Legal

Data Processing Agreement

Effective date: June 15, 2026 · Last updated: June 21, 2026

1. Overview

This Data Processing Agreement (“DPA”) describes how Coravi collects, processes, stores, and protects data submitted by customers through the service. It is intended to satisfy vendor security review requirements for quality management systems operating under ISO 9001, ISO 13485, IATF 16949, AS9100D, and similar frameworks.

2. What data is collected

  • Investigation notes and report inputs: text describing the nonconformance, root cause, containment, and corrective actions.
  • Generated report content: the AI-drafted quality document produced from your inputs.
  • Account and organisation metadata: email address, organisation name, plan tier, report type, status transitions, and audit log entries.
  • Document uploads (Starter and above): investigation documents processed in memory; not persisted separately.

We do not collect payment card data (handled by Stripe), biometric data, or data from individuals under 18.

3. How data is processed

AI generation: Cloudflare Workers AI. Report generation runs on Cloudflare Workers AI using the Llama 3.3 70B model. Your inputs are sent to Cloudflare Workers AI for inference and are not sent to OpenAI, Anthropic, Google, or any other third-party AI provider.

No training on your data. Your submitted data does not train any shared AI model. House-style AI features use your organisation's approved report history for your organisation only.

Storage: Cloudflare D1. All persistent data is stored in Cloudflare D1 within Cloudflare's global network.

4. Encryption

All report content is encrypted at rest using AES-256-GCM with a per-organisation derived key (HKDF-SHA-256 from a master key). Data in transit is encrypted via TLS 1.2+ enforced by Cloudflare.

5. Data retention

PlanRetentionNotes
Free30 daysDeleted 30 days after creation
Starter365 daysMeets ISO 9001 minimum
Pro / TeamUnlimitedSupports IATF 16949 (5yr) and AS9100D (7yr)

6. Sub-processors

ProcessorPurposeLocation
Cloudflare, Inc.Application runtime, database, AI inference, CDNGlobal (US-headquartered)
Stripe, Inc.Payment processingUS

7. Data subject rights

Submit requests to hello@coravi.ai. We respond within 30 days.

8. Security contact

Report vulnerabilities to hello@coravi.ai with subject line “Security.”

9. Changes

Material changes communicated by email at least 14 days before taking effect.