AqNova Marketplace Policies & Disclosures
Global Legal Footer Framework
Comprehensive Compliance & Platform Governance Reference
The Complete Global Privacy Policy Governing Personal Data Processing on the AqNova Platform
Effective Date: April 7, 2026 | Version 1.0 | Arivon Holding Corporation
| Quick Reference — What This Policy Covers WHO WE ARE: AqNova Marketplace, operated by Arivon Holding Corporation 2571 Saturn Avenue, Unit #265, Huntington Park, CA 90255, USA WHAT WE COLLECT: Identity, contact, financial, transaction, technical, usage, marketing preferences, and sustainability profile data. WHY WE COLLECT: To operate the Platform, process orders, prevent fraud, comply with law, improve our services, and communicate with you. WHO WE SHARE WITH: Payment processors, logistics partners, KYC providers, analytics tools, legal authorities (when required), and Vendors (for order fulfillment). YOUR RIGHTS: Access, correct, delete, port, restrict, object, opt-out — and more. Exercise your rights at: [aqnova.co/privacy/rights] or privacy@aqnova.co DO WE SELL YOUR DATA? NO. AqNova does not sell personal data. DPO CONTACT: dpo@aqnova.co |
|---|
This Privacy & Data Protection Policy ("Privacy Policy" or "Policy") is issued by Arivon Holding Corporation, operating the AqNova Marketplace ("AqNova," "we," "us," "our"). It sets out, in full and in plain language, how AqNova collects, uses, stores, transfers, and protects the personal data of every individual who interacts with the AqNova Platform — whether as a Buyer, Vendor, Referral Partner, or Visitor.
This Policy applies globally and constitutes AqNova's master privacy disclosure. It is supplemented by regional addendums (published at [aqnova.co/privacy/regional]) where local law requires additional disclosures, rights, or notices beyond those contained herein. Where a regional addendum conflicts with this master Policy on a matter of local law, the regional addendum governs for users in that jurisdiction.
This Policy is incorporated by reference into the Platform Terms & Conditions (Section 2) and operates alongside the Privacy & Data Protection Overview (Section 3.0), Cookie Policy (Section 3.2), Data Subject Rights Portal Guide (Section 3.3), and Data Retention Schedule (Section 3.4).
| ⚠ IMPORTANT NOTICE THIS POLICY CONSTITUTES A LEGAL DISCLOSURE OF AQNOVA'S DATA PRACTICES. BY USING THE PLATFORM, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS POLICY. YOUR RIGHTS UNDER APPLICABLE PRIVACY LAW ARE ALWAYS PRESERVED. IF YOU DO NOT AGREE WITH THESE PRACTICES, PLEASE DO NOT USE THE PLATFORM. FOR QUESTIONS, CONTACT: privacy@aqnova.co |
|---|
AqNova Marketplace is operated by Arivon Holding Corporation, a company incorporated under applicable law and registered as follows. For the purposes of all applicable data protection laws worldwide, Arivon Holding Corporation is the data controller — the entity that determines the purposes and means of processing your personal data through the Platform.
| AqNova — Data Controller Identity Company Name: Arivon Holding Corporation (operating as AqNova Marketplace) Trading as: AqNova Marketplace Registered Address: C/O Arivon Holding Corporation 2571 Saturn Avenue, Unit #265 Huntington Park, CA 90255, USA CA File Number: B20250418195 US EIN: 41-3210066 D-U-N-S Number: 142957477 GB EORI: GB511467217000 Nigeria Entity: Sahara Eagle Ltd | Reg: 1957145 | Tax ID: 31052811-0001 | NEPC: 0030281 General Privacy: privacy@aqnova.co Data Protection Officer: dpo@aqnova.co Legal Notices: legal@aqnova.com Platform Domain: [aqnova.co] |
|---|
If you are located in the European Union or United Kingdom, AqNova has designated (or is in the process of designating) a local Article 27 representative to act as your point of contact for GDPR and UK GDPR matters. Contact details for the EU and UK representatives are available at [aqnova.co/privacy/representatives] and by emailing gdpr@aqnova.co.
We collect personal data in eight distinct categories. Each category is described below, together with the specific data elements it encompasses and the circumstances in which it is collected. We collect only what is genuinely necessary for the purposes described in this Policy.
Identity data is information that identifies you as an individual. We collect:
Full legal name (required for account registration and, for Vendors, for KYC verification).
Username or display name (chosen by you at registration; may differ from legal name).
Date of birth (collected for age verification purposes; we verify you meet the minimum age requirement for your jurisdiction; we do not retain full date of birth beyond what is necessary for verification in most cases).
Gender (optional and self-identified; collected only where you choose to provide it for personalization purposes).
Profile photograph (optional; uploaded at your discretion to personalize your account).
Government-issued identity document type and reference number (collected for Vendor KYC verification only; held in encrypted form; access is strictly restricted to authorized verification staff).
Identity data is used for: account creation and management; fraud prevention and identity verification; regulatory compliance (AML/KYC); and personalizing your Platform experience. We do not use identity data to infer sensitive characteristics beyond what you have explicitly provided.
Contact data is information that enables us to reach you. We collect:
Email address (required; used for account access, transactional notifications, and, with your consent, marketing communications).
Telephone or mobile number (required for two-factor authentication; used for delivery notifications where relevant; used for account security alerts).
Billing address (required for payment processing and tax compliance).
Delivery / shipping address (required for order fulfillment; stored for convenience if you choose to save addresses in your account).
