Skip to main content
Platform Review
PricingSign in
Arva AI assessment

Arva AI procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for Arva AI
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tiersunknown California residents should be aware that this section does not apply to: Personal information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FCRA), the Gramm-Leach-Bliley Act (GLBA) and its implementing regulations, the California Financial Information Privacy Act (FIPA), and the Driver’s Privacy Protection Act of 1994, or other information subject to a California Consumer Privacy Act (CCPA) exception. If you are a resident of California, you have certain rights in relation to your personal information pursuant to the California Consumer Privacy Act (CCPA). These include your right to: Request information about the personal information that the Company collects about you and the manner in which the Company processes and discloses that information.Captured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown (a) Configurable computing resources. Arva AI’s customers configure compliance workflows, risk thresholds, and standard operating procedures. The Customer does not provision, configure, or manage computing infrastructure. This constitutes business-logic configuration and not computing-resource configuration within the meaning of the definition.Captured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown 1. Arva AI confirms that the EU Data Act’s Chapter VI switching and portability obligations do not apply to its Services as at the date of this Addendum.Captured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown This EU Data Act Addendum (this “Addendum”) supplements the terms and conditions of use agreement (the “Agreement”) between the Customer and Arva AI Inc. (“Arva AI”). This Addendum confirms the non-applicability of Regulation (EU) 2023/2854 (the “EU Data Act”) to Arva AI’s Services and sets out the basis for that determination.Captured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown 2.1 Service Description. Arva AI provides AI-powered financial crime compliance solutions to the Customer, including Screening AI, KYB/KYC AI, Transaction Monitoring AI, and Ongoing Monitoring (the “Services”). The Customer accesses the Services through Arva AI’s platform for the purpose of enabling the Customer to assess compliance decisions, risk assessments, and due diligence reports. 2.2 Article 2(8) of the EU Data Act defines “data processing service” as a digital service enabling “ubiquitous and on-demand network access to a shared pool of configurable, scalable and elastic computing resources”. All elements of this definition must be satisfied cumulatively. 2.3 The European Commission has established that a SaaS provider falls outside scope where customers contract for a purpose-specific outcome and the underlying computing is merely incidental to the Service’s main functionality. 2.4 A financial institution or business subscribes to Arva AI Services for compliance support (which may include automated alert resolution, risk assessments and due diligence) and not for access to configurable computing resources. The AI processing underpinning Arva AI’s Services is the delivery mechanism for those compliance outcomes and is not itself the product. 2.5 Three critical elements of the Article 2(8) definition are absent:Captured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown (b) Customer-controlled scalability and elasticity. Arva AI scales its infrastructure internally to meet demand. Customers have no visibility into, and exercise no control over, the allocation or release of computing resources.Captured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown (c) Minimal provider interaction. Arva AI’s onboarding involves system integration, SoP configuration, and model tuning — a degree of provider involvement inconsistent with the self-service, minimal-interaction model contemplated by the definition.Captured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown California law requires us to verify the requests the Company receives from you when you exercise certain of the rights listed above. To verify your request, the Company will check the information you provide us in your request against third party identity verification tools. As part of this process, the Company may call you after you submit your request to verify information. You may also designate an authorised agent to exercise certain of the rights listed above on your behalf by providing the authorised agent with power of attorney pursuant to the California Probate Code or by executing other documentation the Company may require. The authorised agent may make the request on your behalf by following the instructions above. If an authorised agent submits a request on your behalf, the Company will contact you to verify that they represent you. California law requires that the Company describe certain disclosures of personal information where the Company receives valuable consideration. California law treats such disclosures as “sales” even if no money is exchanged. The Company does not sell information to third parties as defined under California law. The Company does not knowingly sell the personal information of minors under 16 years of age.Captured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown Obtain the specific pieces of personal information that the Company has collected about in the 12 months preceding your request.Captured 2026-07-19Open source →Finding permalink →
Data retentionAll applicable tiersunknown In some cases, the length of time the Company retains data depends on your settings.Captured 2026-07-19Open source →Finding permalink →
Data retentionAll applicable tiersunknown Any legal requirements that the Company is subject to.Captured 2026-07-19Open source →Finding permalink →
Data retentionAll applicable tiersunknown The potential risk of harm from unauthorised use or disclosure of the data.Captured 2026-07-19Open source →Finding permalink →
Data retentionAll applicable tiersunknown Delete certain personal information that the Company has collected about you.Captured 2026-07-19Open source →Finding permalink →
