Skip to policy

Privacy Policy

Effective [EFFECTIVE DATE]Version [VERSION]Archived versions
In this document

Introduction

SorviAI is business software. We collect the information we need to give you an account, keep it secure, bill you and support you. We do not sell your personal information, and we do not use your business data to advertise to you.

Most of the information inside SorviAI is not ours. It belongs to the organisation that put it there. When your employer or a supplier uses SorviAI to store records about you, they decide what happens to that information and we simply hold it for them. The section on our two roles explains this properly, because it changes who you should contact about your data.

Your files and your database are stored in the United Kingdom. A small number of named suppliers help us run the service, and they are all listed under who we share information with. If you want your data corrected or deleted, the section on your rights tells you how to ask, and the section on where you are explains what your local law adds to that.

Who we are

SorviAI is a business software platform operated by [REGISTERED COMPANY NAME], a company registered in [JURISDICTION] under company number [COMPANY NUMBER], with its registered office at [REGISTERED OFFICE ADDRESS].

In this policy, “we”, “us” and “our” mean that company. “You” means the person reading it, whether you hold a SorviAI account yourself or your details appear in someone else’s account.

We are registered with the UK Information Commissioner’s Office under registration number [ICO REGISTRATION NUMBER]. Our data protection contact is [PRIVACY CONTACT EMAIL], and the contact section lists our regional contacts.

Our two roles, and why it matters to you

SorviAI is used by organisations to run their business. That means we handle personal information in two very different ways, and your rights depend on which one applies to you.

When we decide, we are the controller

If you sign up for SorviAI, get invited into a workspace, pay us, visit our website or contact our support team, we decide why and how your information is used. In legal terms we are the data controller, and this policy is the document that governs it.

When our customer decides, we are the processor

If your details are inside SorviAI because an organisation put them there, that organisation is the controller and we are only the processor. This applies if you are an employee whose record sits in the Worklink module, a customer or supplier whose contact and invoice records sit in Finance, someone who reported a repair ticket, a shopper who ordered from a storefront, or someone who exchanged emails with a business using our TeamEmail module.

In those cases we hold your information on that organisation’s instructions and under a written agreement with them. We do not decide what is collected, we do not use it for our own purposes, and we cannot change or delete it on our own initiative.

What this policy covers

This policy applies to the SorviAI platform and every application within it, together with our public website and our sales and support communications.

What it does not cover

  • Online stores run by our customers. Businesses can publish their own storefront using SorviAI. If you are shopping on one of those sites, the business running it is the controller of your information and its own privacy policy applies, not this one.
  • Third-party services our customers connect. If a customer links a Microsoft 365 mailbox, a payment gateway or another external account to SorviAI, that provider’s own terms and privacy policy continue to apply to the data held on their systems.
  • Other websites we link to. We are not responsible for how they handle your information.

Information we collect about you

This section covers information we hold as controller, which means information about you as a user or prospective user of SorviAI.

Account and profile information

When you create an account or accept an invitation to a workspace, we collect your email address, first and last name, and optionally your phone number and a profile picture. We record whether your email address has been verified and when, when your account was created and last updated, and which workspaces you belong to.

Authentication and security information

To keep your account secure we hold your password in hashed form, never as readable text. If you enable two-factor authentication we store the secret needed to verify your codes in encrypted form, along with the time you last used a code so that the same code cannot be replayed. We also issue short-lived tokens when you sign in, switch workspace or accept an invitation.

Device, network and activity information

When you take actions in SorviAI we record what was done, when, by which account, together with the IP address and browser user-agent string of the request. This forms the audit log, which lets workspace administrators see who changed what and lets us investigate security incidents.

Where a workspace administrator has turned on IP-based access restriction for attendance check-in, we compare the IP address of a check-in attempt against the addresses that administrator has allowed.

Billing information

We hold your billing contact details, the plan and subscription associated with your workspace, and a record of invoices and payments. [SUBSCRIPTION PAYMENT PROVIDER, AND WHETHER WE EVER SEE CARD NUMBERS]

Support and correspondence

If you contact us for help we keep the messages you send, our replies, and any diagnostic information you choose to share so that we can resolve the issue and improve the product.

