Skip to content

Legal

Privacy notice

Effective · Questions: support@techvora.net

We handle as little personal data as we need to run ContractIQ well, keep it in the European Union, and never sell it. This notice sets out the detail.

01Who we are

ContractIQ is a contract lifecycle management service provided by Techvora, which operates from Ireland in the European Union. In this notice, “we”, “us” and “our” mean Techvora.

This notice explains what personal data we handle when you visit this website, contact us, or use ContractIQ as a member of a customer organisation, why we handle it, and the choices and rights you have.

02Controller and processor

Customer contract data. When an organisation uses ContractIQ, it decides what contracts, documents, counterparties, obligations, comments and other information to record. For that information the customer organisation is the controller and Techvora is its processor: we process it only to provide the service, on the customer’s instructions and under our terms of service.

Our own data. Techvora is the controller of the personal data we need to run our business and the service itself — for example account and sign-in records, security logs, messages sent through our contact form, and information about customer subscriptions.

If your question concerns information your organisation has recorded in ContractIQ, please contact that organisation first. We will help it respond.

03What we collect

Account and membership

  • Your name, work email address, the organisations you belong to and your role in each.
  • A bcrypt hash of your password. We never store or log the password itself.
  • Preferences you set, such as your timezone and notification choices.

Security and usage records

  • Sessions: a hash of the session token, when it was created and last used, and your browser’s user agent.
  • A keyed hash of your IP address, used for rate limiting and security. We do not store the IP address in readable form in these records.
  • Sign-in attempts and an audit log of changes made in the service — who did what, and when. Audit entries name the fields that changed, not their confidential values.

Contact form

  • Your name, email address, organisation (if you give it), the topic, your message and a keyed hash of your IP address.

Customer content

  • Whatever a customer organisation chooses to record in ContractIQ, which may include names and contact details of its staff and of people at its counterparties. We process this as a processor.

04How we use it and our lawful bases

Under the General Data Protection Regulation (GDPR) we rely on the following lawful bases:

  • Performance of a contract — to create and secure accounts, provide ContractIQ to customer organisations and their members, and send the service messages that go with it, such as invitations, password resets and reminders.
  • Legitimate interests — to keep the service secure (rate limiting, lockout, audit logs, investigating misuse), to reply to messages sent through the contact form, and to understand and improve the service at an aggregate level. We balance these interests against your rights, and you may object.
  • Legal obligation — to keep records we are required to keep, and to respond to lawful requests.
  • Consent — only where we ask for it explicitly. You can withdraw consent at any time.

Where we process customer content as a processor, the customer determines the lawful basis.

05What we do not do

  • We do not sell personal data or customer content.
  • We do not process customer contracts or documents with AI services, and we do not use them to train models.
  • We do not use advertising or tracking cookies, and we do not build marketing profiles.
  • Running the service does not mean reading customers’ agreements. Techvora’s operator tools show organisation-level information, such as the organisation’s name, number of members, storage used and subscription state — not contract records or documents.

06Service providers

We use a small number of providers to run ContractIQ. Each processes personal data only on our instructions and under data processing terms.

  • Supabase — managed PostgreSQL database and private file storage, hosted in AWS eu-west-1 (Ireland).
  • Vercel — application hosting, with server compute in its Dublin region. As a global network, Vercel may route your requests through locations near you.
  • Email delivery provider, where enabled — delivery of service emails such as invitations, password resets and reminders.

We will inform customers before adding or replacing a provider that processes customer content, so they can raise any objection.

07Where data is stored

Customer data and account data are stored in the European Union. If a provider needs to process personal data outside the European Economic Area — for example to deliver an email or route a web request — we rely on appropriate safeguards recognised under the GDPR, such as an adequacy decision or the European Commission’s Standard Contractual Clauses.

08Cookies

We use only cookies that are strictly necessary for the service to work:

  • contractiq_session — keeps you signed in. It is httpOnly, so page scripts cannot read it.
  • contractiq_org — remembers which organisation you last worked in, if you belong to more than one.

Because these cookies are essential and there are no analytics, advertising or tracking cookies, we do not show a cookie consent banner.

09How long we keep data

  • Customer content is kept for as long as the customer’s subscription continues. When a subscription ends, the customer can export its data; we then delete the organisation’s data from the live service after a short period that we confirm to the customer at the time. Copies in the hosting provider’s managed backups expire in line with that provider’s backup cycle.
  • Account records are kept while you are a member of an organisation using ContractIQ, and removed or anonymised when they are no longer needed.
  • Audit and security records are kept for the life of the organisation’s account, because they are the record of who changed what. Rate-limiting records are short-lived.
  • Contact form messages are kept for as long as needed to respond and follow up, and then deleted.

10Security

We protect personal data with technical and organisational measures appropriate to the risk, including organisation isolation enforced in the database, strong password hashing, private document storage and encryption in transit. Our security page describes these controls in detail. If we become aware of a personal data breach affecting customer data, we will notify the affected customer without undue delay.

11Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and receive a copy;
  • have inaccurate data corrected;
  • have data erased, or its processing restricted, in certain circumstances;
  • receive data you provided in a portable format;
  • object to processing based on our legitimate interests; and
  • withdraw consent where we rely on it.

To exercise a right, email support@techvora.net or use the contact form with the topic “Privacy”. We may need to confirm your identity. We respond within the time the law requires. For data recorded by a customer organisation, we will pass your request to that organisation and help it respond.

You also have the right to complain to a supervisory authority. In Ireland this is the Data Protection Commission; you may also contact the authority where you live or work.

12Children

ContractIQ is a business service and is not intended for anyone under 18. We do not knowingly collect personal data from children.

13Changes to this notice

We may update this notice as the service changes. We will change the effective date above and, where the changes are significant, tell customers in advance.

14Contact

Questions about this notice or about how we handle personal data can be sent to support@techvora.net.