Privacy Policy
1. Introduction
Envira ("Envira," "we," "us," or "our") respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, disclose, and safeguard your information when you visit envira.press, create an account, subscribe to our newsletters, or otherwise interact with our services.
2. Data Controller
The data controller for personal data processed via envira.press is:
AW3 TECHNOLOGY, Inc.
511 Alameda de las Pulgas, Belmont CA 94002
EIN: 88-0773227
Email: privacy@envira.press
EU/UK users: we are not currently required to appoint an EU/UK representative under Article 27 GDPR. If that changes, this section will be updated with their contact details.
3. Information We Collect
We may collect the following types of information:
- Account Information: Email address and password when you register for an account. Passwords are stored as salted hashes by our authentication provider; we never see them in plain text.
- Newsletter Information: Email address and selected preferences if you subscribe to one of our newsletters.
- Billing Information: If and when we introduce paid subscriptions, payments are processed by a third-party payment processor. We do not store full card numbers on our servers.
- Usage Data: Pages visited, time spent on site, browser type, device information, and IP address — collected via server logs and any analytics tools we deploy.
- Cookies: Strictly-necessary cookies for authentication and session management. We do not currently set advertising cookies.
- Communications: Any information you provide when contacting us by email or responding to surveys.
4. How We Use Your Information
- To deliver, maintain, and improve our website and services
- To send newsletters, updates, and promotional communications you've opted into
- To authenticate accounts and secure them against unauthorised access
- To process subscriptions and payments (where applicable)
- To analyze usage patterns and improve content
- To comply with legal obligations
5. Legal Basis for Processing (GDPR / UK GDPR)
If you are in the EU, the UK, or another jurisdiction with similar laws, we rely on the following legal bases:
| Processing activity | Legal basis |
|---|---|
| Creating and maintaining your account | Contract (Art. 6(1)(b) GDPR) |
| Sending newsletters you have signed up for | Consent (Art. 6(1)(a) GDPR), withdrawable at any time |
| Processing paid subscriptions and payments | Contract (Art. 6(1)(b) GDPR) |
| Securing the site, preventing abuse, server logs | Legitimate interests (Art. 6(1)(f) GDPR) — operating a secure service |
| Optional analytics / non-essential cookies | Consent (Art. 6(1)(a) GDPR), via our cookie banner |
| Responding to legal requests or enforcing terms | Legal obligation (Art. 6(1)(c)) / legitimate interests (Art. 6(1)(f)) |
6. Sharing & Service Providers
We do not sell your personal information. We share limited data with trusted service providers who help us operate the site:
- Hosting & database: Lovable Cloud (powered by Supabase) hosts our application, database and authentication.
- Email delivery: Transactional and newsletter emails may be delivered through third-party email providers.
- Payments: If we introduce paid subscriptions, a PCI-compliant processor (e.g. Stripe) will handle card data.
We may also disclose information when required by law or to protect our rights, users or the public.
7. International Data Transfers
Our service providers may process data in the United States, the European Union or other regions. Where data is transferred outside your country, we rely on appropriate safeguards such as Standard Contractual Clauses to protect it.
8. Data Retention
| Data type | Retention period |
|---|---|
| Account data (email, hashed password) | While the account is active; deleted within 30 days of account closure |
| Newsletter subscriber email | Until you unsubscribe; suppression record kept to honour opt-out |
| Server / security logs (incl. IP) | Up to 90 days, then deleted or anonymised |
| Analytics / aggregated usage data | Up to 24 months in aggregated form |
| Billing / tax records (if paid subscriptions) | As required by applicable tax law (typically 6–10 years) |
| Support correspondence | Up to 24 months after the issue is resolved |
9. Data Security
We implement industry-standard security measures to protect your personal data. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
10. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing. California residents have additional rights under the CCPA/CPRA, and EU/UK residents have rights under the GDPR — including the right to lodge a complaint with a supervisory authority. To exercise your rights, contact us at privacy@envira.press.
11. AI-Assisted Editorial Content & Automated Decisions
Editorial content on Envira is researched and drafted with the assistance of large language models and other AI tools, then reviewed against published sources. We do not use your personal data to train third-party AI models. We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing within the meaning of Art. 22 GDPR.
12. Children's Privacy
Envira is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
13. Changes to This Policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date at the top of this page.
14. Contact Us
If you have questions about this Privacy Policy, please contact us at:
AW3 TECHNOLOGY, Inc. (Envira)
511 Alameda de las Pulgas, Belmont CA 94002
Email: privacy@envira.press
