Privacy Policy
Last Updated: February 1, 2026
Effective Date: February 1, 2026
ExonPro Innovations LLP ("ExonPro," "we," "us," or "our") operates the xVio platform and its family of applications (collectively, the "Service"). This Privacy Policy explains how we collect, use, and protect your information.
We are committed to protecting your privacy and complying with applicable data protection laws including GDPR and CCPA/CPRA.
Part A: Platform Privacy Policy
This section applies to all xVio applications.
1. Information We Collect
Account Information
When you sign in through your organization's identity provider, we receive:
- ▸ Name and email address — to identify your account
- ▸ User identifier — to link your sessions
- ▸ Organization details — to provide access to your organization's workspace
Usage Information
We automatically collect:
- ▸ Device information — device type, operating system version
- ▸ App usage — features used, usage counts for quota tracking
- ▸ Error data — crash reports to improve stability
2. How We Use Your Information
We use your information to:
- ▸ Provide the Service: process your requests, sync with your connected systems
- ▸ Improve the Service: analyze usage patterns, fix bugs, develop features
- ▸ Communicate: send notifications, respond to support requests
- ▸ Ensure security: authenticate users, prevent unauthorized access
We do NOT:
- ✗ Sell your personal information
- ✗ Share your data with advertisers
- ✗ Create marketing profiles
3. Information Sharing
With Your Organization
Your organization's administrators may access usage reports and configure service settings.
With Your Connected Systems
When you export data, it is sent directly to your organization's connected business systems (such as CRM, ERP, or other integrated applications).
Service Providers
We use service providers for infrastructure and processing. These providers:
- ▸ Process data only on our behalf
- ▸ Are bound by data protection agreements
- ▸ Cannot use your data for their own purposes
Legal Requirements
We may disclose information if required by law or to protect rights, safety, or property.
We never sell your personal information.
4. Data Security
We protect your data using:
Your data is kept separate from other organizations using the platform.
5. Data Retention & Deletion
| Data Type | Retention Period |
|---|---|
| Account data | Duration of your account |
| App-specific data | See app addendum below |
Deleting Your Data
When your account is deleted, your data is removed within 30 days.
6. Your Privacy Rights
For All Users
You have the right to:
your personal data
inaccurate data
your data
your data in a portable format
Additional Rights (GDPR - EU/EEA)
- ▸ Object to processing
- ▸ Restrict processing
- ▸ Withdraw consent
- ▸ Lodge a complaint with your data protection authority
Additional Rights (CCPA - California)
- ▸ Know what personal information is collected
- ▸ Request deletion of personal information
- ▸ Opt-out of sale (we do not sell your data)
- ▸ Non-discrimination for exercising rights
To exercise your rights, email privacy@xvio.ai. We respond within 30 days.
7. Additional Information
Children's Privacy
The Service is not intended for users under 16. We do not knowingly collect data from children.
International Transfers
Your data may be processed in countries outside your own. We ensure appropriate safeguards are in place for international transfers.
Policy Updates
We may update this policy. Material changes will be communicated via email or in-app notification. Continued use after changes constitutes acceptance.
Part B: App-Specific Addendums
xVio Scan
Document scanning and AI data extraction app
Additional Data Collected
| Data Type | Description |
|---|---|
| Uploaded documents | Images and PDFs you scan or upload |
| Extracted data | Text and fields extracted by AI processing |
| Scan metadata | Timestamps, document type, processing status |
The content of your scanned documents may contain personal information. This data is processed to provide the Service and stored according to your organization's retention settings.
Camera Access
xVio Scan can use your device's camera to capture documents for scanning.
- ▸ Camera is only active when you tap the scan button
- ▸ We capture images of documents you choose to scan
- ▸ Images are processed locally for preview before upload
- ▸ Camera access requires your explicit permission (runtime prompt)
- ▸ You can deny or revoke camera permission in your device settings
- ▸ If camera permission is denied, you can still upload existing files
We do not access your camera in the background, record video, or use facial recognition.
File & Media Access
You can upload existing images or PDF files from your device instead of using the camera.
- ▸ We only access files you explicitly select through the system file picker
- ▸ We do not scan or access your full photo library or gallery
- ▸ File access uses limited system permissions (picker-based access)
- ▸ Uploaded files are processed the same way as camera-captured images
You control which files to share. We cannot access files you don't explicitly select.
How Captured Data is Handled
Whether you capture via camera or upload a file, your documents are processed as follows:
- ▸ Images are captured/selected only when you initiate the action
- ▸ A local preview is shown before upload
- ▸ Images are uploaded to our servers only when you confirm
- ▸ Our AI extracts text and data from the document
- ▸ Source images can be deleted immediately after processing (configurable by your organization)
What We Do NOT Do
- ✗ Access your camera in the background
- ✗ Access your full photo library or gallery
- ✗ Record video
- ✗ Use facial recognition
- ✗ Access files you don't explicitly select
AI Processing
- ▸ We use AI-powered text extraction to process your documents
- ▸ Your documents are NOT used to train AI models
- ▸ Extracted data accuracy should be verified for critical decisions
Your documents are never used to train AI models.
Optional Diagnostic Data
Diagnostic logging is disabled by default. If you enable it in Settings for troubleshooting:
- ▸ Detailed processing logs are temporarily stored
- ▸ This data is automatically deleted based on your organization's retention policy
You control when diagnostic data is collected.
Data Retention (xVio Scan)
Scan metadata includes timestamps, document type, and processing status. Original source files can be configured for immediate deletion after AI extraction is complete.
| Data Type | Retention Period |
|---|---|
| Scan metadata | Configured by your organization (default: 1 year) |
| Extracted summary fields | Configured by your organization (default: 1 year) |
| Source files (images/PDFs) | Configurable (can be deleted immediately after processing) |
| Diagnostic logs | 7-90 days (if enabled) |
Contact Us
For privacy questions or to exercise your rights, contact us at privacy@xvio.ai
