Draft — not yet reviewed by counsel. This is placeholder boilerplate published so the site is complete and so you can see our intent. It will be replaced by a professionally reviewed version before general availability. If anything here matters to your decision, write to us and we will answer it directly.
Privacy
Last updated 5 August 2026
Who processes your data
Provetta is operated by AZR Tech-Solutions LLC (d/b/a Provetta), which is the party responsible for the processing described below.
What this covers
Provetta is a quality management system used by organizations to record documents, training, incidents, inspections, suppliers and related evidence. Two different kinds of data flow through it, and they are treated differently.
Data your organization puts in
Records you create belong to your organization, not to us. We process them to provide the service and for no other purpose — we do not sell them, mine them for advertising, or use them to train models.
Access is isolated per organization at the database level. Provetta staff cannot read your records without opening a time-boxed support session, which requires a written reason, expires on its own, can be ended by your administrators, and is recorded in your own audit trail where you can see it.
Data we collect about you
Account details — name, work email, job title, department — supplied by you or your administrator. Authentication data is handled by our infrastructure provider; we never see your password.
We record the IP address of submissions to public forms in order to rate-limit abuse.
Retention, and a real limit on erasure
Business records are retained according to the retention policies your organization configures. There is deliberately no delete path for a controlled record — that is what makes the system usable as evidence.
When a person leaves, their identifying details can be anonymised. Their account identifier is kept, because electronic signatures and a hash-chained audit trail point at it. What was signed, when, and by which distinct person stays provable; who that person was does not. You should know this before choosing the system: complete erasure of a signatory is incompatible with a tamper-evident audit trail.
Sub-processors
We use infrastructure and email delivery providers to run the service. A current list is available on request and will be published here before general availability.
Taking your data with you
You can export everything your organization holds at any time, as often as you like, without asking us.
Questions about this page? Write to hello@provettahq.com.