Business address (required for Vendors as part of storefront disclosure obligations under applicable e-commerce laws).
Contact data is used for: account authentication; sending order confirmations, shipping updates, and receipts (mandatory transactional communications); sending security and fraud alerts; delivering customer support; and — with your consent — sending marketing and promotional communications.
Financial data is information related to your payment methods and financial transactions. We collect differently depending on whether you are a Buyer or a Vendor:
Buyers:
Payment method type (e.g., credit card, debit card, PayPal, Apple Pay, M-Pesa — we store the method type and last four digits of card numbers for display purposes only; we never store full card numbers, CVV/CVC codes, or full card expiry dates).
Billing address associated with the payment method (used for fraud verification and tax compliance).
Currency preference (stored to display prices in your preferred currency).
Vendors:
Bank account name and masked account number (used for payout disbursement; full account numbers are held by our Payment Processor, not by AqNova directly).
Bank sort code or routing number (for payout processing; held by Payment Processor).
Tax identification number (EIN, VAT number, GST number, TIN — required for tax reporting compliance in applicable jurisdictions).
Payout history and settlement records (maintained for 7 years for tax and audit purposes).
Financial data is used for: processing payments and disbursing vendor payouts; fraud detection and prevention; tax reporting and regulatory compliance; and maintaining legally required financial records. All payment data is processed through PCI-DSS Level 1 certified payment processors. AqNova implements field-level encryption for all sensitive financial data stored within its own systems.
Transaction data is a record of all commercial activities you conduct on the Platform. We collect:
Order history: products purchased (Buyers) or sold (Vendors); quantities; prices paid; transaction dates and times; order reference numbers.
Product categories: the categories of goods involved in each transaction (used for tax classification, fraud analytics, and — in aggregate — platform improvement).
Delivery status and tracking information: carrier name, tracking number, delivery confirmation timestamps.
Returns, refunds, and disputes: records of return requests submitted, refunds issued, Buyer Protection claims, and dispute outcomes.
Invoice records: VAT invoices, commercial invoices, and receipts generated for each transaction (retained for 7–10 years for tax compliance).
Promotional code and discount usage: codes redeemed at checkout and their effect on transaction value (used for fraud detection and marketing analytics).
Transaction data is used for: order fulfillment and customer support; tax reporting and regulatory compliance; fraud detection (pattern analysis across transactions); Buyer Protection claims processing; platform analytics and improvement; and, in aggregate, providing Vendors with sales performance insights through the Vendor Dashboard.
Technical data is information automatically generated by your device and network when you interact with the Platform. We collect:
IP address (used for geolocation — country and approximate city — for regulatory compliance, currency settings, fraud detection, and Platform personalization; IP addresses are considered personal data in many jurisdictions and are handled accordingly).
Device type, model, and operating system (used for Platform compatibility, fraud detection, and technical troubleshooting).
Browser type and version (used for Platform rendering and compatibility; combined with other signals for fraud detection).
Browser fingerprint (a combination of technical device characteristics used exclusively for fraud detection and bot identification; this data is processed under legitimate interests with appropriate safeguards).
Screen resolution and display settings (used for Platform rendering optimization).
Time zone and language settings (used to display appropriate currency, language, and localized content).
Session identifiers (temporary identifiers for your browsing session; expire at session end).
Error logs and crash reports (used to identify and fix technical issues on the Platform).
Technical data is used for: ensuring the Platform functions correctly on your device; detecting and preventing fraud, bot activity, and account takeover; improving Platform performance; and legal compliance (e.g., IP address records in connection with contractual acceptance). Technical data is never used to build individual advertising profiles.
Usage data is information about how you interact with the Platform. We collect:
Pages and products viewed, clicked, or searched (used to understand navigation patterns and improve product discovery).
Time spent on pages and features (used for platform improvement and identifying usability issues).
Scrolling and click behavior (used in aggregate for UX analysis; individual-level behavioral profiling is not used for advertising).
Cart additions and abandonments (used to improve the checkout experience and, where you have consented, to send cart abandonment reminders).
Checkout funnel progression (used to identify friction points in the purchase process).
Feature usage (which Platform features you use and how frequently; used for product development decisions).
Referring URL and exit URL (the page from which you arrived at AqNova and the page you visited after leaving; used for marketing analytics and SEO with your consent for analytics cookies).
Usage data is collected primarily through cookies and similar tracking technologies. Please see the Cookie Policy (Section 3.2) for full details of how these technologies operate and how you can manage your preferences.
Marketing preferences data is information about your communication choices and interests. We collect:
Email marketing subscription status: whether you have opted in to receive marketing emails from AqNova; the date of opt-in; the version of the consent notice presented at the time of consent.
Push notification preferences: whether you have enabled push notifications through the AqNova mobile app (where applicable) and your notification category preferences.
SMS/text message marketing consent: recorded separately from email consent; opt-in required in all jurisdictions.
Marketing topic preferences: product categories and interests you have indicated you are interested in receiving communications about.
Communication channel preferences: your preferred method of receiving non-transactional communications.
Opt-out and unsubscribe records: date and method of any opt-out or unsubscribe action; maintained to honor your preferences and as a compliance record.
Marketing and communications preference data is used exclusively for: sending you marketing communications that you have consented to receive; suppressing marketing communications to users who have opted out; and compliance with marketing consent obligations under CAN-SPAM (US), CASL (Canada), the EU ePrivacy Directive, UK PECR, Brazil's LGPD, and equivalent frameworks. Your marketing preferences can be updated at any time through your account settings or by clicking the unsubscribe link in any marketing email.
