Doneven Ventures LLC d/b/a DV Technologies
PRIVACY POLICY
How we collect, use, disclose, and protect personal information
Version 2.2 | Effective Date: January 1, 2026 | Last Updated: January 1, 2026
This Privacy Policy describes how Doneven Ventures LLC d/b/a DV Technologies ("Company," "we," "us," or "our") collects, uses, discloses, and protects personal information in connection with our website at https://www.dvtechnologies.com (the "Website") and our DV Operating System ("DV OS" or the "Services") software-as-a-service platform and related services.
This Policy is designed to comply with applicable U.S. privacy laws, including the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (collectively, the "CCPA"), and the comprehensive privacy laws of other U.S. states. If you are a California resident, see the "California Privacy Rights" section below.
By accessing or using the Website or Services, you acknowledge that you have read and understood this Privacy Policy.
1. SCOPE AND OUR ROLE
This Policy applies to personal information we collect from or about: (a) visitors to our Website; (b) prospective and current customers who create accounts or request information; (c) individuals authorized by our customers to use the Services (owners, office staff, estimators, field contractors, and other "Authorized Users"); (d) individuals whose information is submitted to the Services by our customers, including homeowners, property owners, leads, prospects, subcontractors, and vendors; and (e) individuals who access a customer-shared portal link without holding an account.
Two distinct roles. With respect to Customer Data that our business customers upload or process through the Services, we act as a "service provider" under the CCPA and as a "processor" under analogous laws. Our customers are the "businesses" or "controllers" of that data. With respect to information we collect through the Website, our sales and marketing activities, and our administration of customer accounts, we act as a "business" or "controller."
White-label deployments. The Services may be presented under your own or your provider's branding. Regardless of branding, Doneven Ventures LLC d/b/a DV Technologies operates the underlying platform and this Policy describes our practices in that capacity.
2. INFORMATION WE COLLECT
2.1 Information You Provide Directly
- Account and Contact Information: name, business name, email address, phone number, job title, billing address, and payment information (processed by our third-party payment processor; we do not store full payment card numbers).
- Communications: content of emails, support tickets, chat messages, and other correspondence.
- Marketing Preferences: interests and preferences when you subscribe to communications or request a demonstration.
2.2 Information Collected Automatically
- Device and Usage Data: IP address, browser type and version, operating system, device identifiers, pages viewed, links clicked, time spent, referring and exit pages, and other log data.
- Cookies and Similar Technologies: including browser local storage and IndexedDB used for authentication, interface preferences, and offline capability. See our Cookie Policy.
- Approximate Location: derived from IP address.
2.3 Authorized User and Workforce Information
When our customer provisions accounts for its personnel, we process on the customer's behalf: identity and contact details, role assignment, and permission level; authentication data, session records, and security logs; activity and audit records; time tracking entries (clock-in and clock-out times, job assignment, duration); and location data associated with job site check-in. Where a customer enables check-in, we record the device-reported coordinates at the moment the user affirmatively taps to check in or out. We do not perform continuous or background location tracking, and we do not track Authorized Users outside of an explicit check-in action. Customers are responsible for issuing any required notice at collection to their own workforce and for confining location capture to lawful working purposes.
2.4 Customer Data Processed on Behalf of Our Customers
Our customers may submit personal information of third parties, including: names, phone numbers, email addresses, and physical or property addresses of leads, prospects, and clients; voice recordings of telephone calls, machine-generated transcripts of those calls, and AI-generated summaries, extracted intake fields, and quality-assurance findings derived from them; text message (SMS) content and metadata, and email content and metadata; AI-generated draft communications prepared for the customer to review and send; job details, scope descriptions, photographs of job sites and private property, notes, and related documentation; estimates, bids, change orders, invoices, purchase orders, and job cost records; contract documents, e-signature envelope metadata, signer identity, signature timestamps, and audit trails; and subcontractor and vendor contact details, insurance and licensing information, and bid submissions.
We process Customer Data solely on behalf of and according to the documented instructions of our customers, and in accordance with our Data Processing Addendum.
2.5 Sensitive and Regulated Data
The Services are not designed or authorized for protected health information, biometric identifiers, government identification numbers, financial account numbers, precise continuous location tracking, or information about individuals under 16. Customers are contractually prohibited from submitting such information. The only category of "sensitive personal information" we intentionally process for our own purposes is account login credentials, used solely for authentication.
