GDPR Compliance
Last updated: July 16, 2026
This page explains how Lenviva complies with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the UK GDPR. It is a plain-language summary — for the full details see our Privacy Policy and Data Processing Agreement.
1. Who is the controller?
For personal data collected when you sign up as an individual user, Lenviva is the data controller. For personal data processed on behalf of a business customer (e.g. an employer provisioning accounts for its employees), Lenviva acts as a processor and the business customer is the controller — governed by our DPA.
2. Legal bases for processing (Article 6)
- Contract — to provide the practice interviews, transcripts, and coaching you sign up for.
- Legitimate interests — to secure the service, prevent abuse, and improve product quality; balanced against your rights and freedoms.
- Consent — for optional analytics cookies and marketing communications. You can withdraw consent at any time.
- Legal obligation — for tax, accounting, and lawful requests from authorities.
3. Your rights under GDPR
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — request deletion ("right to be forgotten") where applicable.
- Restriction — ask us to pause processing in certain circumstances.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests, including profiling.
- Withdraw consent — at any time, without affecting the lawfulness of prior processing.
- Automated decisions — we do not use your data for solely automated decisions with legal or similarly significant effects.
- Lodge a complaint — with your local supervisory authority (e.g. Datatilsynet in Norway, ICO in the UK).
To exercise any of these rights, email privacy@lenviva.app. We respond within 30 days and may ask you to verify your identity.
4. International data transfers
Some of our sub-processors are located outside the European Economic Area. Where transfers occur, we rely on the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and additional safeguards where required.
5. Retention
We keep personal data only as long as necessary for the purposes described in our Privacy Policy, and delete or anonymize it afterwards.
6. Security
We apply appropriate technical and organizational measures under Article 32, including encryption in transit and at rest, role-based access controls, MFA for staff, logging, and documented incident response with 72-hour breach notification.
7. Sub-processors
Our current sub-processors are listed in our Privacy Policy. We give business customers at least 30 days' notice of material changes so they may object.
8. Data Protection Officer & EU representative
For questions about our GDPR compliance or to reach our privacy team, email privacy@lenviva.app.
This document is a template provided for convenience. It is not legal advice. Please have a qualified attorney in your jurisdiction review and adapt it to your specific business before relying on it.