Website information

When you visit our public website we collect standard technical information such as IP address, browser type and the pages you viewed, from our server logs. We run no analytics, advertising or marketing scripts on that site, and the one cookie it can set - a “was this helpful?” answer on our articles and guides, stored only if you choose to answer - identifies nobody. Our Cookie Policy sets out the complete position.

Job applications

If you apply for a role through our careers page we hold the name, email address and phone number you give us, the role you applied for, your CV, and an offer letter if you choose to send one. We ask for your consent before you send any of it, and we rely on that consent as our legal basis. Your CV and any offer letter are stored privately, are never published, and are reached only through a link that expires, by the people involved in hiring for that role. We keep an application for 12 months from the day it arrives and then delete it, together with the files. You can withdraw your consent or ask us to delete an application at any time, and we will act on it.

Information we process for our customers

This section covers content that our customers put into their workspace. We process it on their instructions, as described under our two roles. We are telling you what it consists of so that you know what we hold, not because we decide what happens to it.

Business contacts and financial records

Names, job titles, email addresses, phone numbers and postal addresses of a customer’s own clients and suppliers, together with quotes, sales orders, invoices, credit notes, bills, purchase orders, goods receipts, payments, expenses, inventory items, price lists and storefront orders.

Employee records

Customers using the Worklink module can store detailed records about their staff. Depending on what that employer chooses to record, this may include a profile photograph, date of birth, gender, marital status, national identification number, emergency contact name, phone number and relationship, bank name and routing code, uploaded documents such as contracts or right-to-work evidence, and day-to-day attendance, shift, leave and timesheet records.

Mailbox content

Where a customer connects a Microsoft 365 mailbox to the TeamEmail module, we sync and store message content, subject lines, sender and recipient addresses, attachments and threading metadata so that the customer’s team can work on those conversations inside SorviAI. Access is granted by the customer’s own administrator through Microsoft’s consent process and can be revoked by them at any time, which stops any further sync.

Service and repair tickets

Details of reported faults, the device or item concerned, and whatever the person reporting the issue chose to write, along with the contact details needed to keep them updated.

Files and attachments

Any document, image or other file that a user uploads to their workspace.

How we use information, and our legal basis

Data protection law requires us to have a valid reason for each purpose. The table below sets out ours, in the terms used by UK and European law.

What we doInformation usedLegal basis
Provide the platform and the applications you have subscribed toAccount, authentication, workspace contentPerformance of our contract with you or your organisation
Authenticate you, prevent unauthorised access and investigate abuseCredentials, IP address, user agent, audit recordsOur legitimate interest in keeping the platform and our customers’ data secure
Send service and security notices, such as downtime, breach or policy changesAccount contact detailsPerformance of our contract, and legal obligation where a notification is required by law
Bill you and collect paymentBilling and subscription detailsPerformance of our contract, and legal obligation for tax and accounting records
Answer support requestsCorrespondence and diagnostic informationPerformance of our contract, and our legitimate interest in supporting our product
Diagnose faults and improve the productError reports and aggregated usage informationOur legitimate interest in maintaining a reliable service
Send marketing about our productsContact details and your preferencesYour consent, which you can withdraw at any time using the unsubscribe link in every message
Meet legal and regulatory obligations, and establish or defend legal claimsWhatever is relevant and necessaryLegal obligation, and our legitimate interest in defending our rights

Legitimate interests. Where we rely on legitimate interests, we have weighed our interest against your rights and freedoms and concluded that our use does not override them. You can ask us for a summary of that assessment at any time, and you can object to processing based on legitimate interests as described under your rights.

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not disclose it to third parties for their own marketing. That statement is made deliberately in the language of United States state privacy law as well as plain English, because “sale” and “sharing” are defined broadly there. See sale and sharing in the key terms.

Cookies and similar technologies

We use a small number of cookies and similar browser storage to make SorviAI work. There are two categories only:

  • Strictly necessary. These keep you signed in, maintain your session, route you to the correct workspace and protect against cross-site request forgery. The service cannot function without them, so they are set without asking for consent.
  • Preferences. These remember choices such as your light or dark theme setting and your layout preferences. They are written only after you make the choice, and exist purely to make the product behave the way you left it.

We use no analytics, advertising or tracking cookies, on the platform or on our public website, and we allow no third party to set one. That is why you see no consent banner.

