Privacy Policy
How we collect, use and protect personal data, and the choices you have.
Effective September 7, 2026 · Amended September 11, 2026
This Privacy Policy explains how TechMaven LLC ("TechMaven," "we," "us," or "our") collects, uses, discloses, and protects personal data in connection with the TechMaven AI platform (the "Services"), and the choices available to individuals whose personal data we process. This Privacy Policy should be read together with our Terms of Service. Capitalized terms not defined here have the meaning given in the Terms of Service.
1. Introduction and Scope
This Privacy Policy applies to personal data processed through our website at https://www.techmavs.com, the Services, and our related business communications. It does not apply to third-party websites, applications, or services that Customer connects to the Services, which are governed by that third party's own privacy notice.
2. Who We Are
TechMaven LLC, a limited liability company organized under the laws of the State of Delaware, with a registered address at 8 The Grn Ste A, Dover, DE 19901, United States, is the entity responsible for this Privacy Policy. You can contact us as described in Section 25.
3. Two Categories of Personal Data and Our Role
We process two categories of personal data in operating the Services, and our legal role differs for each.
Account Data: personal data about our direct customers and their authorized users, such as name, business email, business details, and billing information. We are the controller of Account Data.
Customer Data: personal data about End Users who interact with an AI Employee configured by our business customer, such as messages, contact details, appointment information, and documents uploaded during a conversation. Our business customer is the controller of Customer Data, and we act as its processor (or "service provider" or "processor" under applicable state law), processing Customer Data solely on that customer's documented instructions and for the purposes described in our data processing agreement. If you are an End User with a question about how your personal data is used by a specific business using our Services, that business is the appropriate party to contact in the first instance, as it controls that data and configures how the AI Employee is used.
4. Personal Data We Collect as Controller
As controller of Account Data, we collect: identifying and contact information (name, business name, email, phone number); account credentials; billing and payment details, processed through our payment Subprocessor; usage and diagnostic data about how the Services are used, including feature usage, error logs, and device and browser information; and communications you send us, such as support requests.
5. Personal Data Processed as Processor
As processor of Customer Data, we process the categories of personal data our business customers configure their AI Employees to collect, which may include an End User's name, contact details, appointment or scheduling information, the content of the End User's conversation with the AI Employee, and documents the End User uploads. We process only what a given configuration requires to operate, and diagnostic logs are automatically redacted before they are written, so that contact details, identification numbers, payment details and credentials are removed from them by default.
6. Sources of Personal Data
We collect Account Data directly from our business customers and their authorized users. We collect Customer Data from End Users through their interactions with an AI Employee, and from integrations that our business customer connects, such as a calendar, telephony, or customer relationship management system.
7. Purposes and Legal Bases for Processing
We use Account Data to provide and maintain the Services, to process payment, to communicate with our business customers about their account, to secure the Services, to comply with legal obligations, and, where you have not opted out, to send product updates. Where the General Data Protection Regulation or the UK GDPR applies to our processing of Account Data, we rely on performance of a contract, our legitimate interests in operating and securing the Services, and compliance with legal obligations as our legal bases, and we rely on consent where required, such as for optional marketing communications.
We process Customer Data solely to provide the Services in accordance with our business customer's instructions and the applicable data processing agreement; we do not determine the purposes for which Customer Data is processed.
8. Automated Decision-Making and AI Processing
An AI Employee generates responses to End Users using artificial intelligence models operated by our model provider Subprocessors. Every AI Employee identifies itself as an artificial intelligence system at the outset of a conversation and upon request, and this disclosure cannot be disabled by our business customers. Actions TechMaven designates as high risk — currently the sending of bulk communications, and the sending of a message to a recipient whose contact details have not been verified — are not executed by an AI Employee. Such an action is refused and recorded for our business customer's review. We do not use an AI Employee to make a final decision producing a legal or similarly significant effect on an End User without the involvement of our business customer, who remains responsible for how it configures and reviews the AI Employee's conduct.
9. Cookies and Tracking Technologies
We use cookies and similar technologies on our website to operate essential functions, remember preferences, and understand aggregate usage. Details of the categories of cookies we use, their purposes, and how to manage your preferences are set out in our Cookie Policy at https://www.techmavs.com/legal/cookies.
10. Sharing of Personal Data
We share personal data with a limited set of Subprocessors that help us provide the Services, including providers of hosting, database, artificial intelligence model, telephony, email delivery, payment processing, and error monitoring services, each listed with its function at https://www.techmavs.com/legal/subprocessors. We provide notice on that page before adding a new Subprocessor. Our model provider Subprocessors process conversation content solely to generate a response and are contractually prohibited from using that content to train their models. We may also disclose personal data to a successor entity in connection with a merger, acquisition, or sale of assets, subject to that entity's assumption of our obligations under this Privacy Policy, and where required to comply with a legal obligation, protect our rights, or respond to a lawful request from a public authority.
