v2026-07-17
Last updated: July 17, 2026
This Privacy Policy explains how Vvidai, the operator of Leviqa ("Leviqa," "we," "us," or "our"), processes personal data and business data when organizations and their users access the platform. Leviqa is a B2B customs classification assistance service. This policy applies to the Leviqa website, application, APIs, support, and contracted features.
1. Roles and responsibilities
The organization that contracts for Leviqa ("Customer") controls its users, decides which business data will be entered, and determines the purposes of the processing performed within its customs workflow. With respect to such data, the Customer generally acts as the controller or business, and Vvidai acts as the operator, processor, or service provider, as applicable under governing law and the data processing agreement.
Vvidai acts as an independent controller for data necessary for account administration, security, fraud prevention, billing, business relationships, compliance with its own obligations, and secure service improvement. In the event of a conflict, the contract, Data Processing Addendum (DPA), and the Customer's commercial order define the applicable roles.
2. Data we process
2.1 Account, identity, and organization
- name, business email address, phone number, language, and profile data;
- authentication identifiers, active organization, associations, invitations, and roles such as Owner, Admin, Reviewer, or Viewer;
- security preferences, login records, MFA, SSO, and support information;
- business contact information, company data, and information required for contracting.
2.2 Customs and business data submitted by the Customer
- commercial invoices, packing lists, bills of lading, spreadsheets, images, and other authorized documents;
- goods descriptions, materials, composition, use, manufacturing process, technical specifications, quantity, value, currency, and country of origin or destination;
- shipment, supplier, importer, consignee, internal reference, and integrated system data;
- candidate codes, confirmed classifications, corrections, approvals, rationales, and user notes.
Business documents may contain personal data relating to representatives, contacts, drivers, or other individuals. The Customer must submit only necessary data, have appropriate authorization or a lawful basis, and avoid sensitive information that is not necessary for the customs purpose.
2.3 Queries and data processed by artificial intelligence
- descriptions, questions, answers, and attributes inferred and corrected during a query;
- retrieved candidates, evidence, alternatives, change factors, confidence level, and context completeness;
- nomenclature, model, and prompt versions, analysis date, and feedback provided;
- data extracted through OCR and normalized by AI from submitted documents.
2.4 Usage, device, and security
- IP address, user-agent, browser, device, date, time, and access channel;
- authentication, authorization, consent, error, latency, consumption, and security event logs;
- tenant, user, query, shipment, correlation, and idempotency identifiers;
- cookies and similar technologies described in the Cookie Policy.
Technical logs are designed not to contain complete documents, full prompts, credentials, or unnecessary commercial values.
2.5 Subscription, usage, and payment
- plan, allowance, metered usage, seats, subscription status, invoices, and change history;
- customer, subscription, and transaction identifiers provided by the payment processor;
- tax and billing data required to issue commercial documents.
Complete card data is collected and processed by the payment provider, not by Leviqa.
3. How we use data
- authenticate users, provision organizations, and enforce permissions by role and plan;
- receive and extract documents, structure items, suggest classifications, resolve tariffs, calculate landed cost, and generate exports when those features are contracted;
- run assisted queries, formulate discriminating questions, and present evidence, alternatives, and uncertainty;
- maintain history, reviews, traceability, and an audit trail of decisions;
- process subscriptions, measure usage, enforce quotas, and provide support;
- protect tenants, detect abuse, investigate incidents, and maintain availability;
- evaluate quality, accuracy, calibration, and performance in a controlled manner;
- comply with contracts, valid orders, and tax, regulatory, and legal obligations;
- send operational communications and, where permitted, marketing communications.
4. Legal bases and conditions
Depending on the location and contractual relationship, we process data based on performance of the contract, the Customer's documented instructions, consent where required, assessed legitimate interests, compliance with a legal obligation, fraud protection, and the establishment, exercise, or defense of legal rights. The Customer is responsible for defining and documenting the applicable basis for data it enters as controller.
5. Artificial intelligence and use for improvement
Leviqa uses AI to interpret language and documents, extract attributes, retrieve authorized candidates, compare hypotheses, and draft evidence-based explanations. AI is assistive: it does not replace professional judgment or produce a binding customs ruling.
- Private content from one tenant is not made available to another tenant.
- We do not use the Customer's private data to train Vvidai's general-purpose models without contractual authorization or a specific opt-in.
- Automatic memory across queries is disabled by default. Any future tenant memory must have a defined purpose, isolation, provenance, and controlled editing and deletion.
- Feedback and corrections may be used to evaluate and improve the service on a tenant-scoped, aggregated, anonymized, or contractually authorized basis; they do not retroactively alter a decision already recorded.
- Data may be sent to AI providers only to the extent necessary to deliver the feature, subject to applicable contractual and security controls.
Additional details are provided in the Artificial Intelligence Usage Policy.
6. Sharing and subprocessors
We do not sell personal data or customs documents. We may share the minimum data necessary with:
- cloud infrastructure, storage, database, observability, and authentication providers;
- OCR, language model, embeddings, reranking, and guardrails providers;
- payment, tax, and billing processors;
- email, notification, support, and Customer-enabled integration providers;
- consultants subject to confidentiality obligations, auditors, and insurers;
- authorities or third parties when required by law or valid order, or to protect rights and safety;
- successors in a corporate reorganization, with compatible protections.
The applicable list of subprocessors and additional terms may be provided in the DPA or upon the Customer's request.
7. Organizations, users, and internal access
Operational data belongs to the organization's tenant. Authorized administrators may manage members, permissions, and access to the organization's resources. Users must use individual accounts; shared accounts undermine audit attribution and may be blocked.
Our personnel access private data only when necessary for authorized support, security, maintenance, or a legal obligation, with least-privilege permissions and traceability.
8. International transfers
Leviqa may process data in the United States and other locations where its subprocessors operate. Where required, we use valid transfer mechanisms, contractual clauses, assessments, and supplementary safeguards. The Customer must assess its own obligations when submitting data from other jurisdictions.
9. Security
We apply measures proportionate to risk, including:
- encryption in transit and at rest;
- tenant isolation, Row-Level Security, and tenant validation in the authenticated context;
- authorization through scopes, roles, and the principle of least privilege;
- segregation of data by service, protected secrets, and restricted access to documents;
- structured logs that minimize sensitive data, monitoring, and incident response;
- idempotency, failure queues, backups, and recovery mechanisms;
- an append-only audit ledger with integrity verification for relevant events.
No system is absolutely secure. The Customer must protect credentials, configure roles appropriately, and report suspected unauthorized access.
10. Retention, expiration, and deletion
We retain data for as long as necessary to provide the service, fulfill the documented purpose and contract, maintain security, perform financial reconciliation, and comply with legal obligations. Final retention periods by data type remain subject to the contract and legal review for each market.
- profile data may be deleted or pseudonymized following a valid request;
- query deletion immediately blocks normal content access and creates a tombstone; the maintenance worker purges content owned by the consultation service;
- that consultation purge does not automatically delete separate shipment, document, export, audit, billing, log, or backup records governed by other stores;
- shipments, documents, logs, commands, outbox, exports, and backups have distinct stores and lifecycles that must be defined in the DPA or an approved schedule;
- customs, financial, consent, and audit records may be retained due to a legal obligation, dispute, investigation, or legal hold;
- withdrawing consent preserves the acceptance/withdrawal history and does not terminate processing based on a contract or legal obligation;
- in the append-only ledger, identity may be pseudonymized without destroying the auditable fact.
We do not promise immediate deletion from all stores or deletion of a record that the law or a legal hold requires us to preserve. The actual production schedule must identify the period, the event that starts the period, backup treatment, legal hold, and deletion method for each category.
11. Rights and requests
Subject to applicable law, an individual may have rights to access, correction, confirmation, portability, objection, restriction, deletion, withdrawal of consent, and review of certain automated processing. The individual may also have the right not to be discriminated against for exercising these rights.
When the data was provided by a Customer, the request should generally be directed to the organization acting as controller. We will assist the Customer in responding in accordance with the DPA. We may verify identity, authority, and scope before fulfilling a request. Rights are not absolute and may be limited by trade secrets, security, third-party rights, or customs or legal obligations.
12. Communications
We send transactional messages concerning accounts, security, queries, shipments, subscriptions, and support. Marketing communications, when used, provide an unsubscribe option. Messages essential to the service cannot be disabled while the account remains active.
13. Children
Leviqa is a professional B2B service and is not intended for children or the personal use of minors. The Customer must not register minors or intentionally submit children's data without a valid need, authorization, and legal basis.
14. Incidents
We will investigate security incidents and notify Customers or authorities when required by contract or law. The Customer must immediately report compromised credentials, unauthorized access, or document exposure through the support channel.
15. Changes
We may update this policy to reflect changes in the product, subprocessors, or law. Material changes will be communicated, and a new version will be published. The frontend selects which policies to verify; for each one, a difference between the accepted version and the latest version may create a pending action. The policy service does not independently determine whether a change is material or which processing activities cease after a withdrawal.
16. Contact
For questions, privacy requests, or information about subprocessors, use the Leviqa support channel. The formal details of the contracting entity and specific privacy contacts are set forth in the applicable order, contract, or DPA.