1 · Two different relationships
Almost all the personal data in Covio belongs to a customer company: its employees' names and work email addresses, who approved what, who opened which document. For that data the company decides what is collected and why, and Covio processes it on the company's instructions.
A small amount of data is Covio's own: the record of which Covio staff member opened a customer's screen, the ledger of what Covio did to a company's account, and the sign-in telemetry Covio keeps to defend the platform. Covio decides those for itself.
2 · What Covio holds about a person
| What | Why it exists | Where it comes from |
|---|---|---|
| Name and email address | So a person can sign in, be invited, and be named on the record of what they did | The invitation their company sent |
| Username, where one was given | An alternative way to sign in | Their company |
| Password, stored only as an Argon2id hash | To verify a sign-in. The password itself is never stored and cannot be recovered | Chosen by the person on the invitation screen |
| WhatsApp number, for owners and administrators | Where the six-digit second-step sign-in code is sent | Given by the person when securing their account |
| WhatsApp number and consent record, where a person subscribed to summaries | To send the daily summaries they asked for, and to prove they asked | Given by the person, with the exact wording they agreed to stored alongside |
| Mobile number and plant note, where an administrator recorded them | The company's own roster details | Entered by the company's administrator |
| Sign-in events: the identifier as typed, IP address, user agent, outcome | To detect and slow down attacks on accounts | Generated by the act of signing in |
| Document access: who opened or downloaded which file, and when | So a company can see who read its documents | Generated by opening a file |
| Approval history: who submitted, who decided, what they wrote | The company's own compliance record | Entered by the company's people |
| Photographs of a machine's own control panel, where that feature is used | To read production figures off the panel instead of typing them | Taken by the company's supervisor |
Covio does not ask for, and has no field for, a national identity number, a bank account, a payment card, a date of birth, a photograph of a person, or location tracking of a person.
3 · What Covio reads on a company's behalf
Where a company uses Covio Connect, Covio reads that company's TallyPrime books: vouchers, ledgers, bills, balances and stock. That reading can contain the names and contact details of the company's own customers and suppliers, because an accounting ledger does.
Covio holds a copy in order to show the company its own figures. The original books are untouched and remain the only system of record — Connect never writes to Tally.
4 · Why Covio holds it
- To provide the service the company bought, which is the reason for nearly all of it.
- To keep accounts secure: hashing passwords, requiring a second step for privileged accounts, rate-limiting sign-in, and keeping sign-in telemetry so an attack can be seen.
- To keep an honest record of what happened: who approved a compliance item, who opened a document, what Covio itself did to a company's account, and which Covio staff member opened which screen.
- To send what a person asked for: the second-step code, and the daily summaries they consented to.
Not settled / not in placeThis policy describes the purposes in plain words rather than naming a legal basis for each one. Which lawful basis applies to each purpose, under which law, is a question for counsel.
5 · Who else touches it
Covio uses a small number of third parties to run the service. They are listed in full, with what each one receives, in the data processing terms.
| Who | What reaches them |
|---|---|
| Hostinger | Hosts the single server everything runs on. All data is at rest on that machine |
| Twilio | Delivers WhatsApp messages: sign-in codes, summaries, and report documents. Receives the destination number and the message content |
| Resend | Delivers transactional email: invitations, password resets, operational alerts. Receives the destination address and the message content |
| Anthropic | Reads a photograph of a machine's control panel, where a company uses that feature and Covio's own reader cannot. Receives the photograph |
Covio does not sell personal data, does not share it for advertising, and uses no analytics, advertising or session-recording service on its own pages.
6 · How long it is kept
While a company is a customer, its data is kept. When a company leaves, it is exported, held for a retention period and then purged — except for a named list of records that deliberately survive, such as the ledger recording that the purge itself happened.
Not settled / not in placeThree of Covio's six retention periods are not yet fixed, including the one that decides how long a departed company's data is held. Covio publishes that as an open question rather than publishing a number nobody has ratified.
7 · What a person can ask for
If you are an employee of a company that uses Covio, your employer controls your record. Ask your owner or administrator first: they can see and change your roster entry, your role and your access, and they can ask Covio for a full export of the company's data, which includes everything Covio holds about you as part of that company.
Covio will pass any request it receives directly from an individual to that person's company, and will help the company answer it. Write to hello@covio.in from the address you sign in with.
Not settled / not in placeCovio can produce a company's complete export today. It cannot today delete one person's data out of a live company while leaving the rest intact, and a purge of a whole departed company is currently refused by the software for the reason given in the retention statement. Both are stated as they are rather than as a right the product cannot yet honour.
8 · Security
The controls Covio actually operates — password hashing, the second sign-in step, rate limiting, transport encryption, authenticated-only document downloads, append-only ledgers, encrypted backups — are described in full, with no certification claimed, in the security summary.
9 · Contact
Questions about this policy: hello@covio.in. Please say which company you are writing about.
Not settled / not in placeCovio has not named a data protection officer or a grievance officer, and does not claim to have one. Whether either is required, and who it should be, is a question for counsel.
What counsel must rule on before this stops being a draft
Covio drafted this document from its own systems rather than from a template, so what follows are the points where engineering cannot decide and a lawyer must.
- 1Which privacy law or laws apply to Covio, and does this policy meet their notice requirements?
- 2Which lawful basis attaches to each purpose in section 4, and does any of it require consent rather than contract or legitimate interest?
- 3Does an erasure right reach sign-in telemetry, which holds email addresses and IP addresses from failed attempts that may not belong to the customer at all? Covio cannot choose between deleting the customer's rows and retaining all of it as security evidence on legal grounds.
- 4Must Covio appoint a data protection officer or a grievance officer, and must this page name them?
- 5Is transferring a photograph of a factory control panel, a WhatsApp number or an email address to a processor outside India permitted, and on what basis?
- 6Should Covio commit to a response time for an individual's request, and what should it be?