CORA
DATA INTEGRITY & PRIVACY

Privacy Policy

Effective Date: January 1, 2026 • Last Updated: August 20, 2026

Zero AI Model Training

Your shoot briefs, rate cards, and client proposals are never used to train public LLMs or proprietary foundation models. Your data remains isolated to your tenant.

AES-256 Bank Grade Encryption

All documents, signed contracts, and GST invoices are encrypted with AES-256 at rest and transmitted strictly over TLS 1.3 protocols.

1. Information We Collect

When you operate your workspace on Cora, we collect only the minimum required data to provide our autonomous operating services:

  • Account Credentials: Name, work email, studio name, and phone number for 2FA authentication.
  • Workspace Records: Leads in CRM pipelines, shoot dates, crew roster assignments, and contract signatories.
  • Financial Identifiers: Business GSTIN, PAN, billing address, and bank payout details for invoice rendering.
  • Technical Metadata: IP addresses, browser user-agents, and audit timestamps for SHA-256 e-signature validity.

2. How We Use Your Data

Your data is processed strictly to power your day-to-day studio operations:

  • Generating automated 18% CGST/SGST/IGST tax invoices and calculation breakdowns.
  • Orchestrating autonomous AI workflows (proposals, voice-to-scope, and shoot call sheets).
  • Cryptographically sealing legal contracts and recording immutable SHA-256 audit logs.
  • Delivering automated WhatsApp and email reminders to your clients and crew.

3. Data Isolation & Multi-Tenant Architecture

Every studio workspace is logically separated in our multi-tenant database using strict row-level security (RLS). No other studio, operator, or team can ever query, view, or access your files or financial ledgers.

4. Third-Party Sub-Processors

We partner only with verified, enterprise-grade cloud infrastructure providers that maintain SOC-2 and ISO-27001 certifications:

Cloud Hosting
AWS & Hostinger Enterprise (Mumbai / Global)
AI Orchestration
Anthropic Claude & Google Vertex AI APIs
Payment Gateways
Razorpay & Stripe (PCI-DSS Level 1)

5. Global Privacy Rights & Data Deletion

Under the Indian Digital Personal Data Protection (DPDP) Act 2023, GDPR, and CCPA, you have full authority to export your data or request complete account erasure:

  • One-Click JSON/CSV Export: Download your entire lead history, contracts, and invoices anytime.
  • Permanent Workspace Erasure: Upon request, all database records, backups, and storage buckets are permanently shredded within 30 days.

6. Privacy Officer Contact

For data access requests, DPA agreements, or privacy inquiries, contact our Data Protection Officer directly:

Cora Platforms Inc. • Data Protection Officer
Response Time: Within 24 business hours