Privacy Policy
Updated July 2026
About our privacy policy
Innovilage Technologies Inc. ("we", "us", or "our") values the privacy, security, and integrity of the data entrusted to us. This Privacy Policy outlines how we collect, process, use, disclose, and safeguard personal data across our operations, enterprise products, and specialized ecosystems, including our EnterpriseDirect webstore portal.
This policy establishes our compliance framework under global data protection laws, specifically:
- The UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (GDPR);
- The California Privacy Rights Act (CPRA) and the California Delete Act;
- Taiwan's Personal Data Protection Act (PDPA);
- Singapore's Personal Data Protection Act 2012 (PDPA); and
- The United Arab Emirates’ Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL).
Information we collect
Depending on the products you license or the services you access, we collect and process the following categories of personal data:
- Identifiers & Contact Details: Real name, business email address, corporate telephone number, and physical billing/shipping addresses.
- Authentication & Access Data: One-Time Passwords (OTPs), encrypted login credentials, and administrator logs tied to our enterprise platforms.
- Technical, Device & Network Data: Internet Protocol (IP) addresses, unique device identifiers (including MAC addresses or hardware IDs used in device node-locking), system configuration data, operating system logs, and telemetry data collected via the Innovilage EnterpriseDirect webstore portal.
- Product-Specific Telemetry: In limited contexts, anonymized or pseudonymous metadata may be compiled during the deployment, licensing, or debugging of our software and hardware solutions (e.g., system health metrics, license key validations).
How we use your information
We process personal data strictly in accordance with applicable legal frameworks to fulfill the following operational requirements:
- Contract Fulfillment & Service Delivery: Managing orders, processing payments, executing software updates, and dispatching physical assets purchased through Innovilage EnterpriseDirect.
- Product Security & Access Control: Authenticating administrative access using OTP systems, validating cryptographic keys, and ensuring the secure configuration of enterprise systems.
- Technical Support & Diagnostics: Troubleshooting deployment failures, evaluating software error logs, and providing specialized engineering support for our hardware and OS solutions.
- Legal Compliance & Risk Mitigation: Enforcing export controls, validating global sanctions compliance, preventing software piracy, and satisfying regulatory record-keeping mandates.
Sharing of your information
We does not sell, rent, or trade your personal data to third parties and restrict information sharing to the following instances:
- Authorised Service Providers: We engage vetted third-party contractors to provide specific infrastructure services, such as secure cloud hosting, payment gateways, international freight forwarding, and local hardware repair partners. These processors are contractually bound by data processing agreements ensuring equivalent protection levels on their ends.
- Corporate Affiliates: Data may be shared among our global corporate entities for internal administrative, operational, or technical support purposes, protected by cross-border data transfer safeguards.
- Legal & Regulatory Disclosures: We may disclose personal data to law enforcement, regulatory bodies, or judicial authorities if compelled by a valid subpoena, court order, or to satisfy domestic security laws within our operational jurisdictions. Before doing so, you will be notified by all available means we have on file to connect with you and strictly excludes any data that is hosted or stored locally on clients' own premises, including but not limited to information stored on owned hardware, on-premise or field deployments, etc.
Finally, we maintain an unequivocal policy of refusing any demand or request to retrieve, access, or disclose cryptographic keys to any third party(ies), absent the express written authorisation of the key owner. Furthermore, we adhere to a strict data minimisation framework, retaining only the cryptographic information strictly necessary to facilitate our baseline or core services.
Your account data
Our processing parametres adapt precisely to the organisational scope and security constraints of your specific account type:
- Enterprise Administrator Account: Covers data required to manage organisational deployments of our high-assurance architectures. This includes IT administrator names, corporate contact channels, access logs, and permissions matrices for managing Saker hardware (including AI-accelerated modules and quantum Hardware Security Modules (HSMs)), CoreEngine OS deployments, and FOSEL (FalcOS Enterprise Linux) infrastructures.
- Professional Account: Focuses on business-to-business (B2B) transaction data, procurement histories, and developer credentials utilised by engineers, data scientists, and researchers licensing our CoreEngine OS software suites (including financial processing engines, GIS systems, and cheminformatics tools) as well as those integrating our MegaData custom datasets.
- Retail/Private User Account: Governs consumer-facing data, including individual order histories, payment confirmations, and residential shipping addresses for private users purchasing standard equipment or accessing our MegaData encyclopedias and baseline data solutions through Innovilage EnterpriseDirect store.
Accessing and updating your information
Registered users can review, modify, or update their personal account information directly by authenticating into their respective account dashboards on 'Innovilage EnterpriseDirect'. To maintain system integrity and prevent supply chain security risks, certain enterprise or administrator account modifications may require secondary authentication or verification by our compliance team.