Our Cookie Policy lists every cookie we set with its purpose and expiry, describes the browser storage we use, and explains how to clear or block it.

Who we share information with

We do not sell your information. We share it only with the suppliers listed below, who process it on our instructions under a written contract, and in the limited legal circumstances set out at the end of this section.

SupplierWhat they do for usWhat they can reachLocation
DigitalOceanManaged hosting, database, cache, background queue and object storage for uploaded filesAll platform data, including attachments, documents, profile and item imagesUnited Kingdom (London)
Twilio SendGridOutbound and transactional email deliveryRecipient addresses and message content[SENDGRID REGION]
Functional Software (Sentry)Error and performance monitoringTechnical error reports, which may include an account identifier and request details[SENTRY REGION]
MicrosoftMailbox integration, where a customer connects oneMailbox content, at that customer’s directionThe customer’s own Microsoft region
StripePayment gateway, where a customer connects one to collect payments from their own customersPayment and payer details for the transactions that customer processes[STRIPE REGION]
GroqPowers optional AI features in document templatesThe template or document content submitted to the featureUnited States

We review this list when our suppliers change. If we add or replace a supplier that processes customer content, we will notify workspace administrators at least [SUB-PROCESSOR CHANGE NOTICE PERIOD] in advance, and a customer who objects may raise it with us under their agreement. The current list is always published at [SUB-PROCESSOR PAGE URL].

Other disclosures

We may also disclose information where we are legally required to, for example in response to a valid court order or a lawful request from a regulator or law enforcement. Where we are permitted to tell you, we will. If our business is sold or reorganised, information may transfer to the acquiring entity, which would remain bound by this policy or a materially equivalent one.

Where your data is stored, and transfers

Our primary database and all uploaded files are stored in the United Kingdom. Each customer’s data is held in a separate database schema, which is explained further under how we protect information.

This is true wherever you are. A customer in India or the United States has their workspace stored in the United Kingdom, on the same infrastructure as everyone else, unless we have agreed something different with them in writing.

Transfers out of the United Kingdom

Some of the suppliers named above operate outside the United Kingdom, most notably Groq in the United States. Where information is transferred out of the UK or the European Economic Area, we rely on [TRANSFER MECHANISM] to make sure your information continues to be protected to the standard required by UK and EU law.

Transfers into the United Kingdom

If you are in India or the United States, using SorviAI means your information is transferred to and stored in the United Kingdom. We rely on your agreement with us, or your employer’s, together with the safeguards described under how we protect information. India’s law permits transfer to most countries subject to any restrictions the government sets, and we will update this section if a restriction affects the United Kingdom.

You can ask us for a copy of the safeguards that apply by writing to the address in the contact section.

How long we keep information

We keep information only as long as we need it for the purposes set out under how we use information, or as long as the law requires.

InformationHow long we keep it
Your account and workspace content, while the account is openFor as long as the account remains active
Records deleted inside the productThey move to Trash, where a workspace administrator can restore them. They are permanently deleted after the period that administrator has configured, which defaults to [DEFAULT TRASH PERIOD]
Everything, after an account is closedDeleted within [POST-CLOSURE DELETION WINDOW] of closure, after a read-only period in which you can export
Backups[BACKUP RETENTION PERIOD], after which backup copies are overwritten in the normal rotation
Audit logs[AUDIT LOG RETENTION]
Error monitoring reports[ERROR REPORT RETENTION]
Email send logs, covering sender, recipients, subject, timestamp and outcome[SEND LOG RETENTION], kept for delivery troubleshooting, audit and abuse investigation
Sign-in and invitation tokensSign-in tokens expire within minutes of being issued. Invitations expire after seven days. Both are single use
Invoices and accounting records about our own customersSix years, as required by UK tax law
Marketing contact detailsUntil you unsubscribe, and then only a suppression record so that we do not contact you again

Where we cannot delete information immediately, for example because it exists in a backup, we isolate it and delete it when that backup is next rotated.

How we protect information

No system is perfectly secure, but these are the specific measures we take.

