Legal
Privacy policy
Version 1.0 · Last updated: August 10, 2026
This is a courtesy translation provided for convenience. Correvo operates under Colombian law and the Spanish version of this policy is the binding text. In the event of any discrepancy between the two versions, the Spanish version prevails.
1. Data controller
The controller of the personal data collected through the Correvo platform is:
| Name | Andrés Mauricio Quiroga Molina |
| Tax ID (NIT) | 1007422146-4 |
| Address | Calle 11 # 6A-56, ChÃa, Cundinamarca, Colombia |
| Contact email | contacto@correvo.app |
This policy is governed by Colombian Law 1581 of 2012, Chapter 25 of Decree 1074 of 2015 and the other Colombian personal data protection regulations, and supplements the Terms and conditions of the Service.
2. What data we process and in what capacity
As a controller, Correvo processes the data required for its own commercial relationship with the Customer: account registration data (name and email address), billing information, audit logs, technical logs and Platform usage metrics.
As a processor, Correvo processes Customer Content — the emails, attachments, contacts, internal comments, drafts, templates and signatures that the Customer and its users store on the Platform. With respect to this data, the Customer is the controller and Correvo acts exclusively on its instructions.
Correvo does not store full credit or debit card details: payment information is processed by the Mercado Pago gateway, which acts as an independent controller with respect to that information.
3. Purposes of processing
- Providing the Service: receiving, storing, indexing, displaying and sending the Customer's email.
- Managing registration, authentication, billing and communication with the Customer.
- Maintaining Platform security, including audit logs of sensitive actions.
- Complying with legal, accounting and tax obligations.
Correvo does not use Customer Content for advertising or commercial purposes, does not sell it or share it with third parties for those purposes, and does not use it to train, fine-tune or improve artificial intelligence models, whether its own or those of third parties.
4. Private correspondence and human access
Customer Content constitutes private correspondence, protected by Article 15 of the Colombian Constitution. Correvo personnel do not access the content of Customers' emails, except in three cases: (a) when the Customer expressly requests it in writing in order to resolve a support incident; (b) when it is indispensable in order to address a critical security incident; or (c) when ordered by a competent authority. Any access carried out under these circumstances is recorded in the audit system and reported to the Customer, unless expressly prohibited by law.
5. Artificial intelligence features
The Platform's AI features are limited to generating thread summaries and reply drafts, and run only on the threads that the user expressly selects, action by action. There is no bulk, automatic or preemptive AI processing of Customer Content, and the AI never sends email automatically. Execution takes place through third-party language model providers acting as sub-processors. The Customer can disable these features for its entire organization from the Platform settings.
6. Processors, sub-processors and international transfers
To provide the Service, Correvo relies on the following sub-processors:
| Sub-processor | Function | Processing location |
|---|---|---|
| Supabase | Database, authentication, queues | Brazil |
| Clouding.io | Compute infrastructure | Spain |
| Resend, Inc. | Inbound and outbound email transport | United States |
| Cloudflare, Inc. | Storage of attachments and original messages | Cloudflare global network |
| Language model provider | Thread summaries and drafts | United States |
| Mercado Pago | Payment processing | Latin America |
Providing the Service involves processing personal data outside Colombian territory, in the countries listed above. Correvo maintains data protection obligations with each sub-processor that are no less strict than those it assumes towards the Customer, and is liable for the conduct of its sub-processors. Any addition or replacement is notified to the Customer at least thirty (30) calendar days in advance.
7. Information security
- Logical isolation between organizations through database-level and application-level controls.
- Integration credentials (such as the Resend API key) stored encrypted and used solely to operate the Service.
- Attachments stored privately, accessible only through temporary signed links.
- HTML sanitization, remote images blocked by default, detection of the actual attachment type, antimalware scanning and blocking of dangerous file types — all automated, with no review of the content of the correspondence.
- Audit logging of sensitive actions.
In the event of a security incident affecting the Customer's personal data, Correvo will report it without undue delay and no later than within forty-eight (48) hours of becoming aware of it.
8. Retention, export and deletion
On paid plans, Customer Content is retained indefinitely, subject to the plan's storage quota. On the Free plan, messages older than thirty (30) days are deleted automatically, with prior notification by email.
The Customer may export all of its Content in MBOX format — an open standard — at any time, free of charge, including after cancelling. Once the contract ends: for the first thirty (30) days the account remains in read-only mode with export available; between days 31 and 90 the Content is kept in cold storage, recoverable upon request; from day 91 onwards it is permanently and irreversibly deleted.
9. Data subject rights and contact channel
Under Colombian Law 1581 of 2012, data subjects may access, update and rectify their data; request proof of the authorization granted; be informed about the use made of their data; file complaints with the Superintendency of Industry and Commerce (Superintendencia de Industria y Comercio); revoke their authorization and request the deletion of their data where no legal or contractual duty to retain it exists.
To exercise these rights, write to contacto@correvo.app. Enquiries and claims are handled within the time limits set out in Articles 14 and 15 of Law 1581 of 2012. Where the request concerns data contained in a Customer's correspondence (in respect of which Correvo acts as a processor), the request will be forwarded to the responsible Customer where it is for that Customer to handle it.
10. Changes to this policy
Correvo may update this policy to reflect regulatory, technical or operational changes. Material changes will be notified to the Customer by email with reasonable advance notice, and the version in force will always be published on this page together with its update date.
