Privacy Policy

Last Updated: May 5th, 2026

1.
Who we are

Covisio LLC ("Covisio," "we," "us," "our") is a Delaware limited liability company operating from New York. We provide go-to-market advisory services to businesses, analyzing sales conversations to help our customers improve how their revenue teams sell.This Privacy Policy explains how we handle personal information in connection with our website at www.covisio.com (the "Site") and our advisory services (the "Services").It does not apply to the websites, products, or services of our customers or of any third party.

2.
Our Two Roles

How we handle personal information — and who you should contact about it — depends on the context.
As a controller. For personal information about visitors to our Site, prospective customers, business contacts, our own personnel, and applicants, we decide why and how the information is used. This Policy governs that handling directly, and you can exercise your rights with us.
As a service provider. When we deliver the Services, we process information our customer provides — principally text transcripts of that customer's sales conversations — on the customer's behalf and on the customer's instructions, under our agreement with that customer. In that role, the customer decides what is sent to us, why, and for how long it is kept. We do not decide those things and we cannot act on that information independently.
If your personal information appears in a customer's transcripts — for example, because you spoke with one of our customer's sales representatives — and you want to exercise a privacy right, please contact that organization. If you contact us instead, we will refer your request to the relevant customer and support them in responding.

3.
Information we collect

3.1 Site visitors: Our Site is an informational marketing website. It is built and hosted on Webflow, and served through Webflow's content delivery network. We do not operate a customer login, account area, or application on the Site.Forms. The Site offers several forms — to request a demo or contact us, to schedule a working session, and to join our community. When you submit one, we collect the information you enter, typically your name, business email address, telephone number, and your message. Form submissions are transmitted to and stored by Webflow, and are also delivered to us by email. We use them only to respond to you and to manage the business relationship you are asking about.Server logs. Our hosting and delivery infrastructure records standard technical information when a page is requested, which may include IP address, browser and device type, the page requested, the referring page, and the time of the request. These records exist for security, abuse prevention, and operational purposes. We do not use them to identify individual visitors or for advertising.Cookies are described in Section 9.
3.2 Business and prospect contacts: When you contact us, or we contact you, we collect the information you provide — typically name, business email address, telephone number, employer, job title, and the content of our correspondence. We may also collect business contact information from public sources such as company websites and professional networking sites.
3.3 Information we process for our customers: Our customers provide us with text transcripts of their sales conversations. Those transcripts may contain personal information about the customer's own sales personnel and about the people they spoke with, including names, job titles, employer names, contact details mentioned in conversation, and the substance of what was discussed.To limit that exposure, we automatically redact transcripts on receipt, before they are stored. Redaction removes or replaces direct identifiers — personal names, email addresses, telephone numbers, and postal addresses — with pseudonymous tokens, so that our analysis works on patterns rather than on identified individuals.Redaction reduces identifiability but does not eliminate it. A conversation may still be attributable through context — a described deal, a role, a specific event. We therefore continue to treat redacted transcripts as personal information and apply our full security controls to them.What we do not receive. We do not record, join, or transcribe calls or meetings. We do not deploy meeting bots or recording agents. We do not receive audio or video. We do not connect to our customers' CRM, email, calendar, or conversation-intelligence systems, and we do not hold credentials to them. Our customers record their own conversations using their own tools, meet their own consent obligations, and send us text.We ask customers not to send us sensitive categories of information — government identifiers, financial account numbers, health information, or biometric data — because our Services are not designed to process them.
3.4 Personnel and applicants: We collect information necessary to engage personnel and evaluate applicants, used only for employment, contracting, and legal compliance purposes.

4.
How we use information

We use personal information to:
- deliver, operate, and improve the Services;
- communicate with customers and prospects about engagements, proposals, and support;
- secure our systems and detect, investigate, and respond to security incidents and abuse;
- maintain business records, invoice, and manage vendor and insurance relationships; and
- comply with legal obligations and enforce our agreements.
We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not use customer information for our own marketing.

