Privacy Policy
Effective date: [date]
Last updated: [date]
Version: 1.0
Version 0.1 draft. Not for publication. Bracketed items require a decision or counsel input.
This policy explains how [Havn entity name] ("Havn," "we," "us") handles personal information in connection with the Havn platform.
1. Our role, and why it matters
For most of the information in the platform, Havn is a service provider acting on behalf of a community association. Association records — owner details, account balances, correspondence, violation and architectural files, governing documents — belong to the association. Havn holds and processes them to provide the platform, and for no other purpose.
This has three practical consequences:
- We do not sell or share personal information, as those terms are defined under California law, and we do not use association records for advertising
- We do not use association records for our own purposes, other than to provide, secure, and support the platform
- If you are a homeowner and want to exercise a right over your information, your association is the right place to start. We will assist your association in responding
For a smaller category — the account details of the people who administer the platform, and information about visitors to our website — Havn acts on its own behalf.
2. Information we handle
Operators (management company staff and board members): name, work email, telephone, organisation and role, authentication data, and security and audit information including IP address and device details.
Homeowners and property records, on behalf of the association: name, property and mailing address, contact details, ownership dates, account status and balances, payment records, requests, violation and architectural records, and correspondence.
Counterparties (title companies, agents, lenders): contact details and order information.
People who appear in records but do not use the platform — for example prior owners, tenants, and estates: whatever the association's records contain about them.
Uploaded documents: governing documents, minutes, financial records, insurance certificates, and correspondence, together with whatever personal information those documents contain. This is the broadest and least predictable category, and its contents are determined by the association, not by us.
Automatically: log data, audit records, and usage information.
We do not receive or store payment card details. Payments are processed by our payment provider and card data is tokenised; it does not reach our systems.
3. Document processing using artificial intelligence
We use optical character recognition and language models to read uploaded documents and extract structured information from them, so that figures and answers can be reused rather than retyped.
This means association documents, which may contain personal information, are transmitted to an artificial intelligence provider for processing.
- Extracted values are recorded with their source, and with whether a person has confirmed them
- [Our AI provider is contractually prohibited from using content submitted through the platform to train its models.] [Counsel and vendor selection: this commitment must be secured before it is stated, and it should be stated plainly rather than buried in a vendor list.]
- We do not use association documents to train our own models [confirm and keep true]
4. How we use information
To provide and operate the platform; to authenticate users and secure accounts; to generate documents at a customer's direction; to communicate about the service; to provide support; to bill; to detect and prevent fraud and abuse; to comply with law; and to establish or defend legal claims.
We do not use association records for advertising, and we do not sell or share personal information.
5. Who we disclose information to
To the association and its management company, which is the purpose of the platform.
To counterparties, where an association or manager directs us to deliver a document to them.
To service providers who process information on our behalf under contract, listed in Section 6.
To authorities, where required by law or legal process, and to protect rights, safety, or property.
On a change of control, to an acquirer, subject to this policy continuing to apply.
We do not disclose association records to our affiliates or partners for their own marketing purposes.
6. Service providers
| Provider | Purpose | Information |
|---|---|---|
| Supabase | Database, file storage, authentication | All platform data and documents |
| Vercel | Application hosting and background processing | Data in transit and during processing |
| Resend | Email delivery | Recipient addresses and message content |
| Stripe | Payment processing | Payer details. We do not receive card data |
| [AI provider] | Document reading and extraction | Document contents. See Section 3 |
All are located in the United States. Platform data is stored in the us-west-2 region. We do not transfer information outside the United States.
This list is versioned. Material additions will be notified in accordance with Section 11.
7. Retention and deletion
Retention of association records is largely determined by the association's obligations, not by us. Community association records are subject to statutory retention periods that vary by state.
- We retain association records for as long as the association's engagement continues
- On termination, records remain available for export for [90] days, after which they are deleted, except where a retention obligation applies
- Residual copies may remain in backups for a further [period] before being overwritten
A request to delete a specific record may not be capable of being honoured where the record is subject to a statutory retention requirement. Where that is the case, we will say so rather than leaving the request unanswered.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to opt out of sale or sharing. We do not sell or share personal information.
Homeowners: contact your association. Your association determines what happens to its records, and we act on its instructions. We will assist it in responding to your request. If you contact us directly, we will forward your request to your association and tell you that we have done so.
Operators may exercise rights over their own account information by contacting us at [address].
We will not discriminate against anyone for exercising a right.
9. Access by Havn personnel
Authorised Havn staff may access association records to provide support, investigate faults, and maintain the platform. Every such access is logged, recording the individual who accessed the information and why. Access is restricted to staff who need it. We do not notify associations of individual access events.
10. Security
We encrypt information in transit and at rest, restrict internal access on a least-privilege basis, maintain audit logs, and use the security controls of our infrastructure providers. No system is completely secure, and we do not represent that ours is. [State only what is true and demonstrable. Do not claim certifications not held.]
11. Changes
We may update this policy. We will notify customers by email or in-product notice before material changes take effect, and will update the version and date above. Previous versions are available on request.
12. Children
The platform is not directed to children. Association records may nonetheless contain information about minors who live in a household, since that is what the records contain. We do not knowingly collect information directly from children.
13. Contact
[Havn entity, address, privacy email]
California residents may also contact the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs at 1625 North Market Blvd., Suite N 112, Sacramento, CA 95834, or (800) 952-5210.