Last updated · August 8, 2026
Privacy Policy
This Privacy Policy describes how Payne Agentic Ventures (“PAV,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects information through its website and entrepreneurship platform.
1. Scope and controller information
This policy is intended to apply to the PAV website, brief introduction form, invitation-only applications, interactive interviews, file-submission features, administrator review tools, assessments, and related transactional communications, and the public PAV Assistant.
Privacy questions and requests may be directed to sales@payneagenticventures.com.
2. Information the platform may process
- Contact information, location, communication preference, age-category confirmation, referral source, initial entrepreneurship interest, originating public page, and optional service interest.
- Application answers, business or idea details, goals, readiness information, confirmations, electronic signatures, and submission history.
- Interactive interview responses, follow-up answers, applicant-confirmed summaries, and optional supporting materials.
- Uploaded-file metadata and content when uploads are separately enabled after private storage and malware scanning are verified.
- Authentication, invitation, session, rate-limit, delivery-status, security, and immutable audit records.
- Administrator notes, evidence-based human reviews, assessments, interview records, action-test evidence, verification status, and human-controlled decisions.
- Technical records needed to secure and operate the service, such as privacy-preserving IP hashes, timestamps, error categories, and provider-delivery metadata.
- Anonymous first-party website-traffic records used to estimate unique and returning visitors without storing page histories or linking the records to applicant or customer profiles.
PAV is designed not to request exact sensitive financial disclosure, protected characteristics, or information that is unnecessary to the approved workflow.
PAV may use a random first-party browser identifier for up to 30 days to estimate anonymous unique and returning website visitors. The server stores only a keyed hash and one daily observation, does not use it for advertising, and deletes traffic observations after 13 months.
3. Why information may be used
Information may be used to operate and secure the platform; respond to an initial inquiry; determine the applicable PAV pathway; administer an invited application; provide save-and-return access; manage deadlines, reminders, and files; support human review; conduct approved interviews and assessments; communicate applicant-safe next steps; maintain audit and legal-hold records; and comply with applicable law.
PAV processes information for the purposes described in this policy and provides notices, consent choices, or opt-out options when required by applicable law.
4. Optional updates and marketing permission
The brief introduction form offers a separate, optional, unchecked choice to receive occasional PAV updates, business resources, and information. Agreeing to inquiry follow-up does not enroll a person in marketing, and declining this optional choice does not affect review of the inquiry. PAV does not use this permission for automatic bulk email.
A person may withdraw optional marketing permission by contacting PAV. PAV then stops marketing contact, removes the retained contact value, and keeps only the minimum consent evidence and a privacy-preserving hashed suppression record needed to honor the withdrawal and maintain an audit trail.
5. Artificial-intelligence processing
PAV Assistant answers general questions from approved public website information. Its chat history remains in the visitor's current browser session and PAV does not save message transcripts in its database. The messages needed to answer a question are transmitted to OpenAI using server-side requests configured with store: false. Short-lived functional session cookies, privacy-preserving request limits, and non-content error records may be used to secure and operate the feature.
PAV Assistant cannot access applications, customer accounts, project status, private records, or administrator systems. Visitors should not provide sensitive information, credentials, financial records, health information, confidential documents, or private customer data in chat.
When separately enabled, PAV may use interactive AI-assisted interview tools and internal AI-assisted evidence organization. AI output is advisory. Authorized people control advancement, hold, decline, paid-engagement, release, and other consequential decisions.
An internal estimate of possible AI assistance in an applicant response may be generated to identify evidence-linked clarification questions. That estimate remains private to authorized administrators, is not disclosed to applicants, and cannot automatically alter readiness, routing, acceptance, decline, integrity, or PAV-fit outcomes. PAV does not request or store hidden model chain-of-thought.
Additional details appear in the AI-Processing Disclosure. External AI processing is used only when the relevant feature is enabled and provider, privacy, and security controls are in place.
6. Service providers and disclosures
PAV currently uses Railway for application hosting and PostgreSQL. PAV may also use Railway private object storage, a ClamAV-compatible malware scanner, Google Workspace for transactional email, Cloudflare Turnstile for abuse prevention, Sentry for minimized error monitoring, and OpenAI for approved AI-assisted processing. Provider access must be limited to the service being performed and governed by applicable terms and data-handling controls.
PAV does not sell applicant information. PAV may disclose information to authorized personnel, approved processors, professional advisers, or authorities when required by law or necessary to protect rights, safety, and service integrity.
7. Retention, deletion, export, and legal holds
PAV generally retains records for declined, withdrawn, or inactive applicants for up to 24 months, subject to applicable law and operational controls. Accepted-client records, provider-specific logs, backups, and legally required records may require different schedules. Automatic deletion remains disabled until the approved retention schedule and restoration behavior are verified.
Verified requests for access, correction, export, or deletion may be submitted to the contact address above. PAV may retain limited records where required for security, fraud prevention, legal claims, legal holds, or compliance. PAV may verify identity before completing a request and will respond within the timeframe required by applicable law.
When an approved deletion request is completed, operational applicant and inquiry data is erased or de-identified under the documented process. Any active optional marketing permission is also withdrawn; the contact value is removed, while minimum consent evidence and a hashed suppression record may remain so PAV does not resume contact.
For Website Development review requests, PAV’s approved schedule is to retain unconverted or declined records for 12 months after the last substantive client or PAV contact about the request. If the request becomes an accepted client project, project records are retained for 3 years after the recorded project closure or termination date, subject to any longer accounting, contract, legal-hold, dispute, or counsel-approved requirement. Backups containing those records are retained for 90 days under the approved rotation, subject to legal holds.
A verified deletion request is handled sooner where legally permitted. PAV removes or de-identifies the Website Development contact and project review information in scope and retains only the minimum audit evidence needed to record verification, the decision, completion, an applicable exception or hold, and the authorized actor. This Website Development schedule is an owner-approved business policy effective August 5, 2026. On August 6, 2026, the owner approved this Website Intake launch under the documented owner-approval release path. PAV will not enable public Website Intake collection until the related operational, accessibility, security, backup, and restoration controls are verified.
8. Minors
A person under 18 may submit only the brief introduction. Invitations, full applications, uploads, assessments, interviews, action tests, and later applicant workflows remain blocked until a minor-specific process is adopted. PAV does not intentionally use later workflows to collect information from minors.
9. Security and limitations
The platform uses access controls, hashed tokens, encrypted TOTP material, private networking, private storage, audit history, rate limits, content validation, and fail-closed feature gates. No security method can guarantee absolute protection. Applicants should not submit unnecessary sensitive information, credentials, or data they are not authorized to provide.
10. Electronic signatures and records
When final submission is enabled, PAV records the applicant’s typed electronic signature, required confirmation versions, and a server-generated timestamp in an immutable submission snapshot. The applicable confirmation language and a copy of the submitted record are provided as part of the submission process.
11. Changes and effective date
PAV may update this policy as its services or legal obligations change. Material changes will be versioned, and PAV will provide any notice required by applicable law. This policy was last updated August 8, 2026.
