Corvlyx Privacy Policy

Effective date: September 1, 2026

Status: Draft for counsel review — not legal advice. Replace placeholder contacts before publishing.


Introduction

Corvlyx (“we”, “us”, “our”) provides software for regulated insurance and financial-services outreach. This Privacy Policy describes how we collect, use, store, share, and protect personal information when you use:

Corvlyx is a software vendor, not an insurance company, agency, or broker. We do not sell insurance products to consumers through the Service.

This policy applies to each single-tenant deployment of Corvlyx (one organization, one database, one shared operator login unless your contract states otherwise).


1. Roles: who is responsible for what

RoleWhoResponsibility
Tenant / CustomerThe licensed agency, MGA, advisory firm, or other organization that operates a Corvlyx deploymentData controller for consumer and client personal information (leads, clients, prospects). Must obtain lawful consent, provide required notices (including GLBA privacy notice where applicable), and comply with telemarketing, insurance licensing, and privacy laws.
Corvlyx (Provider)The software vendor hosting and maintaining the ServiceData processor for tenant consumer data processed solely to deliver the Service, except where we act as controller for our own website analytics, billing, and support contacts.
End individualsConsumers, leads, clients, and message recipientsMay exercise privacy rights through the tenant first; we assist tenants with lawful export/deletion requests affecting data we process on their behalf.

The Service includes compliance assistance features (consent fields, calling windows, do-not-call checks, dry-run defaults). It is a tool, not a compliance certification. Tenants remain solely responsible for their regulatory obligations.


2. Personal information we process

2.1 Lead & client records (Lead Operations / shared client record)

2.2 Voice calling & auto-dialer

2.3 Outreach & messaging

2.4 Marketing & lead ingestion

2.5 Financial OS, FNA & proposals

2.6 Agents, licensing & administration

2.7 Audit, security & operations

2.8 Website & commercial inquiries


3. How we use personal information

We process personal information to:

We do not sell personal information. We do not use tenant consumer data to train public AI models.


4. Lawful basis & consent


5. How we share information

5.1 At tenant direction (integrations)

When the tenant connects third-party services, we share the minimum data needed to:

IntegrationTypical data sharedPurpose
TwilioPhone numbers, message/call bodies, webhook URLsVoice, SMS, WhatsApp
SendGridEmail addresses, message contentOutreach and transactional email
Google (Gmail, Calendar, OAuth)Email metadata, calendar events, OAuth tokensSend, threading, scheduling
Meta (Lead Ads, WhatsApp, Instagram)Lead form data, messaging metadata, tokensLead capture and messaging
OpenAI / Anthropic (if configured)Prompt content necessary for the featureVoice, intake, lead discovery, AI qualification

5.2 Infrastructure & subprocessors

SubprocessorRoleLocation (typical)
Render (or tenant-chosen host)Application hosting, persistent disk for SQLiteUnited States
TwilioTelephony and messagingUnited States
SendGridEmail deliveryUnited States
Google / MetaOAuth APIs as connected by tenantUnited States / global

A current subprocessor list should be maintained in your customer agreement or DPA. Update it when integrations change.

5.3 Legal & safety

We may disclose information to comply with law, court order, or government request, or to protect rights, safety, and integrity of the Service.


6. Security

No system is perfectly secure. Tenants should use strong passwords, protect API keys, and limit who can access the operator application.


7. Retention

Default retention is driven by tenant business and regulatory needs (insurance and GLBA contexts often expect multi-year retention). Unless your agreement specifies otherwise:

Deletion requests: end individuals should contact the tenant. Tenants may request Corvlyx assistance to export or delete data in a deployment, subject to legal holds and audit-log exceptions.


8. Your rights

8.1 If you are a consumer or lead

Contact the organization that collected your information (the tenant). They control your client record. Corvlyx processes data on their instructions.

8.2 If you are a tenant operator

You may access, export, correct, or delete lead data through the Service (where features exist) or by requesting support assistance. You are responsible for honoring end-individual rights for data you control.

8.3 California / other US state privacy laws

Where applicable, tenants may need a separate Data Processing Addendum and consumer-facing notices. Corvlyx does not determine the tenant’s consumer-facing privacy policy text.


9. International transfers

Data is primarily processed in the United States. Cross-border transfers use appropriate contractual safeguards where required.


10. Cookies & similar technologies

Marketing website (`/`)

Operator application (`/app.html`)

Email open/click tracking may occur when outreach or follow-up features enable tracking pixels — tenants should disclose this in their communications.


11. Children’s privacy

The Service is not directed to children under 13 (or 16 where applicable). Tenants must not submit children’s personal information without lawful basis and parental consent where required.


12. Changes to this policy

We may update this policy to reflect product, legal, or operational changes. We will post the new effective date. Material changes affecting tenants will be communicated through reasonable channels (email, in-app notice, or contract amendment).


13. Contact

MatterContact
Tenant support & DPA requestssupport@corvlyx.example (replace before publishing)
Consumer privacy requestsContact the agency or firm that contacted you; they are the data controller
Security incidentssupport@corvlyx.example

14. Related documents

DocumentScope
COMPLIANCE.mdVoice-calling compliance surface (engineering reference, not legal advice)
CUSTOMER_TERMS_DRAFT.mdDraft customer terms (counsel review required)
WEEK0-RC.mdConsent-gated reads, telemetry, audit

Appendix A — Data minimization practices (engineering)

These are product defaults tenants should know about: