Privacy Policy
Last updated: July 25, 2026
1. Introduction
This Privacy Policy explains how Corvault collects, uses, stores, and protects your personal information and files.
Our commitment: You own your data. We do not sell personal information or files and we use strong encryption to protect them.
2. Information We Collect
Account data
- Email, username, and password hash
- Company name and company code if provided
Payment data
- Last four digits of the card, expiration, optional billing address, and Stripe customer ID.
File data
E2E files
Encrypted on your device before upload. Corvault cannot decrypt them.
Server-side files
Processed only for operational needs: sharing, security scanning, support.
We also collect metadata: filename, size, timestamps, uploader identity, access permissions.
Usage data
- Technical logs, IP addresses, device information, and audit records.
- Performance and feature usage data.
3. How We Use Your Information
- To provide the Service and manage files, access, and shared links.
- To process billing, notifications, security, and support.
- To comply with legal obligations and improve the platform.
Legal basis for each purpose
| Why we process it | Legal basis (GDPR Art. 6) |
|---|---|
| Running your account and storing, encrypting and sharing your files | Performance of our contract with you — Art. 6(1)(b) |
| Taking payment and managing your subscription | Performance of our contract — Art. 6(1)(b) |
| Issuing invoices and keeping accounting records | Legal obligation — Art. 6(1)(c) (Italian tax and accounting law) |
| Keeping the service secure: audit logs, brute-force protection, detecting logins that cannot be genuine | Our legitimate interest in protecting accounts and the service from abuse — Art. 6(1)(f) |
| Answering support requests and illegal-content reports | Performance of our contract — Art. 6(1)(b); and legal obligation under the Digital Services Act — Art. 6(1)(c) |
| Sending service emails you need to receive (password resets, billing notices, security alerts) | Performance of our contract — Art. 6(1)(b). These are not marketing and cannot be switched off while your account is open. |
| Keeping a record that you accepted these terms | Our legitimate interest in being able to prove the terms of our agreement — Art. 6(1)(f) |
Where we rely on legitimate interests, you can object at any time — see section 6. We do not use your data for advertising, we do not profile you, and no decision affecting you is made by automated means alone.
5. Data Retention and Deletion
| Data | Kept for |
|---|---|
| Account and profile data | For the life of the account, then deleted within 90 days of closure |
| Your files and their metadata | Until you delete them; 90 days after account closure to allow export |
| Security audit log (logins, permission changes) | 365 days by default; your workspace admin can set 30–3650 days |
| File activity log | 365 days by default; configurable 30–3650 days |
| Technical/application logs | 30 days |
| Password-reset tokens | 30 days |
| Two-factor setup tokens | 7 days |
| Data-export archives | 48 hours, then automatically deleted |
| Encrypted system backups | 7 days on a rolling basis |
| Invoices and accounting records | 10 years — required by Italian law (art. 2220 Civil Code) |
| Records of your acceptance of these terms | 10 years, as evidence of the contract |
End-to-end encrypted files are deleted along with everything else, but note we never held the keys to them in the first place.
Where we must keep something longer to comply with a legal obligation, or to establish or defend a legal claim, we keep only that record and only for as long as the obligation lasts.
6. Your Rights and Choices
- Access, portability, correction, and deletion rights.
- Rights to object to some optional processing.
- Additional GDPR and local privacy rights where applicable.
You can export or delete your account yourself from your account settings — you do not need to ask us. For anything else, write to privacy@corvault.net. We answer within one month, and we do not charge for it.
Your right to complain to a regulator
If you think we have mishandled your data, please tell us first — but you are entitled to go straight to a supervisory authority and you do not need our permission. In Italy that is the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Roma — garanteprivacy.it). If you live in another EU or EEA country, you may complain to your own national authority instead.
7. Security Measures
- TLS in transit and AES-256-GCM at rest.
- Role-based access controls, strong passwords, session limits, and audit logging.
- Infrastructure monitoring and encrypted backups.
No system is perfect. You remain responsible for protecting credentials and encryption keys.
9. Children's Privacy
Corvault is not intended for use by children under 16 and we do not knowingly collect personal information from them.
10. International Data Transfers
Your files, databases and logs are stored in Germany and never leave the EU. Our email provider is in France. So in normal use, your data stays within the EEA.
The one exception is payments. Stripe is contracted through Stripe Payments Europe, Ltd. in Ireland, but some processing takes place in the United States. That transfer is covered by the European Commission's Standard Contractual Clauses, together with the additional safeguards set out in Stripe's own data-processing agreement. Only billing data is involved — never your files.
You can ask us for a copy of the safeguards that apply to any transfer — write to privacy@corvault.net.
11. Changes to This Privacy Policy
- Material changes will be communicated through appropriate channels.
- Updated versions take effect as indicated in the notice.
12. Contact Us
For privacy questions or to exercise your rights, contact us:
Data controller
Corvault
Privacy: privacy@corvault.net
Support: support@corvault.net
Report illegal content: abuse@corvault.net
We are not required to appoint a Data Protection Officer, and we have not appointed one. Privacy questions go to the address above and are handled directly.
Questions about your privacy?
Contact us anytime if you want more clarity.