspace owner, remain the data controller responsible for:

  • Informing your customers how their data is collected and used
  • Obtaining any necessary consents
  • Complying with data protection laws applicable to your business

We process end-customer data strictly according to your instructions, as outlined in our Data Processing Agreement (DPA), and only to provide the services you have authorized (e.g., order fulfillment alerts, inventory management, customer communication drafts).

Important: If your customers (marketplace buyers) have questions or requests about their personal data flowing through Diva AI, you must handle those requests directly or forward them to us at privacy@heydiva.ai, and we will assist in accordance with our processor obligations.


3. Cookies and Tracking Technologies

We use cookies, web beacons, and similar tracking technologies to operate and improve our website and platform. A “cookie” is a small text file stored on your device.

3.1 Types of Cookies We Use

Essential Cookies (Required)

  • Session management and authentication
  • Security features (CSRF protection, fraud detection)
  • Load balancing and platform stability

Analytics Cookies (Functional)

  • Google Analytics with anonymized IP addresses to understand how visitors use our site
  • Internal analytics to measure feature usage and improve user experience
  • Aggregated, de-identified data only; we do not attempt to re-identify individual users from analytics data

Marketing Cookies (Optional, if applicable)

  • Retargeting pixels from Meta, TikTok, or Google Ads to serve relevant advertisements on third-party platforms
  • Conversion tracking to measure the effectiveness of our marketing campaigns

3.2 Managing Cookies

You can control cookies through your browser settings:

  • Most browsers allow you to view, delete, and block cookies
  • Disabling essential cookies may prevent you from logging in or using core features
  • Declining analytics and marketing cookies will not affect platform functionality but may limit our ability to improve the product

For more information on managing cookies, visit allaboutcookies.org.

We do not respond to “Do Not Track” browser signals at this time, as there is no industry-wide standard for compliance.


4. How We Use Your Information

We process personal data for the following purposes:

4.1 Service Delivery and Operation

  • Creating and managing your workspace account
  • Connecting to marketplace APIs and syncing data (products, orders, advertising performance)
  • Running AI agents to automate campaigns, generate alerts, draft creative content, and provide inventory insights
  • Processing payments and generating invoices
  • Sending transactional emails (order confirmations, security alerts, system notifications)

4.2 Customer Support

  • Responding to your inquiries and troubleshooting issues
  • Providing onboarding assistance and training

4.3 Product Improvement and Development

  • Analyzing aggregated, de-identified usage patterns to improve features and user experience
  • Training and refining AI models using anonymized data (we do not use your specific marketplace data to train models shared with other customers)
  • Conducting internal research and development

4.4 Security, Fraud Prevention, and Compliance

  • Detecting and preventing fraud, abuse, and unauthorized access
  • Enforcing our Terms of Service
  • Complying with legal obligations (tax reporting, law enforcement requests, regulatory audits)

4.5 Marketing and Communications

(with your consent where required)

  • Sending product updates, newsletters, and promotional offers (you may opt out at any time via unsubscribe links)
  • Conducting customer satisfaction surveys

5. Legal Basis for Processing

We process personal data under the following legal grounds, as applicable:

  • Consent: When you explicitly grant permission (e.g., connecting marketplace accounts, accepting marketing emails)
  • Contract Performance: To fulfill our agreement with you (providing the Diva AI platform, billing, customer support)
  • Legal Obligation: To comply with laws and regulations (tax reporting, responding to valid legal requests)
  • Legitimate Interests: For purposes such as fraud prevention, security, product improvement, and internal analytics, provided these interests do not override your privacy rights

You may withdraw consent at any time where processing relies solely on consent, without affecting the lawfulness of prior processing.


6. AI and Automated Decision-Making

Diva AI uses artificial intelligence and machine learning to deliver core functionality, including:

  • Automated ad bid adjustments
  • Dynamic pricing recommendations
  • Inventory alerts and restock suggestions
  • Customer communication drafts and response suggestions
  • Campaign performance predictions

6.1 Human Oversight and Control

  • You retain full control over AI-generated actions. All automated decisions (e.g., ad spend changes, price adjustments) require your explicit approval in workspace settings.
  • You can review, override, or disable any AI recommendation or automated action at any time.
  • Critical business decisions (e.g., large budget changes, major pricing shifts) trigger confirmation prompts before execution.

