Privacy Policy
Effective Date: January 1, 2026 • Last Updated: August 20, 2026
Your client briefs, fee schedules, contracts, and proposals are never used to train public LLMs or third-party foundation models. Your data remains isolated strictly to your tenant.
All documents, signed agreements, client records, and GST invoices are encrypted with AES-256 at rest and transmitted strictly over TLS 1.3 protocols.
1. Information We Collect
When you operate your workspace on Cora, we collect only the minimum required data to provide our autonomous operating services:
- Account Credentials: Name, work email, business name, and phone number for secure 2FA authentication.
- Workspace Records: Leads in CRM pipelines, client appointments, team assignments, and contract signatories.
- Financial Identifiers: Business GSTIN, PAN, billing address, and bank payout details for invoice rendering.
- Technical Metadata: IP addresses, browser user-agents, and audit timestamps for SHA-256 e-signature validity.
2. How We Use Your Data
Your data is processed strictly to power your day-to-day business operations across all professional service workflows:
- Generating automated 18% CGST/SGST/IGST tax invoices and calculation breakdowns.
- Orchestrating autonomous AI workflows (proposals, voice-to-scope, and appointment scheduling).
- Cryptographically sealing legal contracts and recording immutable SHA-256 audit logs.
- Delivering automated WhatsApp and email updates to your clients and team members.
3. Data Isolation & Multi-Tenant Architecture
Every business workspace is logically separated in our multi-tenant database using strict row-level security (RLS). No other business, operator, or team can ever query, view, or access your files, client lists, or financial ledgers.
4. Third-Party Sub-Processors
We partner only with verified, enterprise-grade cloud infrastructure providers that maintain SOC-2 and ISO-27001 certifications:
5. Global Privacy Rights & Data Deletion
Under the Indian Digital Personal Data Protection (DPDP) Act 2023, GDPR, and CCPA, you have full authority to export your data or request complete account erasure:
- One-Click JSON/CSV Export: Download your entire lead history, contracts, and invoices anytime.
- Permanent Workspace Erasure: Upon request, all database records, backups, and storage buckets are permanently deleted within 30 days.
6. Privacy Officer Contact
For data access requests, DPA agreements, or privacy inquiries, contact our Data Protection Officer directly: