Legal

Privacy policy

Last updated January 2026

Contents

Overview

Thaevion is a document approval and submission platform used by organisations to manage internal approvals, collect external document submissions, and maintain verified records of every action taken on a document.

This policy explains what personal data we collect, why we collect it, how we store and protect it, and what rights you have over it. It applies to all members of organisations on the platform, to external parties who submit documents through intake portals, and to visitors to our website.

By using Thaevion, you agree to the data practices described in this policy. If you do not agree, you should not use the platform.

Data we collect

We collect personal data across several categories depending on how you interact with the platform.

Identity and verification data

When you register or are invited to the platform, we collect your full name, email address, phone number, and a government-issued identity number. This is required to confirm that every person acting on the platform is a verified individual. We do not accept anonymous accounts or unverified members.

Organisation data

We collect the name, type, registered address, contact email, and registration details of your organisation. This information is used to scope access and maintain separation between different organisations on the platform.

Document data

Every document uploaded, submitted, or processed through the platform is stored on our infrastructure. This includes the file itself, its metadata, all version history, associated approval records, and any notes or descriptions attached to it.

Activity and audit data

We log every action taken on the platform. This includes logins, document uploads, approval decisions, rejections, delegations, recalls, submissions, and every instance of a document being accessed or viewed. Each log entry captures a timestamp, the identity of the actor, and what was done. These logs are permanent and cannot be altered.

Payment data

For paid intake portals, payments are processed by Paystack. We do not store card numbers or sensitive financial credentials. We retain transaction references, amounts, timestamps, and payment status for compliance and record-keeping.

Technical data

We collect standard technical information including IP addresses, device and browser type, and session identifiers. This data is used for security monitoring, abuse prevention, and platform operation.

How we use your data

We use the data we collect to operate, secure, and improve the platform. Specifically:

To operate the platform

We use identity and document data to process approval requests, route documents through approval chains, authenticate members, and maintain the integrity of every record on the platform.

To verify identity

Every person who acts on a document, whether approving, rejecting, delegating, or submitting, must be a verified individual. We use identity data to ensure that no action can be taken anonymously and that every record is tied to a real, confirmed person.

To maintain audit trails

Every action is logged and retained as part of an immutable record. This is central to the platform's purpose and cannot be disabled. The audit trail exists to protect organisations, their members, and the people they interact with.

To process payments

For paid portals, we pass the necessary information to Paystack to complete the transaction and confirm payment before accepting a submission.

To communicate with you

We send notifications related to approvals, submissions, account events, and security. We do not send unsolicited marketing.

To improve the platform

We analyse usage patterns, error rates, and performance data to identify issues and improve the experience. This analysis does not involve selling or sharing personal data with third parties.

Data storage and security

All data is stored on certified enterprise-grade infrastructure with physical and logical controls at every layer. Data is encrypted in transit using TLS and encrypted at rest. Access to storage is strictly governed by role and every access event is logged.

We operate across certified data centres with built-in redundancy and compliance controls. Our security posture covers hundreds of controls across identity, access, document integrity, and infrastructure.

Audit logs are immutable

Once an action is recorded, it cannot be altered, deleted, or overwritten by any party, including platform administrators. This is by design. The permanence of the audit trail is a core feature of the platform, not a side effect.

We conduct regular security reviews and operate on a shared responsibility model. Platform-level security is our obligation. What organisations are responsible for is the governance of their own accounts, roles, and access policies within the platform.

Data sharing

We do not sell your data. We do not share your data with advertisers. We do not use your data to build profiles for third-party targeting.

We share data only in the following circumstances:

Within your organisation. Members with appropriate roles can view document records, approval histories, and submission data within their organisation's scope. Access is governed by role-based permissions set at the organisation level.

With Paystack

For paid portals, payment data is shared with Paystack to process transactions. Paystack's privacy policy governs how they handle that data. We do not pass more information than is necessary to complete the transaction.

With infrastructure providers

Data is stored and processed using third-party infrastructure providers under strict data processing agreements that prohibit use for any purpose other than providing the service.

When required by law. We may disclose data if required to do so by a valid court order, regulatory authority, law enforcement request, or other lawful legal process. We will notify affected parties where we are legally permitted to do so.

Data retention

We retain your data for as long as your organisation's account is active and for a reasonable period thereafter to meet compliance obligations, support dispute resolution, and satisfy applicable legal requirements.

Audit logs are retained indefinitely

They are part of the permanent record of every document and approval on the platform and cannot be removed without compromising the integrity of the records they document.

Document data is retained for the duration of your organisation's account. When an account is closed, we will work with you on a structured data export and deletion schedule, subject to any legal hold requirements.

Payment records are retained for the period required by applicable financial regulations, which may extend beyond the closure of an account.

If a member leaves an organisation, their account is deactivated but their action history remains in the audit log as part of the organisation's permanent record.

Your rights

Depending on your jurisdiction and applicable data protection law, you may have certain rights over your personal data. These typically include the right to access data we hold about you, to request correction of inaccurate data, to request deletion subject to our retention obligations, to object to certain types of processing, and to receive a portable copy of your data.

To exercise any of these rights, contact us at contact@thaevion.com. We will acknowledge your request promptly and respond within the timeframe required by applicable law.

Some data cannot be deleted. Audit logs, in particular, form part of a legally significant record that may not be removed on request. Where we are unable to fulfil a deletion request, we will explain why.

If you believe we have handled your data improperly, you have the right to lodge a complaint with a relevant data protection authority.

External submitters

If you submit a document through a Thaevion intake portal, you are submitting to an organisation that uses our platform to collect documents from external parties. We collect your name, email address, the document you upload, any note you include, and your payment details if the portal charges a fee.

Your submission is stored on our infrastructure and made accessible to the organisation that created the portal. It is not shared with other organisations or third parties except as described in the data sharing section above.

When your submission is accepted, you will receive an email confirmation and a tracking reference. If the portal is paid, you will be directed to Paystack to complete payment before your submission is accepted.

As an external submitter, you have the same rights over your personal data as any other user of the platform. Contact us at contact@thaevion.com to exercise those rights.

Cookies

We use essential cookies to operate the platform. These include session cookies that keep you logged in, security cookies that protect against cross-site attacks, and preference cookies that remember your settings.

We do not use advertising cookies. We do not use cookies to track you across other websites. We do not share cookie data with third-party advertising networks.

You can control or delete cookies through your browser settings. Disabling essential cookies will affect your ability to use the platform.

Changes to this policy

We may update this policy from time to time to reflect changes in how we operate, changes in the law, or feedback from users and regulators. When we do, we will update the date shown at the top of this page.

For material changes, we will notify active platform members by email before the change takes effect, giving you time to review and, if necessary, raise concerns.

Continued use of the platform after a policy update constitutes acceptance of the revised terms.

Contact

If you have questions about this policy, about how we handle your data, or if you wish to exercise any of your rights, contact us at contact@thaevion.com.

We take privacy seriously. All enquiries will be acknowledged promptly and handled with care.

Thaevion. All rights reserved.

contact@thaevion.com