Data retention & security
We apply stringent, industry-standard technical and organisational safeguards appropriate to the highly sensitive environments in which our solutions operate. These include end-to-end cryptographic protection, access isolation, and robust network boundary controls (including our proprietary QRISC™ framework and gateway services).
In addition, we secure all data in transit using industry-leading cryptographic standards. Standard electronic transfers are protected by Transport Layer Security (TLS) utilising AES-128-GCM (or higher) for symmetric encryption, with data integrity verified via SHA-256 hashing. For enterprise clients requiring maximum assurance, high-priority data pipelines are safeguarded using Quantum Key Distribution (QKD) hardware (where applicable) and secured against future cryptographic threats using Post-Quantum Cryptography (PQC) communication protocols.
Personal data is retained only for the duration necessary to satisfy the specific business purposes outlined in this policy, or as mandated by prevailing statutory retention periods (e.g., tax, audit, and hardware compliance laws). Once these thresholds are met, data is irreversibly anonymised or securely purged.
Locations of processing
As a global enterprise provider, your personal data may be transferred to, stored at, or accessed from servers and facilities located outside your country of residence. Our primary operational nodes are situated in: the United States, the Netherlands, Singapore, the United Arab Emirates, Poland, and Taiwan.
Where cross-border transfers occur, we implement valid statutory compliance mechanisms, including:
- GDPR / UK GDPR: EU/UK Standard Contractual Clauses (SCCs) to govern transfers to non-adequate jurisdictions.
- Singapore & Taiwan PDPA: Ensuring the recipient jurisdiction or entity provides a standard of protection comparable to domestic requirements.
- UAE PDPL: Conducting formal Transfer Risk Assessments (TRAs) and implementing approved contractual frameworks aligned with the requirements of the UAE Data Office.
Grounds for processing
We process personal data only when a valid legal basis is established under localised regulations. These grounds consist of:
- Performance of a Contract: Processing required to execute our terms of service, fulfill orders, or manage enterprise software licensing agreements.
- Consent: Where you have explicitly opted into specific processing channels (e.g., marketing communications or voluntary telemetry sharing).
- Legal Obligation: Compliance with mandatory legal, financial, trade compliance, or regulatory frameworks.
- Legitimate Interests: Pursuing our legitimate business objectives, such as optimising platform security, defending our intellectual property (IP), or refining software stability and user experience (UX) - provided these objectives do not infringe upon your primary privacy protections or fundamental freedoms.
Updates and changes to this document
We reserve the right to revise this Privacy Policy to reflect evolving regulatory standards, product expansions, or operational adjustments. Any updates will be published to this page with an amended "Last Updated" date stamp shown at the top of the web page. Material amendments affecting your data rights will be communicated directly via registered account channels or distinct platform notices.
Your data rights
Depending on your regional jurisdiction, you are entitled to specific, legally enforceable rights concerning your personal data:
- Right to Deletion & Erasure: You may request the comprehensive erasure of your personal data. This corresponds directly with the GDPR's Right to Erasure (Article 17), the California Delete Act, Singapore's PDPA, Taiwan's PDPA, and the UAE's PDPL, subject to exceptions where retention is legally or contractually mandated.
- Opt-Out of Training for AI Models: We maintain strict policy controls over our computational resources. You possess an absolute right to opt out of having any of your personal data, developer code metrics, or telemetry ingested for machine learning optimisation, algorithmic training, or artificial intelligence model refinement.
- Access, Correction, and Portability: Regardless of your location, you may exercise your right (as part of Innovilage's global corporate policy) to access a copy of your personal data (in a structured, machine-readable format) indiscriminately and free of charge, as well as demand the immediate rectification of inaccurate or outdated information.
- Objection to Processing & Automated Decisions: You have the right to restrict or object to the automated processing of your data, particularly where processing relies on our legitimate interests or involves automated decision-making that produces legal consequences.
Additionally, we are committed to supporting your individual privacy rights worldwide and indiscriminately. Regardless of where you reside, we endeavour to uphold the highest available standards for data protection across our global operations. Where local data protection legislation affords you elevated privacy rights or controls, we will extend those standards to your personal data, provided such practices comply with the applicable laws in your jurisdiction.
Contact information
To exercise your privacy rights, submit a data subject access request (DSAR), or address inquiries regarding our global data governance practices, please reach out to our Data Protection Office as detailed below:
- Entity: Innovilage Technologies Inc.
- Email: [email protected]
- Address: Unit 6, 3ʳᵈ Floor, No. 502,
Sec. 2, Ren'ai Road, Linkou District
New Taipei City, Taiwan