Effective Date: 2025-11-21
Scope: This policy applies to Corvia AI services, including the Mailblink product suite, provided in on-premises enterprise deployments and multi-tenant cloud services.
1. Information We Process
- Email Content (authorized; deleted upon task completion): Subject, body, and attachments are used solely to provide core features such as auto-classification, labeling, archiving, and draft generation. Content persists only transiently for the specific task and is deleted upon completion; no long-term storage.
- Email Metadata (processed without retention): Sender, recipient, CC/BCC, timestamps, message ID, labels/folders, etc., used to record and retrieve AI analysis information, distinguish/deduplicate emails, and support necessary troubleshooting and compliance auditing.
- Click events (e.g., button clicks, feature toggles) only used to statistical analysis and product experience improvement (e.g., feature usage, flow optimization); not used for personalized advertising.
2. Purposes & Legal Bases
- Purpose: Automate complex email workflows so key information can be handled efficiently within the inbox or enterprise system.
- Legal Bases: Under PIPL, processing is based on your consent; where cross-border transfer occurs, separate consent and outbound transfer compliance are obtained as required.
3. Third-Party Models & Data Minimization
- Subject to stability, compliance, and cost considerations, we may select or rotate among providers such as OpenAI GPT, Google Gemini, Anthropic Claude, Alibaba Qwen, and Zhipu GLM.
- Data Minimization: Only necessary fragments or summaries are sent to model providers; no bulk transfer of historical emails, and any local buffering is temporary and purpose-limited.
- Purpose Limitation & Contracts: Data processing agreements prohibit using your data to train or improve general models and require no or limited retention. Material changes trigger updates and, when required, additional notice or consent.
4. Storage & Security
- Multi-tenant cloud: Data is processed and stored in Hong Kong, China, including any temporary processing or caching.
- On-premises: Data is processed and stored within your own environment; Corvia AI does not host it.
- Controls: Encrypted transmission (and encrypted storage where applicable), tenant isolation, and least-privilege access control; security audit logs are not currently enabled and this policy will be updated if that changes.
5. Retention & Deletion
- Email content: Transient processing for the specific task and deleted upon completion.
- Email metadata: Processed without retention.
- Legal holds: Retention may be extended within the minimum necessary scope to comply with law or resolve disputes, followed by deletion or anonymization once the basis ends.
6. Cross-Border Transfers (incl. Models)
Processing in Hong Kong may constitute overseas processing; when necessary fragments are sent to overseas model providers or their data centers, we will:
- Under PIPL, use standard contracts or certifications and obtain separate consent where required.
- Under GDPR, use SCCs or equivalent safeguards.
- Adhere to data minimization, purpose limitation, and no-training commitments.
- Consent & Withdrawal: Manage authorization and withdrawal via Mail Analysis → Mail Settings.
7. Sharing & Disclosure
- No sale of personal information and no external sharing for partners' own purposes.
- Processors or sub-processors: Only minimal necessary fragments are provided to model providers under contractual controls.
- Legal disclosure: Limited to what is required by law and performed following due process.
8. Automated Processing & Your Choices
- Classification, labeling, archiving, and draft generation constitute automated processing; you may disable all AI features and withdraw consent.
- Under GDPR, you may object to solely automated decisions and request human review. Administrator visibility into employee analysis results is not supported today; notice and consent will precede any change.
9. Your Rights & How to Exercise
- You may access, copy, delete, and rectify your data, and disable all AI features or withdraw consent.
- Access points: In-product via Mail Analysis -> Mail Settings, or by contacting us using the details below. Identity or authority may be verified, and responses are provided within a reasonable timeframe.
10. Minors
The service targets adults and enterprise users and does not target minors. If you believe we processed minors' data without guardian consent, contact us and we will act promptly.
11. Cookies & Similar Technologies
No non-essential cookies are used currently. If a web admin console is introduced, this policy will be updated and consent will be sought where required.
12. Deployment Modes
- Multi-tenant cloud: Processed in Hong Kong with encryption, tenant isolation, configurable third-party models, and no retention of email content or metadata (content deleted after each task, metadata not retained).
- On-premises: Data remains in your environment; external model calls depend on your egress policies, and stricter contractual standards can apply.
13. Incident Response
If a security incident (e.g., breach, alteration, loss) may affect you, we will respond in accordance with law, assess impacts, and notify regulators and you where required, including actions taken and guidance.
14. Changes to This Policy
We will provide prominent notice before changes take effect; material changes such as introducing admin visibility will require additional consent. Continued use constitutes acceptance unless law requires otherwise.
15. Contact
Privacy Contact: jun.niu@corvialabs.ai
