Who we are and what this covers
MV37 Corp. (“MV37,” “we,” “us,” or “our”) provides software security testing and repair tools and operates this website. This Privacy Policy describes how we handle personal information when you visit our website, contact us, create an account, or interact with our business.
Our corporation number with Corporations Canada is 1822946-5. We are based in Ontario, Canada. MV37 Corp. is responsible for the information it collects for these purposes. Direct privacy questions and requests to our privacy contact at connect@mv37.ai.
When a customer provides information for an authorized assessment, we may process it on that customer’s behalf. The customer’s agreement, instructions, and any applicable data processing agreement govern that work. This policy does not replace those agreements or the customer’s own privacy notice.
Information you provide
- Business inquiries. Your name, work email, company, product description, and the ways you would like us to help. You may also provide your role, website, team size, product type, technology stack, hosting and source control providers, test environment, timing, and requirements.
- Communications. Information you include in emails, support requests, meetings, and other correspondence with us.
- Accounts. Your email address, password verification data, one-time password-reset verification data, access permissions, and account activity. MV37 operates the sign-in and recovery service. We store password hashes and verification hashes of reset links and session tokens rather than their original values.
- Authorized connections. If you connect a repository or use an approved workspace, we receive the account, installation, repository, branch, and permission information needed for that connection. Separately authorized work may also involve source files, contributor information, build output, logs, findings, and proposed repairs.
Required fields are identified in the contact form; other details are optional. Without the required information, we may be unable to receive or respond meaningfully to your request.
Please keep initial inquiries high-level. Do not submit passwords, API keys, private keys, production credentials, customer records, sensitive personal information, or confidential source code through the contact form. Share only information you are authorized to provide.
Information collected automatically
Our website infrastructure and account service process technical information needed to deliver and protect the site. This may include IP addresses, browser and device information, requested pages, referring pages, timestamps, session information, errors, and security events.
For contact submissions, we store a receipt identifier, submission time, and information used to recognize duplicate submissions. Where our hosting provider supplies an IP address, the contact service stores a hashed value derived from it to limit abuse. A hashed address can still be personal information; it is not necessarily anonymous. Hosting providers may separately process the original address in their operational logs.
How and why we use information
We use information to respond to inquiries, understand your requirements, arrange requested conversations, evaluate a potential engagement, manage accounts and permissions, provide agreed services, investigate errors, protect our systems, prevent abuse, and meet legal obligations.
Submitting an inquiry asks us to follow up about that inquiry. It does not automatically subscribe you to a newsletter or authorize unrelated promotional messages. You can ask us to stop optional follow-up communications at any time.
Where applicable law requires a legal basis, we rely on your consent for processing that needs consent; steps you request before a contract and performance of a contract where relevant; our legitimate interests in operating and securing our business where those interests are not overridden by your rights; and compliance with legal obligations. We obtain additional consent when the law requires it.
The contact form does not start a security assessment or send your submission to an AI model for assessment. AI processing of customer materials, where agreed, must be addressed in the applicable service and data processing arrangements. We do not use the website to make solely automated decisions that have legal or similarly significant effects on individuals.
Where information is processed
MV37 and its providers may process information in countries other than where you live. Those countries may have different privacy laws, and information may be accessible to their courts, law enforcement, or other authorities under local law.
Where applicable law requires safeguards for an international transfer, those safeguards must be in place for that transfer. Contact us for information about the arrangements relevant to your data. This website does not promise that information will remain in a particular country; any customer residency requirement must be agreed separately before the relevant information is shared.
How long we keep information
We retain personal information for as long as reasonably needed for the purpose for which it was collected, including managing an active inquiry or relationship, maintaining authorized accounts, addressing security issues, resolving disputes, and meeting legal requirements.
The appropriate period depends on the type and sensitivity of the information, the status of the inquiry or account, when we last communicated, contractual requirements, and any applicable legal retention period. We delete or de-identify information when it is no longer needed for those purposes. This is not a promise of automatic deletion after a fixed number of days.
You can request deletion using the contact details below. Some information may need to be retained for a lawful reason, and copies in backups may remain until the applicable backup cycle ends. Retention of customer assessment materials is governed by the relevant agreement and applicable law.
Protecting information
We use measures intended to protect information, including account access controls, permission checks, input validation, and safeguards against abusive submissions. The measures appropriate to customer assessment materials depend on the agreed service and its configuration.
No website, transmission, storage system, or security assessment can be guaranteed completely secure. If a personal information breach requires notification, we will notify affected people and authorities as required by applicable law.
Your choices and privacy rights
You may ask what personal information we hold about you, request access or correction, ask for deletion, or withdraw consent where processing depends on consent. Depending on the law that applies, you may also have rights to restrict or object to processing, receive a portable copy, or appeal a decision about your request. These rights can be subject to lawful exceptions.
Send requests to connect@mv37.ai. Include enough information for us to identify the relevant account or inquiry, but do not send passwords or identity documents unless we arrange an appropriate way to verify identity. We may need proportionate verification before disclosing or changing information. We respond within applicable legal time limits.
Withdrawing consent does not affect prior lawful processing. It may mean we can no longer provide a feature that needs the information; we will explain that consequence. Where we process information for a customer, we may direct your request to that customer and assist as required.
You can raise a complaint with us or the privacy regulator responsible for your location. Where Canadian federal privacy law applies, you may contact the Office of the Privacy Commissioner of Canada. Nothing in this policy limits a right to complain or seek another remedy.
Children and external services
MV37 is intended for adult business users and is not directed to children. We do not knowingly solicit personal information from children under 18. If you believe a child has provided information, contact us so we can investigate and take appropriate action.
External sites and services may have their own privacy practices. You can read the Cloudflare privacy policy, Supabase privacy policy, Resend privacy policy, and GitHub privacy statement for information about those providers. Their notices do not replace MV37’s responsibilities for information under its control.
Changes and contact
We may update this policy to reflect changes to our practices, services, or legal requirements. The date above identifies the latest revision. For material changes, we will provide additional notice and obtain consent when required; posting a new policy does not by itself supply consent for a new use of previously collected information.
For privacy questions, requests, or concerns, contact MV37 Corp., attention: Privacy, at connect@mv37.ai.