Privacy Policy
Last updated: 22 April 2026 · CHEVORA OÜ · EE102863721
CHEVORA OÜ ("CHEVORA", "we", "us"), registered in Estonia (registry code 17237686, VAT EE102863721), Sepapaja 6, Tallinn 15551, Estonia, is the data controller for personal data processed through chevora.ai.
1. Data We Collect
- Account data: name, email address, company name, billing address.
- Order data: document files you upload, jurisdiction, language selection, payment reference (we never store full card numbers).
- Usage data: pages visited, feature interactions, error logs (no persistent fingerprinting).
- Communication data: support messages, DSAR requests.
2. Legal Basis and Purpose
- Contract performance (Art. 6(1)(b) GDPR): processing your order, delivering reports, sending receipts.
- Legitimate interests (Art. 6(1)(f) GDPR): platform security, fraud prevention, improving service quality.
- Legal obligation (Art. 6(1)(c) GDPR): invoicing, tax records, anti-money-laundering checks.
- Consent (Art. 6(1)(a) GDPR): optional newsletter (you may withdraw at any time).
3. Data Retention
Order data and uploaded documents are retained for 7 years to satisfy EU accounting and tax obligations, then permanently deleted. Support messages are deleted after 2 years. You may request earlier deletion of non-mandatory data via DSAR (see Section 6).
4. Sub-Processors and Transfers
- Supabase (US/EU): database and file storage — EU region, DPA in place.
- Vercel (US): hosting — SCCs and DPA in place.
- Mistral AI (FR): AI analysis of uploaded documents — EU servers, GDPR-native.
- Stripe (US): payment processing — SCCs and DPA in place.
- GoDaddy / Secureserver.net (US): transactional email — SCCs in place.
We do not sell your data to third parties. We do not use your documents to train AI models.
5. Your Rights (GDPR Chapter III)
- Access (Art. 15): obtain a copy of all data we hold about you.
- Rectification (Art. 16): correct inaccurate personal data.
- Erasure (Art. 17): "right to be forgotten" — we delete data not required by law.
- Restriction (Art. 18): limit processing while a dispute is resolved.
- Portability (Art. 20): receive your data in machine-readable format.
- Objection (Art. 21): object to processing based on legitimate interests.
6. Submit a Data Subject Access Request (DSAR)
Email privacy@chevora.ai with: your full name, the email address associated with your account, the type of request (access / erasure / portability / rectification / objection), and any relevant details. We will respond within 30 days as required by GDPR Art. 12(3).
If you believe we have not handled your request correctly, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon): www.aki.ee.
7. Cookies and Tracking
We use only essential session cookies required for authentication and order flow. We do not use advertising cookies or third-party tracking pixels.
8. Changes to This Policy
We will notify registered users by email of material changes at least 30 days before they take effect. The latest version is always available at chevora.ai/privacy.
Data controller: CHEVORA OÜ · Registry 17237686 · VAT EE102863721 · Sepapaja 6, Tallinn 15551, Estonia · privacy@chevora.ai