1. Who is responsible for what
Telvi is a product of Datwa Labs, registered in India at 2nd Floor, Plot 343,
Infocity Avenue, Sishu Vihar, Patia, Bhubaneswar, Odisha 751024.
For everything inside a customer’s knowledge space, the customer is the data
fiduciary (controller) and Datwa Labs is the data processor. The
customer decides which systems to connect, which people get access, and what the space is used
for. We act on those instructions under the customer agreement and a data processing agreement,
and for no separate purpose of our own.
This matters if you are an employee of a customer: we hold information about you because your
employer connected the systems you work in. Requests about that data go to your employer first
— see section 11.
We are a data fiduciary in our own right for a narrow set of things: business contacts, demo
enquiries and correspondence. Those are covered in section 13.
2. Customer content we ingest
A knowledge space is built from sources the customer connects. Depending on that choice, the
content may include:
- Code and configuration — repositories, PL/SQL packages, ODI mappings, materialised view definitions, scheduler jobs, commit history and pull request discussion.
- Documentation — Confluence, Notion, shared drives, runbooks, specifications and contracts.
- Tickets and issues — Jira, Linear, Azure DevOps, including comment threads and change history.
- Conversations — Slack, Teams and email, where the customer chooses to connect them.
- Ownership and organisational metadata — team structures, code owners, on-call rotas, role and directory data.
Within that content, the personal data typically includes names, work email addresses,
usernames and account identifiers, authored text such as comments and messages, and records of
who changed what and when. Where conversations are connected, it can also include informal
discussion that was never intended as documentation. That is precisely why it holds the
reasoning nothing else captured, and precisely why it deserves care.
We do not want, and ask you not to connect: health information, payment card
data, government identifiers, or your own customers’ or guests’ personal data. None of it is
needed to explain how a system works.
3. What we do with it
We process connected content only to build and operate the knowledge space for that customer.
In practice, that means:
- parsing and indexing content so it can be searched and referenced;
- resolving entities, so the same object named differently across systems is understood as one thing;
- forming engrams — statements with their reasoning, evidence, owner and confidence;
- re-checking engrams against their sources when those sources change;
- answering questions from authorised users and authorised machine clients, with citations.
We do not sell customer content. We do not use it for advertising, and we do not use it to
build profiles of individual employees. Telvi is designed to explain systems, not to measure
people — but note that content about who did what is inherent to the sources, and an
administrator with broad access can see it. Section 4 covers how that access is bounded.
4. Who can see what
This is the question that decides whether a knowledge tool is safe to deploy. Consolidating
knowledge is useful precisely because it crosses system boundaries — which is also how a
consolidating tool becomes an accidental way to read things you could not read before.
-
Access model within the space. Accounts and their reach are granted by the
customer’s administrators. Every engram carries the identity of the evidence behind it, so
what a statement was built from is always visible. Because a single engram can fuse sources
of differing sensitivity, the exact access model — including how such an engram is governed —
is set out in the security documentation and the data processing agreement, and we answer it
in writing before anything is connected.
-
Datwa Labs staff access. We do not browse customer spaces as a matter of
course. Where access to customer content is needed to diagnose a fault or complete a
migration, it happens on a named basis under the terms of the data processing agreement,
which set out the approval, logging and notification that apply.
-
Tenant isolation. Each customer’s space is separate: connected content,
engrams, accounts and logs belong to one space, and knowledge is never pooled or shared
across customers. The implementation is described in the completed security questionnaire.
-
Customer-side administration. The customer controls who has an account and
what they can reach, and is responsible for keeping that aligned with its own policies.
5. AI models and your content
Telvi uses language models to interpret content and compose answers. Because this is where most
concern about an AI product sits, we state it separately rather than folding it into
“sub-processors”.
-
Which providers receive content. Interpreting content and composing answers
involves a language model provider, so connected content and the questions asked of it can be
sent to that provider for processing. Which providers we use, whether a model can run inside
the customer’s own environment, and the terms that apply to each are named in the data
processing agreement and settled before connection. We do not add or change a provider
without telling customers first.
-
Training. Customer content, the questions asked of it and the answers
generated from it are not used to train or fine-tune models — not ours, and not a
provider’s. Where we use a third-party model we contract on terms that exclude training on
our traffic, and we would not move to a provider unwilling to agree to that without telling
customers first.
-
Prompt and output retention. Questions and generated answers are kept as
query logs so that answers stay auditable — see section 6. Any retention by a model provider
is governed by our contract with that provider and disclosed in the data processing
agreement.
Answers are generated from your content and cite it, so a citation may quote text that includes
a colleague’s name or words. That is intentional — an uncited answer would not be verifiable —
but it means answers can carry personal data and should be treated with the same care as the
source.
6. Accounts and query logs
Operating the product also creates data about its use, which we process as processor for the
customer:
- Account data — name, work email address, role and authentication identifiers for each user the customer provisions.
- Query logs — questions asked, engrams returned, and timestamps, kept so that answers are auditable and so we can diagnose faults.
- Machine client activity — records of agents or services fetching engrams over the API or MCP, and what they retrieved.
