Legal
Privacy notice
DRAFT for counsel review. Not yet adopted.
Effective date: [EFFECTIVE DATE]
This notice explains how Innorve Inc. handles personal information on the Innorve Academy website at [WEBSITE DOMAIN], in its free tools, and in the Innorve Academy training platform.
Innorve Academy trains credit-union staff on using and overseeing AI. It is designed to hold no member (consumer) data. It does not hold credit-union members' names, account numbers or member records. The training cases are fictional.
1. Who we are
Innorve Inc. ("Innorve", "we", "us") is a company incorporated in [STATE OF INCORPORATION], with its registered address at [REGISTERED ADDRESS]. Innorve works as the credit union's extended team for AI and automation.
Our role depends on how you interact with us:
| You are | Who decides how your information is used | Innorve's role |
|---|---|---|
| A website visitor, or someone who submits a form on the website | Innorve | Controller (a "business" under US state privacy laws, where they apply) |
| A user of the free tools (for example the AI Oversight Snapshot) | You. Your answers stay in your own browser unless you submit a form | Controller only for what you submit |
| A platform user invited by a credit union (learner, reviewer, facilitator, sponsor or institution admin) | Your credit union | Service provider or processor, acting under a data processing addendum (DPA) with the credit union |
| An Innorve facilitator or reviewer | Innorve | Controller |
If you are a platform user, your credit union is responsible for your training records. Innorve processes them on the credit union's behalf and only for the purposes the credit union has agreed to. Your credit union's own privacy and employee notices also apply. Send requests about your training records to your credit union. If you send them to us, we will pass them to your credit union and help it respond.
2. What we collect
2.1 Website visitors and form submissions
When you submit a contact form or a design-partner form, we collect:
- name;
- work email;
- organization;
- job role;
- asset-size band;
- program interest;
- your message;
- whether you consented to be contacted; and
- the page you submitted the form from.
If you book a call from the free AI Oversight Snapshot, we also receive your five self-assessment marks from the Snapshot.
2.2 Free tools
The free tools keep your answers in your own browser (in browser local storage). They send nothing to us unless you choose to submit a form. You can clear your answers at any time by clearing your browser's site data.
2.3 Platform users
If your credit union enrolls you in the platform, we hold the following on its behalf:
- Account: your email address and display name.
- Access: your institution memberships and roles (learner, reviewer, facilitator, sponsor or institution admin), invitations sent to your email address, and your cohort enrollments.
- Enrollment notes: if your credit union records them, a withdrawal reason and an optional accommodation note. The accommodation note is meant to record the adjustment you need (for example, extra time), not a health condition or diagnosis. [CONFIRM this field is kept and how it is described to learners]
- Learning records: lesson progress and short reflections, and practice attempts.
- Lab and assessment submissions: free text only. Each submission is versioned.
- Reviewer records: rubric scores, rationale and feedback. Feedback reaches the learner only when a reviewer releases it.
- Pilot workflow records: workflow boundaries, decisions, the names of the people who own or authorize a workflow, and task observations (durations and quality flags). Notes must not contain member data.
- Oversight program records: facilitator notes from tabletop exercises and baseline counts drawn from the credit union's own records. [CONFIRM these features are in the pilot release]
- Evidence-binder status for elements E1 to E8, with owner names and links to documents. The documents stay in the credit union's own systems. The platform stores the link, not the file. A link does not grant access; access is enforced by the credit union's own system.
The platform has no file upload feature.
2.4 Audit events
The platform records an audit event when certain actions happen, such as changes to records, exports and deletions. An audit event holds the actor's user id, the institution id, the action, the record type, the record id, the version, a timestamp and the outcome. Audit events never contain content such as submission text or feedback. They are designed to survive deletion of an institution, as references only.
2.5 Sign-in, email and request logs
- Sign-in. Sign-in is passwordless. We send a one-time sign-in link or a 6-digit code to your email address. We do not store passwords because there are none. Our authentication provider keeps sign-in records, such as sign-in times and session records, which include your IP address and browser details. [CONFIRM retention]
- Email. We send sign-in codes and platform notifications through an email provider. The provider handles your email address and the message content. We keep a record of which notification was sent to which user and when.
