Template notice: This is a plain-English template, not legal advice — have a lawyer review before relying on it.

Privacy Policy

Last updated: 2026-07-18 · Version: 2026-07-18-v3

This Privacy Policy explains how Provamar collects, uses, and protects your information when you use the Service.

What we collect

  • Operating records: the data you enter into the Service — water quality checks, feed records, treatment logs, mortality events, equipment records, and other operational data.
  • Account information: your name, email address, and organisation details provided during sign-up and onboarding.
  • Basic usage data: which features you use, error logs, and general usage patterns — to help us improve the product.
  • Enquiry information: when you contact us or request a pilot, we collect the contact details, organisation details, country, and message you choose to provide so we can respond and assess product fit.

How we use your information

  • To provide the Service: all data you enter is used to operate the logbook, action queue, and reporting features.
  • To improve the product: we may use anonymised, aggregated data (data that cannot identify you or your organisation) to understand usage patterns and improve Provamar.
  • Never sold: we do not sell your personal data to third parties.
  • No commercial sharing without your approval: apart from the service providers needed to operate Provamar, we do not share your data or identity with a supplier, consultant, or other commercial recipient without your explicit approval — for example, when you review and approve a quote request.

Storage and security

  • Organisation-scoped isolation: your data is stored and accessed only within your organisation boundary — users from other organisations cannot see your records.
  • Role-based access control: within your organisation, access is limited by the role assigned to each user.
  • Encrypted at rest: your data is encrypted at rest by our database provider (Supabase / PostgreSQL).
  • Internal support actions are logged: authorised staff can view organisation-scoped information for support. Sensitive support changes require a reason and are written to the audit trail; Provamar does not provide broad unaudited impersonation.

Service providers, data location, and AI processing

  • Current providers: Supabase provides authentication, PostgreSQL, and file storage; Vercel provides application hosting and serverless execution. The current provider list is published on our About & trust page. See the current service-provider list.
  • Production data location: the production Supabase database is hosted in EU Central (Frankfurt, Germany). Vercel may process requests and application logs through its delivery and serverless infrastructure.
  • AI-assisted features: when you deliberately invoke an AI-assisted feature, the content needed for that task may be sent to the AI provider configured for Provamar. AI-derived fields and outputs require your review and do not certify, diagnose, or make decisions for you.

Your rights

  • Export your data: you can export your operating records at any time from within the Service.
  • Request deletion: you may request deletion of your account and associated data. Eligible data is erased after identity verification and a grace period; treatment or medicine records that may be subject to legal retention can be retained or anonymised for up to five years. Provamar shows what will be deleted, anonymised, or retained before irreversible erasure.
  • End at any time: you can stop using the Service and terminate your account at any time. See our Terms of Service for details.

Contact

For privacy-related questions or requests, contact us at todamoonbro@gmail.com.