1. Who we are
Corvanox ("Corvanox", "we", "us") is a technology services company, an Estonian private limited company (OÜ) in formation, based in Tallinn, Estonia. For any privacy question you can reach us at info@corvanox.com.
We are the data controller for the personal data described in this policy. Where we process data on behalf of a client under a services agreement, we act as a data processor, and that processing is governed by the data processing terms in the relevant contract.
2. What data we collect
- Contact and enquiry data — your name, work email, company, role and the content of messages you send us when you contact us or request a discovery call.
- Technical and usage data — IP address, browser and device type, pages viewed and referring source, collected through cookies and analytics only where you have consented (see our Cookie Policy).
- Client project data — where you engage us, the operational data you provide for the systems we build. This is handled under contract as a processor and only for the purposes you instruct.
3. Why we process it, and our legal basis (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Respond to enquiries and prepare proposals | Steps prior to entering a contract; our legitimate interest in responding to you |
| Deliver and support contracted services | Performance of a contract |
| Analytics to understand and improve the site | Your consent (withdrawable at any time) |
| Meet legal, tax and accounting obligations | Compliance with a legal obligation |
| Protect the site against abuse and secure our systems | Our legitimate interest in security |
4. Who we share it with
We do not sell or rent personal data. We share it only with service providers (processors) who help us run the business, under contract and appropriate safeguards. These currently include hosting and content delivery (Cloudflare), business email and productivity (Google Workspace), and, subject to consent, website analytics. We may also disclose data where required by law.
5. International transfers
Some providers process data outside the European Economic Area. Where they do, transfers are protected by appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision.
6. How long we keep it
We keep enquiry data for as long as needed to respond and for a reasonable follow-up period, and business records for as long as required by Estonian tax and accounting law. Client project data is retained per the relevant services agreement and deleted or returned on its termination.
7. Your rights
Under the GDPR you have the right to access, correct, erase, restrict or object to the processing of your personal data, to data portability, and to withdraw consent at any time without affecting prior processing. To exercise any of these, email info@corvanox.com. You may also lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) or your local supervisory authority.
8. California privacy rights (CCPA / CPRA)
If you are a California resident, you have the right to know what personal information we collect and how we use it, to request deletion or correction, and to opt out of any "sale" or "sharing" of personal information. We do not sell or share personal information as those terms are defined under California law, and we do not use it for cross-context behavioural advertising. To make a request, email info@corvanox.com; we will not discriminate against you for exercising these rights.
9. Cookies
We use cookies and similar technologies as described in our Cookie Policy. Non-essential cookies are set only with your consent, which you give or decline through the banner on this site.
10. Changes to this policy
We may update this policy from time to time. The effective date below shows when it was last revised, and material changes will be reflected on this page.
Effective date: to be set on publication · Contact: info@corvanox.com