  • Separation between customers. Every customer’s data lives in its own database schema, not in shared tables filtered by a column. Separation is enforced by the database itself, so a fault in application code cannot leak one customer’s records into another’s workspace.
  • Encryption. Traffic between your browser and our servers is encrypted in transit. Uploaded files are encrypted at rest.
  • Private file access. Uploaded files are private by default and are served through signed links that expire, so a copied link does not grant lasting access. Files that a customer deliberately publishes, such as storefront product images, are served from public addresses that do not expire.
  • Two-factor authentication. Available on every account. The secret used to verify your codes is stored encrypted, and each code can only be used once.
  • Short-lived sessions. Access tokens expire after 60 minutes and must be renewed.
  • Role-based access control. Workspace administrators grant permissions per application, so a user only reaches the modules and records their role allows.
  • Audit logging. Actions are recorded with the account, timestamp, IP address and browser, so unusual activity can be traced. Staff access to workspace content is itself logged.

Your rights

These are the rights we honour for everyone, wherever you are. The section on where you are sets out what your own country’s law adds on top, because the wording and the deadlines differ.

  • Access. Ask for a copy of the personal information we hold about you.
  • Correction. Ask us to correct anything inaccurate or incomplete.
  • Erasure. Ask us to delete your information, where we have no continuing lawful reason to keep it.
  • Restriction. Ask us to pause our use of your information while a concern is resolved.
  • Portability. Ask for the information you gave us in a structured, commonly used, machine-readable format.
  • Objection. Object to processing we carry out on the basis of legitimate interests, and object at any time to direct marketing.
  • Withdraw consent. Where we rely on consent, withdraw it at any time. This does not affect anything we did before you withdrew it.
  • No penalty for asking. We will not deny you service, charge you a different price or give you a worse experience because you exercised a right.

To exercise any of these, write to the address in the contact section. We will respond within one month. If your request is complex we may extend this by up to two further months, and we will tell you within the first month if that happens. We do not charge a fee unless a request is manifestly unfounded or excessive.

We may need to verify your identity before acting, to make sure we are not disclosing your information to someone else.

Where you are, and which law applies

SorviAI is used by businesses in the United Kingdom, the European Economic Area, India and the United States. We apply one standard of protection to everyone, which is the strictest of the four. What changes by region is the name of the law, some of the wording for your rights, and who you can complain to.

Where you areWhat appliesWhat it addsWho you can complain to
United KingdomUK GDPR and the Data Protection Act 2018The rights listed above in full, with a one-month response deadline. This policy is written to the UK standard by default.Information Commissioner’s Office, ico.org.uk
European Economic AreaThe GDPR, as applied in your own countryThe same rights as the UK, in the law the UK version was derived from. Where required, we appoint a representative in the EEA, named in the contact section.The data protection authority in your own country
IndiaThe Digital Personal Data Protection Act 2023 and the rules made under itAccess, correction, completion, updating and erasure, plus two rights specific to India: a grievance redressal process you can use before going to the regulator, and the right to nominate another person to exercise your rights if you die or become incapable of acting. Our India contact is named in the contact section.Data Protection Board of India
United StatesState privacy laws, including California’s. There is no general federal privacy lawRights to know, delete and correct, to opt out of sale, sharing and targeted advertising, to limit the use of sensitive personal information, and not to be discriminated against for exercising them. We do not sell or share your information, so those opt-outs have nothing to act on, and we carry no “Do Not Sell or Share” link for that reason.California residents: the California Privacy Protection Agency or the state Attorney General. Elsewhere: your state Attorney General

AI features and automated decisions

SorviAI includes optional AI features that help generate and edit document templates. When a user chooses to use one of these features, the content they submit is sent to Groq, an AI provider based in the United States, and processed by a large language model to produce the result.

The feature only runs when a user actively triggers it. Content is not sent to any AI provider in the background, and we do not feed your workspace, your customer records or your employee records to a model.

[AI PROVIDER RETENTION AND MODEL-TRAINING POSITION]

We do not make decisions about you by automated means alone that produce legal effects or otherwise significantly affect you.

Children

SorviAI is business software sold to organisations. It is not directed at children and we do not knowingly collect information from anyone under 16, or under 18 where our customer is in India, whose law treats everyone under 18 as a child and prohibits tracking or targeted advertising to them. We do neither to anyone.

If you believe a child has provided us with personal information, contact us at the address in the contact section and we will delete it.

Changes to this policy

We update this policy when the way we handle information changes. The effective date and version at the top always tell you which version you are reading.

