Entravia® — Privacy Policy
Effective Date: January 2, 2026
1. Introduction
Entravia ("Company," "we," "our," "us") respects your privacy and is committed to protecting it. This Privacy Policy explains how we collect, use, and share your information when you use our Services.
2. Information We Collect
We collect information you voluntarily provide, including:
- Company information (legal name, address, NAICS code, EIN, employee counts, payroll systems)
- Contact information (name, email, phone number)
- Sensitive data (payroll data, benefits information, claims history, regulatory status)
- Login and account credentials
We also collect certain technical information automatically (such as IP address, device type, and browser).
Cookies and Similar Technologies: When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email. We (or service providers on our behalf) may then send communications and marketing to these email. You may opt out of receiving this advertising by visiting https://app.retention.com/optout.
3. How We Use Your Information
We use your information to:
- Facilitate PEO matching and quoting services
- Communicate with you about your application
- Improve our platform and offerings
- Manage broker partnerships and control authorized access
- Offer optional premium services
4. How We Share Your Information
We may share your information with:
- Selected PEO providers for the purpose of generating quotes
- A broker if you voluntarily use their invitation link or enter their private access code
- Trusted service providers assisting with hosting, CRM, security, or communications
- Regulatory authorities when legally required
We do not sell your personal information.
5. Data Security
Our infrastructure is built to HIPAA and SOC 2 standards. Data is encrypted in transit (TLS) and at rest (AES-256), with role-scoped access, Postgres row-level isolation, and append-only audit logging. Independent HIPAA attestation and a SOC 2 Type II report are underway with an independent compliance partner. No system is 100% secure, and you acknowledge that you provide information at your own risk.
For our current security commitment and the list of controls live in production, please see our Security & Trust page, or visit our Trust Center for our control list, sub-processors, and available documentation.
6. Your Choices
You may request access, corrections, or deletion of your personal information by contacting us at info@entravia.co. You may opt out of marketing communications at any time.
7. Children's Privacy
Our Services are intended for users 18 years or older. We do not knowingly collect information from minors.
8. Changes to This Policy
We may update this Privacy Policy from time to time. Updates will be posted with a new effective date. Continued use of the Services after changes constitutes acceptance of the updated policy.
9. Contact
If you have any questions about this Privacy Policy, please contact us at info@entravia.co.