1 · Roles
For the personal data a customer company puts into Covio, or that Covio reads on its behalf, the company is the controller and Covio is the processor. Covio processes that data only to provide the service, and only on the company's instructions — which, in practice, are the actions its own people take in the product and the configuration its administrators set.
For a narrow set of records Covio is a controller in its own right: the log of which Covio staff member opened which customer screen, the ledger of platform actions taken on an account, sign-in telemetry, and billing records. These exist as evidence about Covio's own conduct and Covio does not delete them on a customer's instruction.
2 · Subject matter, duration and categories
| Subject matter | Factory visibility: machines and production, documents, compliance activities and approvals, and a read-only copy of the customer's TallyPrime books where Covio Connect is used |
| Duration | For as long as the company is a customer, then the retention period after termination — which is not yet fixed (see the retention statement) |
| Categories of data subject | The customer's employees who use Covio; and, where Connect is used, the customer's own customers and suppliers as they appear in its accounting books |
| Categories of personal data | Names, work email addresses, usernames, hashed passwords, WhatsApp numbers, mobile numbers, roles and site assignments, sign-in events with IP address and user agent, document access records, approval history with free-text comments, and the contents of the customer's accounting ledgers |
| Special category data | None is asked for and no field exists for it. A customer could upload anything into a document or type anything into a comment, which is the customer's decision and not Covio's instruction |
3 · Sub-processors
This is the complete list of third parties that receive customer data. It is derived from the credentials the production system actually holds, not from a vendor wishlist.
| Sub-processor | Purpose | What it receives | When |
|---|---|---|---|
| Hostinger | Infrastructure. The single virtual private server on which every container, both databases and the media store run | All customer data, at rest and in process on that machine | Always |
| Twilio | WhatsApp delivery: second-step sign-in codes, daily and evening summaries, machine reports, and the one-time fetch of a report document | The destination WhatsApp number and the message content, including the figures in a summary | Whenever a message is sent |
| Resend | Transactional email: invitations, password resets, and operational alerts to Covio | The destination email address and the message content | Whenever an email is sent |
| Anthropic | Reading the six values off a photograph of a machine's HMI panel | The photograph itself | Only where a company uses photo capture, and only when Covio's own template reader has not already read the photo |
The photograph reading is the only sub-processor that is conditional. A company that does not use photo capture sends nothing to it. Where Covio's own template reader succeeds, the photograph does not leave the server.
Not settled / not in placeCovio has not yet agreed a data processing addendum with any of these providers, has not assessed where each of them processes data, and does not claim a transfer mechanism. Each provider's own terms apply until counsel rules otherwise.
Covio will give notice before adding or replacing a sub-processor. The notice period, and whether a customer may object, is one of the open questions below.
4 · Security measures
The technical and organisational measures Covio operates are listed in full in the security summary, and that list is the one that forms part of these terms. In summary: identity is taken only from a server-side session and never from the browser; every query is scoped to one company; passwords are hashed with Argon2id; privileged accounts carry a second sign-in step; authentication is rate-limited; traffic is encrypted in transit at an edge that is the only internet-exposed component; neither database is reachable from the internet; documents are never served raw and every read is ledgered; several ledgers are append-only and the database itself refuses to update or delete them; and backups are encrypted.
5 · Covio personnel
Covio staff access to a customer's screens runs under a recorded grant and every screen opened is written to an access log. Both records are included in the customer's export, so the customer can audit Covio rather than take its word.
Not settled / not in placeCovio is a two-person team and has no formal confidentiality agreement, background check policy or security training programme to point at. Stating that plainly is better than implying a personnel control that does not exist.
6 · Assistance to the controller
- Access and portability: a company can be given a complete export of its data at any time. Nineteen modules of the platform contribute to it, and anything Covio cannot include is named in the export's own manifest with the reason, rather than quietly left out.
- Correction: a company's administrators can correct roster data, roles, sites and panel access themselves.
- Deletion: Covio can delete a whole departing company through its offboarding process. It cannot today delete one individual out of a live company, and a production purge is currently refused by the software.
- Security incidents: Covio will notify the company as described below.
7 · Notification of a personal data breach
If Covio becomes aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to customer personal data, Covio will notify the affected company's owner and administrators without undue delay, and will tell them what is known: what happened, which data and roughly how many records are involved, what Covio is doing, and what the company should do.
Covio keeps a record of which companies were told about a platform incident and when, and that record deliberately survives the company's own purge, so the fact that a disclosure was made can always be produced.
Not settled / not in placeNo fixed notification deadline is stated here. Whether Covio must commit to a number of hours, to whom beyond the customer a notification is owed, and whether Covio itself must notify a regulator, are all questions for counsel.
8 · Return and deletion at the end
When the agreement ends, Covio produces the company's export before the account can be terminated — the lifecycle will not advance without one. The download link is authenticated and valid for 72 hours; a new link can be issued.
Covio then deletes the company's data, except for the records named in the retention statement as deliberately retained with a stated basis, and except for the period during which the data still exists in encrypted backups.
9 · Audit
Covio will answer a customer's reasonable written questions about these measures, and will produce the customer's own support-access log and platform-action ledger, which together show everything Covio did to that account.
Not settled / not in placeCovio holds no third-party audit report of any kind. It is not ISO 27001 certified, has no SOC 2 report, has had no penetration test, and has no external certification under any privacy law. A customer asking for one must be told there is none.
What counsel must rule on before this stops being a draft
Covio drafted this document from its own systems rather than from a template, so what follows are the points where engineering cannot decide and a lawyer must.
- 1Is the controller/processor split in section 1 correct, particularly for support-access logs and sign-in telemetry, which Covio treats as its own?
- 2What notice period applies to a new sub-processor, and may a customer object? If it objects, what is the remedy?
- 3Anthropic receives photographs of a customer's machine panel. Is that acceptable as a sub-processor arrangement, and does it need the customer's specific consent rather than general notice?
- 4What breach notification deadline should Covio commit to, and does Covio have an independent obligation to notify a regulator or affected individuals?
- 5Are these processing terms required to be a separate signed agreement, or may they be incorporated by reference into the terms of service?
- 6What audit right is a customer entitled to when Covio holds no third-party attestation?
- 7Must Covio have a written confidentiality undertaking from each person with production access before these terms can be signed?