- Request logs. Our hosting and database providers keep server request logs, which include IP addresses. [CONFIRM retention per provider plan]
2.6 What we do not collect
- Credit-union member (consumer) data of any kind.
- Passwords.
- Uploaded files.
- Payment card or bank account details through the website or platform.
- Advertising or analytics data. We use no advertising or analytics cookies and no third-party trackers.
We do not ask for sensitive personal information, such as government identifiers or health information. Please do not enter it in any free-text field.
3. How we use information, and why
We are a US company serving US credit unions. The table explains why we use each kind of information.
| Information | What we use it for | Basis |
|---|---|---|
| Form submissions | Replying to you, arranging calls, discussing a design partnership or engagement | Your request, and your consent to be contacted |
| Snapshot marks (only if you book a call) | Preparing for the call you booked | Your request |
| Platform records | Providing the training the credit union contracted for: delivering lessons, recording progress, supporting review and release of feedback, running the pilot and oversight workflows, and producing cohort reports and exports for authorized roles | The credit union's instructions under its contract and DPA |
| Audit events | Keeping an accountable record of who did what, supporting security investigations, and proving that deletions happened | Security and accountability; the credit union's instructions |
| Sign-in, email and request logs | Signing you in, keeping the service secure, preventing abuse, and fixing problems | Operating and securing the service |
We do not:
- sell personal information;
- share personal information for cross-context behavioral advertising;
- use platform data for our own marketing; or
- send any platform data to an AI model or AI provider. No AI model processes customer data in this version of the platform. See the AI use statement in our trust packet.
EU and UK visitors. The website is aimed at US credit unions. [CONFIRM whether to keep this paragraph] If you are in the European Economic Area or the United Kingdom and you submit a form, we rely on your consent (to reply to you) and on our legitimate interest in responding to business enquiries. You may have rights to access, correct, delete, restrict or object to our use of your information, to data portability and to complain to your local data protection authority. Your information is stored in the United States.
4. Cookies and local storage
| Item | Where | Purpose | Type |
|---|---|---|---|
| Session cookies | Platform, after sign-in | Keep you signed in. They are HttpOnly, Secure and SameSite=Lax. | Strictly necessary |
| Browser local storage | Free tools | Keep your answers on your own device. Nothing is sent unless you submit a form. | Functional, stays on your device |
We use no advertising or analytics cookies and no third-party trackers.
One exception to note. The static AI Obligations Navigator page loads fonts from Google Fonts. When you open that page, your browser contacts Google's servers, and Google receives your IP address and browser details. Google's own privacy policy governs that request. No other page of the site loads resources from a third party.
5. Who we share information with
We share personal information only as described here.
5.1 Service providers (subprocessors)
We use a small number of service providers to run the website and platform. Each one processes data only to provide its service to us.
| Provider | What it does | Location | Data it handles |
|---|---|---|---|
| Vercel Inc. | Hosts the web application; runs serverless functions | United States ([VERCEL REGION]) | All web traffic in transit; request logs, including IP addresses |
| Supabase Inc. | Database and authentication (managed PostgreSQL) | Amazon Web Services, United States ([SUPABASE REGION]) | All stored platform data, form submissions, authentication records, backups and service logs |
| Email provider (planned: Resend, Inc.) [CONFIRM before first pilot] | Sends sign-in codes and notifications | United States | Recipient email address and message content |
Our source code is kept in a private GitHub repository. GitHub holds no customer data.
The current list is kept in our trust packet (docs/trust/subprocessors.md). Credit-union customers receive notice of changes as set out in their DPA.
5.2 Your credit union
If you are a platform user, people at your credit union with the right roles can see your records, within strict limits. For example, reviewers see work you have submitted but not your drafts, and sponsors see only cohort totals, not your individual drafts or detailed scores. The access-control document in our trust packet sets out each role.
5.3 Legal and safety reasons
We may disclose information if the law requires it, to respond to valid legal process, or to protect the rights, property or safety of Innorve, our customers or others. Where the information belongs to a credit-union customer, we will tell the credit union first unless the law forbids it.
