DRAFT — COUNSEL REVIEW REQUIRED

These documents were drafted from what Covio's own systems actually do. They have not been reviewed by a lawyer, they are not a contract, and no part of them should be relied on as legal advice or as Covio's final position. Open questions for counsel are listed at the end of each document.

Personal data

Privacy Policy

DRAFT — COUNSEL REVIEW REQUIRED

What personal data Covio holds, why, who else touches it, how long it is kept, and what you can ask for.

Drafted 21 September 2026

1 · Two different relationships

Almost all the personal data in Covio belongs to a customer company: its employees' names and work email addresses, who approved what, who opened which document. For that data the company decides what is collected and why, and Covio processes it on the company's instructions.

A small amount of data is Covio's own: the record of which Covio staff member opened a customer's screen, the ledger of what Covio did to a company's account, and the sign-in telemetry Covio keeps to defend the platform. Covio decides those for itself.

2 · What Covio holds about a person

WhatWhy it existsWhere it comes from
Name and email addressSo a person can sign in, be invited, and be named on the record of what they didThe invitation their company sent
Username, where one was givenAn alternative way to sign inTheir company
Password, stored only as an Argon2id hashTo verify a sign-in. The password itself is never stored and cannot be recoveredChosen by the person on the invitation screen
WhatsApp number, for owners and administratorsWhere the six-digit second-step sign-in code is sentGiven by the person when securing their account
WhatsApp number and consent record, where a person subscribed to summariesTo send the daily summaries they asked for, and to prove they askedGiven by the person, with the exact wording they agreed to stored alongside
Mobile number and plant note, where an administrator recorded themThe company's own roster detailsEntered by the company's administrator
Sign-in events: the identifier as typed, IP address, user agent, outcomeTo detect and slow down attacks on accountsGenerated by the act of signing in
Document access: who opened or downloaded which file, and whenSo a company can see who read its documentsGenerated by opening a file
Approval history: who submitted, who decided, what they wroteThe company's own compliance recordEntered by the company's people
Photographs of a machine's own control panel, where that feature is usedTo read production figures off the panel instead of typing themTaken by the company's supervisor

Covio does not ask for, and has no field for, a national identity number, a bank account, a payment card, a date of birth, a photograph of a person, or location tracking of a person.

3 · What Covio reads on a company's behalf

Where a company uses Covio Connect, Covio reads that company's TallyPrime books: vouchers, ledgers, bills, balances and stock. That reading can contain the names and contact details of the company's own customers and suppliers, because an accounting ledger does.

Covio holds a copy in order to show the company its own figures. The original books are untouched and remain the only system of record — Connect never writes to Tally.

4 · Why Covio holds it

  • To provide the service the company bought, which is the reason for nearly all of it.
  • To keep accounts secure: hashing passwords, requiring a second step for privileged accounts, rate-limiting sign-in, and keeping sign-in telemetry so an attack can be seen.
  • To keep an honest record of what happened: who approved a compliance item, who opened a document, what Covio itself did to a company's account, and which Covio staff member opened which screen.
  • To send what a person asked for: the second-step code, and the daily summaries they consented to.

Not settled / not in placeThis policy describes the purposes in plain words rather than naming a legal basis for each one. Which lawful basis applies to each purpose, under which law, is a question for counsel.

5 · Who else touches it

Covio uses a small number of third parties to run the service. They are listed in full, with what each one receives, in the data processing terms.

WhoWhat reaches them
HostingerHosts the single server everything runs on. All data is at rest on that machine
TwilioDelivers WhatsApp messages: sign-in codes, summaries, and report documents. Receives the destination number and the message content
ResendDelivers transactional email: invitations, password resets, operational alerts. Receives the destination address and the message content
AnthropicReads a photograph of a machine's control panel, where a company uses that feature and Covio's own reader cannot. Receives the photograph

Covio does not sell personal data, does not share it for advertising, and uses no analytics, advertising or session-recording service on its own pages.

6 · How long it is kept

While a company is a customer, its data is kept. When a company leaves, it is exported, held for a retention period and then purged — except for a named list of records that deliberately survive, such as the ledger recording that the purge itself happened.

Not settled / not in placeThree of Covio's six retention periods are not yet fixed, including the one that decides how long a departed company's data is held. Covio publishes that as an open question rather than publishing a number nobody has ratified.

7 · What a person can ask for

If you are an employee of a company that uses Covio, your employer controls your record. Ask your owner or administrator first: they can see and change your roster entry, your role and your access, and they can ask Covio for a full export of the company's data, which includes everything Covio holds about you as part of that company.

Covio will pass any request it receives directly from an individual to that person's company, and will help the company answer it. Write to hello@covio.in from the address you sign in with.

Not settled / not in placeCovio can produce a company's complete export today. It cannot today delete one person's data out of a live company while leaving the rest intact, and a purge of a whole departed company is currently refused by the software for the reason given in the retention statement. Both are stated as they are rather than as a right the product cannot yet honour.

8 · Security

The controls Covio actually operates — password hashing, the second sign-in step, rate limiting, transport encryption, authenticated-only document downloads, append-only ledgers, encrypted backups — are described in full, with no certification claimed, in the security summary.

9 · Contact

Questions about this policy: hello@covio.in. Please say which company you are writing about.

Not settled / not in placeCovio has not named a data protection officer or a grievance officer, and does not claim to have one. Whether either is required, and who it should be, is a question for counsel.

What counsel must rule on before this stops being a draft

Covio drafted this document from its own systems rather than from a template, so what follows are the points where engineering cannot decide and a lawyer must.

  1. 1Which privacy law or laws apply to Covio, and does this policy meet their notice requirements?
  2. 2Which lawful basis attaches to each purpose in section 4, and does any of it require consent rather than contract or legitimate interest?
  3. 3Does an erasure right reach sign-in telemetry, which holds email addresses and IP addresses from failed attempts that may not belong to the customer at all? Covio cannot choose between deleting the customer's rows and retaining all of it as security evidence on legal grounds.
  4. 4Must Covio appoint a data protection officer or a grievance officer, and must this page name them?
  5. 5Is transferring a photograph of a factory control panel, a WhatsApp number or an email address to a processor outside India permitted, and on what basis?
  6. 6Should Covio commit to a response time for an individual's request, and what should it be?