Trust and vendor file Data inventory and flows
Data inventory and flows
Last reviewed: [DATE]
This document lists every category of data Innorve Academy handles: where it comes from, where it is stored, how long it is kept and who can see it.
No member (consumer) data. The platform is designed to hold no member names, account numbers or member records. Training cases are fictional. The draft DPA prohibits customers from submitting member information.
Data inventory
"Supabase (US)" means the managed PostgreSQL database on AWS in a US region [SUPABASE REGION]. Retention follows the proposed RET-v1 schedule [CONFIRM with counsel]. "90 days after end" means 90 days after the engagement ends, unless the contract says otherwise.
Innorve platform staff administer institutions and cohorts. Through the application they can read institution records except learner drafts, which database rules deny them. Personnel with provider-console access can reach all stored data; that access is restricted as described in Access control. [CONFIRM]
Website visitors
| Data element | Source | Location | Retention | Access |
|---|---|---|---|---|
| Contact and design-partner form submissions: name, work email, organization, job role, asset-size band, program interest, message, consent flag, source page | Visitor submits a form | Supabase (US) | 24 months after last contact, or deleted on request | Innorve platform staff only |
| AI Oversight Snapshot marks (five self-assessment marks) | Included only if the visitor books a call from the Snapshot | Supabase (US), with the lead | Same as the lead | Innorve platform staff only |
| Lead notification | Generated when a form is submitted | Email provider and Innorve's business mailbox [CONFIRM] | [CONFIRM] | Innorve staff |
| Free-tool answers | Visitor | Visitor's own browser (localStorage). Not sent to Innorve. | Until the visitor clears browser data | The visitor only |
Platform users
| Data element | Source | Location | Retention | Access |
|---|---|---|---|---|
| Account: email and display name | Invitation and sign-in | Supabase (US) | 90 days after end, or earlier on request | The user; people in the same institution whose role requires it; Innorve platform staff |
| Invitations: email, roles, cohort, inviter, expiry (30 days) | Institution admin or Innorve staff | Supabase (US) | 90 days after end | Institution admins; Innorve platform staff [CONFIRM] |
| Memberships and roles (learner, reviewer, facilitator, sponsor, institution admin) | Invitation acceptance; admin changes (audited) | Supabase (US) | 90 days after end | Institution admins; Innorve platform staff |
| Cohort enrollments, with any withdrawal reason and optional accommodation note [CONFIRM field is kept] | Invitation; facilitator | Supabase (US) | 90 days after end | Facilitators; Innorve platform staff [CONFIRM] |
| Lesson progress and short reflections | Learner | Supabase (US) | 90 days after end | Learner; facilitators see status [CONFIRM whether they see reflection text] |
| Practice attempts | Learner | Supabase (US) | 90 days after end | Learner [CONFIRM other roles] |
| Lab and assessment submissions (free text only, versioned) | Learner | Supabase (US) | 90 days after end | Learner (own drafts and submissions); reviewers (submitted work only, in scope). Not visible as drafts to facilitators, sponsors or Innorve staff. |
| Reviewer rubric scores, rationale and feedback | Reviewer | Supabase (US) | 90 days after end | Reviewers; the learner, only after release; facilitators see released results; sponsors see aggregates only |
| Pilot workflow boundaries, decisions, owner and authorizer names, authorization references | Learners and facilitators | Supabase (US) | 90 days after end | Enrolled cohort members, facilitators, sponsors (results) |
| Pilot task observations: durations and quality flags; notes (no member data) | Learners and facilitators | Supabase (US) | 90 days after end | Enrolled cohort members, facilitators, sponsors (results) |
| Oversight records: tabletop decision logs; baseline counts from the credit union's own records [CONFIRM in pilot release] | Facilitators | Supabase (US) | 90 days after end | Facilitators; cohort members [CONFIRM] |
| Evidence binder E1 to E8: status, owner names, notes, links to documents in the credit union's own systems | Cohort members and facilitators | Supabase (US). Links only; documents stay in the credit union's systems | 90 days after end | Cohort members; sponsors (status) |
