Privacy Policy
Last updated: July 10, 2026
This document is provided in English. If it is made available in other languages, the English version prevails in case of conflict.
This Privacy Policy explains how CovenorOS (“CovenorOS”, “we”, “us”, or “our”) collects, uses, and protects personal data when you visit our website, create an account, or use the CovenorOS platform (the “Service”).
CovenorOS is a cloud-based platform that helps nonprofit organizations manage their operations. It is operated by [Insert company legal name], a Romanian legal entity (registered office: [Insert registered office]).
This Policy should be read together with our Terms & Conditions. Capitalized terms used here have the meaning given in the Terms & Conditions.
1. Our Role: Controller and Processor
CovenorOS acts in two different roles under the General Data Protection Regulation (EU) 2016/679 (“GDPR”):
- As a controller for the personal data of visitors and Users that we collect for our own purposes — for example account registration data, contact form submissions, and technical logs.
- As a processor for the personal data that Customer organizations store in their Workspace — for example information about their donors, volunteers, members, beneficiaries, employees, or partners (“Customer Data”). For this data, the Customer organization is the controller and decides why and how it is processed; we process it only to provide the Service.
If you are a donor, volunteer, beneficiary, or other individual whose data was entered into CovenorOS by an organization you interact with, please direct privacy questions and requests to that organization first. We will support the organization in responding, as required by GDPR.
2. Personal Data We Collect
Depending on how you interact with the Service, we may collect:
- Account data — your name, email address, and authentication credentials (a hashed password, a magic-link sign-in, or your Google account identity if you choose to sign in with Google).
- Organization data — the legal name, fiscal identification code (CUI), and related details of the organization you register, and your role within it.
- Contact and demo requests — the name, email address, organization, subject, and message you submit through our contact form.
- Customer Data — the operational records your organization stores in its Workspace (projects, donors, volunteers, beneficiaries, financial records, documents, reports). We process this data as a processor on the organization's behalf.
- Technical data — IP address, browser and device information, timestamps, and log data generated when you use the Service, used for security, debugging, and service operation.
- Usage data — aggregated, privacy-friendly analytics about how pages of the Service are used (see the Cookies section below).
3. Purposes and Lawful Bases
We process personal data for the following purposes and lawful bases:
- To create and manage your account and provide the Service — performance of a contract (GDPR art. 6(1)(b)).
- To respond to contact and demo requests — our legitimate interest in responding to enquiries (art. 6(1)(f)) and steps taken at your request before entering into a contract (art. 6(1)(b)).
- To secure the Service, prevent abuse, and keep audit records — our legitimate interest in protecting the Service and its users (art. 6(1)(f)).
- To send service communications such as invitations, notifications, and important account or legal notices — performance of a contract and legitimate interest.
- To improve the Service using aggregated or anonymized usage information — our legitimate interest in developing the product.
- To comply with legal obligations, including accounting and tax rules — legal obligation (art. 6(1)(c)).
- Customer Data is processed on the documented instructions of the Customer organization (the controller), under the Terms & Conditions and, where applicable, a Data Processing Agreement.
We do not sell personal data and we do not use it for third-party advertising.
4. AI-Assisted Features
Some features of the Service use artificial intelligence to assist you — for example, suggesting how the columns of an imported file map to CovenorOS fields during data migration.
- When you use an AI-assisted feature, only the data needed for that feature (for example, column headers and a small sample of the file being imported) is sent to the AI model provider, solely to produce the result.
- AI output is advisory and is always shown to you for review before anything is saved.
- We do not permit AI providers to use data submitted through the Service to train their models, to the extent the provider offers that control.
5. Service Providers and Subprocessors
We use a small number of carefully selected service providers to operate CovenorOS. Where they process personal data on our behalf, they act under data processing terms consistent with GDPR:
- Vercel — application hosting and privacy-friendly, cookieless web analytics.
- Supabase — database, authentication, and file storage.
- Resend — transactional email delivery (magic links, invitations, notifications, contact form delivery).
- Sentry — error monitoring, used to detect and fix defects in the Service.
- Google — if you choose to sign in with your Google account (OAuth authentication).
- AI model providers — only when you use an AI-assisted feature, as described in section 4.
Messages sent through our contact and demo-request form are also delivered to the email inboxes of the CovenorOS team members who handle enquiries; those inboxes may be hosted by third-party email providers, including Google (Gmail).
We may add or replace providers as the Service evolves. Material changes to this list will be reflected in an updated version of this Policy.
6. International Transfers
Our service providers may store and process data on infrastructure located outside the EU/EEA, including in the United States. Where personal data is transferred outside the EU/EEA, transfers are protected by an adequacy decision of the European Commission (including the EU–U.S. Data Privacy Framework, where the provider is certified) or by Standard Contractual Clauses and additional safeguards, as required by Chapter V of the GDPR.
7. Data Retention
We keep personal data only as long as it is needed:
- Account data — for as long as your account exists, and for a limited period afterwards to allow reactivation, resolve disputes, and meet legal obligations.
- Customer Data — for as long as the Customer organization uses the Service; after termination it is retained for a limited period to allow export, then deleted or anonymized (see the Terms & Conditions, section 23).
- Contact form messages — for as long as needed to handle the enquiry and maintain a record of the correspondence.
- Technical logs and backups — for limited, rotating periods appropriate to security and disaster recovery.
- Data we must keep by law (for example accounting records) — for the period required by the applicable law.
8. Security
We apply technical and organizational measures appropriate to the risk, including HTTPS encryption in transit, encryption at rest for stored data, secure password hashing, role- and permission-based access controls (including row-level security in our database), managed cloud infrastructure, backups, and monitoring.
No online service can be guaranteed completely secure. If we become aware of a personal data breach affecting your data, we will act in accordance with our GDPR obligations, including notifying the competent supervisory authority and affected controllers or individuals where required.
10. Your GDPR Rights
Where CovenorOS is the controller of your personal data, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data (“right to be forgotten”), where applicable;
- Restrict or object to processing based on our legitimate interests;
- Receive your data in a portable format;
- Withdraw consent at any time, where processing is based on consent;
- Lodge a complaint with a supervisory authority — in Romania, the National Supervisory Authority for Personal Data Processing (ANSPDCP, www.dataprotection.ro), or the authority of your habitual residence.
To exercise these rights, contact us at contact@covenoros.com. We will respond within the timeframes required by GDPR. Where CovenorOS acts as a processor, we will forward your request to the Customer organization that controls your data and support them in responding.
11. Children
The Service is intended for use by organizations and their adult Users; we do not knowingly allow individuals under 18 to create accounts. Customer organizations that store data about minors (for example beneficiaries of their programs) are responsible, as controllers, for having a lawful basis and appropriate safeguards for doing so.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When changes are material, we will take reasonable steps to notify you, such as by email, in-product notice, or a notice on our website. The date at the top of this page shows when the Policy was last updated.
13. Contact
For privacy questions or requests, contact:
- CovenorOS
- Legal name: [Insert company legal name]
- Registered office: [Insert registered office]
- Email: contact@covenoros.com