If a change materially affects your rights or how we use your information, we will give workspace owners at least [POLICY CHANGE NOTICE PERIOD] notice by email and show a notice inside the product before the change takes effect. Minor corrections take effect when published.

Previous versions remain available at [ARCHIVE URL].

How to contact us

For anything about this policy or your personal information, contact us using the details below. One address reaches us wherever you are, and we answer in English. We aim to acknowledge every privacy enquiry within [ACKNOWLEDGEMENT TIME] working days, and to answer fully within the deadline your own law sets.

Data protection contact

Email
[PRIVACY CONTACT EMAIL]
Entity
[REGISTERED COMPANY NAME]
Post
[REGISTERED OFFICE ADDRESS]

Regional contacts

Some of the regional laws set out above require a named contact inside the region. Where one is required of us, it is listed here.

European Economic Area
[EU REPRESENTATIVE, IF REQUIRED]
India, grievance officer
[INDIA GRIEVANCE CONTACT]
Data protection officer
[DPO NAME, IF APPOINTED]

Complaints

If you are unhappy with how we have handled your information, please tell us first so that we can put it right. You also have the right to complain to the regulator for your region, listed under where you are. In the United Kingdom that is the Information Commissioner’s Office, at ico.org.uk or on 0303 123 1113.

Key terms

The words in this policy that carry a specific legal meaning, in plain language.

Personal information

Any information that identifies you, or could identify you when combined with something else. A name and an email address obviously qualify. So do an IP address, an account identifier and a photograph. Different laws use different words for the same idea: “personal data” in the UK and Europe, “personal information” in the United States, “digital personal data” in India.

Controller and processor

Two roles defined by data protection law. The controller decides why and how personal information is used and carries the legal responsibility for it. The processor only handles it on the controller’s instructions and cannot use it for its own purposes.

SorviAI is the controller for your account with us, and the processor for the business records our customers keep in their own workspaces. The section on our two roles explains which applies to you. India’s law calls the same two roles the data fiduciary and the data processor, and calls you the data principal rather than the data subject.

Legitimate interests

A legal basis that lets an organisation process information for a genuine business reason, but only after weighing that reason against your rights and deciding it does not override them. We use it for security, abuse investigation and keeping the service reliable.

It is the most easily abused basis in the law, which is why we will send you a summary of the balancing exercise if you ask, and why you can object to any processing that rests on it.

Sale and sharing (United States)

Terms with a specific and broad meaning under California’s privacy law and several other state laws. “Sale” covers disclosing personal information for money or other value, not only a cash transaction. “Sharing” covers passing it to another business for cross-context behavioural advertising, which is advertising based on your activity across unrelated sites.

Both are broad enough to catch things a normal reader would not call selling data, which is why we state plainly that we do neither, in those words.

Sub-processor

A supplier we bring in to help us deliver the service, which touches personal information in the process. The companies named under who we share information with are our sub-processors. Each one is under a written contract that binds it to the same obligations we owe our customers, and we stay responsible to you for what they do.

International transfer

Moving personal information out of the country whose law protects it, or letting someone in another country access it. It is regulated because information does not keep its legal protection automatically when it crosses a border.

Your data sits in the United Kingdom. If you are in India or the United States, using SorviAI is itself a transfer to the UK. Where information leaves the UK or the EEA, the section on where your data is stored names the safeguard we rely on.

Data Processing Agreement

The contract that has to be in place whenever one organisation processes personal information on another’s instructions. It sets out what the processor may do, the security it must apply, what happens to the data at the end, and the terms on which sub-processors may be used.

Where we are your processor, this is the document that governs it, and it sits alongside rather than inside this policy.

India's DPDP Act

The Digital Personal Data Protection Act 2023, India’s general data protection law, together with the rules made under it. It applies to processing digital personal data in India, and to processing outside India connected with offering goods or services to people in India.

It gives rights of access, correction and erasure, requires a grievance redressal route, and uniquely allows you to nominate someone to exercise your rights if you die or become incapable. Complaints go to the Data Protection Board of India.

Personal data breach

Not only a hacker getting in. It covers any security failure that leads to personal information being destroyed, lost, altered, disclosed or accessed without authorisation, including by accident and including by someone inside the organisation. Sending a file to the wrong customer is a breach. So is losing a backup.

The section on how we protect information sets out what we do when one happens.