{"effective_date":"September 1, 2026","summary":"Corvlyx processes personal data on behalf of your organization (the tenant) to deliver lead intake, voice, messaging, outreach, and financial review workflows. Tenants remain data controllers for consumer information; Corvlyx acts as a processor. Consumer data is encrypted at rest when DB_ENCRYPTION_KEY is configured. The Service assists with compliance checks but does not certify legal compliance.","ui_snippet":"Consumer data in Corvlyx is stored on an encrypted client record controlled by your organization. You must provide required privacy notices and obtain lawful consent before outreach. Corvlyx connects to Twilio, SendGrid, Google, and Meta only when you configure those integrations.","policy_doc":"docs/PRIVACY_POLICY.md","draft":true,"version":"2026-09-01","body":"# Corvlyx Privacy Policy\n\n**Effective date:** September 1, 2026\n\n**Status:** Draft for counsel review — not legal advice. Replace placeholder contacts before publishing.\n\n---\n\n## Introduction\n\nCorvlyx (“**we**”, “**us**”, “**our**”) provides software for regulated insurance and financial-services outreach. This Privacy Policy describes how we collect, use, store, share, and protect personal information when you use:\n\n- the Corvlyx marketing website and inquiry forms;\n- the operator application (Lead Operations, Financial OS, and Marketing modules); and\n- APIs, webhooks, and integrations connected to your deployment.\n\nCorvlyx is a **software vendor**, not an insurance company, agency, or broker. We do not sell insurance products to consumers through the Service.\n\nThis policy applies to each **single-tenant deployment** of Corvlyx (one organization, one database, one shared operator login unless your contract states otherwise).\n\n---\n\n## 1. Roles: who is responsible for what\n\n| Role | Who | Responsibility |\n|------|-----|----------------|\n| **Tenant / Customer** | The licensed agency, MGA, advisory firm, or other organization that operates a Corvlyx deployment | **Data controller** for consumer and client personal information (leads, clients, prospects). Must obtain lawful consent, provide required notices (including GLBA privacy notice where applicable), and comply with telemarketing, insurance licensing, and privacy laws. |\n| **Corvlyx (Provider)** | The software vendor hosting and maintaining the Service | **Data processor** for tenant consumer data processed solely to deliver the Service, except where we act as controller for our own website analytics, billing, and support contacts. |\n| **End individuals** | Consumers, leads, clients, and message recipients | May exercise privacy rights through the **tenant** first; we assist tenants with lawful export/deletion requests affecting data we process on their behalf. |\n\nThe Service includes compliance **assistance** features (consent fields, calling windows, do-not-call checks, dry-run defaults). It is a **tool, not a compliance certification**. Tenants remain solely responsible for their regulatory obligations.\n\n---\n\n## 2. Personal information we process\n\n### 2.1 Lead & client records (Lead Operations / shared client record)\n\n- **Identity & contact:** name, email, phone, postal address, date of birth (when collected), preferred language.\n- **Insurance / product interest:** product lines, coverage needs, underwriting answers collected in intake or voice flows.\n- **Consent & notices:** `consent_to_store_data`, `consent_to_calls_texts`, `consent_autodialed_written_agreement`, `privacy_notice_provided` (GLBA), channel-specific opt-outs, internal and FTC DNC status when configured.\n- **Operational metadata:** lead score, validation errors, assignment, campaign history, call attempts, incidents, deduplication matches, vendor source fields, quarantine flags.\n- **Voice intake:** call SID, turn transcripts or structured answers from Twilio `<Gather>` flows when voice intake is enabled.\n\n### 2.2 Voice calling & auto-dialer\n\n- Call initiation metadata (timestamps, agent, lead, disposition).\n- Twilio webhook payloads (call status, from/to numbers).\n- Voice approval-transfer and realtime voice session state when those features are enabled.\n- **Call recording:** not enabled by default in Corvlyx voice modules unless your deployment configures it separately.\n\n### 2.3 Outreach & messaging\n\n- **Weekly outreach agent:** email/SMS content, delivery status, unsubscribe events, frequency-cap metadata.\n- **SMS / WhatsApp / Instagram DM agent:** template sends, thread metadata, inbound replies, STOP/opt-out handling, 24-hour care-window replies.\n\n### 2.4 Marketing & lead ingestion\n\n- Vendor ping/post payloads, TikTok and Meta Lead Ads webhook data (including raw `source_fields_raw` preservation).