Effective Date: 2025-11-21
Scope: Applies to Corvia AI services, including the Mailblink product suite, provided in on-premises enterprise deployments and multi-tenant cloud services.
1. Definitions
- 1. Service: Corvia AI services, including the Mailblink product suite, Software-as-a-Service, plug-ins, APIs, and related components that enable auto-classification, labeling, archiving, and draft generation for authorized mailboxes.
- 2. You/User: The enterprise entity or its authorized natural-person users who register, enable, configure, and use the Service.
- 3. User Data: Data you submit to, authorize for, or have processed by the Service on your behalf, including email subject, body, attachments, and transient email metadata generated during processing.
- 4. Third-Party Model Provider: LLM providers configured by you (e.g., OpenAI GPT, Google Gemini, Anthropic Claude, xAI Grok, Alibaba Qwen, Zhipu GLM).
- 5. On-premises: Deployment within your owned or controlled environment.
- 6. Multi-tenant Cloud: Our hosted multi-tenant environment with the data region in Hong Kong.
2. Contractual Framework & Order of Precedence
This Agreement, the Privacy Policy, and, where applicable, the Data Processing Agreement (DPA) and SLA/Support Terms collectively govern the Service.
Unless otherwise agreed, precedence is: Master or offline agreement → DPA → SLA/Support Terms → this Agreement → Privacy Policy. Mandatory laws prevail in case of conflict.
3. Services & Functional Boundaries
- 7. Upon valid mailbox authorization, the Service performs classification, labeling, archiving, and draft generation.
- 8. We only access or process subject, body, and attachments as necessary for each task and delete them upon completion; no long-term storage.
- 9. Email metadata is used only during processing and is not retained afterwards.
- 10. AI outputs are recommendations or drafts that require your human review.
- 11. Admin visibility into employee analysis results is not supported; if introduced, prior notice and consent will be sought.
- 12. All access requires your active authorization, which you may withdraw anytime via Mail Analysis → Mail Settings.
4. Deployment & Data Regions
- Multi-tenant cloud: Processed and stored in Hong Kong, including necessary temporary processing or caching.
- On-premises: Processed and stored within your environment; connectivity to third-party models follows your network policies.
- For cross-border transfers, applicable compliance obligations will be fulfilled and separate consent obtained where required.
5. Accounts, Authorization & Eligibility
You warrant that accounts, domains, and mailboxes used to access the Service are lawful and valid with proper authority. You are responsible for actions and outcomes (including those of staff or contractors). The Service is not directed to minors unless guardian consent and applicable law permit.
6. Acceptable Use Policy
Prohibited activities include unlawful conduct, security violations, infringement, resource abuse, bypassing quotas, billing, or security controls, reverse engineering (unless allowed by law), disclosing unauthorized benchmarks, and using the Service to develop directly competing products.
7. Third-Party Services & Open Source
You may configure third-party LLMs such as GPT, Gemini, Claude, Grok, Qwen, or GLM. We transmit only necessary fragments or summaries and contractually restrict model providers from training on or reusing your data beyond the agreed purpose. Availability and compliance of third-party services depend on their policies and regional constraints. Open-source components are governed by their respective licenses.
8. Fees & Activation
Pricing, taxes, trials, delinquency handling, and suspension follow the Order or Master Agreement (or applicable addenda).
9. Service Levels & Support
Availability targets, severity classifications with response and restoration times, maintenance notifications, and ticketing channels follow the SLA or Support Terms.
10. Security & Confidentiality
We employ encrypted transmission (and encrypted storage where applicable), tenant isolation, and least-privilege controls; security audit logs are not currently enabled. We will respond to security incidents in accordance with applicable law and provide required notices or reports.
11. Privacy & Data Protection
We process personal information and User Data under the Privacy Policy; where a DPA is in place, it governs specific obligations. We will not use your data to train or improve general models unless permitted by law or expressly authorized by you.
12. Intellectual Property
The Service and related documentation, interfaces, and technology are owned by us or the respective rightsholders, while User Data remains owned by you or its lawful owner.
You grant us and necessary model providers a non-exclusive, worldwide, revocable, limited license during the term to process User Data solely to perform the Service per your instructions. Non-confidential feedback is licensed to us on a royalty-free, irrevocable, sublicensable basis.
13. Term & Termination
This Agreement is effective upon your acceptance and remains in force until either party lawfully terminates it. You may withdraw authorization at any time via Mail Analysis → Mail Settings, and we may suspend or terminate for material breach or unlawful use.
After termination, for the multi-tenant cloud we delete task-specific content and retain no metadata per the Privacy Policy; for on-premises deployments, you manage the data directly, subject to legal retention requirements. Provisions on intellectual property, liability, dispute resolution, and similar obligations survive termination.
14. Disclaimers & Limitation of Liability
To the fullest extent permitted by law, the Service is provided as is and as available without express or implied warranties. We are not liable for issues caused by third-party services, public networks, or force majeure, and AI outputs are for reference only and require your review.
We are not liable for indirect, incidental, punitive, or consequential damages where permitted by law.
15. Indemnity
You shall indemnify and hold harmless us, our affiliates, employees, and agents from third-party claims, fines, or costs arising from your breach of this Agreement, the Acceptable Use Policy, or applicable laws, to the extent permitted by law.
16. Force Majeure
Neither party is liable for delays or failures resulting from earthquakes, fires, floods, wars, government actions, public network outages, major supplier failures, or similar events, provided reasonable efforts are made to mitigate impacts.
17. Notices
We may notify you via website announcements, in-product notices, email, or other contact details you provide. You may contact us using the methods specified in this Agreement.
18. Changes
We may update this Agreement due to feature, supplier, or legal changes; material updates (such as introducing admin visibility) will be prominently communicated and consent will be requested where required. Continued use constitutes acceptance where permitted by law.
19. Governing Law & Dispute Resolution
Governing law and forum follow the Master Agreement or supplemental terms.
20. Miscellaneous
Section titles do not affect interpretation; invalidity of any clause does not impact the rest; no assignment without written consent except for corporate transactions. This Agreement together with the Privacy Policy, DPA, and SLA constitutes the entire agreement regarding the Service.
21. Contact
Privacy/Compliance: jun.niu@corvialabs.ai