6.2 Model Training and Data Isolation

  • We train AI models using aggregated, anonymized data across our user base to improve general performance.
  • Your specific marketplace data (product catalogs, customer lists, advertising strategies) is never used to train models accessible to other Diva AI customers.
  • Data is siloed per workspace; other customers cannot see or benefit from your proprietary business information.

7. Sharing and Disclosure

We share personal data only in the following circumstances:

7.1 With Connected Marketplaces

When you authorize us to connect to Shopee, TikTok Shop, Lazada, Tokopedia, or other marketplaces, we share data with those platforms to execute the actions you request (e.g., updating product listings, launching ad campaigns, syncing inventory). This sharing is governed by each marketplace’s own terms and privacy policies.

7.2 With Service Providers and Sub-Processors

We engage trusted third-party vendors to support our operations. These sub-processors are contractually obligated to process data only on our instructions and to maintain appropriate security measures.

Key sub-processor categories:

Cloud Infrastructure: AWS Singapore / Google Cloud Jakarta (Hosting, database, storage)
Payment Processing: Stripe / Xendit (PCI DSS certified payment handling)
Email Delivery: SendGrid / AWS SES (Transactional and marketing emails)
Customer Support Tools: Intercom / Zendesk (Live chat, ticketing, help center)
Analytics: Google Analytics (Anonymized website usage analysis)

A complete, up-to-date list of sub-processors is available upon request at privacy@heydiva.ai.

7.3 For Legal Compliance and Safety

We may disclose personal data when required by law or when we believe disclosure is necessary to:

  • Comply with valid legal processes (court orders, subpoenas, government investigations)
  • Enforce our Terms of Service or investigate violations
  • Protect the rights, property, or safety of Diva AI, our customers, or the public
  • Detect, prevent, or address fraud, security breaches, or technical issues

7.4 Business Transfers

If Diva AI is involved in a merger, acquisition, reorganization, or sale of assets, personal data may be transferred as part of that transaction. We will notify affected customers via email and provide notice on our website before any transfer, and the acquiring entity will be bound by this Privacy Policy (or you will be given the opportunity to opt out).

7.5 What We Do NOT Do

  • We do not sell personal data to third parties for their own marketing purposes.
  • We do not share your proprietary business data (advertising strategies, product catalogs, customer lists) with other Diva AI customers.
  • We do not use your end-customer data (marketplace buyers’ information) for our own purposes beyond providing the services you request.

8. International Data Transfers

Diva AI operates globally, and personal data may be transferred to and processed in countries outside your country of residence, including:

  • Indonesia (primary data processing location)
  • Singapore (cloud infrastructure and regional hosting)
  • United States (payment processing, certain sub-processors)

8.1 Safeguards for International Transfers

When data is transferred to countries that do not have an “adequacy decision” from the European Commission or equivalent Indonesian recognition, we rely on the following safeguards:

  • Standard Contractual Clauses (SCCs): EU-approved model contracts that require recipients to protect data to EU/EEA standards
  • Encryption in transit and at rest: AES-256 and TLS 1.3 encryption to protect data during transfers
  • Contractual obligations: Sub-processors are contractually required to implement appropriate security measures

If you have questions about specific transfers or would like a copy of the SCCs we use, contact privacy@heydiva.ai.


9. Data Retention

We retain personal data only as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required or permitted by law.

9.1 Active Workspaces

  • Account and workspace data: Retained for the duration of your active subscription
  • Marketplace data: Continuously synced and updated while your marketplace connections are active
  • Usage and analytics data: Retained for up to 24 months, then aggregated and de-identified

9.2 After Subscription Cancellation

  • 90-day grace period: All data is retained for 90 days after cancellation to allow you to resubscribe without data loss
  • Permanent deletion: After 90 days, personal data is permanently deleted from our production systems and backups, except as noted below

9.3 Legal and Compliance Retention

Certain data is retained longer to meet legal obligations:

  • Financial records (invoices, payment history): 10 years (Indonesian tax and accounting laws)
  • Legal hold requests: Retained until legal proceedings are resolved
  • Fraud and security logs: Up to 7 years for abuse prevention and law enforcement cooperation

9.4 Aggregated and De-identified Data

Data that has been aggregated and de-identified (i.e., cannot be used to identify any individual) may be retained indefinitely for analytics, research, and product improvement. We do not attempt to re-identify this data.


10. Security

We implement industry-standard technical and organizational measures to protect personal data from unauthorized access, disclosure, alteration, or destruction.

