Privacy Policy · Corivo
Version: 2026-08-31
The Polish version of this document is the binding one. In case of any discrepancy between language versions, the Polish version prevails.
1. Data controller
The controller of Users' personal data is Medialan Paweł Landowski, a sole trader entered in the Polish CEIDG register, registered at ul. Górki Zawadzkie 28C, 33-300 Nowy Sącz, Poland, tax ID (NIP) 5551993726, REGON 361317450, e-mail: support@corivo.pl.
We have not appointed a data protection officer — for any matter concerning the processing of your data, write to the e-mail address above.
2. Two roles: controller and processor
This distinction is key to understanding the whole document.
Where Corivo acts as a processor, we process data solely on the Customer's documented instructions. If your data reached Corivo because you are, for example, a contact or client of a company using the Service, that company is the controller and any requests regarding your rights should be addressed to them.
3. What we process as controller
Account data: first and last name, e-mail address, password (as a hash), profile picture, phone number, address details, language and notification preferences.
Technical data: IP address, session identifier, browser and operating system type, login timestamps.
Document acceptance data: which document, which version, when, from which IP address and using which browser, processed in order to demonstrate consent.
Application error logs: error messages and context, which may include User and Organization identifiers.
Correspondence: the content of support requests and complaints.
4. Legal bases and purposes
5. Recipients of data
Data may be transferred to:
- hosting and infrastructure providers: SEOHOST.PL (servers located in Poland) — the application, the database and stored files run on its infrastructure;
- e-mail providers: handling transactional messages (address verification, password reset, invitations);
- Google Ireland Limited: where you sign in with a Google account or connect the Organization to Google Calendar — limited to authentication data and data synchronised on your instruction;
- artificial intelligence model providers selected by the Customer: see section 6;
- map and geospatial data providers and video players: see section 7;
- entities providing Corivo with accounting and legal services;
- public authorities, where required by law.
6. AI Features
The Service operates on a bring-your-own-key basis: the Customer selects the AI model provider and configures the API key. Data sent to AI features goes directly to that provider and is subject to their privacy policy. Corivo does not intermediate in the choice of provider and does not use Customer data to train its own models.
The Customer controls the AI features' access to Records by choosing one of three modes in the Organization settings:
- full: AI tools see Record data unchanged;
- restricted: personal data (e-mail addresses, phone numbers, personal data in "person" fields, addresses in location fields, longer digit sequences) is masked before reaching the model;
- disabled: tools that reach into Records are not made available to the model at all.
The default mode is full. We recommend a deliberate choice of mode matching the sensitivity of the data processed in the Organization.
7. Maps and geospatial data
The map view, the "location" field, the address search and the route planner fetch data directly from third-party servers, in the User's browser. When you use these features, your device's IP address and the content of the query (the address typed, coordinates, the map extent) reach those parties:
- OpenStreetMap Foundation (United Kingdom) — base map tiles and address search and geocoding (the Nominatim service);
- Project OSRM — route calculation in the route planner;
- Esri (United States) — alternative satellite base map (ArcGIS Online);
- GUGiK / Geoportal, Wody Polskie / ISOK, State Forests (BDL), GDOŚ (Poland) — public data layers: cadastral parcels, utility networks, zoning plans, hydrography and flood risk zones, forest data and protected areas;
- Joint Research Centre of the European Commission (JRC) (European Union) — solar irradiation data.
These parties are separate controllers of the data you send them and process it under their own privacy policies. Requests are sent only when a map feature is opened and are not accompanied by Records — beyond the location you are asking about.
The Service may also embed video (YouTube, Vimeo) where an Organization administrator adds a field
of that type. The player is loaded from the provider's servers and may set its own cookies; for
YouTube we use the no-tracking-cookie mode (youtube-nocookie.com).
8. Templates: what we collect from Configuration
We develop a catalog of ready-made Templates based on Module structures created in the Service. Because this concerns our Customers' data, we describe the mechanism explicitly.
What is collected: the structure of a Module only: names of Modules and fields, field types, detail layout, list view configuration and relationships between Modules.
What is NOT collected:
- Records or any data entered by Users,
- personal data,
- files and attachments,
- the content of AI assistant conversations.
Technically, the mechanism reads only the Module and field definition tables; the Records table is never opened during this process.
How a Template is prepared:
- Automatic masking of contact details and identifiers detected in names, descriptions and labels.
- Removal of references to files belonging to the Organization.
- Flagging for review of any fragments containing the Organization's name.
- Manual review by a Corivo administrator, only afterwards may a Template be published.
Source anonymity: Templates do not disclose which Customer a given Configuration originates from. Provenance information remains solely in the internal administration panel.
Objection: you may at any time request that your Organization be excluded from this mechanism by writing to support@corivo.pl. Exclusion takes effect immediately.
9. Retention periods
10. Transfers outside the EEA
The Service's infrastructure — application servers, database and files — is located entirely in Poland, with the hosting provider SEOHOST.PL. Records, files and Account data are not moved outside the EEA in the ordinary operation of the Service.
A transfer outside the European Economic Area may occur in three situations, each initiated by the Customer's or User's own action:
- An AI model provider outside the EEA configured by the Customer (section 6). The transfer occurs on the Customer's instruction and responsibility, on terms set by that provider; it is for the Customer to assess its legal basis.
- Map features (section 7) — opening a map sends your IP address and query to the OpenStreetMap Foundation (United Kingdom, covered by a European Commission adequacy decision) and, if the satellite base map is selected, to Esri (United States). The data is limited to the IP address and the content of the map query.
- Embedded video players (section 7), where an Organization administrator adds a field of that type.
These transfers do not include Records or Organization files.
11. Your rights
You have the right to: access your data, rectify it, erase it, restrict processing, data portability, object to processing based on legitimate interest, and withdraw consent at any time (without affecting the lawfulness of processing before withdrawal).
Send requests to support@corivo.pl. We respond within one month of receiving a request.
You also have the right to lodge a complaint with the President of the Polish Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw).
12. Automated decision-making
We do not make decisions about you based solely on automated processing that would produce legal effects or similarly significantly affect you. AI Features are advisory in nature and their output is subject to verification by the User.
13. Security
We apply technical and organisational measures appropriate to the risk, including: transport encryption (HTTPS), storing passwords as hashes, role-based access control, data isolation between Organizations, and encryption of AI provider API keys.
14. Cookies
The rules for using cookies are described in the separate Cookie Policy.
15. Changes to this policy
We announce material changes in the Service and by e-mail to the address assigned to the Account, at least 14 days in advance.
This version applies from 2026-08-31.
Document version: 2026-08-31