5.
Artificial intelligence

Our Services use AI models to analyze transcripts and produce insights and recommendations.
All processing happens inside our own environment. Inference runs either on open-weight models we host ourselves within our Google Cloud project, or through Google Cloud Vertex AI within our own Google Cloud tenant. No customer information is sent to any external AI provider or inference API. Google does not use Vertex AI customer data to train its models.
We do not train on customer data. We do not use customer information to train, fine-tune, or improve any general-purpose or foundation model, and we do not train a bespoke language model.
What we do learn. We maintain a knowledge base of general go-to-market patterns — the kinds of situations sellers encounter and the approaches that work — which improves through our advisory work. Where an engagement suggests a new pattern, the proposed addition is reviewed and approved by a person, is derived from redacted material, and is written as a general pattern with no customer identity, no customer-identifying context, and no verbatim customer content. Analysis specific to a customer is held separately from that shared knowledge base and is never read across customers.
Human review. Our personnel review transcripts and AI output in the course of delivering the Services, on a need-to-know basis and under access controls. Every deliverable is reviewed by a person before it reaches the customer.
Accuracy. AI-generated output can be incomplete or incorrect. It supports human judgment and should not be the sole basis for a decision that materially affects an individual.

6.
Who we share information with

Google. Google is our only subprocessor for customer information. We use Google Workspace for business operations and deliverables, and Google Cloud for storage, processing, and AI inference. Our current subprocessor list is published at www.covisio.com.
Professional advisors. Our attorneys, accountants, and insurers, where necessary and under a duty of confidentiality.
Legal and safety. Where required by law or legal process, or where we reasonably believe disclosure is necessary to protect rights, safety, or property. Where legally permitted, we will notify the affected customer before disclosing their information in response to legal process.
Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to the recipient honoring this Policy.
We notify customers in advance before adding any subprocessor that will process their information.

7.
Where information is stored

Covisio operates entirely within the United States. Our personnel are located in the United States. Customer information is stored and processed in Google Cloud in the United States East region, and our Google Cloud organization policy restricts resources to United States regions.
Our Google Workspace data region is configured to the United States.Where a customer agreement requires it, we store and process that customer's information only within the agreed region and restrict access by personnel outside it.If you access our Site from outside the United States, your information will be transferred to and processed in the United States, where data protection laws differ from those of your country.

8.
How long we keep information

Customer information is retained for the period set out in the applicable customer agreement. Where the agreement is silent, we retain it only for as long as needed to deliver the Services, and we return and delete it within 90 days of the end of the engagement or on the customer's request. 
Security and operational logs are retained for a minimum of 13 months.
Business and prospect contacts are retained while the relationship is active and for a reasonable period afterward.
Records we must keep — contracts, invoices, tax and corporate records — are retained for the periods required by law.
Deletion is performed from active systems using platform deletion together with retention and purge settings. Backups are overwritten on their normal cycle, so information may persist in backups for a limited period after deletion. A legal hold suspends deletion for the information covered by it.

