Privacy Policy

We believe your privacy is a fundamental right. This policy explains exactly what data COVIS AI collects, why we collect it, and how you remain in control at all times.

Version 1.0Effective March 30, 2026GDPR CompliantPCI-DSS Compliant

Who We Are

COVIS AI ("we", "us", "our") operates the COVIS AI tenant portal — an AI-powered multi-tenant SaaS platform designed to streamline business operations through intelligent agents, proposal generation, client management, and workforce collaboration tools. We are the data controller responsible for your personal data.

Contact TypeEmail
Privacy Requests & GDPRprivacy@covis.ai
General Supportsupport@covis.ai
Security Vulnerabilitiessecurity@covis.ai
Legal Inquirieslegal@covis.ai
2

Scope

This Privacy Policy applies to:

  • All users of the COVIS AI platform (Super Admins, Company Admins, Professionals, Clients)
  • Visitors to our web portal and landing pages
  • Anyone who contacts us for support, partnership, or business inquiries
This policy does not apply to third-party services linked or integrated with our platform. Please review those services' privacy policies separately.

Data We Collect

3.1 Account & Identity Data

DataPurpose
Full nameAccount identification, personalization
Email addressAuthentication, notifications, support
Company / organization nameTenant workspace identification
Job title / roleAccess control, feature gating, personalization
Profile photo (optional)UI personalization
Password (hashed — never plain text)Authentication
Years of experienceProfessional profile enrichment

3.2 Billing & Payment Data

DataPurpose
Subscription plan & tierService delivery, feature access
Invoice & transaction historyBilling records, tax compliance
Payment method (tokenized via Stripe)Payment processing — raw card numbers never stored
Billing addressTax calculation, invoicing
Order IDs from payment providerPayment confirmation and reconciliation

3.3 Usage & Activity Data

DataPurpose
Token consumption (count, type, timestamp)Billing, quota management, overage tracking
AI agent type and configuration usedAnalytics, billing, service optimization
Feature usage patternsProduct improvement, UX optimization
Login timestamps and session frequencySecurity, fraud detection
Call log metadata (duration, timestamp, participants)Business records, analytics
LinkedIn profile interaction dataLead sourcing analytics, professional matching
Support ticket activityCustomer success, platform improvement

3.4 Content Data

DataPurpose
Chat inputs and AI promptsAI response generation
AI-generated outputs (proposals, messages)Service delivery, history
Uploaded files and documentsAI processing, knowledge base
Custom AI agent configurationsService personalization
Knowledge base entriesCompany-specific AI training and retrieval
LinkedIn profile importsProfessional lead management
Important: Chat inputs, prompts, and uploaded files are transmitted to third-party AI providers to generate responses. See Section 7 for full details.

3.5 Technical & Device Data

DataPurpose
IP addressSecurity, fraud prevention, geolocation
Browser type and versionCompatibility, debugging
Operating systemCompatibility
Error logs and crash reportsDebugging, service quality
Referring URLsAnalytics
4

How We Collect Data

  • Directly from you — when you register, configure your workspace, send messages, upload files, or contact support
  • Automatically — via server logs, session tracking, and usage metrics as you use the platform
  • From your organization — when a Company Admin or Super Admin creates your account and invites you to a workspace
  • From payment processors — transaction confirmations and billing events from our payment provider
  • From LinkedIn — when you import profile data using our LinkedIn integration

How We Use Your Data

  • Deliver the Service: Process AI requests, store your history, manage your workspace, enable AI agents
  • Billing: Calculate token and resource usage, generate invoices, process payments
  • Security: Detect fraud, unauthorized access, and abuse patterns
  • Support: Respond to your tickets, resolve technical issues
  • Communications: Send transactional emails (invoices, alerts, security notices, service updates)
  • Compliance: Meet our legal and regulatory obligations
  • Product improvement: Analyze aggregated, anonymized usage patterns to improve features
What we do NOT do: We do not sell your data to third parties. We do not use your Input Data or AI outputs to train AI models without your explicit written consent. We do not serve advertising based on your data.

Data Sharing & Third Parties

We share data only when necessary to provide the Service:

7.1 AI Model Providers

Your chat inputs, prompts, and uploaded file contents are transmitted to AI model providers to generate responses. These providers act as data processors under our instructions.

