Skip to main content
ilveno
Buy now

Legal

Privacy Policy

Last updated: 16 September 2026
DRAFT — pending legal review. This document has been written to describe the Ilveno Cloud service as it actually operates, but it has not been reviewed by a qualified lawyer. Passages marked TODO still require a decision before this text is relied on as binding.

This policy explains what personal data Ilveno processes, why, on what legal basis, how long we keep it, and what your rights are. It covers visitors to ilveno.com, customers who subscribe to Ilveno Cloud, and the people whose data is processed inside a customer's Cloud workspace.

Who we are

Ilveno is operated by Ege Bilge, sole proprietor, trading as "Ilveno".

Contact for anything in this policy: [email protected]

TODO — the registered postal address must be published here. It is currently only available on request, which is not sufficient for an operator that hosts customer data.

Two roles: where we are controller and where we are processor

This distinction decides everything else in this policy, so we state it first.

  • For account, subscription and billing data, and for visits to ilveno.com, we are the controller. We decide why and how that data is processed, and this policy is our notice to you about it.
  • For the content inside a Cloud workspace — notes, boards, chat messages, files, calendar entries, tickets, the customer's own user accounts — the customer is the controller and we are the processor. We process that data only to run the service, on the customer's instructions.
  • For an Enterprise on-premise installation we are neither: we never receive workspace content at all. We are controller only for the licence and billing relationship.

If your employer uses Ilveno and you want to know why your personal data is in a workspace, how long it is kept, or you want it corrected or deleted, your employer is the controller and you should ask them. We will pass such a request on and assist them.

The processor terms — the Article 28(3) contract between us and each Cloud customer — are at https://ilveno.com/legal/dpa.

Data we process as controller

  • Customer and account records — company or customer name, business email address, the subscription's product, seat count, billing period and status, the Polar customer identifier, the allocated workspace subdomain and its provisioning state.
  • Licence records — licence identifier, edition, entitlements, seat count, issue and expiry dates, and for on-premise installs the check-in metadata (install fingerprint, seats in use, version, timestamp).
  • Billing data — invoices and transaction records. Card details are entered on Polar's checkout and never reach our systems; we do not see or store them.
  • Support and sales correspondence — the emails you send us and our replies.
  • Website server logs for ilveno.com — IP address, user agent, referrer and requested path, kept briefly for security and abuse prevention.
  • Administrative access records for our internal panel — who signed in and when.

We do not sell, rent or trade personal data, and we do not use it to train machine-learning models.

Legal basis for the data we process as controller

  • Performance of a contract (GDPR art. 6(1)(b)) — creating and running your workspace, provisioning, entitlement, renewals, support.
  • Legal obligation (art. 6(1)(c)) — bookkeeping and tax records.
  • Legitimate interests (art. 6(1)(f)) — security and abuse prevention, keeping the platform available, service and renewal notices, defending legal claims. You may object to processing based on legitimate interests at any time.
  • Consent (art. 6(1)(a)) — only where required, and withdrawable at any time without affecting processing already carried out.

Workspace content — what we do as processor

Each Cloud customer gets a dedicated stack: its own application container, its own PostgreSQL database, its own Redis instance and its own file storage volume, reachable on its own subdomain. There is no shared application database and no row-level separation between customers — the isolation boundary is the container, not a condition in a query.

We do not read workspace content. Our staff can reach a workspace's infrastructure because we operate it, and that access is used to run and repair the service, to apply updates, and — for support — when a customer asks us to look at something. Every such access is limited to what the task needs.

We do not use workspace content for analytics, profiling, advertising or model training, and we do not disclose it except as the customer instructs or the law requires.

Subprocessors and service providers

We use a small number of providers. Each acts under a written agreement and processes data only on our instructions.

