01Who we are
Scovara is operated by Triven Kadiata, Entrepreneur individuel (EI), established in France (134 avenue des Bleuets, 93370 Montfermeil, France; SIREN 889 890 141). In this policy, “Scovara”, “we” and “us” refer to that operator.
We are the data controller for the account, technical and feedback information described below. When you upload agreements or record client requests that contain information about other people — for example your clients’ names or contact details — you decide what to upload and why, and we process that content to provide Scovara to you.
Scovara has not appointed a data protection officer. For any privacy question, contact dev.triven.kadiata@gmail.com.
02Information we collect
Account information
- Your name, email address and, where available, your profile photo.
- Account identifiers from our authentication provider, and the workspaces you belong to with your role in each.
- If you sign in with Google, the basic profile information Google shares for sign-in: your name, email address and profile photo. We do not receive your Google password.
Passwords, email verification and sign-in sessions are handled by our authentication provider. Scovara does not store your password.
Workspace and project information
- Workspace names and members.
- Project names, client names and project descriptions.
Agreements you upload
- The files you upload, such as agreements, statements of work and similar contract documents, with their file name, type and size.
- The text extracted from those files, split into sections so it can be referenced as evidence.
- The scope proposed from each agreement, the changes you make to it, and who verified it and when.
Client requests
- The request text you enter, the sender name if you provide it, and the date it was received.
- The analysis of each request: its classification, the contract evidence cited, explanations, any estimates and suggested responses.
- The decision recorded by your team, any internal note, who made the decision and when.
Change requests
- Change request drafts and their deliverables, the edits you make, finalized change requests, and the PDF documents generated from them.
Feedback
- Bug reports, feature requests and other feedback you send from within Scovara, the page you were on when you sent it, and whether you agreed to be contacted about it.
Technical information
- A cookie that remembers which workspace you selected, and the session information our authentication provider needs to keep you signed in, including information about your signed-in devices.
- Operational records of background processing, such as job status and error messages, used to run and repair the service.
- Our hosting and infrastructure providers process technical request information, such as IP addresses and browser details, as part of delivering the service.
Website analytics
On our public website pages (the home page, pricing, guides and legal pages), we use Vercel Web Analytics to understand how many people visit and which pages they view. This analytics is cookieless and stores nothing on your device. For each page view, Vercel receives the page address without any query string, the website that referred you if you came from another site, your approximate location (country, region and city), your browser, operating system and device type, and the time of the visit. Vercel tells visitors apart with a hash of the incoming request that is discarded after 24 hours, and gives us aggregated statistics only.
Pages inside the signed-in application, and the sign-in and sign-up pages, are not measured. Scovara does not use advertising trackers and does not build advertising profiles.
03How we use information
We use the information described above to:
- create and operate your account and workspaces, and sign you in;
- store your projects, agreements, client requests and change requests;
- extract text from agreements and propose scope for your review;
- analyze client requests against the scope your team verified, and show the supporting evidence;
- draft responses and change requests, and generate change request PDFs;
- manage paid subscriptions and billing;
- keep the service secure, prevent abuse, diagnose errors and keep processing reliable;
- review feedback and, where you agreed, contact you about it;
- measure visits to our public website pages in aggregate, to understand which pages are useful;
- comply with legal obligations that apply to us.
The operator’s platform administration can view account, workspace, project, request and feedback records where needed to support users, investigate problems, moderate feedback and keep the service running. We do not sell personal information.
04Legal bases for processing
Where the EU General Data Protection Regulation (GDPR) applies, we rely on the following legal bases:
- Performance of a contract — to create and operate your account and to process the content you submit so Scovara can provide the features you use.
- Legitimate interests — to secure the service, prevent abuse, debug errors, keep processing reliable, improve Scovara, measure visits to our public website in aggregate and respond to feedback. We consider these interests not to override your rights, given the limited technical information involved.
- Legal obligation — to keep records or respond to requests where the law requires it.
Scovara does not currently rely on consent as a legal basis. If that changes, we will ask for consent first and you will be able to withdraw it at any time.
05AI processing
Scovara uses AI models provided by OpenAI to assist with tasks such as:
- extracting a proposed scope from an uploaded agreement;
- comparing a client request with the scope your team verified, and citing the relevant evidence;
- drafting explanations and suggested responses;
- drafting change requests.
To do this, the relevant content — such as agreement text, verified scope entries, client request text and related project details — is sent to OpenAI for processing.
AI output is advisory. It can be incomplete or wrong. Proposed scope must be reviewed and verified by your team before it is used for analysis, and decisions on client requests are recorded by people, not by the AI. Classifications are not legal advice, and the AI does not change your contracts. Review generated content before you rely on it or send it to anyone.
We do not use AI output to make decisions about you that produce legal or similarly significant effects.
06Uploaded agreements and client requests
Agreements and change request PDFs are stored as private files and are not publicly accessible. Their content is shown only to signed-in members of the workspace they belong to, and to the operator’s platform administration where needed as described above.
These documents often contain confidential business information and may contain personal data about you, your colleagues or your clients. Only upload content you are allowed to share with Scovara and the service providers listed below, and avoid uploading sensitive personal data that Scovara does not need.