| Cohort CSV exports (assessment records, observations, progress) | Generated on request | Downloaded to the requester's device. Not stored by Innorve. | Customer's control once downloaded | Authorized roles [CONFIRM which]; every export is logged |
Operational and technical data
| Data element | Source | Location | Retention | Access |
|---|---|---|---|---|
| Audit events: actor id, institution id, action, record type, record id, version, timestamp, outcome. No content. | Generated by the database | Supabase (US) | 3 years. Survives institution deletion as references only. | Innorve platform staff; the institution's admins and facilitators [CONFIRM] |
| Sign-in records: email, sign-in times, sessions (including IP address and browser details) | Supabase authentication | Supabase (US) | [CONFIRM per provider] | Innorve platform staff through the provider console |
| Email send log: user id, notification template, time sent, error | Generated when email is sent | Supabase (US) | 90 days after end (with institution) [CONFIRM] | Innorve platform staff only |
| Email content in transit: recipient address, sign-in code or link, notification text | Generated by the platform | Email provider (planned: Resend, US) [CONFIRM before first pilot] | Provider's standard retention [CONFIRM] | Email provider; recipient |
| Server request logs, including IP addresses | Every request | Vercel (US) and Supabase (US) | Provider's standard retention [CONFIRM per provider plan] | Innorve platform staff through provider consoles |
| Database backups | Automated daily | Supabase (US) | 7 days [CONFIRM plan before first pilot] | Supabase; Innorve platform staff for restore |
| Session cookie | Set at sign-in | User's browser (HttpOnly, Secure, SameSite=Lax) | Session lifetime [CONFIRM] | Not readable by page scripts |
Content (not customer data)
| Data element | Source | Location | Access |
|---|---|---|---|
| Course content: lessons, fictional cases, rubrics | Innorve | Web application and database | Enrolled users by program |
| Answer keys and unseen assessments | Innorve | Supabase (US) only, behind role checks. Never in the application code (build check). | Reviewers; learners see an unseen item only after a facilitator releases it; Innorve platform staff |
| Source code | Innorve | Private GitHub repository. No customer data. | Innorve personnel [CONFIRM] |
What is never collected
- Member (consumer) data of any kind.
- Passwords.
- Uploaded files.
- Payment card or bank account details.
- Advertising or analytics data.
- Data sent to any AI model or AI provider.
Data flow diagram
PUBLIC WEBSITE
==============
Visitor's browser
|-- free tools: answers stay in browser localStorage (nothing sent)
|-- Navigator page only: browser fetches fonts from Google Fonts
|
|-- submits form (HTTPS) --> Vercel (US) --> Supabase (US): leads table
|
+--> lead notification --> Innorve [CONFIRM route]
PLATFORM
========
Institution admin or Innorve staff
|-- creates invitation (email, roles, cohort) --> Supabase (US)
|
Email provider (planned Resend, US) <-- sign-in link / 6-digit code
|
v
Staff member's work mailbox (controlled by the credit union)
|
|-- signs in with invited email --> invitation accepted --> membership + enrollment
v
Staff member's browser
| HTTPS only (TLS, HSTS); HttpOnly session cookie
v
Vercel (US): Next.js server code
| checks authorization on every request and export
| acts as the signed-in user (no service key)
v
Supabase (US): PostgreSQL
| row-level security on every query
| composite foreign keys keep each institution's records together
| computes rubric totals; enforces immutability
| writes content-free audit events
|
|-- daily backups (7 days) [CONFIRM plan]
|-- CSV export (authorized roles, logged) --> requester's device
Evidence binder: stores a LINK --> document stays in the credit union's own system,
which enforces its own access control.
Not in any flow: member data, uploads, AI models, analytics or ad trackers.
Where data is stored
All stored customer data is in the United States:
- Supabase: managed PostgreSQL on AWS, US region [SUPABASE REGION].
- Vercel: serverless functions in a US region [VERCEL REGION].
- Email provider: United States [CONFIRM before first pilot].
See Subprocessors for details.