  • Polar Software Inc. (polar.sh) — merchant of record: payment, invoicing, VAT and sales tax, and the customer portal. Processes customer and billing data.
  • Resend — transactional email (welcome messages, licence delivery, notifications, support and product email).
  • TODO — our hosting and infrastructure provider, which runs the servers your workspace container, database and file volume live on. The provider's legal name and the data-centre region must be filled in here before publication; we have deliberately not guessed them.
  • Meeting audio and video is routed by a LiveKit server we operate ourselves, on the same hosting provider listed above. It is software we run, not a separate company we send your data to, so it is not a subprocessor. Meeting media passes through it while a meeting is in progress and is not recorded or stored.
  • OpenAI — only if AI features are switched on and a key is supplied. The product has no AI capability unless an API key is configured, either by an individual user for their own account or by the operator for the installation. Where a key is configured, the text sent to the assistant is transmitted to OpenAI under that key holder's own relationship with OpenAI. If no key is configured, nothing is sent and the feature is not available.
  • Accounting and tax services, strictly within statutory bookkeeping scope.

The current subprocessor list for Cloud customers, and how we notify you of changes to it, are in the Data Processing Addendum at https://ilveno.com/legal/dpa.

Where data is hosted, and international transfers

TODO — the hosting region for Cloud workspaces must be stated here precisely (provider, country, data-centre region). Customers choose a hosted service partly on this answer, so it cannot be left vague and must not be guessed.

Some of our providers are established outside the European Economic Area. Where personal data is transferred outside the EEA, we rely on the safeguards permitted by GDPR art. 46 — in practice the European Commission's Standard Contractual Clauses (Implementing Decision 2021/914), supplemented by additional measures where a transfer assessment calls for them. For data subjects in Türkiye, the corresponding mechanisms under KVKK art. 9 apply.

REVIEW NEEDED — the exact transfer mechanism in place with each provider has not been verified for this draft. It must be checked provider by provider before this section is published. A copy of the safeguards in place can be requested at [email protected].

Retention

  • Workspace content: for as long as the subscription is active. On suspension the data is retained, not deleted — see the retention window in section 8 of our Terms of Service at https://ilveno.com/legal/terms, which is still to be confirmed.
  • Customer, subscription and licence records: while the relationship is active, and afterwards for the period required by bookkeeping law.
  • Invoices and tax records: as required by statute.
  • Support correspondence: up to three (3) years after the last exchange.
  • Website server logs: up to thirty (30) days.
  • Operational backups: TODO — state the backup retention period once it is fixed operationally.

Security

The measures we actually operate are described in the Data Processing Addendum at https://ilveno.com/legal/dpa. In summary: one database, one cache and one storage volume per customer rather than a shared database; HTTPS with certificates issued and renewed automatically for every workspace; secrets generated per tenant; authenticated access to the datastores; two-factor authentication available for workspace users; and our internal panel restricted to an explicit allowlist of accounts behind single sign-on.

We hold no security certification. We are not ISO 27001 certified, we have no SOC 2 report, and we do not claim either. If you need an audited assurance, ask us before you subscribe rather than assuming one exists.

Cookies and analytics

ilveno.com sets no tracking cookies and runs no third-party analytics. The only values stored on your device are functional preferences — your chosen theme and language. Details are in our Cookie Policy at https://ilveno.com/legal/cookies.

Inside a Cloud workspace, the application sets the cookies it needs for sign-in and session management. Those are strictly necessary for a service the customer's users have asked for.

Your rights

If the GDPR or UK GDPR applies to you, you have the rights of access, rectification, erasure, restriction, portability and objection, the right not to be subject to solely automated decisions with legal effect (we take none), and the right to withdraw consent where processing rests on it.

If you are in Türkiye, your rights under KVKK art. 11 are described in our KVKK notice at https://ilveno.com/tr/legal/kvkk .

Write to [email protected] to exercise any right. We answer within one (1) month, free of charge, unless a request is manifestly unfounded or excessive.

Where we act as processor, we forward your request to the controller — your employer or whoever operates the workspace — because it is their decision to make, and we assist them in answering it.

You also have the right to complain to a supervisory authority: in the EEA, the authority of your habitual residence, place of work or place of the alleged infringement (art. 77); in the United Kingdom, the Information Commissioner's Office; in Türkiye, the Personal Data Protection Authority (KVKK).

Children

Ilveno is sold to businesses and is not directed at children. We do not knowingly collect personal data from children. If a customer places children's data in a workspace, they are the controller for it and responsible for the lawful basis.

Changes to this policy

We may revise this policy. The "Last updated" date at the top of the page always reflects the current version, and material changes are notified by email to active customers.