ProviderData SharedPurpose
Anthropic (Claude)Chat inputs, promptsAI response generation
OpenAI (GPT)Chat inputs, promptsAI response generation
Additional providers (listed in-app)Chat inputs as applicableSpecialized AI capabilities

7.2 Payment Processors

ProviderData SharedPurpose
StripeBilling details, transaction dataPayment processing — raw card data never stored by COVIS AI

7.3 Cloud Infrastructure & Communications

We use cloud infrastructure providers for hosting, storage, and compute, and transactional email providers for system notifications. All providers are contractually bound under Data Processing Agreements (DPAs).

7.4 Legal Disclosures

We may disclose your data if required by law, court order, or governmental authority. Where legally permitted, we will notify you before complying.

8

AI Data Processing — Special Notice

When you use COVIS AI, your input (message, prompt, uploaded file, or agent configuration) is processed by third-party AI model providers. COVIS AI does not control what providers do with data once transmitted — please review their privacy policies.
  • Your input is sent from our servers to the selected AI model provider
  • The AI provider processes your input and returns a response
  • Both the input and response are stored in your workspace history (subject to your retention settings)
  • Custom AI agent configurations are stored on COVIS AI servers and shared with AI providers only at the time of a request
Recommendation: Do not include highly sensitive personal data (national ID numbers, financial account credentials, medical records) in AI prompts or uploaded files unless strictly necessary for your business purpose.

International Data Transfers

COVIS AI may transfer your data to countries outside your home jurisdiction. We safeguard all international transfers through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data Processing Agreements (DPAs) with all sub-processors
  • Adequacy decisions where applicable

To request a copy of the safeguards in place, contact privacy@covis.ai.

10

Cookies & Tracking

Cookie TypePurposeCan Opt Out?
EssentialSession management, authentication, securityNo — required for the Service
FunctionalLanguage preference, theme, UI settingsYes
AnalyticsAggregated usage patterns, feature adoptionYes
We do not use advertising cookies, retargeting cookies, or third-party social media tracking pixels.

Your Privacy Rights

RightDescriptionHow to Exercise
AccessReceive a copy of all personal data we holdAccount Settings → Privacy → Request My Data
RectificationCorrect inaccurate or incomplete dataAccount Settings → Profile
ErasureRequest deletion of your personal dataAccount Settings → Privacy → Delete Account
PortabilityExport your data in machine-readable formatAccount Settings → Privacy → Export My Data
RestrictionPause processing in certain circumstancesEmail privacy@covis.ai
ObjectionObject to processing based on legitimate interestsEmail privacy@covis.ai
Withdraw ConsentWithdraw where processing is consent-basedEmail privacy@covis.ai

Response time: We respond to all requests within 30 days. Complex requests may be extended to 60 days with notice. Identity verification may be required before processing.

Data Security

Encryption in Transit

TLS 1.2+ for all browser-server communication

Encryption at Rest

AES-256 encryption for all stored data

Access Controls

Role-based access control (RBAC) — need-to-know basis

Multi-Factor Authentication

MFA available for all accounts

Audit Logging

All sensitive data access is logged and monitored

Security Audits

Regular third-party penetration testing

Data Breach Notification: In the event of a breach affecting your data, we will notify affected users within 48 hours and the relevant supervisory authority within 72 hours as required by GDPR. Report security vulnerabilities to security@covis.ai.

Children's Privacy

The COVIS AI Service is not directed at or intended for individuals under the age of 18. We do not knowingly collect personal data from minors. If we discover that we have collected data from a minor without verifiable parental consent, we will delete it immediately.

If you believe a minor has provided us with personal data, contact privacy@covis.ai immediately.

14

Data Retention

Data is retained according to our Data Retention Policy. Key periods:

Data TypeRetention Period
Account & identity dataDuration of account + 30 days
Chat history & AI outputs12 months (configurable by Admin)
Call logs12 months
LinkedIn profile dataAccount active + 30 days
Token usage logs12 months
Billing & invoice records7 years (legal requirement — cannot be shortened)
Audit logs24 months, then anonymized
Technical / error logs90 days

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Notify you via email to your registered address
  • Display an in-app notification banner requiring acknowledgement
  • Update the "Last Updated" date at the top of this document

Previous versions are archived and available on request at privacy@covis.ai.

Contact Us

Response time: within 30 days · GDPR requests: within 30 days, may extend to 60 days with notice