Data retentionAll applicable tiersunknown Delete your Personal Data from our records.Captured 2026-07-19Open source →Finding permalink →
Data retentionAll applicable tiersunknown The Company will retain your Personal Data for only as long as it needs in order to provide our Service to you, or for other legitimate business purposes such as resolving disputes, safety and security reasons, or complying with our legal obligations. How long the Company retains Personal Data will depend on a number of factors, such as: Our purpose for processing the data (such as whether the Company needs to retain the data to provide our Services).Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown Group Companies: The Company may share your information with our group of companies for the purposes of business administration, maintaining security and regulatory compliance, providing support services to end users (including IT support, where relevant), marketing and analytics.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown Cookies and Similar Technologies: The Company may use cookies, pixel tags, web beacons and other similar technologies to better understand how you interact with our Services, monitor aggregate usage by our users, and monitor web traffic routing to help us improve our Services. Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown /The sharing of personal data may involve the cross-border transfer of personal data. The Company makes cross-border transfers of personal data in accordance with relevant data privacy law requirements which may include ensuring that personal data that is transferred outside of the EEA benefits from an adequate level of protection by requiring sub-processors to enter into the European Commission approved Standard Contractual Clauses (and/or their UK and Switzerland equivalents) if they are not in a country that has the benefit of an adequacy decision and if there is no alternative transfer safeguard. You can request a copy of these by contacting us at privacy@arva.ai .Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown Business Account Administrators: Administrators may access and control your account, including being able to access your Content. In addition, if you create an account using an email address belonging to your employer or another organisation, the Company may share the fact that you have an account and certain account information, such as your email address, with your employer or organisation to, for example, enable you to be added to their business account.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Government Authorities or Other Third Parties: The Company may share your Personal Data, including information about your interaction with our Services, with government authorities, industry peers, or other third parties in compliance with the law (i) if required to do so to comply with a legal obligation, or in the good faith belief that such action is necessary to comply with a legal obligation, (ii) to protect and defend our rights or property, (iii) if the Company determines, in its sole discretion, that there is a violation of our terms, policies, or the law; (iv) to detect or prevent fraud or other illegal activity; (v) to protect the safety, security, and integrity of our products, employees, users, or the public, or (vi) to protect against legal liability.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium The Company may disclose your Personal Data in the following circumstances: Vendors and Service Providers: To assist us in meeting business operations needs and to perform certain services and functions, the Company may disclose Personal Data to vendors and service providers, including providers of hosting services, customer service vendors, cloud services, content delivery services, support and safety monitoring services, email communication software, web analytics services, payment and transaction processors, and other information technology providers. Pursuant to our instructions, these parties will access, process, or store Personal Data only in the course of performing their duties to us. Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Other entities related to legal process and emergency situations: The Company may disclose personal information to third parties as permitted by, or to comply with, applicable laws and regulations. Examples include responding to a subpoena or similar legal process, protecting against fraud and cooperating with law enforcement or regulatory authorities. Information disclosed for these purposes may include device and online identifiers, information about your internet, browser, and network activity, and location data.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Third-Parties: The Company is entitled to share with third-party agents, partners and service providers, who (i) are only permitted to use your information as the Company allows (which may include contacting you on our behalf), and (ii) are required under law or contract to keep your personal information confidential.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown Business Transfers: If the Company is involved in strategic transactions, reorganisation, bankruptcy, receivership, or transition of service to another provider (collectively, a “Transaction”), your Personal Data may be disclosed in the diligence process with counterparties and others assisting with the Transaction and transferred to a successor or affiliate as part of that Transaction along with other assets.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown Relevant Entities: The Company may disclose information to banks, financial institutions, legal and financial advisors or auditors Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Affiliates: The Company may disclose Personal Data to our affiliates, meaning an entity that controls, is controlled by, or is under common control. Our affiliates may use this Personal Data in a manner consistent with this Privacy Policy.Captured 2026-07-19Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.