Privacy and security

How Credivra handles the documents and personal data you entrust to us.

Data we process

We process the documents your organisation uploads and the account details of the people who use the platform. Documents are stored to support the verification and the audit record connected to them. We do not sell data and we do not use customer documents to train models.

Access control

Access is scoped to your organisation. Every request is authenticated and checked against the permissions of the signed in account, and database rules enforce that separation at the data layer rather than only in the interface. Administrators decide who is approved, what role they hold and when access is withdrawn.

Storage and transport

Traffic between your browser and Credivra is encrypted in transit. Uploaded files are kept in private storage that is not publicly reachable, and access is granted through short lived, permission checked links.

Traceability

Verification steps, outcomes and administrative actions such as invitations, approvals and removals are written to an audit record that is created server side and cannot be edited from the application.

Retention and deletion

Documents and results remain available to your organisation while your agreement is active. On request we remove customer documents and associated results within the timeframe agreed in your contract, keeping only what we are required to retain.

Your rights and questions

If you have a question about how your data is handled, or need to act on a data subject request, contact us and we will respond within one business day.