Privacy Policy
Privacy Policy
Uva Software, LLC (Scanii)
This Privacy Policy explains how Uva Software, LLC (“Uva Software”, “we”, “us”) collects, uses, shares and retains personal data when you visit our websites (www.scanii.com, docs.scanii.com and related sites, the “Sites”), register for or use the Scanii content-analysis service and its web portal (the “Services”), or otherwise deal with us. “Personal Data” means information relating to an identified or identifiable individual.
1. WHO WE ARE AND OUR TWO ROLES
Uva Software, LLC is a limited liability company organized in Indiana, USA, with its address at 11650 Olio Rd STE 1000-171, Fishers, IN 46037. Uva Software operates Scanii, an application programming interface that analyzes files submitted by our customers to identify unsafe or unwanted content.
We process Personal Data in two distinct roles. For the Personal Data described in this Privacy Policy, being account, billing, support, website and usage data about our customers, their authorized users, prospects and visitors, we act as a controller. For the contents of files that customers submit to the Services for analysis, and any metadata they attach (“Customer Data”), we act as a processor, or sub-processor, on the customer’s documented instructions under our Customer Data Processing Addendum (https://docs.scanii.com/article/172-dpa, the “DPA”). This Privacy Policy governs our controller role. Our processing of Customer Data is governed by the DPA and our agreement with the relevant customer, and questions about Customer Data should be directed to that customer.
2. PERSONAL DATA WE COLLECT
Account and billing information. When you register, you or your organization provide a name, email address, password (stored as a hash) or a sign-in identity from a third-party identity provider, company name, and, for paid plans, a billing email address and billing details. Payment card details are collected and held by our payment processor, Stripe; we do not store card numbers. We also hold the API keys, plan, invoices and subscription details associated with the account, and the names and email addresses of the users your organization adds to it.
Website and contact information. When you fill in a form on the Sites, request a quote, apply for our startup program, or correspond with us by email, we collect the information you provide, typically your name, business affiliation and email address and the content of your message.
Support information. When you contact us for support we keep the correspondence and related records in our helpdesk system so that we can resolve your request and refer to it later.
Usage and technical information. When you use the Services or the Sites we collect information generated by that use: API request metadata (account and API key identifiers, request timestamps, the client software identifier or user-agent string, processing region, request outcome and detection findings), portal activity, and security events such as sign-in attempts. Our servers also record IP addresses and similar connection information in access and security logs, which are retained for a limited period as described in Section 9. We do not collect usage information about your own end users beyond what is necessary to provide and secure the Services.
Marketing and attribution information. If you arrive at the Sites from an online advertisement we may record the advertising click identifier and referring source in a first-party cookie and, if you register, against your account, so that we can measure which advertising leads to sign-ups. See Section 4.
Information we do not collect. In our controller role we do not collect special categories of Personal Data (such as health, racial or ethnic origin, religion or sexual orientation) or protected-classification characteristics about our customers, prospects or visitors, and we do not knowingly collect Personal Data from children (Section 13). Files submitted to the Services by customers may contain any category of personal data as determined by the customer; that Customer Data is processed on the customer’s instructions as described in Section 1 and is not collected by Uva Software for its own purposes.
3. HOW WE USE PERSONAL DATA AND OUR LEGAL BASES
We use Personal Data to create and administer accounts, authenticate users, provide, secure and support the Services, process payments and manage subscriptions, communicate with you about your account and about changes to the Services or our terms, measure and improve the Services and the Sites, prevent fraud and abuse, comply with law, and enforce our agreements. We do not sell Personal Data, and we do not use Customer Data to train detection models or for any purpose other than providing the Services.
Where the GDPR or the UK GDPR applies, our legal bases are:
· Performance of a contract: account creation and administration, provision of the Services, billing and payment, customer support.
· Legitimate interests: securing the Services and preventing fraud and abuse, understanding and improving use of the Services and the Sites, measuring advertising effectiveness, and communicating with business contacts about our Services, in each case balanced against your rights and freedoms.
· Consent: marketing communications and non-essential cookies where consent is required; you may withdraw consent at any time.
· Legal obligation: retaining records required for tax, accounting and other legal purposes, and responding to lawful requests.