5.4 Business transfers
If Innorve is involved in a merger, acquisition or sale of assets, information may transfer as part of that transaction. Platform data stays subject to each credit union's DPA. [CONFIRM]
6. Where information is stored
We store information in the United States. Our hosting and database providers run in US regions.
7. How long we keep information
This is our proposed default retention schedule, called RET-v1. [CONFIRM with counsel]
| Information | How long we keep it |
|---|---|
| Form submissions (leads) | 24 months after our last contact with you, or until you ask us to delete them |
| Free-tool answers | We do not receive them. They stay in your browser until you clear them. |
| Platform records for an institution | Deleted 90 days after the engagement ends, unless the credit union's contract says otherwise. The credit union can export its records (CSV) before deletion. |
| An individual user account (email and display name) | Deleted after the credit union's institution data is deleted, if you belong to no other institution on the platform, or earlier if the credit union asks us to delete the account [CONFIRM process] |
| Audit events | 3 years. They hold references only, never content. |
| Database backups | Deleted data can remain in backups until those backups rotate out, up to 7 days |
| Sign-in, email and request logs | As kept by each provider under its standard retention [CONFIRM per provider plan] |
Deletion is carried out by Innorve platform staff through audited database functions. Deleting an institution requires typing its exact name. Deleting a user account requires typing the person's exact email address.
8. How we protect information
A summary of our safeguards:
- All traffic uses TLS (HTTPS only, with HSTS).
- Our providers encrypt stored data at rest.
- Every institution's records are isolated. Database row-level security checks access on every query, and the server checks authorization again on every request and export.
- The application has no database service key. It acts as the signed-in user.
- Answer keys and unseen assessments are stored only in the database behind role checks. They are never shipped in the web application's code.
- An automated test suite checks tenant isolation and role boundaries.
- Sign-in is passwordless, so there are no passwords to steal from us.
No system is perfectly secure. Our trust packet describes our controls in detail, including what we have not yet done: Innorve does not yet have a SOC 2 report or an independent penetration test.
9. Your choices and rights
9.1 Everyone
You can ask us to:
- tell you what personal information we hold about you;
- correct it; or
- delete it.
Email [PRIVACY CONTACT EMAIL]. We will verify your request, usually by replying to the email address we hold for you. We aim to respond within 45 days. [CONFIRM]
You can also opt out of further contact from us at any time by replying to any message or emailing [PRIVACY CONTACT EMAIL].
Platform users: your credit union controls your training records. We will pass your request to your credit union and act on its instructions.
9.2 California residents
[CONFIRM applicability: counsel to confirm whether Innorve currently meets the CCPA definition of a "business".]
If the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA), applies to us, California residents have the right to:
- know what personal information we collect, use and disclose, and to get a copy;
- delete personal information, subject to legal exceptions;
- correct inaccurate personal information;
- opt out of the sale or sharing of personal information. We do not sell or share personal information, as those terms are defined in the CCPA;
- limit the use of sensitive personal information. We do not collect sensitive personal information for the purpose of inferring characteristics; and
- not be discriminated against for using these rights.
The categories of personal information we collect are described in section 2: identifiers (name, email, IP address), professional information (organization, job role), and internet activity limited to request logs. We collect them from you, from your credit union (for platform users) and automatically (logs). We use them for the purposes in section 3 and disclose them only to the service providers in section 5. We keep them for the periods in section 7.
You, or an authorized agent, can make a request by emailing [PRIVACY CONTACT EMAIL]. We will verify your identity before acting on the request.
9.3 Other US states
Some other states give residents similar rights. Many of those laws do not apply to business-contact information or to information about employees acting in their work role. If a law applies to you, contact us at [PRIVACY CONTACT EMAIL] and we will respond as that law requires. [CONFIRM applicability]
10. Children
The website and platform are for credit-union professionals. They are not intended for anyone under 16. We do not knowingly collect personal information from anyone under 16. If you believe we have, contact us at [PRIVACY CONTACT EMAIL] and we will delete it.
11. Changes to this notice
We will update this notice when our practices change. We will post the new version with a new effective date. If a change materially affects how we handle platform data, we will notify our credit-union customers as their DPA requires.
12. Contact
Innorve Inc. [REGISTERED ADDRESS] Privacy questions and requests: [PRIVACY CONTACT EMAIL]