Privacy Policy

Last updated: July 2026

1. Introduction

Cevoriq LLC ("Company", "we", "us") operates the Cevoriq™ platform. This Privacy Policy explains how we collect, use, store, and protect your information when you use our Service.

2. Information We Collect

2.1 Account Information

When you create an account, we collect your name, email address, and organization details. Authentication is handled through Clerk, our identity provider.

2.2 Platform Data

Data you enter into the platform — contracts, assets, incidents, shipping records, catalog items — is stored securely and associated with your organization (tenant).

2.3 Usage Data

Our hosting provider (Vercel) collects standard server request logs (timestamps, IP addresses, request paths) for reliability, performance, and security purposes. We do not currently use third-party web analytics or cross-site tracking tools.

2.4 Audit Logs

We maintain audit logs of actions taken within the platform (create, update, delete operations) for security and compliance purposes.

2.5 AI Processing Data

If your organization configures an AI provider in Settings (OpenAI, Google Gemini, or Azure OpenAI), summary asset and device data is sent to that provider — using your organization's own API key — to generate refresh recommendations and insights. This processing is governed by the selected provider's own terms and privacy policy in addition to this one. AI processing is enabled by default for new organizations and can be disabled at any time in Settings > Compliance. Without a configured provider, the platform falls back to a built-in rule engine that does not send data to any third party.

3. How We Use Your Information

  • To provide and maintain the Service
  • To authenticate users and manage access
  • To send service-related notifications (contract expiry, SLA alerts)
  • To improve the Service and develop new features
  • To respond to support requests
  • To comply with legal obligations

4. Data Storage and Security

Your data is stored in PostgreSQL databases hosted on secure cloud infrastructure. We employ:

  • Encryption in transit (TLS/SSL)
  • Encryption at rest for database storage
  • Logical tenant isolation — each organization's data is segregated
  • Role-based access control (RBAC) within the platform
  • Regular security reviews and updates

5. Data Sharing

We do not sell your data. We may share data only with:

  • Service providers — Infrastructure, authentication, and email-delivery partners (Vercel, Supabase, Clerk, Resend) necessary to operate the Service
  • AI providers — Only when your organization configures an AI provider (OpenAI, Google Gemini, or Azure OpenAI), and only the asset/device summary data needed to generate recommendations — see Section 2.5
  • Third-party integrations — Only when you explicitly configure integrations (e.g., ServiceNow, Jira), and only the data necessary for that integration
  • Legal requirements — If required by law, court order, or governmental authority

6. Data Retention

We retain your data for as long as your account is active, according to your organization's configured retention policy. The default is 7 years (2,555 days) for general platform data and 10 years (3,650 days) for audit logs; organization Owners and Admins can adjust both periods for their organization in Settings > Compliance. After account termination, data is retained per this policy before deletion, unless you submit an earlier deletion request as described in Section 7.

7. Your Rights

You have the right to:

  • Access your data through the platform or by requesting an export
  • Correct inaccurate data
  • Request deletion of your account and associated data by contacting privacy@cevoriq.com
  • Export your data in CSV format
  • Object to processing of your data for specific purposes

8. Cookies

We use essential cookies for authentication and session management only. We do not currently use tracking or advertising cookies. You can control cookie preferences through your browser settings.

9. International Data Transfers

Your data may be processed in data centers located in the United States, European Union, or Asia Pacific, depending on the data region your organization selects in Settings > Compliance (currently: US East, US West, EU West, EU Central, Asia Pacific Singapore, or Asia Pacific Tokyo). We ensure appropriate safeguards are in place for international transfers.

10. GDPR & Data Processing Agreements

Organizations with EU data subjects can enable GDPR mode in Settings > Compliance, which lets you record a Data Controller and Data Protection Officer contact for your organization. If your organization requires a signed Data Processing Agreement, contact legal@cevoriq.com.

11. Children's Privacy

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification. The "Last updated" date at the top indicates when the policy was last revised.

13. Contact Us

For privacy-related questions or requests, contact us at privacy@cevoriq.com.