4. COOKIES AND ANALYTICS
The Sites and the web portal use first-party cookies that are necessary to sign you in, keep your session secure and remember your preferences. The public Sites also use Google Analytics and Google Ads conversion measurement to understand how visitors find and use the Sites and whether our advertising leads to sign-ups; where you arrive from an advertisement, the click identifier is stored in a first-party cookie for up to ninety (90) days. The web portal includes a support widget provided by Help Scout that sets its own cookies when used. Where required by law, non-essential cookies are set only with your consent. You can control cookies through your browser settings; disabling necessary cookies will prevent you from signing in.
5. HOW WE SHARE PERSONAL DATA
We do not sell, rent or trade Personal Data, and we do not share it with third parties for their own marketing. We share Personal Data only:
· with the service providers listed in Section 7, who process it on our behalf and on our instructions under written contracts that include data protection terms, to host, deliver, bill for and support the Services;
· with your organization’s account administrators, who can see the users, API keys and activity of the account they administer;
· to comply with law, regulation, legal process or an enforceable governmental request, including lawful requests by public authorities for law enforcement or national security purposes, to enforce our agreements, or to protect the rights, property or safety of Uva Software, our customers or others; and
· in connection with a merger, acquisition, financing, reorganization or sale of assets, in which case we will require the recipient to use Personal Data only in accordance with this Privacy Policy.
6. INTERNATIONAL TRANSFERS
Uva Software is located in the United States, and Personal Data described in this Privacy Policy is processed there. Customer Data submitted to the Services is processed in the service region selected by the customer, as described in the DPA and at https://docs.scanii.com/article/161-endpoints-and-regions.
Adequacy. Where Personal Data is transferred to us from the European Economic Area, the United Kingdom or Switzerland, we rely primarily on adequacy mechanisms: Uva Software participates in the EU-U.S. Data Privacy Framework (recognized by the European Commission’s adequacy decision of 10 July 2023), the UK Extension to the EU-U.S. DPF (recognized by the Data Protection (Adequacy) (United States of America) Regulations 2023), and the Swiss-U.S. DPF (recognized by Switzerland with effect from 15 September 2024). See Section 11.
Contractual safeguards. In addition, our DPA incorporates the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914) and the UK Information Commissioner’s International Data Transfer Addendum as an automatic contractual fallback if an adequacy mechanism ceases to apply. You may obtain details of the mechanism under which your Personal Data is transferred by contacting privacy@uvasoftware.com.
7. SERVICE PROVIDERS AND SUB-PROCESSORS
This section is the Sub-processor List referred to in Section 5.2 of the DPA. We will notify customers of changes to it as the DPA provides.
Sub-processor of Customer Data (files submitted to the Services):
· Amazon Web Services, Inc. (cloud infrastructure and file-content processing). File contents are processed in the service region the customer selects: US1 (Virginia, USA), EU1 (Dublin, Ireland), EU2 (London, United Kingdom), AP1 (Sydney, Australia), AP2 (Singapore) or CA1 (Montreal, Canada). Account administration and the job-metadata described in the DPA are hosted in the United States.
Service providers for account, billing, support and website data (controller role), all located in the United States:
· Stripe, Inc.: payment processing and subscription billing.
· Help Scout PBC: helpdesk, support ticketing and the in-portal support widget.
· Microsoft Corporation: corporate email, identity and productivity services.
· Google LLC: advertising and website analytics for the public Sites. Google does not process Customer Data.
8. SECURITY
We maintain, and require our service providers to maintain, technical and organizational measures appropriate to the risk, including encryption of data in transit and at rest, multi-factor authentication and least-privilege access for our personnel, logging and monitoring, independent penetration testing, and documented incident response procedures. Details are published in our Security Overview at https://docs.scanii.com/article/122-security-overview. No method of transmission or storage is completely secure, and we encourage you to protect your credentials and API keys.
9. RETENTION
We keep Personal Data only as long as needed for the purposes described in this Privacy Policy, then delete or irreversibly anonymize it. Our retention periods are:
· Account and user information: for the life of the account. When an account is deleted by its administrator or terminated by us, the account, its users’ Personal Data, API keys and related records are deleted or irreversibly anonymized within thirty (30) days, except as stated below. Free-tier accounts with no sign-in and no use of the Services for twelve (12) consecutive months may be terminated on thirty (30) days’ notice and then deleted in the same way.
· Billing and transaction records: for the period required by tax and accounting law, in anonymized form where the account has been deleted. Payment records are held by Stripe under its own retention rules.
· Customer Data: file contents are deleted on completion of analysis. Analysis result records are retained in the processing region for up to four hundred (400) days and can be deleted earlier by the customer through the API; they are deleted within thirty (30) days of account deletion, as set out in the DPA.