07Service providers
We rely on the following providers to run Scovara. They process information on our behalf for these purposes:
- Clerk — sign-in, account management and session security.
- Google — optional “Sign in with Google”, only if you choose it.
- OpenAI — AI-assisted scope extraction, request analysis and drafting.
- Cloudflare (R2) — private storage of uploaded agreements and generated PDFs.
- Trigger.dev — running background jobs such as document processing, AI analysis and PDF generation.
- Vercel — hosting the Scovara web application, and cookieless website analytics for our public pages (see Website analytics).
- Our managed PostgreSQL database provider — storing application data.
Each provider processes information under its own terms and privacy policy. We may disclose information if the law requires it, or to protect the rights, property or safety of Scovara, our users or others.
Payments and billing — Stripe
We use Stripe to process subscription payments, manage billing and subscription-related services, support payment security and fraud prevention, and assist with payment recovery where applicable.
When you purchase or manage a paid subscription, Stripe may process information such as your name, email and contact details, billing information (such as a business name, billing address and, where you provide one, a tax identification number such as a VAT number), transaction and subscription details, and payment-method information. Payment details and tax identification numbers are entered on Stripe’s pages. Scovara does not store your full payment-card details.
Stripe processes personal data in accordance with its own privacy practices, described in Stripe’s Privacy Policy.
Connected services — Slack
If a workspace owner or admin connects Slack and maps a Slack channel to a Scovara project, Scovara may receive new messages and related source information from that channel in order to create and analyze client requests. Imported messages are analyzed individually; prior Slack conversation history is not used as analysis context. Scovara does not automatically post replies to Slack. Events from channels that are not mapped to a Scovara project may still reach Scovara, but they are discarded and are not imported as client requests.
Depending on the data provided by Slack, Scovara may process message content, sender information (the Slack user identifier and the sender’s display name), channel and workspace identifiers and names, and message or event identifiers and timestamps needed to associate and deduplicate requests. We use this information to import client requests from mapped channels, associate each request with the right project, show where it came from and who sent it, perform Scovara’s scope analysis, and avoid recording the same Slack message twice.
Imported Slack messages become client requests and follow the retention rules for project content described under Data retention. Disconnecting Slack stops new imports but does not delete requests that were already imported.
Credentials used to maintain the Slack integration are stored in protected, encrypted form.
Customers are responsible for ensuring that they are authorized to connect Slack channels to Scovara and for providing any notices required to channel participants under applicable law.
Slack is a third-party service and processes information according to its own privacy practices, described in Slack’s Privacy Policy.
08International data transfers
Several of the providers above are based in the United States, and information may be processed in the United States or other countries outside the European Economic Area.
Where personal data is transferred outside the European Economic Area, we rely on the transfer mechanisms made available by those providers under the GDPR, such as the European Commission’s Standard Contractual Clauses or an adequacy decision where one applies. You can contact us for more information about these safeguards.
09Data retention
We keep information for as long as it is needed to provide Scovara, and in particular:
- Account, workspace and project content — including agreements, client requests, analyses, decisions and change requests — is kept while your account and workspace remain active, unless it is deleted earlier.
- Files whose upload was started but never completed are not treated as agreements and are removed automatically by a storage rule.
- Feedback is kept while it is useful for supporting you and improving Scovara.
- Some technical and operational records may be kept for longer where needed for security, to resolve disputes or to meet legal obligations.
Scovara does not currently apply fixed automatic deletion periods to workspace content.
10Account and project deletion
Scovara does not yet offer self-service deletion of accounts, workspaces, projects, agreements or client requests. You can edit or remove proposed scope entries while reviewing an agreement’s scope.
To delete your account, a workspace or specific content, email dev.triven.kadiata@gmail.com from the address linked to your account. We will verify the request and delete the data concerned, including the related stored files, unless we need to keep some of it for a legal reason, which we will explain.
Removing your sign-in account with our authentication provider does not, on its own, delete your Scovara workspace content. Copies of deleted data may remain for a limited time in backups kept by our infrastructure providers.
11Security
We use reasonable technical and organizational measures designed to protect information, including authentication for every workspace page, access checks on workspace content, private file storage and encrypted connections (HTTPS).
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe your account has been compromised, contact us.
13Your rights
Where the GDPR applies, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict how we process your data;
- object to processing based on our legitimate interests;
- receive data you provided in a portable format;
- withdraw consent at any time, where processing is based on consent.
To exercise these rights, email dev.triven.kadiata@gmail.com. We may need to verify your identity, and we aim to respond within one month.
You also have the right to lodge a complaint with a supervisory authority. In France, this is the CNIL (Commission nationale de l’informatique et des libertés, www.cnil.fr).
14Children
Scovara is a professional tool and is not intended for children. You must be at least 18 years old to use it, and we do not knowingly collect personal data from children.
15Changes to this policy
We may update this policy as Scovara changes. The “Last updated” date above shows when it last changed. If we make significant changes, we will let you know in Scovara or by email before they take effect.
16Contact
For privacy questions or requests, email dev.triven.kadiata@gmail.com, or write to Triven Kadiata, 134 avenue des Bleuets, 93370 Montfermeil, France.
See also our Terms of Service and Legal Notice.
