Privacy Policy
Summary
- AIVA is an internal enterprise assistant provided by Alyasra to its personnel and authorised users. It is not a consumer product and is not offered to the general public.
- We collect your work account identity, the content you submit to the assistant, and technical usage data needed to operate and secure the Service.
- We do not sell your personal data, and we do not use your content to train third-party foundation models.
- Camera, microphone, photo library, and notification access are optional, requested only when you use a feature that needs them, and revocable in your device settings.
- You can request access, correction, export, or deletion of your personal data — see Your Data Protection Rights.
1. Who We Are
AIVA ("Alyasra Intelligence Virtual Assistance") is an enterprise software application provided by Alyasra ("Alyasra", "the Company", "we", "us", or "our"), the data controller responsible for the personal data described in this Policy.
| Data controller | Alyasra |
|---|---|
| Registered address | United Arab Shipping Company Building, 55 Airport Road, Kuwait City, Kuwait |
| Governing jurisdiction | State of Kuwait |
| Privacy contact | aiva@alyasra.com |
2. Scope of This Policy
This Policy explains how we handle personal data when you use AIVA, whether you access it through the web application, the mobile application, an installed desktop or progressive web app, or an integration such as Microsoft Teams or an Excel add-in. Together these are referred to as the "Service".
AIVA is provided for internal business use by Alyasra personnel, contractors, and other users to whom Alyasra has granted access. Access requires an organisational account issued and administered by Alyasra. The Service is not available for public registration.
Where you use AIVA in the course of your work, Alyasra may also process your data in its capacity as your employer or engaging entity. That processing is governed by the applicable employment and internal data protection policies, which operate alongside this Policy.
3. Definitions
- Account — the organisational identity issued to you by Alyasra that authenticates your access to the Service.
- Affiliate — an entity that controls, is controlled by, or is under common control with Alyasra, where "control" means ownership of 50% or more of the voting interests.
- Application — the AIVA software, in any of the forms described in Section 2.
- Content — the prompts, messages, documents, images, audio, and other material you submit to, or generate using, the Service.
- Device — any computer, mobile phone, tablet, or other hardware used to access the Service.
- Personal Data — any information relating to an identified or identifiable individual.
- Processing — any operation performed on personal data, including collection, storage, use, disclosure, and deletion.
- Service Provider / Sub-processor — a third party that processes personal data on our behalf and under our instructions.
- Usage Data — technical data generated automatically by your use of the Service or by the Service infrastructure.
- You — the individual accessing or using the Service.
4. Data We Collect
4.1 Account and identity data
When Alyasra provisions your access, and when you sign in, we process:
- Your name and work email address
- Your organisational identifier, and where applicable your department, division, role, and reporting relationships
- Your access permissions and feature entitlements within the Service
- Authentication events and session records, including sign-in times and the identity provider response
Authentication is performed through Microsoft Entra ID. We receive the identity claims returned by that sign-in process; we never receive or store your account password.
4.2 Content you submit
The Service processes the Content you provide in order to respond to you. This includes chat messages and prompts, uploaded documents and spreadsheets, images and scanned cards, voice input where you use speech features, and the outputs the Service generates for you, such as generated images, videos, summaries, and reports.
Please do not submit personal data of others, or special-category or highly sensitive data, unless doing so is necessary for a legitimate business purpose and permitted by Alyasra's internal policies.
4.3 Usage and device data
We collect this automatically when you use the Service:
- IP address and approximate region derived from it
- Device type, operating system and version, and application version
- Browser type and version, or mobile browser equivalent
- Device identifiers used to maintain your session and, where enabled, to deliver push notifications
- Pages and features accessed, actions taken, timestamps, and duration of use
- Diagnostic and error data, including crash reports and performance traces
4.4 Cookies and local storage
We use cookies and equivalent browser storage that are strictly necessary to operate the Service: to keep you signed in, to maintain your session, to protect against cross-site request forgery, and to remember interface preferences such as language and theme. We do not use advertising cookies, and we do not use third-party cross-site tracking or behavioural advertising technologies.
5. Device Permissions
On mobile and desktop, certain features require your permission before they can access device capabilities. Each permission is requested only at the point you first use the relevant feature, is optional, and can be withdrawn at any time through your device or browser settings. Declining a permission disables only the feature that depends on it.
| Permission | Why it is requested | What happens to the data |
|---|---|---|
| Camera | To capture documents, business cards, and images for scanning or analysis. | Captured images are processed to deliver the requested feature and stored against your account. No continuous or background capture occurs. |
| Photo library | To let you attach an existing image to a prompt or upload it for analysis. | Only the files you explicitly select are read and uploaded. We do not scan or index your library. |
| Microphone | To support voice input, dictation, and live translation. | Audio is streamed to Azure Speech services to produce a transcript. Recording occurs only while a voice feature is active. |
| Notifications | To alert you about completed tasks, briefings, approvals, and alerts you have configured. | A device push token is stored to deliver notifications. It is deleted when you disable notifications or sign out. |
| Storage / files | To upload documents for analysis and to save downloads you request. | Only the files you select are accessed. |
AIVA does not collect precise or background geolocation, does not access your contacts, call logs, or messages, and does not track you across other applications or websites.
6. How We Use Your Data
We use personal data for the following purposes:
- To provide the Service — to authenticate you, respond to your prompts, run the features you invoke, and store your work so you can return to it.
- To administer access — to provision, manage, and revoke accounts, permissions, and feature entitlements.
- To secure the Service — to detect, investigate, and prevent unauthorised access, abuse, fraud, and security incidents, and to maintain audit trails.
- To operate and improve — to monitor availability and performance, diagnose faults, and improve reliability and usability.
- To communicate with you — to send service, security, and administrative messages, and notifications you have enabled.
- To meet legal and regulatory obligations — including record-keeping, responding to lawful requests, and enforcing our agreements and internal policies.
We do not sell personal data. We do not use your Content for advertising or behavioural profiling, and we do not disclose it to third parties for their own marketing purposes.
7. Legal Bases for Processing
Where data protection law requires us to identify a legal basis, we rely on the following:
| Processing activity | Legal basis |
|---|---|
| Providing and administering the Service to authorised users | Performance of a contract, and our legitimate interest in operating internal business systems |
| Security monitoring, audit logging, and abuse prevention | Legitimate interests, and compliance with legal obligations |
| Service reliability, diagnostics, and improvement | Legitimate interests |
| Camera, microphone, photo library, and notification access | Your consent, withdrawable at any time in device settings |
| Retention for legal, tax, or regulatory purposes | Compliance with legal obligations |
8. AI Processing and Automated Features
AIVA uses artificial intelligence models hosted on Microsoft Azure, within Alyasra's own Azure tenant and subscription, to generate responses, summaries, images, video, translations, and analyses.
- Your Content is not used to train foundation models. Content you submit is processed to produce a response for you and is not used by us or by Microsoft to train or fine-tune publicly available models.
- Processing stays within the Azure services we operate. We do not send your Content to consumer AI services or to third-party model providers outside the Azure environment described in this Policy.
- Content safety filtering applies. Prompts and generated output pass through Azure content-safety and abuse-monitoring systems, which may flag material that violates applicable use policies.
- Outputs may be inaccurate. AI-generated content can be incomplete or wrong. You remain responsible for reviewing it before relying on it for any business decision.
- No solely automated decisions with legal effect. The Service does not make decisions about you that produce legal effects or similarly significant consequences without human involvement. Where AIVA supports a workflow such as an approval, a person makes the decision.
9. How We Share Your Data
We disclose personal data only in the circumstances below:
- With service providers — to the sub-processors listed in Section 10, who process data on our behalf under contractual confidentiality and security obligations.
- Within Alyasra and its affiliates — where necessary to administer the Service, on the same terms as this Policy.
- With other users of your organisation — where you deliberately share content, for example by submitting an approval request, publishing to a shared workspace, or sending a report. Content you keep private is not visible to other users, other than authorised administrators acting in that capacity.
- For legal reasons — where required by law, court order, or a valid request from a public authority, or where necessary to establish, exercise, or defend legal claims.
- In a corporate transaction — in connection with a merger, acquisition, reorganisation, or sale of assets. We will notify you before your personal data becomes subject to a different privacy policy.
- With your consent — for any other purpose we describe to you at the time.
10. Service Providers and Sub-processors
We rely on the following providers to operate the Service. Each processes data only as needed to deliver its function:
| Provider | Function | Data processed |
|---|---|---|
| Microsoft Azure | Cloud hosting, database, file and media storage, application infrastructure | All categories described in Section 4 |
| Microsoft Entra ID | Identity and access management, single sign-on | Account and authentication data |
| Azure OpenAI & Azure AI Foundry | AI model inference, text and media generation, document intelligence | Prompts, documents, images, and generated output |
| Azure AI Speech | Speech-to-text, text-to-speech, translation | Audio input and transcripts |
| Microsoft 365 & Microsoft Graph | Email, calendar, and document integrations you choose to enable | Only the mailbox, calendar, or file data required by the feature you invoke |
| Microsoft Teams | Assistant access inside Teams, where enabled | Account identity and conversation content within Teams |
We do not use third-party analytics, advertising, or tracking providers.
