Plain-language summary. Aieia is a software that runs on a local computer. Experimental data, results, and screenshots never leave your device and are never transmitted to Survon. In Standard deployment mode, we receive only action metadata (no experimental data) in audit logs, stored on SOC 2 certified, HIPAA compliant servers in Switzerland. We do not sell personal data. We do not use your data for advertising.
Survon, Inc. ("Survon", "we", "our", or "us") develops and operates Aieia, an autonomous AI platform for research and life sciences. Our contact details are at the end of this policy.
This policy applies to information collected through the Aieia desktop application, the Aieia Web Portal (aieia.survon.co), and any communications you send to us (e.g. via our contact form or by email). It does not apply to data that remains exclusively on your instrument computer, which Survon never accesses.
Contact form and email. When you contact us through the website or by email we collect your name, email address, and the content of your message.
Audit log metadata (Standard deployment mode only). During task execution, Aieia sends action metadata to our Swiss-hosted servers. Audit log entries contain: step number, action type, timestamp, and task status. They do not contain screenshots, extracted data, results, or any experimental information.
Aieia Web Portal account data. If you create a portal account we collect your email address, a hashed password, and the names or identifiers you assign to connected devices.
Basic website analytics. We may collect standard web server logs (IP address, browser type, pages visited, referrer) for security and performance purposes.
Survon does not collect, receive, or have access to:
We use the data we collect to:
We do not use your data for advertising, behavioural profiling, or sale to third parties.
We do not sell personal data. We may share data only in these circumstances:
We retain contact enquiry data for as long as necessary to respond to and follow up on your request, and then delete it. Audit log metadata is retained for the duration of your subscription or active use and deleted within 90 days of account termination unless a longer period is required by law. Web Portal account data is retained until you delete your account.
Data stored locally on your instrument computer (screenshots, session records, local audit logs in Private Cloud Routing mode) is entirely under your control. Survon has no access to it and no ability to modify or delete it.
Our Swiss-hosted audit log servers are SOC 2 certified and HIPAA compliant. We use HTTPS for all data in transit. We restrict access to personal data to personnel who need it to operate and support the service. No security measure is perfect; if you discover a security concern, please contact aieia@survon.co.
Depending on your location, you may have rights to access, correct, delete, or object to the processing of your personal data, or to receive a copy of it in a portable format. To exercise any of these rights, email us at aieia@survon.co. We will respond within the timeframe required by applicable law.
If you are located in the European Economic Area, United Kingdom, or Switzerland, you may also have the right to lodge a complaint with your local data protection authority.
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the following applies in addition to the rest of this policy.
Data controller. Survon, Inc. is the data controller for personal data processed under this policy.
Legal bases for processing. We process your personal data on the following legal bases:
Your rights. Under GDPR you have the right to: access your personal data; rectify inaccurate data; request erasure ("right to be forgotten") where processing is no longer necessary; restrict or object to processing; receive your data in a portable format; and withdraw consent at any time where processing is consent-based. To exercise any of these rights, email aieia@survon.co. We will respond within one month as required by GDPR (extendable by two further months for complex requests).
Supervisory authority. You have the right to lodge a complaint with your local data protection authority. A list of EU supervisory authorities is available at edpb.europa.eu. UK residents may contact the Information Commissioner's Office (ico.org.uk). Swiss residents may contact the Federal Data Protection and Information Commissioner (edoeb.admin.ch).
B2B data processing. Where Survon processes personal data on behalf of your organisation as a data processor (for example, personal data that may appear in audit log entries), we are available to enter into a Data Processing Agreement (DPA) consistent with Art. 28 GDPR. Please contact aieia@survon.co to request a DPA.
Survon is based in the United States. If you are located in the EEA, UK, or Switzerland, your personal data may be transferred to and processed in the US or other countries that may not provide the same level of data protection as your home country.
Where we transfer personal data from the EEA to a third country, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) adopted by the European Commission, or other recognized transfer mechanisms. Our audit log servers are hosted in Switzerland, which the European Commission has recognized as providing adequate data protection.
You may request a copy of the safeguards we use for international transfers by contacting aieia@survon.co.
We may update this policy from time to time. We will post the revised policy on this page with an updated effective date. For material changes we will provide additional notice (for example, by email or a notice on the Aieia Web Portal). Continued use of our services after the effective date constitutes acceptance of the revised policy.
For privacy questions or to exercise your rights, please contact us at:
Survon, Inc.
aieia@survon.co