Sustainability profile data is a distinctive data category reflecting AqNova's identity as a curated sustainable marketplace. We collect:
Sustainability interest categories: product categories you have browsed or purchased in — such as organic food, clean energy products, eco-friendly home goods, electric vehicle accessories, Fair Trade goods, and zero-waste products — which indicate your sustainability interests and preferences.
Certification preferences: certification types you have filtered by or shown preference for (e.g., USDA Organic, Fair Trade, FSC, B Corp, Energy Star).
Sustainability goals (optional): if you have completed AqNova's optional sustainability preferences questionnaire, the responses you provided about your personal sustainability priorities.
Purchase-derived sustainability indicators: inferences drawn from your purchase history about your likely sustainability preferences (e.g., consistent purchase of zero-packaging products suggests a low-waste preference). These inferences are used only for product recommendations and are never shared with third parties as individual-level profile data.
| Sustainability Profile Data — Important Notice Sustainability profile data is used exclusively to personalize your AqNova experience — specifically, to surface products that are most relevant to your sustainability values. We do NOT: — Share individual sustainability profile data with third parties for their own use. — Use sustainability profile data to make decisions about your eligibility for financial products, insurance, or other consequential services. — Treat sustainability preferences as a proxy for other personal characteristics. — Use sustainability profile data for purposes unrelated to the AqNova Platform. You may opt out of sustainability profiling at any time through your account settings. Opting out disables personalized sustainability recommendations but does not affect your ability to search and browse the Platform freely. |
|---|
We collect personal data through three primary channels:
You provide data directly when you: register an account; complete checkout; fill in your profile; upload product listings (Vendors); contact customer support; participate in surveys or promotions; sign up for marketing communications; submit reviews or ratings; complete KYC verification; or apply for the Founding Vendor Program or Referral Partner Program.
We automatically collect technical and usage data (Categories 5 and 6 above) when you visit the Platform through cookies, web beacons, pixels, server logs, and similar technologies. We deploy these technologies subject to the consent framework described in our Cookie Policy (Section 3.2). Most analytical and marketing cookies require your consent before activation. Essential cookies, which are necessary for the Platform to function, operate without consent on the basis of legitimate interests/necessity.
We receive personal data from third parties in the following circumstances:
Identity verification providers: we receive verification outcomes (pass/fail) and, where necessary, document reference data from our KYC/AML service providers during vendor onboarding.
Payment processors: we receive confirmation of payment authorization, payment method type, and fraud scoring signals from payment processing partners.
Logistics partners: we receive delivery confirmation, tracking milestones, and delivery exception alerts from shipping carriers.
Social login providers: if you choose to register or log in using a third-party social or identity provider (e.g., Google Sign-In, Apple Sign In), we receive the specific data elements you authorized the provider to share (typically name, email address, and profile picture).
Referral partners: where you arrive at AqNova through a referral link from a Vendor Referral Partner, we receive a referral code and the referring partner's identifier for commission attribution purposes.
Fraud detection networks: we receive fraud risk signals and alerts from industry fraud prevention networks for the purpose of protecting all Platform users from financial fraud.
We use your personal data only for the purposes described below. We do not repurpose personal data for uses that are incompatible with the original collection purpose without obtaining a new legal basis and, where required, your consent.
We process your personal data to accept and process orders placed on the Platform; verify payment authorization; transmit order details to the applicable Vendor for fulfillment; coordinate order dispatch and delivery with logistics partners; track delivery progress and notify you of shipping updates; handle returns, refunds, and Buyer Protection claims; and provide post-sale customer support.
This is the core operational purpose for which the Platform exists. Without this processing, AqNova cannot function as a marketplace. Legal basis: performance of a contract (GDPR Art. 6(1)(b); LGPD Art. 7(V); POPIA § 11(1)(a); equivalent in all applicable jurisdictions).
We process your personal data to create, maintain, and secure your account; verify your identity at login; send security alerts for suspicious account activity; process account preference changes; and manage account closure and data deletion requests.
Legal basis: performance of a contract (account terms); legitimate interests (account security). Multi-factor authentication operates on legitimate interests (protecting users from account takeover) with optional user consent for the specific MFA method.
We process your personal data — including technical data, transaction history, behavioral signals, and device fingerprints — to detect and prevent fraudulent transactions, payment fraud, account takeover, bot activity, and other forms of Platform abuse. This processing is ongoing and automated, supported by machine learning models trained on anonymized fraud patterns.
Fraud prevention is one of AqNova's most critical processing activities. Without it, Buyers would be exposed to financial fraud and Vendors would be exposed to fraudulent orders and chargebacks at scale. Legal basis: legitimate interests (fraud prevention; protecting users; maintaining Platform integrity). A Legitimate Interests Assessment (LIA) is maintained for this processing activity and is available on request from dpo@aqnova.co.
We process your contact data and marketing preferences to send you:
Transactional communications: order confirmations, shipping notifications, payment receipts, security alerts, account notices. These are non-optional and sent on the basis of contract performance/legitimate interests.
Marketing communications: promotional emails, product recommendations, personalized offers, AqNova news and updates. These are sent only with your explicit opt-in consent (where required by applicable law) and you may unsubscribe at any time.
Sustainability-focused content: curated sustainability tips, new eco-product arrivals, vendor spotlights. Sent to users who have expressed an interest in sustainability content, subject to consent.
