Skip to content
ArveBot

GDPR

Your GDPR rights.

You stay in control of your personal data. This page explains your rights and the extra terms that apply when a business asks ArveBot to process documents for it.

Last updated: 18 July 2026

What you can ask us to do

  • Give you a copy of your personal data.
  • Correct data that is wrong or incomplete.
  • Delete data when there is no legal reason to keep it.
  • Restrict or object to certain processing.
  • Provide portable data where the law requires it.
  • Stop consent-based processing at any time.

How to make a request

Email hello@arvebot.com from the address connected to your account or waitlist entry. Tell us what you want us to do. We may ask for enough information to confirm your identity, but we will not ask for unnecessary documents. We normally reply within one month.

If your business processes documents with ArveBot

For personal data in server-processed invoices or bank statements, your organisation is the controller and Healthview AI OÜ is the processor. Browser-only invoice work is not received by us. The following GDPR Article 28 terms apply while you use server processing:

  • We process document data only to perform the check or conversion you request, for the live request, and on your documented instructions unless EU law requires otherwise.
  • Your organisation is responsible for a lawful basis, required notices, accurate instructions and deciding whether ArveBot is suitable for the data.
  • The data may include people named in invoices or transactions and their contact, identity, bank, invoice and payment details. Do not submit special-category data unless you have a lawful reason.
  • Authorised staff are bound by confidentiality. We use appropriate security, EU hosting and deletion-focused processing.
  • Our subprocessors are listed in the Privacy Policy and are bound by equivalent data-protection duties. You authorise their use for the stated tasks. We will publish material changes and use GDPR safeguards for transfers outside the EEA.
  • We will assist with data-subject requests, security duties and impact assessments where reasonably required, and notify you without undue delay if we become aware of a personal-data breach affecting your document data.
  • We return your requested result and delete document data after processing. When processing ends, we will delete or return any remaining personal data at your choice unless law requires retention.
  • We will provide information reasonably needed to show compliance, support proportionate audits and tell you if an instruction appears unlawful.

If you are unhappy

Contact us first so we can try to resolve the issue. You may also complain to the Estonian Data Protection Inspectorate or the data-protection authority where you live or work.

Legal references