Privacy Policy
Last updated: September 2026
1. Introduction
Cevoriq LLC ("Company", "we", "us") operates the Cevoriq™ platform. This Privacy Policy explains how we collect, use, store, and protect your information when you use our Service.
2. Information We Collect
2.1 Account Information
When you create an account, we collect your name, email address, and organization details. Authentication is handled through Clerk, our identity provider.
2.2 Platform Data
Data you enter into the platform — contracts, assets, incidents, shipping records, catalog items — is stored in our database and associated with your organization (tenant). Files you upload — contract documents and purchase-order attachments — are stored in object storage provided by Cloudflare R2, separately from the database, and are readable only through the platform.
2.3 Usage Data
Our hosting provider (Vercel) collects standard server request logs (timestamps, IP addresses, request paths) for reliability, performance, and security purposes. We do not currently use third-party web analytics or cross-site tracking tools.
2.4 Audit Logs
We maintain audit logs of actions taken within the platform (create, update, delete operations) for security and compliance purposes.
2.5 AI Processing Data
Several features send data to a third-party AI provider to produce a result. What is sent depends on the feature, and for some it is more than a summary:
- Contract Intelligence — the full contents of a contract document you upload are sent to the provider to extract its terms and assess risk. This includes counterparty names, pricing, liability and payment terms.
- Device health and refresh recommendations — asset and device records (model, age, incident and repair history, warranty status).
- Reporting assistant — your question, and the query results needed to answer it, drawn from your organization's data.
Whose account the data goes through. By default, processing uses an AI provider account held by Cevoriq (Google Gemini first, with Anthropic and OpenAI as alternates), under Cevoriq's agreement with that provider. Your organization may instead configure its own provider and API key in Settings (Google Gemini, Anthropic, OpenAI, or Azure OpenAI); data is then sent to your account under your agreement with the provider, and Cevoriq's account is not used.
In either case the provider processes the data on its own infrastructure, which may be outside the United States and outside the region described in Section 9, and under its own terms and privacy policy in addition to this one. AI processing is enabled by default for new organizations and can be disabled at any time in Settings > Compliance; without a provider, the platform uses a built-in rule engine that sends nothing to any third party.
3. How We Use Your Information
- To provide and maintain the Service
- To authenticate users and manage access
- To send service-related notifications (contract expiry, SLA alerts)
- To improve the Service and develop new features
- To respond to support requests
- To comply with legal obligations
4. Data Storage and Security
Your records are stored in a PostgreSQL database; uploaded files are stored in object storage. We employ:
- Encryption in transit (TLS)
- Encryption at rest for the database and for object storage
- Database-enforced tenant isolation — row-level security policies on the tables themselves, so a query that omits its tenant returns nothing rather than everything
- Role-based access control within the platform
- An adversarial test suite against the tenant boundary that runs on every code change and blocks release if any query returns data it should not
Our Security & architecture page describes each of these mechanisms, and states what Cevoriq does not yet claim.
5. Data Sharing
We do not sell your data. The providers below process it on our behalf. For each we state what it receives and where it processes, because a residency statement that names the database but not every other provider is incomplete.
| Provider | Role | Customer data it receives | Processing location |
|---|---|---|---|
| Vercel | Application hosting | All data in transit through the application; request logs | US East (Virginia) |
| Supabase | Database (PostgreSQL) | All platform records | US East (Virginia) |
| Cloudflare R2 | Object storage | Uploaded files: contract documents, purchase-order attachments | United States (Cloudflare location hint: Eastern North America) |
| Clerk | Identity and sign-in | Name, email address, sign-in credentials and sessions | Clerk's infrastructure (United States); not bound by your region |
| Resend | Email delivery | The contents of notification emails: contract expiry notices, SLA alerts, dispatch offers to service partners, report share links, invitations | Resend's infrastructure; not bound by your region |
| Upstash QStash | Scheduled-job trigger | None. It calls the platform on a schedule; the request carries no customer data | Not applicable |
| AI providers | See Section 2.5 | Contract document contents, asset and device records, reporting queries — per feature, as described in Section 2.5 | The provider's infrastructure; may be outside the United States |
We may also share data:
- With third-party systems you connect — only when your organization configures an integration, and only the data that integration needs. Available connectors cover HR systems (Personio), IT service management (ServiceNow, Jira Service Management, Zoho Desk, Freshservice, Zendesk), digital-experience monitoring (Nexthink, ControlUp, Lakeside), shipping carriers (FedEx, UPS, DHL), device management (Microsoft Intune, Jamf), and OEM or distributor product feeds. Data flows to a connected system only after you supply its credentials.
- Legal requirements — If required by law, court order, or governmental authority
6. Data Retention
We retain your data for as long as your account is active. We do not currently operate automated, retention-schedule-based deletion: data is retained until you or your organization requests its deletion, or until your account is terminated and we delete it. Configurable, automatically enforced retention periods are on our roadmap, and we will update this policy before they take effect.
You can request deletion at any time as described in Section 7, and organization Owners and Admins can erase an individual data subject's personal data at any time from Settings > Compliance.
7. Your Rights
You have the right to:
- Access your data through the platform or by requesting an export
- Correct inaccurate data
- Request deletion of your account and associated data by contacting privacy@cevoriq.com
- Export your data in CSV format
- Object to processing of your data for specific purposes
8. Cookies
We use essential cookies for authentication and session management on the platform itself. We do not currently use tracking or advertising cookies. You can control cookie preferences through your browser settings.
9. International Data Transfers
Your platform records and uploaded files are stored in the United States (US East (Virginia)). We do not currently operate other regions, and a region preference recorded in Settings > Compliance does not move data until that region becomes available; we will update this policy before any does.
That statement covers storage, not every provider. Three categories of processing are not bound by it and are listed with their locations in Section 5: identity and sign-in (Clerk), email delivery (Resend), and AI processing (Section 2.5), where the provider may process data outside the United States. A security review that needs the full processing chain should read Section 5 together with this section.
Our Data Residency page sets out our region strategy, which categories of data are held in your region and which are held globally, and the status of each planned region. Roadmap items described there are not commitments — see section 8 of our Terms of Service.
If you are located outside the United States, using the Service therefore involves transferring your data to the United States. If your organization requires specific transfer safeguards or a Data Processing Agreement, contact legal@cevoriq.com.
10. GDPR & Data Processing Agreements
Organizations with EU data subjects can enable GDPR mode in Settings > Compliance, which lets you record a Data Controller and Data Protection Officer contact for your organization. If your organization requires a signed Data Processing Agreement, contact legal@cevoriq.com.
11. Children's Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification. The "Last updated" date at the top indicates when the policy was last revised.
13. Contact Us
For privacy-related questions or requests, contact us at privacy@cevoriq.com.