Legal
Privacy Policy
How Tavio collects, uses, and protects personal information.
Last updated — 9 August 2026
Introduction
Your privacy is important to us. This Privacy Policy describes how Tavio AI (“Tavio”, the “Company”, “we”, “us”, or “our”) collects, uses, discloses, and otherwise processes personal information in connection with our websites, applications, and services (together, the “Services”).
Tavio applies artificial intelligence to the work involved in delivering and managing buildings, beginning with procurement. Asset owners, facilities teams, and their advisors use the Services to run tenders, source and assess suppliers, compare bids, verify invoices, and maintain a record of procurement decisions.
We are committed to being transparent about the information we collect and the purposes for which we use it. We may update this Privacy Policy from time to time in accordance with the section headed “Changes” below, and we encourage you to review it periodically.
Capitalised terms used but not defined in this Privacy Policy have the meanings given to them in the applicable agreement between you or your organisation and Tavio.
Scope of this Privacy Policy
This Privacy Policy applies to personal information that we process as a controller, meaning information in respect of which we determine the purposes and means of processing. This includes information relating to visitors to our websites, prospective customers, and authorised users of the Services.
This Privacy Policy does not apply to the following categories of information:
- Customer Content. Where our customers upload or otherwise submit procurement materials to the Services, including tenders, specifications, contractor submissions, compliance documentation, and invoices (“Customer Content”), such materials may contain personal information relating to the customer’s personnel and suppliers. We process Customer Content solely as a processor, acting on the documented instructions of the relevant customer, and our commitments in respect of such processing are governed by the data processing terms forming part of that customer’s agreement with us and not by this Privacy Policy. Where you wish to exercise rights in respect of personal information contained within a customer’s account, you should direct your request to that customer, and we will provide reasonable assistance to the customer in responding.
- Personnel information. Personal information relating to our employees, workers, contractors, and job applicants is governed by our internal employment and recruitment privacy notices and not by this Privacy Policy.
How we collect and use (process) your personal information
We collect personal information directly from you, automatically through your use of the Services, and from third party sources, as described below.
Categories of information we collect
- Account information, including your name, business email address, telephone number, employer, job title, and account credentials.
- Billing and payment information, including billing contact details, billing address, and purchase order references. Where card payments are accepted, such payments are processed by our third party payment provider and we do not store full payment card numbers.
- Contact information you provide, including details of colleagues, suppliers, or other third parties whom you invite to participate in a tender or add to your organisation’s account.
- Settings and preferences, including interface preferences, notification settings, and workflow configuration.
- Device and technical information, including IP address, browser type and version, operating system, device identifiers, and referring pages.
- Project information, including details of the tenders, packages, and projects administered through the Services and the parties involved in them.
- Usage information, including features accessed, actions taken, timestamps, and audit records of procurement decisions.
- Communications, including correspondence, support requests, meeting notes, and feedback that you submit to us.
- Recordings and transcripts, where you use functionality within the Services that records, transcribes, or summarises meetings, calls, or site visits, or where you submit such materials to the Services. Your responsibilities in respect of obtaining consent to recording are set out in our Terms of Service.
- Information obtained from third party sources, including supplier and company information obtained from registries and data providers such as company registries, credit and business information providers, accreditation registers, planning records, and market pricing services. Such information relates principally to businesses, although publicly available records may include limited personal information such as the names of company directors or accredited tradespeople.
Purposes for which we process personal information
We process personal information for the following purposes:
- to provide, operate, maintain, and administer the Services;
- to establish and administer accounts and manage access rights;
- to generate the outputs for which the Services are provided, including the drafting of specifications, the sourcing and assessment of suppliers, the comparison of bids, and the verification of invoices;
- to maintain audit records so that procurement decisions remain traceable;
- to provide customer support, onboarding, and training;
- to invoice for the Services and collect amounts payable;
- to develop and improve the Services, including diagnosing faults and prioritising product development;
- to conduct research and analysis using aggregated or de-identified information;
- to communicate with you regarding the Services, including notifications concerning availability, security, and changes to applicable terms;
- to market our products and services to business contacts, subject to applicable law and to the provision of an unsubscribe facility in each marketing communication;
- to protect the security and integrity of the Services, including detecting, investigating, and preventing unauthorised access, misuse, and fraud; and
- to comply with our legal, tax, accounting, and regulatory obligations, and to establish, exercise, or defend legal claims.
Legal bases for processing
Where the UK General Data Protection Regulation or the EU General Data Protection Regulation applies, we rely on the following legal bases: (i) performance of a contract, in respect of the provision of the Services and the administration of billing; (ii) our legitimate interests, in respect of customer support, product development, information security, and business to business marketing, in each case where such interests are not overridden by your interests or fundamental rights; (iii) your consent, in respect of non-essential cookies and certain marketing communications; and (iv) compliance with a legal obligation, where processing is required by applicable law.
Artificial intelligence processing and model training
The Services employ artificial intelligence models to produce drafts, analysis, comparisons, and compliance indicators. The following commitments apply to such processing:
- Customer Content is not used to train our models or the models of our model providers. Customer Content is processed for the purpose of generating outputs for the relevant customer and is excluded from training datasets. Our agreements with model providers prohibit the training of models on data submitted through the Services.
- Outputs are advisory in nature. The Services are designed to support, and not to replace, the judgement of your personnel. Decisions concerning award, approval, and rejection remain with you. We do not carry out automated decision making producing legal effects concerning you, or similarly significantly affecting you, within the meaning of Article 22 of the UK GDPR.
Tavio employee access to Customer Content
We recognise that Customer Content is commercially sensitive. Our personnel do not access Customer Content in the ordinary course of providing the Services.
Access by our personnel to the documents, records, comments, and annotations contained within a customer account is permitted only in the following circumstances:
- where the customer or an authorised user has expressly authorised such access, including where support assistance has been requested in respect of a specified matter;
- where access is reasonably necessary to investigate a suspected security incident, misuse of the Services, or threat to the integrity of the Services;
- where access is required in order to comply with applicable law or a valid request from a competent authority; or
- where access is necessary in an emergency in order to prevent serious harm to any person.
Access is granted on a least privilege basis, is restricted to personnel who require it for the relevant purpose, and is logged. Authorisation granted for support purposes may be withdrawn by the customer at any time.
Use of the Company website
When you visit our website, we automatically collect certain technical information, including your IP address, browser type and version, operating system, the pages you access, the duration of your visit, and the website from which you were referred.
We process such information in order to operate and secure the website, to analyse how the website is used, and to improve the content and functionality we make available.
Where you submit information through a form on our website, including a request for a pilot or an enquiry to our team, we process the information you provide in order to respond to your enquiry and, where permitted by applicable law, to contact you regarding the Services.
International data transfers
We and our service providers operate internationally, and our customers are located in a number of countries. Personal information may therefore be transferred to, stored in, and processed in countries other than the country in which it was collected, including the United States, and such countries may not afford an equivalent standard of data protection to that of your own country.
Where we transfer personal information originating in the United Kingdom, the European Economic Area, or Switzerland to a country that has not been the subject of an adequacy decision, we implement an appropriate transfer mechanism, which is ordinarily the UK International Data Transfer Addendum or the European Commission Standard Contractual Clauses, supported by a transfer risk assessment where required.
You may request further information regarding the safeguards applied to a particular transfer by contacting us using the details set out below. Customers subject to data residency requirements may discuss available regional deployment options with us.
Information on third parties
We engage third party service providers in connection with the operation of the Services, including providers of cloud hosting and storage, artificial intelligence model capacity, email delivery, and business support tooling. Such providers store or otherwise process personal information on our behalf, are engaged under written contract, and are permitted to process personal information only in accordance with our instructions and for the purposes for which they are engaged.
We do not sell personal information. Save as described above, we disclose personal information only in the following circumstances:
- where you have authorised the disclosure or directed us to make it;
- to other authorised users within your organisation’s account, in accordance with the access controls configured by your administrators;
- to our professional advisors, including auditors and legal advisors, where necessary and subject to obligations of confidentiality;
- where disclosure is required in order to comply with applicable law, a court order, or a valid request from a competent authority;
- where disclosure is necessary in an emergency in order to prevent serious harm to any person; or
- in connection with a merger, acquisition, reorganisation, financing, or sale of assets, subject to appropriate notice.
Where you interact with us through third party platforms, including professional networking and social media platforms, such platforms process your information in accordance with their own privacy policies, over which we have no control. Where we operate a page or campaign on such a platform and receive aggregated audience statistics, we may act as a joint controller with the platform in respect of that limited processing.
Data Subject rights
Subject to the conditions and exemptions provided under applicable data protection law, you may have the following rights in respect of your personal information:
- The right to be informed as to the manner in which your personal information is processed, which this Privacy Policy is intended to satisfy.
- The right of access to the personal information we hold concerning you, and to receive a copy of it.
- The right to rectification of personal information that is inaccurate or incomplete.
- The right to erasure of your personal information in certain circumstances.
- The right to restrict processing of your personal information in certain circumstances.
- The right to object to processing carried out on the basis of our legitimate interests, and to object to direct marketing at any time.
- The right to data portability, being the right to receive personal information you have provided to us in a structured, commonly used, and machine readable format, and to have it transmitted to another controller where technically feasible.
- The right to withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
- The right to lodge a complaint with the supervisory authority in your country of residence, place of work, or the place of the alleged infringement. In the United Kingdom, the relevant authority is the Information Commissioner’s Office (ico.org.uk). Within the European Economic Area, the relevant authority is the data protection authority of the member state concerned. We would welcome the opportunity to address your concerns before you approach a supervisory authority.
You may exercise any of these rights by contacting us at mateo@trytavio.ai. Where your personal information is contained within a customer account, please refer to the section headed “Scope of this Privacy Policy” above.
U.S. State Resident Rights
If you are a resident of a United States state that has enacted comprehensive privacy legislation, including California, Colorado, Connecticut, and Virginia, you may have the following additional rights, subject to the conditions and exemptions provided under the applicable state law:
- the right to know the categories of personal information collected, the sources from which it was collected, the purposes for which it is used, and the categories of third parties to whom it is disclosed;
- the right to request a copy of the personal information we have collected about you;
- the right to request deletion of your personal information;
- the right to request correction of inaccurate personal information;
- the right to opt out of the sale or sharing of personal information and of targeted advertising;
- the right to limit the use and disclosure of sensitive personal information;
- the right not to be subject to discrimination for exercising any of these rights; and
- the right to appeal a refusal to act on a request, where provided for under the applicable state law.
We do not sell or share personal information, as those terms are defined under the California Consumer Privacy Act as amended by the California Privacy Rights Act, and we do not process personal information for the purposes of cross context behavioural advertising.
California residents may additionally request information regarding disclosures of personal information to third parties for those third parties’ direct marketing purposes under California Civil Code section 1798.83, commonly known as the “Shine the Light” law. We do not make disclosures of this nature.
You may use an authorised agent to submit a request on your behalf, provided that we are able to verify the agent’s authority to act for you.
Verification process for individual rights requests
In order to protect your personal information from unauthorised disclosure, we are required to verify your identity before acting upon a request to exercise your rights. We will ordinarily do so by asking you to confirm information that we already hold about you. Where a request is broad in scope, or where the sensitivity of the information warrants it, we may request additional information in order to verify your identity to a higher degree of certainty. Information provided for verification purposes is used solely for that purpose.
We will acknowledge receipt of your request within ten business days. We will respond substantively within one month where the UK GDPR or the EU GDPR applies, and within forty five days where the applicable United States state law so provides. Where a request is complex, or where we have received a number of requests from you, we may extend the period for response to the extent permitted by applicable law, and will inform you of the extension and the reasons for it within the original response period.
We retain records of rights requests and our responses to them for a period of twenty four months in order to demonstrate compliance with applicable law. Requests are dealt with free of charge, save where a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to act, giving reasons.
Data storage and retention
We retain personal information for so long as is necessary for the purposes for which it was collected, following which it is deleted or anonymised. We may retain personal information for a longer period where required in order to comply with a legal, tax, accounting, or regulatory obligation, or where retention is necessary in order to establish, exercise, or defend legal claims.
Given that auditability is a core function of the Services, procurement records and associated audit trails are retained for the duration of the applicable customer agreement in order that procurement decisions remain traceable. Customers control the export and deletion of records within their own accounts.
You may request deletion of your personal information at any time in accordance with the section headed “Data Subject rights” above, subject to verification of your identity and to any applicable legal exemption.
Children’s data
The Services are intended for business use and are not directed at children. We do not knowingly collect personal information from any individual under the age of sixteen.
If you believe that a child has provided personal information to us, please contact us at mateo@trytavio.ai and we will take steps to delete such information without undue delay.
How to contact us
If you have any question concerning this Privacy Policy, or wish to exercise any of your rights, please contact us at mateo@trytavio.ai.
Please refer also to our Terms of Service and our Cookie Policy.
Changes
We may amend this Privacy Policy from time to time in order to reflect changes in our practices, the Services, or applicable law. Any amended version will be posted on this page with a revised date of last update. Where an amendment is material, we will provide notice by email or through the Services before it takes effect. Your continued use of the Services following the effective date of an amended Privacy Policy constitutes acceptance of it.