Legal

Privacy Policy

Written without a solicitor, at the operator's instruction, and grounded in current ICO/UK GDPR guidance. This policy is in effect and governs real customer data, but it has not been reviewed by a qualified solicitor.

Effective date: 28 September 2026

1. Who we are

Covenn ("we", "us") is a trading name of Nerthus Ltd (company number 17482273). Contact: [email protected]. ICO registration reference: ZC258362.

For your own account data (name, work email, billing details, usage data), we are the data controller. For personal data that happens to appear inside content you upload — for example a contract signatory's name — you are the controller and we act as your data processor, on the terms set out in section 10 ("Data processing terms") of the Terms of Service. The rest of this policy mainly concerns the first category; where it discusses uploaded content, that Terms section governs.

2. What we collect

3. Why we process it, and on what basis

4. Who we share it with

We use the following sub-processors, each solely to provide the Service — we do not sell your data:

5. Automated decisions

The Service calculates figures and drafts correspondence using a mix of deterministic calculation and AI-assisted extraction, but it never makes a decision with a legal or similarly significant effect on anyone without your review — no claim letter is ever sent without you choosing to send it, and low-confidence extractions are flagged rather than acted on. If you believe a specific output was wrong, contact us at [email protected].

6. Marketing emails

We may occasionally email you about the Service at a work address that belongs to a company or other corporate body — UK rules on electronic marketing (PECR) don't require prior consent for this "corporate subscriber" case, provided we identify ourselves clearly and give you a simple way to opt out, which every marketing email will include. If your account is a sole trader or an English/Welsh/Northern Irish partnership rather than an incorporated company, that exemption doesn't apply and we'll only email you with your consent.

7. Retention

We keep account data and uploaded content for as long as your account is active. When you ask us to delete your data or close your account (see "Your rights" below), we do this within 30 days — except billing records, which UK tax law requires us to keep for 6 years, and anything else we're legally required to retain. We don't currently delete data automatically after a period of inactivity; there's no self-service account-deletion feature in the product yet, so a request to [email protected] is how this happens today.

8. Your rights

Under UK GDPR you can ask us to: give you a copy of your data, correct it, delete it, restrict or object to processing, or receive it in a portable format. Contact us at [email protected] to exercise any of these — we aim to respond within one month, as UK GDPR requires. If you're unhappy with our response you can complain to the ICO. We're not required to appoint a formal Data Protection Officer at our current size, but [email protected] is the responsible contact for anything in this policy.

9. Security

Passwords are hashed, not stored in plain text. Access to uploaded contracts is isolated per account. Login attempts are rate-limited. No system is perfectly secure; we'll notify affected users and the ICO of any breach as required by law.

10. Children

The Service is for business use and not directed at children.

11. Changes

We may update this policy; material changes will be notified via the Service or by email.