ViaMeet by TenviaOS
Privacy policy
Last updated 6 August 2026.
1. Scope
This policy explains how TenviaOS, a division of New Venture Management ("TenviaOS", "we", "us"), handles personal information when you visit our website, enquire about our products, join early access, or use one of our platforms: Tenvia Coworks, Tenvia Build, or Tenvia PM (each a "Platform").
We act in two different roles, and it matters which one applies:
- As a controller: for information we collect about you directly, such as a website enquiry, an early access signup, or a subscriber account.
- As a processor: for information our customers load into a Platform about their own clients, tenants, members, or staff. That information belongs to the customer. We process it on their instructions. See section 5.
2. Information we collect
Information you give us
- Enquiry and early access details: name, company name, email address, phone number, industry, number of locations or projects, and anything you write in the message field.
- Account details: if you subscribe to a Platform: account holder name, business details, billing contact, and user records for staff you invite.
- Support correspondence: messages you send us and our replies.
Information collected automatically
- Technical data: IP address, browser type and version, device type, operating system, and referring page.
- Usage data: pages viewed, features used, and timestamps, used to operate and improve the service.
- Log data: server logs recording requests to our systems, retained for security and troubleshooting.
Information we do not collect
We do not store full payment card numbers. Card payments are handled by a third-party payment processor and we retain only a processor-issued token and the limited details needed to identify a payment method (such as card brand and last four digits). We do not purchase personal information from data brokers, and we do not sell personal information.
3. How we use information
| Purpose | What this means in practice |
|---|---|
| Responding to enquiries | Replying to your message, arranging a demo, answering questions about pricing or fit. |
| Providing the service | Creating and maintaining accounts, delivering Platform functionality, providing support. |
| Billing | Issuing invoices, processing subscription payments, maintaining financial records. |
| Product improvement | Understanding which features are used so we can prioritise development. |
| Security and integrity | Detecting abuse, investigating incidents, maintaining audit records. |
| Service communication | Notifying you about changes, outages, security matters, or terms updates. |
| Early access updates | Sending roadmap and release information if you asked for it. You can stop these at any time. |
| Legal compliance | Meeting obligations under applicable law, and responding to lawful requests. |
We do not use your information to make decisions about you by automated means that produce legal or similarly significant effects.
4. Legal basis for processing
Where the UK GDPR or EU GDPR applies to our processing, we rely on the following bases:
- Contract: to provide a Platform to a subscriber and administer their account.
- Legitimate interests: to respond to business enquiries, secure our systems, and improve our products, where those interests are not overridden by your rights.
- Consent: for optional marketing and early access updates, and for analytics cookies. You may withdraw consent at any time.
- Legal obligation: where we are required to retain or disclose information by law.
Where Canadian federal privacy law (PIPEDA) applies, we collect, use, and disclose personal information with your knowledge and consent, except where the law permits otherwise, and for purposes a reasonable person would consider appropriate in the circumstances.
5. Customer data in our platforms
Our customers use TenviaOS Platforms to manage their own operations. In doing so, they enter information about their clients, members, tenants, subcontractors, or staff. We call this Customer Data.
- The customer determines what Customer Data is collected and why. They are the controller of it. We are the processor.
- We process Customer Data only to provide the Platform, to support the customer, to keep the service secure, and as otherwise instructed by the customer.
- We do not use Customer Data to market to the individuals it describes, and we do not sell it.
- Each customer operates in an isolated tenant. Customer Data is scoped to the tenant that owns it.
- If you are an individual whose information is held in a Platform by one of our customers, direct your access, correction, or deletion request to that customer. If you contact us instead, we will refer you to them.
6. Sharing and service providers
We do not sell personal information. We share it only in these circumstances:
- Service providers: vendors who perform functions on our behalf, including cloud hosting, form handling, email delivery, payment processing, error monitoring, and customer support tooling. They are bound to use the information only to provide their service to us.
- Analytics: if you consent to analytics, Google receives website usage data as described in section 11. Analytics does not run unless you accept it.
- Professional advisers: lawyers, accountants, and auditors, where necessary and under a duty of confidentiality.
- Legal requirement: where we are required to disclose by law, court order, or a lawful request from a public authority.
