Effective Date: May 22, 2025
Last Updated: June 24, 2025
Taleva (“we,” “us,” or “our”) respects your privacy and is committed to protecting your Personal Data. This Privacy Policy explains:
Scope & Applicability
Definitions
Information We Collect
How We Use Your Information
Legal Bases for Processing
Third-Party Sharing & Disclosure
International Data Transfers
Cookies, Tracking & Analytics
Data Retention
Data Security
Your Rights
Children’s Privacy
Automated Decision-Making & Profiling
Changes to This Policy
Contact Information
Annex: Data Processing Addendum
This Privacy Policy applies to:
All visitors to our website at www.taleva.co
Users of our mobile app “Taleva” (Android & iOS)
Customers who place orders or create accounts
Anyone who communicates with us via email, chat, phone, or social media
It does not apply to other websites, apps or services that link to or from ours. Always check each site’s own policy before providing Personal Data elsewhere.
Personal Data / Personal Information: Any information relating to an identified or identifiable natural person.
Processing: Any operation performed on Personal Data (collection, use, storage, disclosure, deletion, analysis, or transfer).
Controller: Taleva, which determines how and why Personal Data is processed.
Processor: A third party acting on our instructions to process Personal Data.
Data Subject: You, the individual to whom the Personal Data belongs.
Consent: A freely given, specific, informed, and unambiguous indication of wishes authorizing the Processing of Personal Data.
Phone Number: Collected at checkout or registration to arrange and complete services. Used only to coordinate with our partners; not for marketing calls or SMS.
Email Address: Collected only if you create an account or request a password reset. Used solely to send a secure, one-time password-reset link. We do not send newsletters or promotional emails unless you opt in separately.
Support Communications: Any data you provide when contacting customer service (order ID, questions, feedback), stored to manage your request.
We do not collect device identifiers, usage logs, analytics data, location data, cookies, or tracking pixels. Our site and app are designed to avoid unnecessary tracking or profiling.
Service Fulfillment: Share your phone number and details with partners to deliver services and optionally send updates.
Account & Security: Use your email to send a one-time, time-limited password-reset link. Passwords are never stored in plain text; they are hashed and salted.
Legal Compliance & Dispute Resolution: Retain records to comply with tax, accounting, and audit requirements. Use support records to resolve disputes.
Internal Quality & Improvement: Aggregate anonymized data for demand forecasting and service improvements—no individual can be re-identified.
| Purpose | Legal Basis |
|---|---|
| Service fulfillment | Contractual necessity |
| Account recovery & security | Legitimate interest |
| Legal compliance & tax records | Legal obligation |
| Aggregated analysis | Legitimate interest |
Partners: Share phone number, address, and service details under confidentiality agreements.
Email Service Providers: Share email and reset tokens solely to send password-reset emails.
Legal Authorities: Disclose minimal data when required by law (e.g., court orders).
Aggregated/Anonymized Data: Share only fully anonymized statistics with partners for market research.
Your data may be processed or stored outside Jordan by our certified service providers. We use Standard Contractual Clauses, Data Processing Agreements, and encryption to ensure adequate safeguards.
We do not use cookies, analytics tools, or tracking pixels. Our website and app are free of third-party trackers.
Phone Number: Retained up to 12 months after last service for support and dispute resolution.
Email Address: Kept until account deletion or 30 days after password-reset activity.
Support Communications: Retained for 2 years for quality assurance and audit trails.
Aggregated Data: Retained indefinitely for business analytics.
HTTPS encryption (TLS 1.2+)
AES-256 encryption of data at rest
Role-based access control & multi-factor authentication
Firewall protections & regular vulnerability scans
Documented incident response plan
You have the right to:
Access: Request a copy of your Personal Data.
Correction: Ask us to update inaccurate information.
Deletion: Request erasure of your data, subject to legal constraints.
Restriction: Limit processing in certain scenarios.
Portability: Receive your data in machine-readable format.
Objection: Object to processing based on legitimate interests.
Withdraw Consent: For consent-based processing at any time.
To exercise these rights, email support@taleva.co. We will respond within 30 days.
Our services are not directed to children under 16. We do not knowingly collect data from minors. If we learn that we have collected data from a minor, we will promptly delete it.
We do not engage in automated decision-making or profiling that produces legal or similarly significant effects. All account decisions are reviewed by human personnel.
We may update this Privacy Policy from time to time. The “Effective Date” and “Last Updated” date will reflect the latest revision. We encourage you to review this page periodically.
Taleva
Amman, Jordan
Email: support@taleva.co
Website: www.taleva.co
This DPA governs the Processing of Personal Data by our Processors on behalf of Taleva:
Purpose: Outlines obligations of Processors handling Personal Data.
Scope: All sub-processors in delivery, email, hosting, and support.
Security Measures: Processors must implement comparable controls.
Sub-Processing: Requires our written authorization.
Data Subject Rights: Processors will assist in fulfilling requests.
Audit & Inspection: We reserve the right to audit compliance.
A standalone DPA is available upon request at support@taleva.co.