Legal basis: consent (GDPR Art. 6(1)(a); ePrivacy Directive; CASL; LGPD Art. 7(I)) for marketing communications; contract performance / legitimate interests for transactional communications. Consent records are maintained in our Consent Management Platform.
We process aggregated and pseudonymized usage data to understand how the Platform is used; identify technical issues and usability friction points; measure the effectiveness of new features; optimize Platform performance; and develop new products and services. Individual-level behavioral profiling is used only to the extent necessary for fraud detection and personalization, as described in this Policy.
Legal basis: legitimate interests (improving the Platform for all users). Where analytics require the use of non-essential cookies, consent is obtained through the Cookie Consent Manager (Section 3.2).
We use your transaction history, search behavior, browsing patterns, and sustainability profile data to personalize search results, product recommendations, and homepage content to reflect your interests. Our recommendation algorithms are designed to surface products that are genuinely relevant to your expressed preferences — not to maximize time on site or expose you to irrelevant advertising.
Legal basis: legitimate interests (improving user experience through relevance; ensuring users find products that meet their needs). Where personalization involves profiling that may have significant effects on individuals, you have the right to object and to request human review (see Section 3.1.8).
We process personal data to comply with our legal obligations, including: anti-money laundering (AML) and Know Your Customer (KYC) requirements; tax reporting and record-keeping obligations; product recall cooperation with regulatory authorities; compliance with court orders and lawful government requests; data protection law compliance (including responding to data subject rights requests and breach notifications); and compliance with trade sanctions screening obligations.
Legal basis: legal obligation (GDPR Art. 6(1)(c); equivalent provisions under all applicable national laws). We do not use legal obligation as a pretext to process more data than is genuinely required by the applicable legal requirement.
For Vendors, we process personal and business data to verify Vendor identity and eligibility for Platform participation; conduct KYC/AML screening; process Vendor applications and the Founding Vendor Program; manage the Vendor Account and store setup; process payouts and tax reporting; provide Vendors with sales analytics and performance data; and manage Vendor compliance with Platform policies.
Legal basis: contract performance (Vendor Agreement); legal obligation (AML/KYC and tax requirements); legitimate interests (Platform integrity and fraud prevention).
Every processing activity we conduct must rest on a valid legal basis under applicable data protection law. The following table maps our principal processing activities to their legal bases across the frameworks most relevant to our global user base:
| Processing Activity | Primary Legal Basis (EU/UK GDPR) | Equivalent Basis (Other Jurisdictions) |
|---|---|---|
| Account registration & authentication | Art. 6(1)(b) — Contract performance | Contract necessity: LGPD Art. 7(V); POPIA § 11(1)(a); PDPA Singapore § 13; APPI Art. 18 |
| Order processing & fulfillment | Art. 6(1)(b) — Contract performance | Contract necessity (all applicable jurisdictions) |
| Payment processing | Art. 6(1)(b) Contract / Art. 6(1)(f) Legitimate interests | Contract necessity / legitimate purpose (LGPD; PIPA; NDPA 2023) |
| Fraud detection & prevention | Art. 6(1)(f) — Legitimate interests (LIA maintained) | Legitimate purpose: LGPD Art. 7(IX); POPIA § 11(1)(f); PDPA § 15; PIPA Art. 15 |
| KYC / AML identity verification | Art. 6(1)(c) — Legal obligation (AML Directives) | Legal obligation: BSA/FinCEN (US); PCMLTFA (Canada); FMPA (Nigeria); all applicable AML laws |
| Tax reporting & record-keeping | Art. 6(1)(c) — Legal obligation | Legal obligation (all applicable tax law jurisdictions) |
| Marketing communications | Art. 6(1)(a) — Consent (ePrivacy Directive) | Consent: CASL (Canada); LGPD Art. 7(I); IT Rules 2011 (India); APPI; PIPA; PDPA |
| Personalization & recommendations | Art. 6(1)(f) — Legitimate interests / Art. 6(1)(a) Consent (where profiling) | Legitimate purpose (opt-out available); consent for sensitive inferences (CPRA) |
| Analytics & platform improvement | Art. 6(1)(f) — Legitimate interests (pseudonymized data) | Legitimate purpose (all jurisdictions); consent for analytics cookies under ePrivacy/PECR |
| Sustainability profiling | Art. 6(1)(a) — Consent / Art. 6(1)(f) Legitimate interests | Consent or legitimate purpose depending on sensitivity; opt-out available globally |
| Security & abuse prevention | Art. 6(1)(f) — Legitimate interests | Legitimate purpose / legal obligation in most jurisdictions |
| Responding to legal requests | Art. 6(1)(c) — Legal obligation / Art. 6(1)(d) Vital interests | Legal obligation (all applicable jurisdictions) |
| Customer support & disputes | Art. 6(1)(b) Contract / Art. 6(1)(f) Legitimate interests | Contract necessity / legitimate purpose |
| Sending transactional notifications | Art. 6(1)(b) — Contract performance | Contract necessity (all applicable jurisdictions) |
Where we rely on legitimate interests as our legal basis, we have conducted a Legitimate Interests Assessment (LIA) balancing our interests against your rights and freedoms. Our primary legitimate interests include: preventing fraud and protecting all Platform users from financial harm; maintaining Platform security and integrity; improving the Platform experience for all users; and providing you with relevant personalized content that enhances your use of the Platform.
You have the right to object to processing based on legitimate interests at any time (see Section 3.1.8 — Your Rights). Where you object, we will cease the relevant processing unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is for the establishment, exercise, or defense of legal claims.