11. No Sale of Personal Data
We do not sell personal data, and we do not share personal data for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act and similar state privacy laws.
12. International Data Transfers
We and our Subprocessors are based principally in the United States. Where we or a Subprocessor transfer personal data originating in the European Economic Area, the United Kingdom, or Switzerland to the United States or another country, we rely on an appropriate transfer mechanism recognized under applicable law, such as the European Commission's Standard Contractual Clauses or the UK International Data Transfer Addendum, as applicable.
13. Data Retention
We retain Account Data for as long as necessary to provide the Services and for a reasonable period afterward to comply with legal, accounting, and dispute-resolution obligations. We retain Customer Data for as long as our business customer's workspace remains active. Our business customer may request deletion of Customer Data, in whole or for a specified period or category, by writing to support@techmavs.com, and we will confirm deletion in writing, including the date on which any remaining copies held in encrypted backups are expected to expire. Configurable automatic retention periods are not currently available. When personal data is deleted, we provide confirmation of the date on which any remaining copies held in encrypted backups are expected to expire.
14. Data Security
We maintain administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, disclosure, alteration, and destruction, including tenant-level isolation of each business customer's data at the database layer, encryption of data in transit, and role-based access controls. No system is completely secure, and we cannot guarantee absolute security.
15. Children's Privacy
The Services are intended for use by businesses and are not directed to children. We do not knowingly collect personal data directly from children through our website in a manner requiring parental consent under the Children's Online Privacy Protection Act. If a business customer's use case results in the collection of a child's personal data as Customer Data, that business customer is responsible for ensuring it has the legal basis and parental consent required by applicable law, including the Children's Online Privacy Protection Act where applicable.
16. Your Privacy Rights — General
Subject to applicable law and the exceptions available under it, individuals may have the right to know what personal data we hold about them, to access or obtain a copy of it, to correct inaccurate data, to request deletion, and to object to or restrict certain processing. Where we act as a processor of Customer Data, we will direct a request received from an End User to the relevant business customer, or will assist that business customer in responding to the request, as required by our data processing agreement.
17. California Privacy Rights
California residents have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, including the right to know, delete, correct, and limit use of sensitive personal data, and the right to non-discrimination for exercising these rights. As stated in Section 11, we do not sell personal data or share it for cross-context behavioral advertising, so no opt-out of sale or sharing is required. California residents may exercise their rights as described in Section 20, and may designate an authorized agent to submit a request on their behalf, subject to verification.
18. Other US State Privacy Rights
Residents of states with comprehensive consumer privacy laws in effect, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states as their laws take effect, have similar rights of access, correction, deletion, portability, and appeal, subject to the exceptions and thresholds in the applicable state law. We honor these rights as required by the law of the state in which the individual resides.
19. European Economic Area and United Kingdom Rights
Where the General Data Protection Regulation or the UK GDPR applies to our processing of your personal data, you have the right to access, rectify, erase, or restrict processing of your personal data, to data portability, to object to processing based on our legitimate interests or for direct marketing, and to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal. You also have the right to lodge a complaint with your local supervisory authority.
20. How to Exercise Your Rights
You may exercise the rights described above by writing to support@techmavs.com. We will verify your identity before acting on a request, and will respond within the timeframe required by applicable law. If you are an End User whose data is Customer Data controlled by one of our business customers, we recommend contacting that business directly, and we will support it in responding to your request.
21. Business Customer Obligations as Controller of Customer Data
Where our business customer is the controller of Customer Data, that customer is responsible for providing End Users with any privacy notice required by applicable law, for establishing a lawful basis for collecting and processing End Users' personal data, and for responding to or coordinating with us on End Users' privacy rights requests, in each case as further described in our data processing agreement at https://www.techmavs.com/legal/dpa.
22. Telephone, SMS and Email Communications Data
Where an AI Employee communicates with an End User by telephone, SMS, or email, call metadata, message content, and delivery status may be processed as Customer Data for the purposes of providing the Services, including opt-out and consent-management features made available to our business customers. Telephone and messaging Subprocessors may also retain metadata as required for carrier compliance and billing purposes, consistent with their own privacy practices.
23. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version with a revised effective date, and where a change is material, we will provide additional notice by email or through the Services at least thirty (30) days before it takes effect.
24. Complaints and Supervisory Authorities
If you have a concern about our handling of your personal data that we have not resolved to your satisfaction, and applicable law gives you the right to do so, you may lodge a complaint with your local data protection or consumer protection authority.
25. Contact Us
Questions about this Privacy Policy or requests concerning your personal data should be directed to support@techmavs.com. Security-related reports should be directed to security@techmavs.com. TechMaven LLC, 8 The Grn Ste A, Dover, DE 19901, United States.