1. Overview
This Data Processing Agreement (“DPA”) describes how Coravi collects, processes, stores, and protects data submitted by customers through the service. It is intended to satisfy vendor security review requirements for quality management systems operating under ISO 9001, ISO 13485, IATF 16949, AS9100D, and similar frameworks.
2. What data is collected
- Investigation notes and report inputs: text describing the nonconformance, root cause, containment, and corrective actions.
- Generated report content: the AI-drafted quality document produced from your inputs.
- Account and organisation metadata: email address, organisation name, plan tier, report type, status transitions, and audit log entries.
- Document uploads (Starter and above): investigation documents processed in memory; not persisted separately.
We do not collect payment card data (handled by Stripe), biometric data, or data from individuals under 18.
3. How data is processed
AI generation: Cloudflare Workers AI. Report generation runs on Cloudflare Workers AI using the Llama 3.3 70B model. Your inputs are sent to Cloudflare Workers AI for inference and are not sent to OpenAI, Anthropic, Google, or any other third-party AI provider.
No training on your data. Your submitted data does not train any shared AI model. House-style AI features use your organisation's approved report history for your organisation only.
Storage: Cloudflare D1. All persistent data is stored in Cloudflare D1 within Cloudflare's global network.
4. Encryption
All report content is encrypted at rest using AES-256-GCM with a per-organisation derived key (HKDF-SHA-256 from a master key). Data in transit is encrypted via TLS 1.2+ enforced by Cloudflare.
5. Data retention
| Plan | Retention | Notes |
|---|---|---|
| Free | 30 days | Deleted 30 days after creation |
| Starter | 365 days | Meets ISO 9001 minimum |
| Pro / Team | Unlimited | Supports IATF 16949 (5yr) and AS9100D (7yr) |
6. Sub-processors
| Processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Application runtime, database, AI inference, CDN | Global (US-headquartered) |
| Stripe, Inc. | Payment processing | US |
7. Data subject rights
Submit requests to hello@coravi.ai. We respond within 30 days.
8. Security contact
Report vulnerabilities to hello@coravi.ai with subject line “Security.”
9. Changes
Material changes communicated by email at least 14 days before taking effect.