invr
How it worksFor cyberFor corporationsPress roomFAQ
Get the app
Menu
How it worksFor cyberFor corporationsPress roomFAQGet the app

Legal

Privacy Notice

How invr protects privacy in its decentralised capability and invitation network.

Effective date: 2026-08-30

invr is built on a simple principle: people are never inventory. You decide what you disclose, when you disclose it, and whether an introduction should continue.

This notice explains how SilverAspen, the U.S.-based operator of invr ("invr", "we", "us"), handles information when you use the invr website, application, invitation service, and related network services. invr is designed for a global network. We apply this notice worldwide and comply with privacy laws that apply to a particular person or processing activity, which may include U.S. state privacy laws, the EU General Data Protection Regulation ("EU GDPR"), the UK GDPR, and other national frameworks.

1. Privacy by architecture

invr is a decentralised, privacy-preserving opportunity network. It is not a public directory and does not expose a searchable database of people.

  • Organisations and people express capabilities, needs, missions, grants, mentoring, circles, ventures, or other opportunities.
  • Capability matching is performed without making your identity publicly searchable.
  • We contact your peerwise decentralised identifier ("peerwise DID") when a relevant match exists.
  • An out-of-band introduction allows you and the other participant to decide whether to connect.
  • You decide what additional information, if any, to disclose to that participant.

How SilverAspen verification services stay separate

SilverAspen offers multiple services that can help you verify identity or professional capabilities. Those services operate as separate service entities and separate data contexts. They do not share identity, credential, account, or activity data with invr or with one another.

The person—not SilverAspen—is the bridge between the services:

  1. You may choose a SilverAspen service to verify an identity or capability claim.
  2. That service returns a proof or credential to you. The underlying verification data stays within that service and is not sent to invr.
  3. The invr invitation service does not query the verification service for your identity and does not receive its account records.
  4. If an invitation becomes relevant, you decide whether to present a proof and exactly what it should reveal.
  5. You may share that proof directly with a connection, such as a potential employer, mentor, coach, peer circle, team, or venture.

Verification does not create automatic disclosure. A SilverAspen service can help you prove something, but only you decide whether that proof moves into a relationship.

2. Information we are designed to process

For the invitation service, we are designed to process only the minimum information needed to establish capability and deliver a match:

  • your peerwise DID and the technical routing information needed to send an invitation;
  • redacted proof of professional capabilities, credentials, or claims;
  • capability, interest, and opportunity preferences you choose to express;
  • match and invitation state, such as whether an invitation was delivered, declined, or accepted; and
  • limited security and operational records required to protect the network and diagnose failures.

We do not ask you to provide conventional direct identifiers such as your legal name, home address, personal email address, telephone number, government identifier, photograph, date of birth, or an unredacted credential as part of capability matching. You should remove those details before disclosing a professional credential to invr.

A DID, redacted credential, or capability combination may still be treated as personal data when it can be linked to you. We therefore protect it as personal data even when it does not contain conventional personally identifiable information ("PII").

If you contact support, press, or partnership teams by email, we will receive the contact details and message you choose to provide. Those communications are handled separately from your private matching profile.

3. How we use information

We use the information described above to:

  • verify or evaluate disclosed capability evidence;
  • determine whether relevant capability and opportunity matches exist;
  • deliver private invitations to your peerwise DID;
  • facilitate an out-of-band introduction when you choose to engage;
  • maintain network integrity, prevent abuse, and investigate security incidents;
  • respond to requests you send us; and
  • meet legal obligations that apply to the service.

Depending on the activity and applicable law, processing is based on performing the service you request, your consent, our legitimate interests in operating a safe and reliable network, or a legal obligation. You may withdraw consent at any time. Withdrawal does not affect processing that was lawful before withdrawal.

4. Capability proofs and selective disclosure

We ask for proof of capability, not proof of civil identity. Where a professional credential contains direct identifiers or unrelated information, disclose only a redacted or selectively disclosed proof that demonstrates the relevant capability.

Do not send us an original credential containing names, addresses, identification numbers, photographs, signatures, dates of birth, or other unrelated identifying information. If we receive unnecessary direct identifiers, we will take reasonable steps to remove or delete them.

5. Matches and introductions

Before you accept an introduction, a prospective participant should receive only the capability signal necessary to understand that a relevant match may exist. They should not automatically receive your identity or a complete credential.

After an introduction, you control what you share with the organisation or person seeking your capabilities, or with someone offering support such as mentoring, a peer circle, a grant, a team, or a venture. Information you share directly with another participant is governed by your relationship with that participant and their privacy practices. invr cannot delete information from a recipient's systems or device after you have chosen to share it with them.