\n- Meta marketing OAuth tokens and page identifiers when connected.\n- Lead discovery (OpenAI-assisted) uses configured models; prompts should not include unnecessary PII.\n\n### 2.5 Financial OS, FNA & proposals\n\n- Financial needs analysis inputs (income, debts, assets, goals) and generated reports.\n- Insurance plan proposals generated from a stored FNA analysis.\n- OAuth tokens for Google Calendar and Gmail (encrypted; no raw passwords).\n\n### 2.6 Agents, licensing & administration\n\n- Agent registry: name, license numbers, states, carrier appointments (self-reported — not verified against NIPR/DOI in the Service).\n- Account-type metadata, seat allocation, license provisioning events.\n- Shared deployment login credentials (password stored hashed; session JWTs).\n\n### 2.7 Audit, security & operations\n\n- Hash-chained audit log entries (`audit_log`, module-specific audit tables).\n- Report access logs, AI audit logs, follow-up send logs, DLQ entries.\n- **Telemetry** (only when `TELEMETRY_ENABLED=true`): allowlisted events with PII scrubbing; lead identifiers hashed where used.\n- Security and rate-limit events; health checks (no consumer PII).\n\n### 2.8 Website & commercial inquiries\n\n- Pilot, demo, and contact form submissions: name, agency, work email, state, plan interest, honeypot fields.\n- Cookie-banner dismissal stored in browser `sessionStorage` on the marketing site (not sent to our servers).\n\n---\n\n## 3. How we use personal information\n\nWe process personal information to:\n\n- provide, operate, secure, and improve the Service;\n- route leads, run campaigns, place calls, and send messages **only where tenant configuration and recorded consent allow**;\n- enforce tenant-configured suppression, calling windows, and dry-run gates;\n- generate worksheets (FNA) and proposals for agent review;\n- sync with connected integrations (Twilio, SendGrid, Google, Meta) when credentials are supplied;\n- maintain tamper-evident audit trails and support incident response;\n- respond to tenant support requests and legal process;\n- comply with applicable law.\n\nWe do **not** sell personal information. We do **not** use tenant consumer data to train public AI models.\n\n---\n\n## 4. Lawful basis & consent\n\n- **Contract:** processing necessary to deliver the Service to the tenant.\n- **Legal obligation:** retention or disclosure where required by law.\n- **Legitimate interests:** security monitoring, fraud prevention, and product reliability — balanced against tenant and individual rights.\n- **Consent:** tenants must obtain and document consumer consent where required (TCPA, state autodial statutes, CAN-SPAM, SMS marketing rules, GLBA privacy notice, etc.). The Service records consent fields and may block actions when consent is missing.\n\n---\n\n## 5. How we share information\n\n### 5.1 At tenant direction (integrations)\n\nWhen the tenant connects third-party services, we share the minimum data needed to:\n\n| Integration | Typical data shared | Purpose |\n|-------------|---------------------|---------|\n| **Twilio** | Phone numbers, message/call bodies, webhook URLs | Voice, SMS, WhatsApp |\n| **SendGrid** | Email addresses, message content | Outreach and transactional email |\n| **Google** (Gmail, Calendar, OAuth) | Email metadata, calendar events, OAuth tokens | Send, threading, scheduling |\n| **Meta** (Lead Ads, WhatsApp, Instagram) | Lead form data, messaging metadata, tokens | Lead capture and messaging |\n| **OpenAI / Anthropic** (if configured) | Prompt content necessary for the feature | Voice, intake, lead discovery, AI qualification |\n\n### 5.2 Infrastructure & subprocessors\n\n| Subprocessor | Role | Location (typical) |\n|--------------|------|------------------|\n| **Render** (or tenant-chosen host) | Application hosting, persistent disk for SQLite | United States |\n| **Twilio** | Telephony and messaging | United States |\n| **SendGrid** | Email delivery | United States |\n| **Google / Meta** | OAuth APIs as connected by tenant | United States / global |\n\nA current subprocessor list should be maintained in your customer agreement or DPA. Update it when integrations change.\n\n### 5.3 Legal & safety\n\nWe may disclose information to comply with law, court order, or government request, or to protect rights, safety, and integrity of the Service.\n\n---\n\n## 6. Security\n\n- **Encryption at rest:** lead blobs, integration tokens, and sensitive columns use AES-256-GCM when `DB_ENCRYPTION_KEY` is set (required in production deployments).\n- **Indexing:** HMAC-SHA256 for exact-match phone/email lookups without storing plaintext in index columns.\n- **Encryption in transit:** HTTPS for all browser and API traffic.