- Operational telemetry — errors, latency and ingestion health.
Query logs deserve a plain warning: a record of what someone asked can be sensitive
in itself, and it is visible to the customer as controller. We keep them because an
audit trail is a security requirement for most buyers, not to enable monitoring of individuals,
and we ask customers to tell their staff that the logs exist.
How long logs are kept is agreed with the customer rather than fixed by us. A customer that
wants a shorter window, or wants retention limited to what an open investigation needs, can
have one — we would rather hold fewer logs than more.
7. Legal bases
We are established in India and subject to the Digital Personal Data Protection Act,
2023. Where personal data relates to people in the EU, EEA or UK, the
GDPR or UK GDPR applies as well.
-
Customer content, accounts and logs. Processed on the customer’s
instructions. The customer is responsible for having a lawful basis for the systems it
connects and for informing its staff — including, where required, consulting works councils
or employee representatives before connecting conversation sources.
-
Our own business contacts. Our legitimate interest in responding to and
managing a business relationship; under the DPDP Act, data voluntarily provided for a purpose
we have told you about.
8. Sub-processors
We use third parties to run the service. The current list, including model providers and
hosting, is maintained in the data processing agreement, and customers are notified before we
add or change one so they can object.
The list names every provider that can process customer content, hosting and model providers
included. If you want to see it before you talk to us at all, ask
security@telvi.ai and we will send the current one.
9. International transfers
We operate from India and some providers operate globally, so personal data may be processed
outside the country it came from. Where the GDPR or UK GDPR applies to a transfer, we rely on
the European Commission’s Standard Contractual Clauses or the UK Addendum, together with the
transfer terms of the provider concerned.
We tell you which region your space runs in before you connect anything. If your policy
requires a particular region, ask: where we can commit to it we will say so in the contract,
and where we cannot we will tell you that instead rather than leave it vague.
10. Retention and deletion
-
While the agreement is live. Connected content, and the engrams derived from
it, are retained so the space stays current.
-
When source content is deleted. If a page, ticket or message is deleted or
access is withdrawn at source, the engrams citing it are re-checked and the derived knowledge
is withdrawn or superseded. A knowledge space that outlives its sources would be a way to
resurrect deleted data, which we treat as a defect.
-
On termination. We delete or return customer content, the derived knowledge
space, accounts and logs. The deletion window and any backup retention tail are written into
the agreement, and we confirm completion in writing rather than leave you to assume it.
-
Records we must keep. Contracts, invoices and tax records for as long as
Indian law requires.
11. Your rights
Depending on where you are and which law applies, you can ask for confirmation of what is held
about you and a copy of it, correction of anything inaccurate, erasure where there is no reason
to keep it, restriction of or objection to a particular use, portability where the GDPR grants
it, and withdrawal of consent where consent was the basis. Under the DPDP Act you may also
nominate someone to exercise your rights on your behalf, and you are entitled to a grievance
process.
If you are an employee of a Telvi customer, the fastest route is your own
organisation — it controls the data, the connections and the accounts. When a customer asks us
to help with a request, we assist promptly. If you approach us directly, we will pass your
request to the relevant customer and tell you we have done so, unless we are instructed
otherwise.
For anything else, write to
security@telvi.ai. We respond within one month, and
tell you if a request is complex enough to need longer.
12. Security
We take reasonable technical and organisational measures to protect personal data, and we would
rather describe them plainly than gesture at them. We currently hold no security
certifications — no SOC 2, no ISO 27001, no third-party attestation. If you are
running a security review, write to security@telvi.ai:
we complete questionnaires in full, label every answer self-assessed rather than audited, and
write “no” where the answer is no.
If we become aware of a personal data breach we notify affected customers and the relevant
authorities without undue delay, in line with the DPDP Act and, where applicable, the GDPR. To
report a suspected vulnerability, email
security@telvi.ai.
13. Business contacts and this website
Separately from the product, we hold ordinary business contact data where we are the data
fiduciary. If you book a demo, email or call us, we keep what you give us — name, work email,
telephone number, employer and what you tell us about your systems — plus our notes, to reply
and to follow up. We do not add you to a marketing list because you asked for a demo, and we
delete an enquiry if you ask us to. The demo form is delivered to our inbox by
EmailJS, a third-party email delivery service that processes what you typed in
order to send it on; the enquiry is not stored on this website.
This website is deliberately plain: it sets no cookies, runs
no analytics, and carries no advertising or session recording. Two things
happen automatically — the site is hosted on Microsoft Azure, which logs standard request data
including IP address, and typefaces load from Google Fonts, which means Google receives your IP
address and user-agent. A content blocker will stop the second one, and the site still works.
Telvi is an enterprise product sold to organisations. It is not directed at children and we do
not knowingly collect children’s data.
14. Changes to this policy
If we change how we handle personal data we will update this page and move the effective date.
Material changes affecting customers are notified under the customer agreement rather than left
for you to notice here.
15. Contact and grievances
If we do not resolve your complaint you may escalate it to the Data Protection Board of India,
or — where the GDPR or UK GDPR applies to you — to your local supervisory authority.