DRAFT — COUNSEL REVIEW REQUIRED

These documents were drafted from what Covio's own systems actually do. They have not been reviewed by a lawyer, they are not a contract, and no part of them should be relied on as legal advice or as Covio's final position. Open questions for counsel are listed at the end of each document.

Covio legal

Terms, privacy and data handling

DRAFT — COUNSEL REVIEW REQUIRED

Seven documents describing what Covio does with a company's data, written from what the system actually does rather than from a template. Every one of them is a draft.

Drafted 21 September 2026

What Covio does not claim

Covio holds no security or privacy certification of any kind: no ISO 27001, no SOC 2, no audit report, no certification under any privacy law, and no independent penetration test. These pages describe controls that exist in Covio's own code and configuration. They do not describe an attestation by anybody else, and a customer asking for one must be told there is none.

Where something is not settled — a retention period nobody has ratified, a backup destination that has not been built, a country of storage Covio cannot yet evidence — the document says so in place rather than leaving the reader to assume. Every one of those is marked DRAFT — COUNSEL REVIEW REQUIRED at the top of its page and listed as a question for counsel at the bottom.