\n- **Access control:** API key and session authentication; optional RBAC flags (`RBAC_ENFORCE`). Shared login per deployment today — not per-operator identity.\n- **Operational defaults:** live outreach, messaging, and follow-up sends are **off** until explicitly enabled; promotion workflows available for follow-ups.\n- **Audit:** hash-chained audit entries for sensitive actions where implemented.\n\nNo system is perfectly secure. Tenants should use strong passwords, protect API keys, and limit who can access the operator application.\n\n---\n\n## 7. Retention\n\nDefault retention is driven by **tenant business and regulatory needs** (insurance and GLBA contexts often expect multi-year retention). Unless your agreement specifies otherwise:\n\n- **Lead/client records:** retained until the tenant deletes them or the deployment is decommissioned.\n- **Audit and send logs:** retained for compliance and dispute resolution (default design target: up to **7 years** where not shortened by contract).\n- **OAuth tokens:** retained while the integration is connected; revoked on disconnect.\n- **Website inquiries:** retained for sales follow-up and operational records.\n- **Telemetry:** minimal retention when enabled; no raw PII in catalog events.\n\nDeletion requests: end individuals should contact the **tenant**. Tenants may request Corvlyx assistance to export or delete data in a deployment, subject to legal holds and audit-log exceptions.\n\n---\n\n## 8. Your rights\n\n### 8.1 If you are a consumer or lead\n\nContact the **organization that collected your information** (the tenant). They control your client record. Corvlyx processes data on their instructions.\n\n### 8.2 If you are a tenant operator\n\nYou may access, export, correct, or delete lead data through the Service (where features exist) or by requesting support assistance. You are responsible for honoring end-individual rights for data you control.\n\n### 8.3 California / other US state privacy laws\n\nWhere applicable, tenants may need a separate **Data Processing Addendum** and consumer-facing notices. Corvlyx does not determine the tenant’s consumer-facing privacy policy text.\n\n---\n\n## 9. International transfers\n\nData is primarily processed in the **United States**. Cross-border transfers use appropriate contractual safeguards where required.\n\n---\n\n## 10. Cookies & similar technologies\n\n### Marketing website (`/`)\n\n- **Session storage:** dismisses the cookie/privacy banner for the browser session.\n- **Analytics:** third-party analytics load only if IDs are configured in the deployment; default marketing build ships with none.\n- **No advertising cookies** in the default Corvlyx marketing template.\n\n### Operator application (`/app.html`)\n\n- **Session token:** stored in browser storage for authenticated API calls; required to use the app.\n- **No third-party ad tracking** in the default operator UI.\n\nEmail open/click tracking may occur when outreach or follow-up features enable tracking pixels — tenants should disclose this in their communications.\n\n---\n\n## 11. Children’s privacy\n\nThe Service is not directed to children under 13 (or 16 where applicable). Tenants must not submit children’s personal information without lawful basis and parental consent where required.\n\n---\n\n## 12. Changes to this policy\n\nWe may update this policy to reflect product, legal, or operational changes. We will post the new effective date. Material changes affecting tenants will be communicated through reasonable channels (email, in-app notice, or contract amendment).\n\n---\n\n## 13. Contact\n\n| Matter | Contact |\n|--------|---------|\n| **Tenant support & DPA requests** | support@corvlyx.example (replace before publishing) |\n| **Consumer privacy requests** | Contact the agency or firm that contacted you; they are the data controller |\n| **Security incidents** | support@corvlyx.example |\n\n---\n\n## 14. Related documents\n\n| Document | Scope |\n|----------|--------|\n| [COMPLIANCE.md](../COMPLIANCE.md) | Voice-calling compliance surface (engineering reference, not legal advice) |\n| [CUSTOMER_TERMS_DRAFT.md](../CUSTOMER_TERMS_DRAFT.md) | Draft customer terms (counsel review required) |\n| [WEEK0-RC.md](WEEK0-RC.md) | Consent-gated reads, telemetry, audit |\n\n---\n\n## Appendix A — Data minimization practices (engineering)\n\nThese are product defaults tenants should know about:\n\n- Consent-gated `GET /api/leads/:id` when store consent is missing.\n- Redacted lead views (`?view=redacted`) without email/phone.\n- Report and PDF export masking unless a separate PII access token is presented.\n- Telemetry fail-closed (`TELEMETRY_ENABLED=false` by default on Render).\n- Dry-run defaults for outreach and messaging until live flags and credentials are set.\n"}