10.1 Technical Security Measures

  • Encryption in transit: TLS 1.3 for all data transmitted between your browser and our servers
  • Encryption at rest: AES-256 encryption for all stored data (databases, backups, file storage)
  • Access controls: Role-based permissions; employees and contractors have access only to data necessary for their job functions
  • Multi-factor authentication (MFA): Required for all workspace accounts; enforced for administrative access to production systems
  • Secure credential storage: Passwords are hashed using bcrypt; API keys and secrets are encrypted with rotating keys

10.2 Organizational Security Measures

  • Employee training: Regular security awareness training for all staff
  • Vendor management: Sub-processors undergo security assessments before onboarding
  • Incident response plan: Documented procedures for detecting, responding to, and recovering from security incidents
  • Third-party audits: Annual independent security assessments

10.3 Breach Notification

No security system is 100% secure. In the event of a confirmed data breach that affects your personal data:

  • We will notify affected customers via email within 72 hours of discovery (as required by GDPR)
  • The notification will include the nature of the breach, categories of data affected, and steps we are taking to mitigate harm
  • Where required by law, we will also notify relevant supervisory authorities (Indonesia’s Ministry of Communication and Informatics, EU data protection authorities, etc.)

If you discover a security vulnerability in Diva AI, please report it immediately to security@heydiva.ai. We do not take legal action against good-faith security researchers.


11. Your Rights and Choices

Depending on your location and applicable laws, you may have the following rights regarding your personal data:

11.1 Access and Portability

  • Right to access: Request a copy of the personal data we hold about you
  • Right to data portability: Receive your data in a structured, commonly used, machine-readable format (CSV or JSON) to transfer to another service

11.2 Correction and Deletion

  • Right to rectification: Correct inaccurate or incomplete personal data
  • Right to erasure (“right to be forgotten”): Request deletion of your personal data, subject to legal retention obligations (e.g., financial records)

11.3 Restriction and Objection

  • Right to restrict processing: Limit how we use your data in certain circumstances (e.g., while we verify accuracy)
  • Right to object: Object to processing based on legitimate interests (we will cease unless we have compelling legal grounds to continue)
  • Right to opt out of marketing: Unsubscribe from promotional emails via the link in each message, or contact privacy@heydiva.ai

11.4 Withdraw Consent

  • Where processing is based on your consent (e.g., marketing emails, marketplace API access), you may withdraw consent at any time
  • Withdrawing consent does not affect the lawfulness of processing prior to withdrawal

11.5 How to Exercise Your Rights

Submit requests to privacy@heydiva.ai with the subject line “Privacy Rights Request.” Include:

  • Your full name and workspace email address
  • The specific right you wish to exercise (access, deletion, correction, etc.)
  • Any relevant details to help us locate your data

Response time: We will respond within 14 business days for simple requests, and 30 days for complex requests (e.g., large data exports). If we need more time, we will notify you and explain the delay.

Verification: To protect your privacy, we may ask you to verify your identity before processing your request (e.g., by confirming account details or responding from your registered email address).

11.6 Complaints and Supervisory Authorities

If you believe we have not handled your personal data in accordance with this policy or applicable laws, you have the right to lodge a complaint with a supervisory authority:

We encourage you to contact us first so we can address your concerns directly.


12. Children’s Privacy

Diva AI is a business-to-business (B2B) platform designed for professional use by marketplace sellers and business teams. Our services are not directed at individuals under the age of 18, and we do not knowingly collect personal data from children.

If we become aware that we have inadvertently collected personal data from a person under 18 without parental consent, we will take steps to delete that information as soon as possible. If you believe we have collected data from a minor, please contact us immediately at privacy@heydiva.ai.


13. Third-Party Links and Services

Our website and platform may contain links to third-party websites, services, or integrations (e.g., marketplace platforms, payment processors, analytics providers). This Privacy Policy applies only to Diva AI.

We are not responsible for the privacy practices of third parties. We encourage you to review the privacy policies of any third-party services you interact with through our platform (e.g., Shopee’s privacy policy, TikTok’s privacy policy).


14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or new features. When we make material changes:

  • We will notify you by email at least 14 days before the changes take effect (sent to your workspace email address)
  • We will post a notice on our website and update the “Last Updated” date at the top of this policy
  • Continued use of Diva AI after the effective date constitutes acceptance of the updated policy

Non-material changes (e.g., clarifications, formatting updates, contact information changes) may be made without advance notice. We encourage you to review this policy periodically.

Previous versions of this Privacy Policy are available upon request at privacy@heydiva.ai.


15. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at privacy@heydiva.ai.