Where consent is the applicable basis, we will seek it clearly and separately for each purpose. You may withdraw consent at any time without affecting the lawfulness of processing that took place before withdrawal. To withdraw consent: update your preferences in account settings; click the unsubscribe link in any marketing email; or contact privacy@aqnova.co. Consent withdrawal for non-essential cookies can be managed through our Cookie Consent Manager at any time.
When you place an order, we share with the applicable Vendor the data necessary to fulfill your order: your name, delivery address, order details (products, quantities, special instructions), and contact information for delivery coordination. Vendors are contractually prohibited from using your personal data for any purpose other than fulfilling your order and providing post-sale support for that order. Vendors cannot use your contact information for unsolicited marketing, and they cannot transfer your data to third parties for their own purposes.
We share payment-related data with our payment processing partners — which may include Stripe, PayPal, Adyen, local payment providers (M-Pesa, PIX, UPI, SPEI, and others), and card networks — for the purpose of processing your payment, managing chargebacks, and conducting fraud screening. Payment processors are independent data controllers for their own regulatory compliance purposes and operate under PCI-DSS Level 1 certification. AqNova does not store your full payment card details.
We share your name, delivery address, and order reference number with logistics carriers and fulfillment partners for the purpose of arranging delivery and providing you with tracking information. Where you have provided a telephone number for delivery notifications, this may also be shared with the carrier. Logistics partners process this data solely for delivery services.
For Vendor onboarding, we share identity and business registration data with our KYC/AML verification partners for identity verification and sanctions screening purposes. These providers act as data processors under AqNova's instruction and are subject to Data Processing Agreements (DPAs) that restrict processing to the stated purpose.
We use cloud infrastructure, security, analytics, and operational software tools provided by third-party technology partners. Personal data processed in or through these systems is covered by DPAs that require processors to maintain appropriate security measures, process data only as instructed, and not engage sub-processors without authorization. Our current list of material sub-processors is maintained at [aqnova.co/privacy/sub-processors].
In the event of a merger, acquisition, reorganization, or sale of all or substantially all of AqNova's business assets, personal data may be transferred to a successor entity as part of the transaction. We will notify you of any such transfer and your rights in connection with it, in accordance with applicable law, including providing you with the opportunity to delete your account before the transfer takes effect, where feasible.
We may share your personal data with third parties not described above where you have given your explicit, informed consent to the specific sharing. This may include participation in AqNova partner promotions, third-party loyalty programs, or co-branded features. Consent is always sought separately for each such sharing and can be withdrawn at any time.
AqNova operates as a global marketplace. Your personal data may be transferred to, stored, and processed in countries other than your country of residence — including the United States (our principal place of business), countries where our cloud infrastructure is hosted, and countries where our vendors and partners are located. These transfers are necessary to operate the Platform and fulfill your orders.
Whenever we transfer personal data internationally, we implement appropriate safeguards to ensure that your data receives a level of protection equivalent to that required in your jurisdiction. The safeguards we use include:
EU Standard Contractual Clauses (SCCs): for transfers from the EEA to countries without an EU adequacy decision, we use the European Commission's Standard Contractual Clauses (Commission Implementing Decision 2021/914/EU).
UK International Data Transfer Agreement (IDTA): for transfers from the United Kingdom, we use the UK IDTA or an addendum to the EU SCCs, as appropriate.
Adequacy Decisions: for transfers to countries that have received formal adequacy recognition from the European Commission or the UK Secretary of State (e.g., Canada, Japan, South Korea, Israel, New Zealand, Switzerland, and others), we rely on adequacy as the transfer basis.
Binding Corporate Rules (BCRs): AqNova is in the process of developing and seeking approval for BCRs to cover intra-group international transfers. We anticipate BCR submission in Q4 2026.
Transfer Impact Assessments: for all SCC-based transfers, we conduct documented Transfer Impact Assessments to assess whether the legal framework of the recipient country provides equivalent protection and to identify supplementary measures where needed.
Other jurisdiction-specific mechanisms: for transfers from Brazil (LGPD Art. 33 standard contractual clauses), South Africa (POPIA § 72 binding agreements), Australia (APP 8 contractual obligations), Singapore (PDPA contractual obligations), and other jurisdictions, we implement the mechanisms required by local law.
You can obtain copies of the specific transfer safeguards we apply, where permitted by applicable law, by contacting dpo@aqnova.co.
You have meaningful rights over your personal data. The rights available to you depend on your jurisdiction of residence, but AqNova's highest-common-denominator approach means we honor the broadest set of rights across all applicable frameworks for all Platform users. The full Data Subject Rights Portal is available at [aqnova.co/privacy/rights].
You have the right to ask us what personal data we hold about you, why we hold it, who we share it with, how long we retain it, and what rights you have in relation to it. We will provide you with a copy of your personal data in a commonly used electronic format. We aim to respond within 30 days globally. EU/UK users: 1-month response period per GDPR Art. 15. California users: 45-day response period per CCPA. Brazil users: 15-day response period per LGPD Art. 18. India users: 15-day response period per DPDPA 2023.
You have the right to ask us to correct personal data that is inaccurate or incomplete. For most data fields (name, address, contact details, preferences), you can update your information directly through your account settings. For data that cannot be self-corrected (e.g., KYC-verified information, tax records), please contact privacy@aqnova.co with supporting documentation.