2.6 Information from Third Parties
We may receive information from business partners, publicly available sources, and integrated services that a customer chooses to connect (for example, e-signature, telephony, calendar, accounting, or AI note-taking platforms).
3. HOW WE USE PERSONAL INFORMATION
As a business/controller (Website, sales, account administration), we use personal information to: provide, operate, maintain, secure, and improve the Services and Website; create and manage customer accounts and process transactions; communicate about the Services, including service announcements, security alerts, support, and administrative messages; send marketing communications, subject to your preferences and applicable law; detect, prevent, and respond to security incidents, fraud, abuse, and unlawful activity; comply with legal obligations and enforce our Terms of Service and Acceptable Use Policy; and analyze usage trends and perform research and development.
As a service provider/processor, we process Customer Data only to: deliver the contracted functionality; perform automated transcription of call recordings, and automated extraction, summarization, and quality-assurance analysis of transcripts, where the customer has enabled those features; generate draft communications for customer review, and, where the customer has expressly elected autonomous mode, transmit communications on the customer's behalf; maintain security, prevent abuse, and produce audit logs; provide support at the customer's request; comply with law; and improve and develop the Services only as described in Section 4.
We do not use Customer Data for our own marketing, and we do not combine Customer Data with data from other sources except as permitted by the CCPA for a service provider.
4. ARTIFICIAL INTELLIGENCE AND MODEL DEVELOPMENT
Automated processing. The Services use artificial intelligence, provided through third-party model providers, to transcribe calls, extract intake information, score call quality, summarize conversations, and draft communications. AI output can be inaccurate or incomplete. The Services are designed so that a human reviews AI output before it is relied upon, and customers who enable autonomous sending accept responsibility for the resulting communications.
No automated decisions with legal effect. We do not use AI to make decisions that produce legal or similarly significant effects about an individual without human involvement. Customers are contractually prohibited from configuring the Services to do so.
Model improvement. We may use Customer Data to improve the Services, including to evaluate and improve the accuracy of transcription, extraction, and drafting features. Where we do so: (1) we de-identify the data before it is used for model development, including removal or replacement of names, telephone numbers, email addresses, street addresses, and other direct identifiers; (2) we maintain technical and organizational measures prohibiting re-identification, and we do not attempt to re-identify de-identified data; (3) we do not permit one customer's data to appear in, or be recoverable from, output delivered to another customer; (4) we use Customer Data for model development only where the customer has separately and affirmatively opted in (that election is made on the Order Form or in account settings, is unbundled from the purchase of the Services, and may be withdrawn at any time on written notice, effective prospectively); and (5) our third-party AI providers are contractually prohibited from using data submitted through the Services to train their own general-purpose models.
If you are an individual whose call was recorded by one of our customers and you object to the use of that recording for model development, contact the customer directly, or contact us at privacy@dvtechnologies.com and we will route your request to the responsible customer.
5. HOW WE DISCLOSE PERSONAL INFORMATION
We disclose personal information to: Service Providers and Subprocessors (a current named list is published at https://www.dvtechnologies.com/legal/subprocessors); recipients directed by our customers (portal links, contracts for signature, messages); business transfers (merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to confidentiality protections); legal and safety purposes; with your consent or direction; and aggregated or de-identified data that cannot reasonably be used to identify any individual.
We do not sell personal information. We do not "sell" or "share" personal information as those terms are defined under the CCPA for cross-context behavioral advertising. We do not knowingly process the personal information of consumers under 16 for purposes that would constitute a sale or share.
6. DATA RETENTION
We retain personal information only as long as necessary for the purposes for which it was collected, to satisfy legal, accounting, or reporting requirements, and to resolve disputes and enforce agreements.
- Website visitor logs and analytics: up to 24 months.
- Marketing and prospect contact records: until you unsubscribe, then up to 24 months for suppression purposes.
- Customer account and billing records: duration of the relationship plus 7 years.
- Customer Data generally (leads, jobs, estimates, documents): duration of the subscription, plus 30 days after termination for export, then deleted or de-identified.
- Call recordings: customer-configurable. Default 12 months from the call, then deleted. Customers may set a shorter period.
- Call transcripts and AI summaries: duration of the subscription, subject to the customer's configured period.
- SMS and email content transmitted through the Services: duration of the subscription.
- Executed contracts and e-signature audit trails: duration of the subscription plus 7 years, or as the customer directs.
- Security, authentication, and audit logs: 12 to 24 months.
