Legal

Privacy Policy

Last updated: 2 July 2026

This Privacy Policy explains how Xacent Global Technologies (“Xacent”, “we”, “us”), a Tovari Global company, collects, uses, and protects personal information when you use Zhivia, our training platform, including our websites, applications, and related services (the “Service”). By using the Service you agree to the practices described here.

For corporate customers, the organisation that provides you access is the controller of your training records, and Xacent acts as a processor on their behalf. Where that applies, your organisation’s own privacy notice may also govern how your information is handled.

Information we collect

Information you provide

  • Account information: name, email address, password, and, for corporate users, your organisation and department.
  • Payment information: processed by our payment provider (Stripe). We do not store full card numbers on our systems.
  • Communications: messages you send us, including demo requests and support enquiries.

Information generated through use

  • Training and compliance data: lesson progress, quiz scores, certificates, and retraining status.
  • Technical data: IP address, device and browser type, and log data used to operate and secure the Service.
  • Cookies: see our Cookie Policy for details on the cookies we use.

How we use information

  • To provide, maintain, and improve the Service.
  • To track training progress and generate compliance reports and certificates.
  • To send transactional messages, including retraining reminders and receipts.
  • To process payments and manage subscriptions.
  • To secure the Service, prevent abuse, and comply with legal obligations.

How we share information

We do not sell personal information. We share it only as needed to run the Service, with the service providers (sub-processors) below, with your organisation’s administrators (for corporate accounts), and where required by law or to protect our rights.

  • Supabase: database, authentication, and application backend.
  • Stripe: payment processing and subscription billing.
  • Resend: transactional email delivery.
  • Twilio: SMS notifications, where an organisation enables them.
  • Hostinger: application and video (MinIO) hosting.

Data retention

We retain personal information for as long as your account is active and as needed to provide the Service. Compliance records may be retained longer where an organisation or applicable law requires an audit trail. When data is no longer needed, we delete or anonymise it.

How we protect information

Security is built into the platform: row-level security isolates each organisation’s data at the database layer, video is served through short-lived presigned URLs, and traffic is encrypted in transit over HTTPS. No system is perfectly secure, but we work to protect your information using appropriate technical and organisational measures.

Your rights

Depending on where you live, you may have the right to access, correct, delete, or export your personal information, and to object to or restrict certain processing. To exercise these rights, contact us using the details below. If your access is provided by an employer, we may direct your request to that organisation as the controller of your records.

International transfers

We and our sub-processors may process information in countries other than your own. Where we transfer data internationally, we rely on appropriate safeguards such as standard contractual clauses.

Children

The Service is not directed to children under 16, and we do not knowingly collect their personal information.

Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where appropriate, by additional notice.

Contact us

Questions about this policy or your information can be sent to privacy@zhivia.com.