Privacy Policy
Effective: August 5, 2026Last updated: August 5, 2026
Version: 1.0
Corveonic LLC operates this website and the Corveonic client portal. This policy explains what information we handle, why, who we share it with, how long we keep it, and how to reach us about it.
We have written it to be read. If something here is unclear, email support@corveonic.com and we will answer in plain language.
1. What we collect
If you visit this website.
- What you type into the contact form: your name, work email, company, and message, plus phone number, industry, and budget band if you choose to give them.
- Standard server logs generated by our host, including IP address, browser type, and the pages requested.
- Aggregate, cookie-free traffic measurement. We do not use tracking cookies, we do not build advertising profiles, and we do not run session-replay tooling that records your mouse movements, keystrokes, or screen.
- Anti-spam signals collected by our bot-protection provider when you submit the form.
If you are a client using the portal.
- Account information: names, business email addresses, roles, and authentication credentials (passwords are stored hashed, never in readable form).
- Billing contact details and a record of your plan, invoices, and payments.
- Your own business records that you put into, or connect to, the platform. Depending on what you have us build, that can include your customers' names, phone numbers, addresses and job history; message logs; and consent records.
Payment information. Payments are processed by Stripe. Card numbers, security codes, and bank credentials never enter Corveonic's systems. We see the last four digits, the card brand, and whether a charge succeeded.
Two different roles. For your business records inside the portal, we are a service provider acting on your instructions — the data is yours, we process it to run what you hired us to run, and we do not use it for our own purposes. For website visitors and our own prospect and client contact records, we decide how the information is used and are responsible for it directly.
2. Why we use it
- To answer enquiries and prepare proposals.
- To deliver the services in your agreement — building, running, monitoring and supporting the workflows, integrations, dashboards, messaging and voice systems in scope.
- To bill you and collect payment.
- To keep the platform secure: authentication, abuse and fraud prevention, error diagnosis, and audit logging.
- To meet legal, tax, and accounting obligations.
- To improve our own service using operational and performance metrics — how fast a workflow ran, whether a job failed, how much capacity a tenant used. We do not read, mine, or repurpose your business records or your customers' data for this.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
3. Who else handles it — our subprocessors
We use a small number of vendors to run the service. Each one only receives what it needs.
| Vendor | What it does | What it can see |
|---|---|---|
| Vercel | Hosts this website and the portal front end; cookie-free traffic measurement | Server logs, IP addresses, aggregate page requests |
| Supabase | Database, authentication and file storage for the client portal | Portal account data and client operational data |
| Stripe | Payment processing and subscription billing | Billing contact, payment method tokens, invoice and charge history |
| Resend | Delivers transactional email (contact-form notifications, account email) | Sender/recipient addresses and message contents |
| Cloudflare | Bot protection on the contact form | Anti-spam signals from the submitting browser |
| Twilio | Carries SMS and voice traffic | Phone numbers, message contents, call audio and metadata |
| Amazon Web Services | Cloud infrastructure and compute for the systems we run | Client operational data processed by those systems |
| Anthropic | Provides AI models used in the workflows we build | The text and data a workflow sends to the model |
| OpenAI | Provides AI models used in the workflows we build | The text and data a workflow sends to the model |
| NVIDIA | Provides AI model and compute services used in the workflows we build | The text and data a workflow sends to the model |
We keep this list current. If we add a subprocessor that handles client data, we will update this page.
4. How long we keep it
| What | How long |
|---|---|
| Contact-form submissions from people who don't become clients | 6 months |
| Client account and operational data | For the life of the engagement, then 30 days for export, then deleted |
| Call recordings and transcripts | 6 months |
| Message logs and consent records | 4 years |
| Invoices, tax and accounting records | As long as tax and corporate law require |
| Backups | 6 months, after which deleted copies age out |
5. How we protect it
We maintain administrative, technical and physical safeguards appropriate to the size of our business and the sensitivity of the data we hold. In practice that means:
- Access is limited to the people who need it, and separated per client — one client's data is not reachable from another client's account.
- Data is encrypted in transit and at rest.
- Multi-factor authentication is required on administrative accounts.
- Administrative and data access is logged.
- We review the security practices of the vendors listed in §3 before we use them, and we contract for confidentiality.
- Card data never enters our systems (see §1).
- We train ourselves on these practices and review them quarterly.
- Data is securely disposed of when it reaches the end of its retention period.
No system is perfectly secure, and we do not claim ours is.
7. If something goes wrong [+IA]
If we discover a breach of security affecting private information we hold, we will notify affected individuals and the required New York authorities within 30 days, and we will notify any affected client without undue delay and no later than 15 days so they can meet their own obligations.
8. Your choices and how to exercise them
You can ask us to show you the personal information we hold about you, correct it, or delete it. Email support@corveonic.com and we will respond within 7 days.
If your request concerns information held inside a client's portal account — for example, you are a customer of a business that uses Corveonic — we handle that data on that business's instructions. Send your request to them, or send it to us and we will pass it on and support them in answering it.
9. Children
This service is built for businesses and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have, contact us and we will delete it.
10. Data processing agreements [+IA]
If your organisation needs a data processing agreement, email support@corveonic.com and we will send our standard form.
12. Changes to this policy
We will post any change here and update the "Last updated" date. If a change materially affects how we handle client data, we will tell clients directly.
13. Contact
support@corveonic.com · (718) 513-8979 · 3130 43rd Street, Astoria, NY 11103
Corveonic LLC, a New York limited liability company.