Trust and vendor file Data inventory and flows

Data inventory and flows

Last reviewed: [DATE]

This document lists every category of data Innorve Academy handles: where it comes from, where it is stored, how long it is kept and who can see it.

No member (consumer) data. The platform is designed to hold no member names, account numbers or member records. Training cases are fictional. The draft DPA prohibits customers from submitting member information.

Data inventory

"Supabase (US)" means the managed PostgreSQL database on AWS in a US region [SUPABASE REGION]. Retention follows the proposed RET-v1 schedule [CONFIRM with counsel]. "90 days after end" means 90 days after the engagement ends, unless the contract says otherwise.

Innorve platform staff administer institutions and cohorts. Through the application they can read institution records except learner drafts, which database rules deny them. Personnel with provider-console access can reach all stored data; that access is restricted as described in Access control. [CONFIRM]

Website visitors

Data element Source Location Retention Access
Contact and design-partner form submissions: name, work email, organization, job role, asset-size band, program interest, message, consent flag, source page Visitor submits a form Supabase (US) 24 months after last contact, or deleted on request Innorve platform staff only
AI Oversight Snapshot marks (five self-assessment marks) Included only if the visitor books a call from the Snapshot Supabase (US), with the lead Same as the lead Innorve platform staff only
Lead notification Generated when a form is submitted Email provider and Innorve's business mailbox [CONFIRM] [CONFIRM] Innorve staff
Free-tool answers Visitor Visitor's own browser (localStorage). Not sent to Innorve. Until the visitor clears browser data The visitor only

Platform users

Data element Source Location Retention Access
Account: email and display name Invitation and sign-in Supabase (US) 90 days after end, or earlier on request The user; people in the same institution whose role requires it; Innorve platform staff
Invitations: email, roles, cohort, inviter, expiry (30 days) Institution admin or Innorve staff Supabase (US) 90 days after end Institution admins; Innorve platform staff [CONFIRM]
Memberships and roles (learner, reviewer, facilitator, sponsor, institution admin) Invitation acceptance; admin changes (audited) Supabase (US) 90 days after end Institution admins; Innorve platform staff
Cohort enrollments, with any withdrawal reason and optional accommodation note [CONFIRM field is kept] Invitation; facilitator Supabase (US) 90 days after end Facilitators; Innorve platform staff [CONFIRM]
Lesson progress and short reflections Learner Supabase (US) 90 days after end Learner; facilitators see status [CONFIRM whether they see reflection text]
Practice attempts Learner Supabase (US) 90 days after end Learner [CONFIRM other roles]
Lab and assessment submissions (free text only, versioned) Learner Supabase (US) 90 days after end Learner (own drafts and submissions); reviewers (submitted work only, in scope). Not visible as drafts to facilitators, sponsors or Innorve staff.
Reviewer rubric scores, rationale and feedback Reviewer Supabase (US) 90 days after end Reviewers; the learner, only after release; facilitators see released results; sponsors see aggregates only
Pilot workflow boundaries, decisions, owner and authorizer names, authorization references Learners and facilitators Supabase (US) 90 days after end Enrolled cohort members, facilitators, sponsors (results)
Pilot task observations: durations and quality flags; notes (no member data) Learners and facilitators Supabase (US) 90 days after end Enrolled cohort members, facilitators, sponsors (results)
Oversight records: tabletop decision logs; baseline counts from the credit union's own records [CONFIRM in pilot release] Facilitators Supabase (US) 90 days after end Facilitators; cohort members [CONFIRM]
Evidence binder E1 to E8: status, owner names, notes, links to documents in the credit union's own systems Cohort members and facilitators Supabase (US). Links only; documents stay in the credit union's systems 90 days after end Cohort members; sponsors (status)
Cohort CSV exports (assessment records, observations, progress) Generated on request Downloaded to the requester's device. Not stored by Innorve. Customer's control once downloaded Authorized roles [CONFIRM which]; every export is logged

Operational and technical data

Data element Source Location Retention Access
Audit events: actor id, institution id, action, record type, record id, version, timestamp, outcome. No content. Generated by the database Supabase (US) 3 years. Survives institution deletion as references only. Innorve platform staff; the institution's admins and facilitators [CONFIRM]
Sign-in records: email, sign-in times, sessions (including IP address and browser details) Supabase authentication Supabase (US) [CONFIRM per provider] Innorve platform staff through the provider console
Email send log: user id, notification template, time sent, error Generated when email is sent Supabase (US) 90 days after end (with institution) [CONFIRM] Innorve platform staff only
Email content in transit: recipient address, sign-in code or link, notification text Generated by the platform Email provider (planned: Resend, US) [CONFIRM before first pilot] Provider's standard retention [CONFIRM] Email provider; recipient
Server request logs, including IP addresses Every request Vercel (US) and Supabase (US) Provider's standard retention [CONFIRM per provider plan] Innorve platform staff through provider consoles
Database backups Automated daily Supabase (US) 7 days [CONFIRM plan before first pilot] Supabase; Innorve platform staff for restore
Session cookie Set at sign-in User's browser (HttpOnly, Secure, SameSite=Lax) Session lifetime [CONFIRM] Not readable by page scripts

Content (not customer data)

Data element Source Location Access
Course content: lessons, fictional cases, rubrics Innorve Web application and database Enrolled users by program
Answer keys and unseen assessments Innorve Supabase (US) only, behind role checks. Never in the application code (build check). Reviewers; learners see an unseen item only after a facilitator releases it; Innorve platform staff
Source code Innorve Private GitHub repository. No customer data. Innorve personnel [CONFIRM]

What is never collected

  • Member (consumer) data of any kind.
  • Passwords.
  • Uploaded files.
  • Payment card or bank account details.
  • Advertising or analytics data.
  • Data sent to any AI model or AI provider.

Data flow diagram

 PUBLIC WEBSITE
 ==============
 Visitor's browser
   |-- free tools: answers stay in browser localStorage (nothing sent)
   |-- Navigator page only: browser fetches fonts from Google Fonts
   |
   |-- submits form (HTTPS) --> Vercel (US) --> Supabase (US): leads table
                                                   |
                                                   +--> lead notification --> Innorve [CONFIRM route]

 PLATFORM
 ========
 Institution admin or Innorve staff
   |-- creates invitation (email, roles, cohort) --> Supabase (US)
                                                       |
   Email provider (planned Resend, US) <-- sign-in link / 6-digit code
   |
   v
 Staff member's work mailbox (controlled by the credit union)
   |
   |-- signs in with invited email --> invitation accepted --> membership + enrollment
   v
 Staff member's browser
   |  HTTPS only (TLS, HSTS); HttpOnly session cookie
   v
 Vercel (US): Next.js server code
   |  checks authorization on every request and export
   |  acts as the signed-in user (no service key)
   v
 Supabase (US): PostgreSQL
   |  row-level security on every query
   |  composite foreign keys keep each institution's records together
   |  computes rubric totals; enforces immutability
   |  writes content-free audit events
   |
   |-- daily backups (7 days) [CONFIRM plan]
   |-- CSV export (authorized roles, logged) --> requester's device

 Evidence binder: stores a LINK --> document stays in the credit union's own system,
                                    which enforces its own access control.

 Not in any flow: member data, uploads, AI models, analytics or ad trackers.

Where data is stored

All stored customer data is in the United States:

  • Supabase: managed PostgreSQL on AWS, US region [SUPABASE REGION].
  • Vercel: serverless functions in a US region [VERCEL REGION].
  • Email provider: United States [CONFIRM before first pilot].

See Subprocessors for details.