Insights · Privacy & security · · 1 min read
Shared infrastructure, separate data
Running several companies on shared foundations raises an obvious question: does the group combine what it knows about people across products? At Oryvelon the default answer is no.
Our default: no cross-product user graph
Each company keeps its own users, its own database and its own privacy boundary. A person who uses two Oryvelon products is, by default, two separate customers.
Boundaries by company
| Company | Data kept separate | Special rule |
|---|---|---|
| MerchNivo | Stores, orders, products, customers | Store-by-store tenant isolation |
| CastLyra | Talent profiles, briefs, messages | Explicit consent and business access rules |
| EduRelia | Student, parent, teacher and school data | School tenants, row-level security, child-data minimisation |
| ZodiVela | Profiles, readings, uploads | No cross-product profiling |
| KeşifAtlası | Assessments and application details | Minimised sensitive data, versioned rules |
| Noveniq | Commerce data | Independent production business |
Marketing consent is not product consent
Agreeing to use a product is not agreement to be marketed to by other companies in the group. The two are recorded and handled separately.
What every product plans for
- Minimum data collection
- Role-based access
- Auditability of critical actions
- A retention policy
- A way to export and delete data
Shared AI without shared data
Our AI gateway standardises model access, cost limits and monitoring. It does not merge prompts, knowledge bases or user profiles. Each product has its own AI project, keys, budget and logs.