- Backups: rolling window, overwritten within 35 days.
- De-identified data used for analytics or model development: retained indefinitely in de-identified form.
Following termination, we make Customer Data available for export for thirty (30) days, after which we delete or de-identify it. Deletion from active systems occurs within 30 days of request; residual copies in backups are purged on the backup rotation cycle.
7. SECURITY
We implement and maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption of data in transit (TLS) and at rest; row-level security policies at the database layer that enforce tenant isolation; role-based access control within each customer's account; least-privilege administrative access; authentication managed by a dedicated identity service; audit logging of significant record changes; time-limited, revocable, single-purpose tokens for portal links; secrets stored in a managed secret store; and regular dependency and configuration security review. Further detail is published in our Security Overview at https://www.dvtechnologies.com/security.
No method of transmission over the Internet or method of electronic storage is completely secure. While we use commercially reasonable means to protect personal information, we cannot guarantee absolute security.
Incident notification. If we confirm a security incident affecting a customer's personal information, we will notify the affected customer without undue delay and no later than seventy-two (72) hours after confirmation. Notification to affected individuals is the customer's responsibility where we act as service provider, and we will cooperate reasonably.
8. CALIFORNIA PRIVACY RIGHTS (CCPA/CPRA)
If you are a California resident, you have the following rights with respect to personal information we collect about you in our capacity as a business (information collected through the Website or in connection with sales, marketing, and account administration, and not Customer Data we process solely as a service provider): Right to Know / Access; Right to Delete (subject to statutory exceptions); Right to Correct; Right to Opt Out of Sale or Sharing (we do not sell or share); Right to Limit Use of Sensitive Personal Information (we use sensitive personal information only for authentication); and Right to Non-Discrimination.
If your information is in the Services because a contractor you contacted uses our platform, we hold it as a service provider. Direct your request to that business. If you are not sure who that is, contact us at privacy@dvtechnologies.com and we will identify the responsible customer or forward your request.
How to exercise your rights: email privacy@dvtechnologies.com. We will verify your identity before processing. We respond within the timeframes required by the CCPA (generally 45 days, extendable by 45 days when reasonably necessary).
Categories collected in the preceding 12 months include identifiers; customer records; commercial information; internet/network activity; geolocation data; audio/electronic data (call recordings, transcripts, SMS and email content); visual information (job site photographs); professional or employment information; inferences; and limited sensitive personal information (account login credentials). We have disclosed personal information in these categories to service providers and subprocessors for business purposes. We have not sold or shared personal information for cross-context behavioral advertising.
9. OTHER STATE PRIVACY RIGHTS
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky, Rhode Island, and other states with comprehensive privacy laws may have rights to access, correct, delete, obtain a portable copy of, or opt out of certain processing of personal information, and to appeal a denial. We do not engage in targeted advertising, the sale of personal information, or profiling in furtherance of decisions producing legal or similarly significant effects. Contact privacy@dvtechnologies.com. If we deny your request, you may appeal by replying with the word "Appeal."
Washington My Health My Data and similar laws: we do not knowingly collect consumer health data, and the Services are not authorized for it.
10. CHILDREN'S PRIVACY
The Services and Website are intended for business use and are not directed to individuals under 18. We do not knowingly collect personal information from children under 16. Customers are prohibited from submitting information about individuals under 16 through the Services. Contact privacy@dvtechnologies.com if you believe we have collected such information.
11. INTERNATIONAL DATA TRANSFERS
The Services are hosted and operated in the United States and are offered to businesses located in the United States. If you access the Services from outside the United States, your information may be transferred to, stored, and processed in the United States.
12. CHANGES TO THIS PRIVACY POLICY
We may update this Policy from time to time. We will post the revised Policy with an updated "Last Updated" date and maintain prior versions in our legal archive. If we make material changes, we will provide additional notice as required by law. Continued use after the effective date constitutes acceptance.
13. CONTACT US
Privacy requests: privacy@dvtechnologies.com
Legal inquiries: legal@dvtechnologies.com
Security reports: security@dvtechnologies.com
Address: [Principal Place of Business Address], California
© 2026 Doneven Ventures LLC d/b/a DV Technologies. All rights reserved.
legal@dvtechnologies.com | [Principal Place of Business Address], California
This document is maintained by Doneven Ventures LLC d/b/a DV Technologies. It describes our practices and contractual terms. It is not a certification, an audit report, or legal advice.