You have the right to ask us to delete your personal data in certain circumstances — for example, where the data is no longer necessary for the purpose for which it was collected; where you withdraw consent and no other legal basis applies; or where we are processing data unlawfully. We will honor erasure requests unless we are required or permitted by applicable law to retain the data (e.g., for tax records, AML records, or active legal proceedings). Where we cannot fully comply with an erasure request, we will explain why and describe the specific data we are required to retain.
You have the right to receive a copy of the personal data you have provided to us, in a structured, commonly used, machine-readable format (e.g., JSON or CSV), and to transfer that data to another service provider. Portability applies to data processed on the basis of contract or consent, where the processing is carried out by automated means. You can access your data export through your account settings or by contacting privacy@aqnova.co.
You have the right to ask us to restrict (pause) the processing of your personal data in certain circumstances — for example, while you contest the accuracy of the data we hold, or while an objection to processing is being assessed. During a restriction, we will continue to store your data but will not process it for other purposes.
You have the right to object at any time to our processing of your personal data for the following purposes:
Direct marketing: you have an unconditional right to object to processing for direct marketing purposes. We will stop sending marketing communications promptly upon receipt of your objection.
Profiling for recommendations and personalization: you have the right to object to profiling based on your interests and behavior. We will stop personalized recommendations. You will still be able to use the Platform but will receive generic rather than personalized content.
Processing based on legitimate interests: you may object to other processing based on legitimate interests. We will assess your objection and cease processing unless we can demonstrate compelling legitimate grounds.
California opt-out (CCPA/CPRA): California residents have the right to opt out of the "sale" or "sharing" of personal information for cross-context behavioral advertising. AqNova does not sell personal information. You may submit a Do Not Sell or Share request at [aqnova.co/privacy/do-not-sell] or by contacting privacy@aqnova.co. AqNova honors the Global Privacy Control (GPC) browser signal.
Sensitive personal information (CPRA): California residents have the right to direct AqNova to limit its use of sensitive personal information to uses necessary to perform the services reasonably expected by an average consumer.
AqNova does not make binding automated decisions about individual users — such as permanent account bans, denial of services, or financial determinations — without human review of the relevant circumstances. Where automated systems flag an account for suspension, enforcement, or restriction, a human reviewer assesses the automated recommendation before final action is taken (except for immediate security suspensions to prevent ongoing fraud, which are reviewed promptly after the protective action is taken).
You have the right to request human review of any automated decision that affects you significantly. To exercise this right, contact privacy@aqnova.co with the subject line "Automated Decision Review."
We will not penalize you, degrade your service, charge you a higher price, or deny you access to the Platform because you have exercised any privacy right. The right to non-discrimination applies in all jurisdictions where we operate, regardless of whether it is specifically mandated by local law.
Where processing is based on your consent, you can withdraw that consent at any time by updating your account preferences, clicking the unsubscribe link in any marketing communication, or contacting privacy@aqnova.co. Withdrawal of consent does not affect the lawfulness of processing that took place before withdrawal.
| Submitting a Privacy Rights Request Online (preferred): [aqnova.co/privacy/rights] — structured form, fastest processing Email: privacy@aqnova.co — subject line: 'Privacy Rights Request — [Your Country]' Post: Data Protection Officer, Arivon Holding Corporation, 2571 Saturn Avenue, Unit #265, Huntington Park, CA 90255, USA We will verify your identity before acting on your request. Identity verification is proportionate to the sensitivity of the request. We do not charge fees for rights requests unless they are manifestly unfounded or excessive. If we refuse your request, we will provide a written explanation and inform you of your right to escalate to the relevant supervisory authority. |
|---|
We keep your personal data for no longer than is necessary for the purposes for which it was collected, or as required by applicable law. The table below summarizes our retention periods for each principal data category. The complete Data Retention Schedule (Section 3.4) provides an exhaustive category-by-category breakdown.
| Data Category | Retention Period & Basis |
|---|---|
| Identity Data (active account) | Duration of active account plus 3 years from account closure date, to support dispute resolution, fraud prevention, and regulatory audit requirements. |
| Contact Data | Duration of active account plus 3 years from account closure; marketing contact data retained until consent is withdrawn or 3 years from last communication, whichever is earlier. |
| Financial Data | 7 years from the date of the relevant transaction (extended to 10 years in jurisdictions where local tax law requires). Payout records: 7 years. |
| Transaction Data | 7 years from the date of the transaction for accounting and tax compliance in most jurisdictions (10 years in select jurisdictions with extended requirements). |
| KYC / Identity Verification Records | 5 years from the end of the business relationship, consistent with AML record-keeping requirements (EU 6AMLD; UK MLR 2017; US BSA; Canada PCMLTFA; equivalent national AML laws). |
| Technical Data (logs) | Security and access logs: 12 months rolling. Security incident records: 3 years. Confirmed fraud investigation records: 7 years. |
| Usage Data | Aggregated and pseudonymized usage analytics: retained indefinitely as they cannot be linked to individuals. Individual-level session data: 13 months, consistent with industry analytics standards. |
| Marketing Preferences / Consent Records | Consent records retained for 3 years from the last marketing communication sent under the consent, or until consent is withdrawn, to demonstrate valid consent in any regulatory inquiry. |
| Sustainability Profile Data | Duration of active account plus 12 months; deleted within 90 days of account closure unless legally required to retain. |
| Customer Support Communications | 3 years from the date of the last communication in a thread, unless relating to a dispute or legal claim (retained until final resolution plus applicable limitation period). |
| Deleted Account Data | Substantive personal data deleted or anonymized within 90 days of account closure, subject to legal retention obligations. Aggregated, anonymized data derived from the account may be retained indefinitely. |
When the applicable retention period expires, we delete personal data from our live systems and from backup systems within 90 days of the live deletion. Deletion is accomplished by secure erasure (overwriting) or by destruction of the storage medium, as appropriate to the data type and storage technology. Where full deletion is not technically feasible (e.g., in encrypted database archives), we apply anonymization so that the data can no longer be linked to any individual.