- Protecting rights: where disclosure is necessary to investigate suspected fraud, enforce our terms, or protect the safety of any person.
- Business transfer: if TenviaOS is involved in a merger, acquisition, financing, or sale of assets, information may transfer as part of that transaction. We will give notice before your information becomes subject to a materially different privacy policy.
7. International transfers
TenviaOS operates from Canada, and our service providers may process information in other countries, including the United States and the European Economic Area. Where we transfer personal information out of a jurisdiction with data export restrictions, we rely on an appropriate transfer mechanism, such as standard contractual clauses or an adequacy decision.
Information stored or processed in another country may be accessible to the courts and law enforcement of that country under its laws.
8. Retention
| Category | Retention |
|---|---|
| Website enquiries | Up to 24 months from last contact, unless a customer relationship begins. |
| Early access signups | Until you unsubscribe or ask us to remove you. |
| Account and Customer Data | For the life of the subscription, plus a limited window after termination for export. See our Terms of Service. |
| Billing and financial records | As required by applicable tax and corporate law. |
| Security and audit logs | Retained for a limited period appropriate to the purpose. |
Where information is no longer needed for a purpose set out in this policy and we are not required to keep it, we delete or anonymise it.
9. Your rights
Depending on where you are, you may have the right to:
- Ask what personal information we hold about you and get a copy.
- Ask us to correct information that is inaccurate or incomplete.
- Ask us to delete information, where we have no continuing basis to keep it.
- Object to, or ask us to restrict, certain processing.
- Ask us to provide information you gave us in a portable format.
- Withdraw consent where we relied on it, without affecting processing already carried out.
- Complain to a supervisory authority. In Canada, that is the Office of the Privacy Commissioner of Canada. In the EEA or UK, it is your local data protection authority.
Use the contact form to make a request. We may need to verify your identity before acting, and we will respond within the timeframe required by applicable law. We will not treat you differently for exercising a right.
10. Security
We maintain technical and organisational measures appropriate to the risk, including tenant-level data isolation, role-based access controls, access-controlled document storage, payment tokenisation, and audit logging. Further detail is on our security page.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, and you send information to us at your own risk. If you believe you have found a vulnerability, tell us through the contact form before disclosing it publicly.
11. Cookies and analytics
Strictly necessary
Our website uses only what is necessary to serve pages and remember your cookie choice. Your analytics preference is stored locally in your browser, not on our servers. Our web font is loaded from a third-party font service, which will receive your IP address as part of that request.
Analytics: optional, off until you say otherwise
We use Google Analytics 4 to understand how the website is used, so we can improve it. It does not run unless you accept it. When you first visit, we ask. If you decline, no analytics script is loaded and no analytics cookies are set. If you accept:
- Google Analytics sets cookies (typically
_gaand_ga_<id>) to distinguish visitors and sessions. These usually expire after up to two years. - We collect pages viewed, approximate location derived from IP address, device and browser type, referring source, and on-site actions.
- IP anonymisation is enabled, and Google advertising and personalisation signals are disabled.
- We do not use analytics data to identify you personally, and we do not combine it with your enquiry or account records.
Legal basis and control
Where the UK GDPR or EU GDPR applies, our basis for analytics is your consent. You can withdraw it at any time using the Cookie settings link in the footer of any page. That clears your choice, deletes the analytics cookies we can reach, and asks you again. Most browsers also let you block or delete cookies through their own settings.
Google as a recipient
Analytics data is processed by Google, which may process it outside your country, including in the United States. Google acts as our processor for this purpose under its data processing terms. See Google's Privacy Policy. You can also install Google's browser opt-out add-on.
We do not run advertising cookies and we do not sell or share personal information for cross-context behavioural advertising.
12. Children's information
Our products are business software sold to organisations. They are not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, contact us and we will delete it.
13. Changes to this policy
We may update this policy as our products and legal obligations change. We will change the effective date at the top of the page. If a change materially affects how we handle your information, we will give reasonable notice before it takes effect, by email to account holders, or by a notice on this website.
14. How to contact us
For any privacy question, access request, or complaint, use the contact form. Tell us it is a privacy matter and we will route it to the right person.
If you are an individual whose information is held in a Platform by one of our customers, contact that organisation directly. They control that data, not us.
See also the booking terms.