Privacy Policy

Last updated: July 20, 2026

Anavai Technologies, an Udyam MSME Registered in Delhi, India (Proprietorship, GSTIN 07BBBPB9772P1Z4) ("Anavai", "we", "us"), operates the Anavai Incentive Compensation Management platform (the "Service"). This policy explains what information we collect through the Service, how we use it, and who we share it with.

1. Who this policy covers

The Service is used by business customers ("Customers") to design incentive compensation plans and calculate payouts for their own employees or sales representatives ("End Users"). Customers are responsible for the employee/rep data they choose to process through the Service; for Customer account holders themselves (admins and org owners), Anavai is the data controller.

2. Information we collect

  • Account information — name, work email, and organization membership, via our authentication provider when you sign up or sign in.
  • Compensation plan data — incentive plans, KPI configurations, payout curves, and rules that a Customer builds within the Service.
  • Usage and audit logs — a record of actions taken within the Service (e.g. plan changes, admin actions), kept for security and accountability purposes.

Employee/rep performance data entered via CSV upload is handled differently from the categories above — see Section 3 below.

3. Employee/rep data uploaded via CSV

When a Customer uploads employee or sales-rep performance data via CSV to calculate payouts, that data is processed only for the duration needed to compute and display the results. We do not persist this uploaded data in our database, and Anavai has no standing access to it or visibility into it — it is not stored beyond the active session in which it is processed and is cleared on refresh or when the session ends. At higher subscription tiers, a Customer may optionally request that the processed CSV results be delivered to them via email; this is opt-in and can be disabled for any Customer on request.

4. CRM integration (upcoming feature)

Direct CRM synchronization — automatically pulling employee/rep performance data from a Customer's connected CRM rather than manual CSV upload — is an upcoming capability planned for higher-tier plans. It is not yet available to Customers today. When it launches, data synced through this feature will be stored and processed under a separate Data Processing Agreement (DPA) entered into with each participating Customer, governing retention, access, and deletion of that data specifically.

5. How we use information

We use collected information to: operate and provide the Service (plan design, payout calculation, reporting); maintain audit trails for security and accountability; respond to support requests; and improve the reliability and functionality of the Service. We do not sell personal information, and we do not use Customer data to train any third-party AI model.

6. AI-assisted features

The Service includes an optional AI assistant that answers questions about a Customer's plans and simulations in natural language. When this feature is used, a summarized representation of the relevant plan, KPI, or simulation data is sent to a third-party large language model provider (currently one of Google Gemini, OpenAI, or Anthropic, depending on configuration) to generate the response. We select providers that state they do not use API-submitted data to train their models, but we encourage Customers who handle especially sensitive compensation data to be mindful of this data flow before using the AI assistant.

7. Third parties we share data with

We use a small number of third-party service providers ("sub-processors") to operate the Service, each bound to process data only as needed to provide their service to us:

  • Our authentication provider — sign-in and organization/user management.
  • Our cloud infrastructure provider — application hosting and database storage.
  • Google Gemini, OpenAI, or Anthropic — large language model providers powering the optional AI assistant feature described above.
  • Our email delivery provider — sending transactional emails (e.g. processed CSV results) that a Customer explicitly requests.

We do not share Customer or End User data with any other party for their own marketing purposes, and we do not sell personal information.

8. Data retention and deletion

When a Customer workspace is deleted, its data is first soft-deleted and access is immediately blocked; permanent deletion is performed as a deliberate administrative action. Audit logs are retained beyond workspace deletion for security and accountability purposes. You may request deletion of your account information, or export/deletion of your organization's data, by contacting us at the address below.

9. Cookies and similar technologies

We use cookies and similar technologies (including browser local storage) that are strictly necessary to operate the Service — for example, to keep you signed in and to remember display preferences such as light/dark mode. We do not use third-party advertising or cross-site tracking cookies.

10. Security and compliance

Data in transit is encrypted (HTTPS/TLS). Each Customer's data is logically isolated from other Customers at the application layer, and access to Customer data within Anavai is restricted to what is operationally necessary. We align our data handling practices with globally recognized privacy frameworks, including principles reflected in the EU General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act, 2023 (DPDP Act). The Service is designed with SOC 2 principles from the ground up (tenant data isolation, access controls, audit logging), and we intend to pursue formal SOC 2 certification as we scale.

11. Your rights

Depending on your location and applicable law, you may have rights to access, correct, or request deletion of your personal information, or to withdraw consent for its processing. To exercise any of these rights, contact us at connect@anavaihq.com. If you are an End User whose data was uploaded by your employer (a Customer), we will direct your request to that Customer, as they control that data.

12. Children's privacy

The Service is a business tool and is not directed at, or knowingly used by, individuals under 18.

13. Changes to this policy

As the Service is in active development, this policy may be updated from time to time. We will update the "Last updated" date above when we do, and will make reasonable efforts to notify Customer admins of material changes.

14. Contact

Questions about this policy or your data can be sent to connect@anavaihq.com.