11. International Data Transfers
Alyasra operates from Kuwait, and the Service runs on Microsoft Azure regions that may be located outside Kuwait, including in the European Union and the United States. Your personal data may therefore be transferred to, stored in, and processed in countries whose data protection laws differ from those of your own jurisdiction.
Where we transfer personal data internationally, we rely on appropriate safeguards, including the contractual data protection commitments and standard contractual clauses in our agreements with Microsoft, together with encryption in transit and at rest. We take reasonable steps to ensure your data receives an equivalent level of protection wherever it is processed.
12. Data Retention
We retain personal data only as long as necessary for the purposes set out in this Policy:
| Category | Retention period |
|---|---|
| Account and identity data | For the duration of your authorised access, then deleted or anonymised in line with Alyasra's records policy |
| Conversations, prompts, and generated media | Until you delete them, or until your access is removed and the associated records are cleared |
| Uploaded documents and files | Until you delete them, or until removed with your account |
| Security and audit logs | Typically up to 12 months, or longer where required for security investigation or legal obligation |
| Diagnostic and error data | Typically up to 90 days |
We may retain specific records for longer where we have a legal obligation or a lawful basis to do so, such as an ongoing investigation, audit requirement, or legal claim.
13. Security
We implement technical and organisational measures appropriate to the risk, including:
- Encryption of data in transit using TLS, and encryption at rest for stored data
- Enterprise single sign-on through Microsoft Entra ID, with multi-factor authentication where enabled by Alyasra
- Role-based access control, so users and administrators see only what their role permits
- Time-limited, signed URLs for access to stored media and documents
- Protection against common web application attacks, including cross-site request forgery and content-injection defences
- Audit logging of security-relevant events, and monitoring for anomalous access
- Segregation of production environments and least-privilege administrative access
No method of transmission or storage is completely secure. While we use commercially reasonable measures to protect your personal data, we cannot guarantee absolute security. If we become aware of a personal data breach affecting you, we will notify you and the relevant authorities where required by applicable law.
14. Your Data Protection Rights
Subject to applicable law, you have the right to:
- Access — obtain confirmation of whether we process your personal data, and a copy of it
- Rectification — have inaccurate or incomplete data corrected
- Erasure — request deletion of your personal data where we have no overriding legal basis to retain it
- Restriction — ask us to limit processing in certain circumstances
- Portability — receive your data in a structured, commonly used, machine-readable format
- Objection — object to processing based on our legitimate interests
- Withdraw consent — withdraw any consent you have given, including device permissions, without affecting the lawfulness of prior processing
- Complain — lodge a complaint with a competent data protection authority in your jurisdiction
Within the Service you can delete individual conversations, uploaded files, and generated media directly. For any other request, contact us using the details in Section 18. We will respond within 30 days, or sooner where required by applicable law, and may need to verify your identity before acting. Exercising these rights is free of charge, unless a request is manifestly unfounded or excessive.
Because AIVA is an enterprise system, some records — such as audit logs and approval history — may be retained even after a deletion request, where Alyasra has a legal or legitimate business obligation to keep them. We will tell you if that applies to your request.
15. Children's Privacy
The Service is intended solely for use by adults in a professional capacity. It is not directed at children, and we do not knowingly collect personal data from anyone under the age of 18. Access requires an organisational account issued by Alyasra. If you believe a minor has provided us with personal data, contact us and we will delete it.
16. Links to Other Sites
The Service may contain links to websites we do not operate, and may display content or citations from external sources. We are not responsible for the content or privacy practices of those third parties. We recommend reviewing the privacy policy of any external site you visit.
17. Changes to This Policy
We may update this Policy from time to time to reflect changes to the Service, our practices, or legal requirements. When we do, we will revise the "Last updated" date above and increment the version number. Where changes are material, we will provide additional notice through the Service or by email before they take effect.
We encourage you to review this Policy periodically. Continued use of the Service after a change takes effect constitutes acceptance of the updated Policy.
18. Contact Us
For questions about this Policy, or to exercise any of the rights described in Section 14:
Email: aiva@alyasra.com
Post: Alyasra — Data Protection, United Arab Shipping Company Building, 55 Airport Road, Kuwait City, Kuwait
Please include enough detail for us to identify your account and understand your request. Do not include sensitive personal data in your initial message.