6. When information is shared

We may make limited information available to:

  • a matched participant, only as needed to present a private capability match or after you choose to engage;
  • infrastructure and security providers acting under instructions and confidentiality obligations;
  • professional advisers where necessary to protect the network or establish legal rights; and
  • authorities where disclosure is required by applicable law.

We do not sell personal data. We do not provide organisations with a browsable list of members. We do not permit people to search for or target you by employer, identity, or public profile.

Other SilverAspen services are not recipients of invr data. invr does not receive their identity, credential, account, or activity data. If you choose to use a proof created by another service, you present the proof yourself under your own disclosure settings.

7. Disconnecting and deletion

You can disconnect from the invitation service at any time. When you disconnect, we will stop using your peerwise DID for new matches and delete the information about you that remains under our control without undue delay.

Deletion applies to your peerwise DID routing record, capability proof records held by the service, preferences, and invitation state. Residual encrypted backup copies may remain until they expire through normal backup rotation; they are isolated from ordinary use, and deletion will be reapplied if a backup is restored.

We may retain only information that we are legally required to keep or the minimum security record necessary to establish, exercise, or defend legal claims. Any such information is restricted from matching and deleted when the reason for retention ends.

Disconnecting cannot erase information that you previously chose to disclose directly to another network participant. You must address deletion requests for that information to the recipient.

8. Your privacy rights

Subject to applicable law, you may have the right to:

  • be informed about processing;
  • access information associated with you;
  • correct inaccurate information;
  • request deletion or restriction;
  • object to particular processing;
  • receive portable information where applicable;
  • withdraw consent; and
  • raise a concern with a data protection authority.

Because invr avoids conventional identity records, we may need you to prove control of the relevant peerwise DID before acting on a request. We will not require additional identity information unless it is reasonably necessary to prevent unauthorised access or deletion.

To exercise a right, contact privacy@invr.ai. We will not discriminate against you for exercising a privacy right. You may authorise an agent where local law permits. We may ask you or the agent for information reasonably necessary to verify authority and control of the relevant peerwise DID.

EEA and UK

Where the EU GDPR or UK GDPR applies, you may also complain to the data protection authority where you live or work or where you believe an infringement occurred. This may include an EEA supervisory authority or the UK Information Commissioner's Office.

California

Where the California Consumer Privacy Act ("CCPA") applies, California residents may request to know, access, correct, or delete covered personal information and may exercise rights concerning sale, sharing, or sensitive personal information. invr does not sell personal information or share it for cross-context behavioural advertising, and does not use or disclose sensitive personal information for purposes that require a right to limit under the CCPA.

The categories we are designed to collect may include identifiers (a peerwise DID and technical routing identifiers), professional or employment-related information (redacted capability evidence), internet or network activity (security and delivery events), and inferences (potential capability matches). Sources are you, your device, proofs you choose to present, public verification material required to validate those proofs, and network interactions. We use these categories for the purposes in Section 3 and may disclose them to the categories of recipients in Section 6. We do not sell or share these categories for targeted advertising.

California residents may use an authorised agent. We may require proof of the agent's authority and may ask you to confirm the request through control of your peerwise DID. We honour legally recognised browser opt-out preference signals where they apply, although the website does not currently sell or share data for targeted advertising.

Other U.S. states and countries

Residents of other jurisdictions may have similar rights, including rights to confirm processing, access, correct, delete, obtain a portable copy, or opt out of targeted advertising, sale, or certain profiling. We will honour rights that apply to the relevant person and processing activity.

9. Security

We use technical and organisational safeguards intended to minimise collection, separate contexts, protect routing data, and prevent unauthorised disclosure. No network or storage system is guaranteed to be completely secure. Protect the keys and devices that control your DID, and notify us promptly if you believe they have been compromised.

10. International processing

invr is operated from the United States, and network infrastructure and participants may be located in different countries. Information may therefore be processed in the United States or another country whose privacy laws differ from those where you live.

Where a restricted transfer is made under our control, we use a lawful transfer mechanism as required, such as an adequacy decision, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, together with required transfer assessments and supplementary safeguards. Information you independently disclose to another participant may be processed wherever that participant operates.

11. Children

invr is a professional opportunity network and is not directed to children. You must have legal capacity to use the service. Do not submit information about a child through the invitation service.

12. Cookies and website data

The public website does not currently use advertising or analytics cookies. Essential delivery and security information may be processed by our hosting infrastructure. See our Cookie Policy for details.

13. Changes to this notice

We may update this notice as the network or applicable law changes. The effective date appears above, and material changes will be communicated through an appropriate network or website notice. Policy revisions are retained in our version history.

14. Contact

Privacy questions and requests can be sent to privacy@invr.ai.

invr is powered by SilverAspen.

invr

Opportunities will find you.

ProductHow it worksFor cyber
CompanyFor corporationsPress roomFAQ
LegalContactPrivacyTermsCookies
Built on the SilverAspen Network.© 2026 invr