9.
Cookies and similar technologies

9.1 Where cookies are and are not used
Cookies are small text files a website stores on your device. We use them only on our public website at www.covisio.com.
No cookies are set in connection with our Services. We deliver advisory services rather than software. Our customers do not log in to a Covisio application, and the systems that process customer information are internal to Covisio. No cookie, tag, pixel, tracker, or similar technology is placed on any customer's website, product, or systems, and none is used in the course of analyzing transcripts or producing deliverables.
9.2 What we use on our website
Our Site is built and hosted on Webflow. The cookies below are set by Webflow and by the infrastructure that delivers the Site.
Category: Strictly necessary
Purpouse:
Delivering the Site reliably and securely: routing requests, load balancing, distinguishing genuine visitors from automated traffic, and protecting forms from spam and abuse.
Set by: Webflow and its delivery network
Type: Mostly session; some persist for a short period
Category: Functional
Purpose:
Remembering choices you make on the Site during a visit, such as form state
Set by: Webflow
Type: Session
9.3 What we do not use
We do not use advertising cookies. We do not use cross-site tracking, retargeting, or advertising pixels. We do not permit third parties to place advertising or tracking technologies on our Site. We do not sell personal information or share it for cross-context behavioral advertising.
9.4 Analytics
We use Google Analytics, Webflow Analyze, to understand how visitors find and use our Site in aggregate — which pages are viewed, how visitors arrive, and which content is useful. This uses cookies that assign your browser a random identifier. We use this information to improve the Site, not to identify you individually.
9.5 Managing cookies
Most browsers let you see the cookies a site has set, delete them, and refuse new ones, through the browser's settings or privacy menu. Browser help pages explain how.
If you block strictly necessary cookies, parts of the Site — particularly form submission — may not work correctly. Blocking any other category will not prevent you from using the Site.
You can also use a browser or extension that transmits a Global Privacy Control signal. Where we receive one, we treat it as a request to opt out of any sale or sharing of personal information; as stated in Section 4, we do not sell or share personal information in any event.
9.6 Changes
If we add a cookie, an analytics tool, or an embedded third-party feature to the Site, we will update this Section and the "Last updated" date above before or at the time the change goes live.

10.
Security

We maintain a written information security program covering the confidentiality, integrity, and availability of the information entrusted to us, consistent with the New York SHIELD Act. Its controls include:
- automated redaction of transcripts on ingest;
- information classification with handling rules for each level;
- least-privilege access on a need-to-know basis, with quarterly documented access reviews;
- mandatory multi-factor authentication on every account;
- encryption in transit and at rest, with the production database on private networking and no public endpoint;
- separation of production from development environments, with a prohibition on customer information in non-production;
- mandatory peer review before any code reaches production, with automated dependency, static analysis, and secrets scanning;
- security awareness training at onboarding and annually;
- vendor due diligence and annual reassessment; and
- a documented incident response procedure with defined escalation and notification timeframes.
A designated Security Officer owns the program and reviews it at least annually.
No system is completely secure and we cannot guarantee absolute security. Details of our program are available to customers and prospective customers under a non-disclosure agreement.

11.
Your rights

Depending on where you live and on our role, you may have the right to request access to the personal information we hold about you, correction, deletion, a portable copy, restriction of or objection to certain processing, and withdrawal of consent where processing relies on it. You have the right not to be discriminated against for exercising these rights.
How to make a request. Email privacy@covisio.com describing your request. We will acknowledge it and respond within 30 days of receipt, unless a longer period is permitted by law and we notify you. We verify identity before acting on a request, and will explain if we must decline.
Authorized agents. You may use an authorized agent, with proof of authorization.Requests about customer information. As described in Section 2, where we hold information on a customer's behalf we will refer your request to that customer.
California. We do not sell personal information and do not share it for cross-context behavioral advertising, and have not done so in the preceding twelve months. Where we process personal information on a customer's behalf, we act as a service provider under the CCPA and are contractually restricted from retaining, using, or disclosing it for any purpose other than providing the Services.
New York. We maintain a written data security program as required by the New York SHIELD Act and will notify affected individuals and the New York Attorney General as required if a breach involving private information occurs.

12.
Children

Our Services are business tools for organizations. They are not directed to children and we do not knowingly collect personal information from anyone under 16.
If you believe a child has provided us personal information, contact us and we will delete it.

13.
Changes to this Policy

We may update this Policy. We will revise the "Last updated" date and, where a change is material and affects customers, notify affected customers by email to the designated contact. Material changes take effect 30 days after notice, except where an earlier date is required by law. Prior versions are available on request.

14.
Contact us

Covisio LLC 
For Privacy inquiries: privacy@covisio.com 
For Security inquiries: security@covisio.com
We respond to privacy and security inquiries promptly.