Insights · Privacy & security · · 1 min read

Shared infrastructure, separate data

Running several companies on shared foundations raises an obvious question: does the group combine what it knows about people across products? At Oryvelon the default answer is no.

Our default: no cross-product user graph

Each company keeps its own users, its own database and its own privacy boundary. A person who uses two Oryvelon products is, by default, two separate customers.

Boundaries by company

CompanyData kept separateSpecial rule
MerchNivoStores, orders, products, customersStore-by-store tenant isolation
CastLyraTalent profiles, briefs, messagesExplicit consent and business access rules
EduReliaStudent, parent, teacher and school dataSchool tenants, row-level security, child-data minimisation
ZodiVelaProfiles, readings, uploadsNo cross-product profiling
KeşifAtlasıAssessments and application detailsMinimised sensitive data, versioned rules
NoveniqCommerce dataIndependent production business

Marketing consent is not product consent

Agreeing to use a product is not agreement to be marketed to by other companies in the group. The two are recorded and handled separately.

What every product plans for

  • Minimum data collection
  • Role-based access
  • Auditability of critical actions
  • A retention policy
  • A way to export and delete data

Shared AI without shared data

Our AI gateway standardises model access, cost limits and monitoring. It does not merge prompts, knowledge bases or user profiles. Each product has its own AI project, keys, budget and logs.