AqNova uses automated processing and profiling in the following contexts. We are committed to transparency about these systems and to ensuring that automated processing does not produce decisions with significant effects on individuals without appropriate human oversight.
| Automated System | Purpose, Scope & Safeguards |
|---|---|
| Fraud Detection & Prevention Engine | Automated analysis of transaction patterns, device signals, behavioral data, and account history to identify potentially fraudulent activity. May automatically flag transactions, apply temporary holds on payouts, or trigger account review. EFFECT: May cause temporary payment holds or account restrictions. Human review is conducted for all significant actions (permanent suspensions, account terminations). You may request human review of any automated decision. |
| KYC / Identity Verification Screening | Automated document verification and liveness checks during Vendor onboarding; automated sanctions screening against prohibited-party lists. May produce a pass, fail, or refer-for-manual-review outcome. EFFECT: A 'fail' result without manual review does not result in permanent rejection. All automated KYC failures are reviewed by a human analyst before final action. Vendors may appeal a rejection. |
| Search Ranking & Product Recommendations | Algorithmic ranking of search results and personalized product recommendations based on your browsing history, purchase history, sustainability profile, and Platform engagement patterns. EFFECT: Influences the products you see prominently; does not affect your ability to find any product through direct search. Opt-out available through account settings (disables personalization; you will see default ranking). |
| Dynamic Pricing Display (Vendor-Set Prices) | AqNova displays Vendor-set prices in your local currency. Exchange rate calculations are automated. Note: AqNova does not engage in dynamic pricing — it does not adjust prices based on your personal profile or browsing behavior. Displayed prices reflect Vendor-set prices converted at prevailing exchange rates. |
| Content Moderation Screening | Automated scanning of Vendor listing content for potential policy violations (prohibited products, suspicious certification claims, pricing anomalies). EFFECT: Listings that trigger automated flags are placed in a review queue; they are reviewed by a human compliance analyst before any action is taken. Vendors are notified and may appeal any listing removal. |
| Sustainability Claims Verification | Automated scanning of listing text to detect potential greenwashing or unsubstantiated sustainability claims (e.g., use of certification marks not matched to the Vendor's verified certifications). EFFECT: Triggers human review, not automatic removal. Vendors are notified before any action. |
In connection with automated processing that may produce significant effects, you have the following rights:
Right to be informed: this section constitutes our disclosure of automated processing that may significantly affect you.
Right to human review: you may request that a human review any automated decision that significantly affects your account, your payouts, or your ability to use the Platform. Contact privacy@aqnova.co with the subject line "Automated Decision Review — [describe the decision]."
Right to object: you may object at any time to profiling for marketing or recommendation purposes. We will cease personalization immediately upon your objection.
Right to explanation: you may request a meaningful explanation of any automated decision that has been applied to your account. We will explain the principal factors that influenced the decision.
These rights apply regardless of your jurisdiction, consistent with AqNova's highest-common-denominator standard. GDPR Article 22 and equivalent provisions under LGPD, DPDPA, PIPA, and other frameworks provide the specific legal framework for these rights in each jurisdiction.
The Platform is not directed at children under the age of 18 (or the applicable age of majority in your jurisdiction). AqNova does not knowingly collect personal data from children under 13 (or under 16 for EU users in jurisdictions applying the GDPR Article 8 age threshold). If you believe your child has provided personal data to AqNova without your consent, please contact safety@aqnova.co immediately. We will promptly delete the child's data and terminate their account.
Age verification mechanisms are built into the registration process. We cooperate with parental oversight requests and comply with the Children's Online Privacy Protection Act (COPPA, US), GDPR Article 8, the UK Age Appropriate Design Code, and equivalent provisions in all applicable jurisdictions.
We implement a comprehensive suite of technical and organizational measures to protect your personal data from unauthorized access, disclosure, alteration, destruction, or accidental loss. Key measures include:
Encryption in transit (TLS 1.2/1.3) and at rest (AES-256) for all personal data stored on our systems.
PCI-DSS Level 1 compliant payment processing for all card and payment data.
Multi-factor authentication (MFA) available and encouraged for all user accounts; mandatory for all AqNova staff with access to personal data systems.
Role-based access controls (RBAC) ensuring that personal data is accessible only to staff with a documented need for access.
Regular penetration testing and security audits by independent third-party security experts.
Web Application Firewall (WAF), DDoS mitigation, and intrusion detection systems.
Mandatory annual data protection and security training for all AqNova staff.
Data Protection Impact Assessments (DPIAs) for new high-risk processing activities.
No security system is impenetrable. In the event of a data breach that is likely to result in risk to your rights and freedoms, we will notify you and the applicable regulatory authority as required by applicable law. Our breach notification obligations and timelines are set out in the Privacy & Data Protection Overview (Section 3.0.11).
