Privacy Policy
Effective date: 28 September 2026
1. Who we are
Covenn ("we", "us") is a trading name of Nerthus Ltd (company number 17482273). Contact: [email protected]. ICO registration reference: ZC258362.
For your own account data (name, work email, billing details, usage data), we are the data controller. For personal data that happens to appear inside content you upload — for example a contract signatory's name — you are the controller and we act as your data processor, on the terms set out in section 10 ("Data processing terms") of the Terms of Service. The rest of this policy mainly concerns the first category; where it discusses uploaded content, that Terms section governs.
2. What we collect
- Account data — name, work email, hashed password.
- Uploaded content — the contracts, purchase orders, goods-receipt records and invoices you provide. These may name individuals (e.g. signatories) incidentally.
- Billing data — handled by Stripe; we hold a reference to your Stripe customer/subscription, not full card details.
- Usage data, only if you accept analytics cookies — pages viewed, features used. See the Cookie Policy. This is off by default.
3. Why we process it, and on what basis
- To provide the Service you've signed up for (contract performance).
- To process payment and prevent fraud (contract performance / legal obligation).
- To improve the Service, only where you've consented to analytics (consent).
- To secure the Service — e.g. rate-limiting login attempts (legitimate interest).
4. Who we share it with
We use the following sub-processors, each solely to provide the Service — we do not sell your data:
- Anthropic (Claude API) — processes contract text to extract clauses. Anthropic is based in the US; this transfer is protected under Anthropic's Data Processing Addendum, which incorporates the UK Addendum to the EU Standard Contractual Clauses (template version B.1.0, issued by the UK Information Commissioner's Office).
- Stripe — payment processing. Stripe's Data Processing Agreement offers the UK International Data Transfer Addendum as one of its transfer mechanisms for data leaving the UK.
- Cloudflare (R2) — stores uploaded contracts, purchase orders, invoices and goods-receipt records in a private bucket, accessible only to our backend. Cloudflare's Data Processing Addendum incorporates the EU Standard Contractual Clauses; we have not independently confirmed a UK-specific addendum is also in place for our account and are following this up directly with Cloudflare.
- Cloudmersive — scans uploaded files for malware before storage; files are scanned and not retained by Cloudmersive afterwards. We have not reviewed Cloudmersive's international data transfer safeguards in the same depth as our other sub-processors above — flagged here rather than assumed.
- Render and Neon — host the application and its database. Neon's database runs in AWS's London region and Render's compute runs in Frankfurt, so the data itself stays in the UK/EU; both providers are US-headquartered, so we rely on their standard data processing agreements for any transfer their support or maintenance access might involve.
- PostHog — usage analytics, only if you've given consent via the cookie banner. Our PostHog project is hosted on PostHog's EU cloud, so this data doesn't leave the UK/EEA.
5. Automated decisions
The Service calculates figures and drafts correspondence using a mix of deterministic calculation and AI-assisted extraction, but it never makes a decision with a legal or similarly significant effect on anyone without your review — no claim letter is ever sent without you choosing to send it, and low-confidence extractions are flagged rather than acted on. If you believe a specific output was wrong, contact us at [email protected].
6. Marketing emails
We may occasionally email you about the Service at a work address that belongs to a company or other corporate body — UK rules on electronic marketing (PECR) don't require prior consent for this "corporate subscriber" case, provided we identify ourselves clearly and give you a simple way to opt out, which every marketing email will include. If your account is a sole trader or an English/Welsh/Northern Irish partnership rather than an incorporated company, that exemption doesn't apply and we'll only email you with your consent.
7. Retention
We keep account data and uploaded content for as long as your account is active. When you ask us to delete your data or close your account (see "Your rights" below), we do this within 30 days — except billing records, which UK tax law requires us to keep for 6 years, and anything else we're legally required to retain. We don't currently delete data automatically after a period of inactivity; there's no self-service account-deletion feature in the product yet, so a request to [email protected] is how this happens today.
8. Your rights
Under UK GDPR you can ask us to: give you a copy of your data, correct it, delete it, restrict or object to processing, or receive it in a portable format. Contact us at [email protected] to exercise any of these — we aim to respond within one month, as UK GDPR requires. If you're unhappy with our response you can complain to the ICO. We're not required to appoint a formal Data Protection Officer at our current size, but [email protected] is the responsible contact for anything in this policy.
9. Security
Passwords are hashed, not stored in plain text. Access to uploaded contracts is isolated per account. Login attempts are rate-limited. No system is perfectly secure; we'll notify affected users and the ICO of any breach as required by law.
10. Children
The Service is for business use and not directed at children.
11. Changes
We may update this policy; material changes will be notified via the Service or by email.