· Support correspondence: for as long as needed to resolve the request and for a reasonable period afterwards to handle follow-ups and disputes.
· Access, sign-in and security logs: up to ninety (90) days.
· Advertising attribution cookies: up to ninety (90) days, or until you register.
· Backups: copies of the above may persist in encrypted backups for up to ninety (90) days under our backup rotation. Backups are not restored except to recover the Services.
We may retain Personal Data for longer where required by law, legal process or a governmental request, or where reasonably necessary to establish, exercise or defend legal claims, for the applicable limitation period.
10. YOUR RIGHTS AND CHOICES
Depending on where you live, you may have the right to access the Personal Data we hold about you and to receive a copy; to have inaccurate or incomplete Personal Data corrected; to have Personal Data erased; to restrict or object to processing, including processing based on legitimate interests; to receive Personal Data you provided to us in a portable format; to withdraw consent where processing is based on consent; and to obtain information about the safeguards applied to international transfers. You may object at any time to direct marketing, and every marketing email we send includes an unsubscribe link. Account administrators can update account and user details, and delete the account, from the account settings pages of the web portal.
To exercise these rights, email privacy@uvasoftware.com. We may ask you to verify your identity before acting on a request, and we respond within the timeframes required by applicable law. If you are dissatisfied with our response you may lodge a complaint with your data protection supervisory authority; in the United Kingdom this is the Information Commissioner’s Office. If your request concerns Customer Data for which we act as processor, we will refer it to the relevant customer, who is the controller of that data, and assist them as required by the DPA.
11. EU-U.S. DATA PRIVACY FRAMEWORK
Uva Software, LLC complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Uva Software, LLC has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. Uva Software, LLC has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this Privacy Policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.
Uva Software is responsible for the processing of personal data it receives under the DPF and subsequently transfers to a third party acting as an agent on its behalf, and remains liable under the DPF Principles if its agent processes such personal data in a manner inconsistent with the Principles, unless Uva Software proves that it is not responsible for the event giving rise to the damage. Uva Software may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. With respect to personal data received or transferred pursuant to the DPF, Uva Software, LLC is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission.
Complaints and recourse. Uva Software commits to resolve DPF Principles-related complaints about our collection and use of your personal information. EU, UK and Swiss individuals with inquiries or complaints regarding our handling of personal data received in reliance on the DPF should first contact us at privacy@uvasoftware.com. Uva Software has further committed to refer unresolved DPF Principles-related complaints to Data Privacy Framework Services, an alternative dispute resolution provider operated by BBB National Programs, at no cost to you. If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, please visit https://bbbprograms.org/programs/all-programs/dpf-consumers/ProcessForConsumers for more information or to file a complaint. Under certain conditions, you may invoke binding arbitration for residual claims not resolved by other redress mechanisms; see Annex I of the DPF Principles at https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction.
12. CALIFORNIA PRIVACY RIGHTS
Uva Software provides the Services to businesses. Where we process Customer Data containing personal information of California residents on behalf of a customer, we do so as a service provider under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA), in accordance with the DPA and our agreement with that customer; California residents wishing to exercise CCPA rights over such data should contact the relevant customer. For the Personal Data we collect as a business in our own right, described in Section 2, we do not sell personal information or share it for cross-context behavioral advertising, and we do not use or disclose sensitive personal information other than as permitted by the CCPA. California residents may exercise their rights to know, delete and correct, and will not be discriminated against for doing so, by emailing privacy@uvasoftware.com; an authorized agent may submit a request on your behalf with your written permission, and we will verify the request with you directly.
13. CHILDREN
The Sites and Services are intended for business use and are not directed to children under the age of 16. We do not knowingly collect Personal Data from children under 16. If you believe a child has provided us with Personal Data, please contact us at privacy@uvasoftware.com and we will delete it.
14. THIRD-PARTY LINKS
The Sites may link to third-party websites and services that we do not control. This Privacy Policy does not apply to them, and we encourage you to review their privacy policies.
15. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy to reflect changes in law, technology or our business. We will post the updated version on the Sites with a revised “Last updated” date and, for material changes affecting customers, notify the email address associated with the account in advance.
16. CONTACT US
Questions, requests and complaints about this Privacy Policy or our handling of Personal Data may be sent to privacy@uvasoftware.com or to Uva Software, LLC, 11650 Olio Rd STE 1000-171, Fishers, IN 46037, USA.
Last updated September 8, 2026.