This master Privacy Policy is supplemented by regional addendums that contain additional disclosures, rights notices, and regulatory information required by specific jurisdictions. Regional addendums are published at [aqnova.co/privacy/regional] and are incorporated into this Policy by reference. The following addendums are currently available or in development:
| Jurisdiction | Addendum Contents |
|---|---|
| California, USA — CCPA/CPRA Addendum | Categories of personal information collected, sold, shared, and disclosed in the past 12 months; Do Not Sell or Share notice; sensitive personal information disclosure; CPPA-compliant privacy notice format; opt-out mechanisms; anti-discrimination notice; authorized agent procedures. |
| European Union — GDPR Addendum | EU Article 27 representative details; lead supervisory authority identification; GDPR-compliant data subject rights notice; lawful basis for each processing activity in GDPR format; cross-border transfer basis documentation; DPIA summary where applicable. |
| United Kingdom — UK GDPR Addendum | UK Article 27 representative details; ICO registration; IDTA transfer basis; UK-specific data subject rights (including provisions of the Data Protection Act 2018 that supplement UK GDPR); PECR cookie compliance notice. |
| Canada — PIPEDA / Quebec Law 25 Addendum | Privacy Management Program summary; Quebec privacy impact assessment disclosures; Quebec-specific consent requirements; OPC contact; provincial privacy officer contact; bilingual (English/French) notice confirmation. |
| Brazil — LGPD Addendum | Encarregado (DPO equivalent) contact details; ANPD registration information; LGPD-format processing basis disclosure; Brazilian data subject rights (Portuguese); 15-day response commitment; LGPD Art. 9 transparency notice. |
| Nigeria — NDPA 2023 Addendum | NDPC registration details; Nigerian data subject rights notice; 72-hour breach notification commitment; DPCO audit compliance; NDPR 2019 historical compliance note. |
| South Africa — POPIA Addendum | Information Officer contact and registration; PAIA Manual reference; POPIA conditions for lawful processing compliance; Information Regulator contact; South African data subject rights notice. |
| India — DPDPA 2023 Addendum | Grievance Officer contact; DPDPA-format consent notice; data fiduciary obligations summary; Indian data principal rights; cross-border transfer restrictions notice; 15-day rights response commitment. |
| Australia — Privacy Act / APPs Addendum | All 13 Australian Privacy Principles compliance disclosure; NDB scheme notification procedures; OAIC contact; APP 8 cross-border disclosure notice; additional rights available under state privacy laws. |
| Asia & Asia-Pacific Regional Addendum | Singapore PDPA compliance notice; Japan APPI compliance (PPC registration, third-party provision records); South Korea PIPA compliance (domestic representative, consent records, destruction obligations); Indonesia PDPL 2022 compliance notice. |
| Latin America Regional Addendum | Colombia Ley 1581 — SIC registration, ARCO rights in Spanish; Chile Ley 19,628 compliance; Argentina Ley 25,326 — AAIP registration, habeas data rights; Mexico LFPDPPP — ARCO rights, INAI contact, Spanish-language privacy notice. |
We may update this Privacy Policy periodically to reflect changes in our data practices, changes in applicable law, or Platform developments. When we make material changes to this Policy — meaning changes that significantly affect how we collect, use, or share your personal data, or that significantly affect your rights — we will:
Notify you by email at the email address registered to your account at least 30 days before the changes take effect (60 days for EU/UK users per DSA requirements; 15 days for changes required by regulatory action).
Display a prominent notice on the Platform's homepage and in your account dashboard during the notice period.
Provide a clear, plain-language summary of what has changed and why.
Obtain renewed consent where the applicable legal basis for a processing activity changes to require consent.
The version history of this Policy, including a description of changes in each version, is maintained at [aqnova.co/privacy/changelog]. Continued use of the Platform after the effective date of any updated Policy constitutes acceptance of the updated terms, except where applicable law requires affirmative consent for material changes.
| AqNova — Privacy & Data Protection Contact Directory General Privacy Inquiries: privacy@aqnova.co Data Protection Officer (DPO): dpo@aqnova.co Data Subject Rights Requests: privacy@aqnova.co [Subject: DSR — [Jurisdiction]] Rights Portal (online): [aqnova.co/privacy/rights] EU/UK GDPR Representative: gdpr@aqnova.co Brazil LGPD Encarregado: privacy@aqnova.co [Subject: LGPD — Brazil DPO] India Grievance Officer (DPDPA): grievance-india@aqnova.co South Africa Information Officer (POPIA):privacy@aqnova.co [Subject: POPIA — South Africa] Nigeria NDPC Contact: privacy@aqnova.co [Subject: NDPC — Nigeria] Korea PIPA Domestic Representative: privacy@aqnova.co [Subject: PIPA — Korea] Cookie / Consent Manager: [aqnova.co/privacy/cookies] Do Not Sell or Share (CCPA/CPRA): [aqnova.co/privacy/do-not-sell] Sub-Processor List: [aqnova.co/privacy/sub-processors] Regional Addendums: [aqnova.co/privacy/regional] Data Breach Reports (Security): security@aqnova.co Child Safety: safety@aqnova.co Legal Notices: legal@aqnova.com Postal: Data Protection Officer, Arivon Holding Corporation, 2571 Saturn Avenue, Unit #265, Huntington Park, CA 90255, USA California File Number: B20250418195 | EIN: 41-3210066 | D-U-N-S: 142957477 GB EORI: GB511467217000 Nigeria (Sahara Eagle Ltd) — Reg: 1957145 | Tax ID: 31052811-0001 | NEPC: 0030281 |
|---|
AqNova Marketplace | Global Legal Footer Framework | Section 3.1: Privacy & Data Protection Policy (Master)
© 2026 Arivon Holding Corporation. All rights reserved. Effective April 7, 2026. Version 1.0.