Corvus← Back to home
Legal

Data Processing Agreement

Effective and last updated: 8 August 2026

Processor: STRIATUM AI LTD (company number 17306880), incorporated in England and Wales

Privacy contact: [email protected]

Part of the Corvus agreement

This DPA applies when STRIATUM AI LTD processes Customer Personal Data for a Corvus customer. The customer identity is the organisation or sole-trader business identified in the account or Order. It is designed for UK GDPR, EU GDPR where applicable, the Australian Privacy Act, applicable United States state privacy laws and equivalent worldwide requirements.

1.Formation, scope and precedence

This Data Processing Agreement ("DPA") forms part of the Corvus Terms of Service or other written agreement governing Customer's use of Corvus (the "Service Agreement"). It becomes binding when Customer accepts the Service Agreement, signs an Order incorporating it, or signs this DPA.

It applies only to Customer Personal Data that Striatum processes on Customer's behalf as a processor or service provider. It does not govern information for which Striatum independently determines the purposes and means, such as its own account administration, billing, security, legal-compliance and direct-business records, which are addressed in the Privacy Policy.

If documents conflict on a data-protection matter, the order is: any mandatory transfer clauses; this DPA; the Order; the Service Agreement; then the Privacy Policy. Commercial liability provisions in the Service Agreement apply to this DPA unless this DPA expressly says otherwise or law prohibits it.

2.Definitions

"Customer Personal Data" means personal data, personal information or equivalent regulated information contained in Customer Data and processed by Striatum on Customer's behalf through Corvus.

"Data Protection Laws" means laws applicable to the relevant processing, including the UK GDPR and Data Protection Act 2018 as amended (including by the Data (Use and Access) Act 2025), the EU GDPR where applicable, the Australian Privacy Act 1988 and Australian Privacy Principles, applicable United States state privacy laws, and binding replacement or implementing laws.

"Controller", "processor", "data subject", "personal data breach" and "processing" have the meanings in applicable Data Protection Laws. Where Australian or United States law uses different terminology, references to controller or processor describe the parties' practical roles and include equivalent terms such as business, service provider or contractor where appropriate. "Subprocessor" means a third party appointed by Striatum to process Customer Personal Data for the Services.

3.Roles and Customer responsibilities

Customer is the controller or the party determining why and how Customer Personal Data is handled. Striatum is the processor acting for Customer. Each party remains responsible for obligations imposed directly on it by Data Protection Laws.

Customer must ensure its instructions and use of Corvus are lawful; provide required privacy and collection notices; establish a valid legal basis; handle consent where required; respect data-subject rights; minimise data; and avoid submitting sensitive, special-category or criminal-offence information unless necessary, lawful and appropriately protected. Before submitting special-category personal data, Customer must identify and document an applicable condition under Article 9 UK GDPR or EU GDPR, or an equivalent condition under applicable law. Customer must also meet Article 10 and Data Protection Act 2018 requirements for criminal-offence data where applicable.

Customer warrants that it is authorised to disclose Customer Personal Data to Striatum and permit the processing and international transfers described in this DPA. Customer remains responsible for the accuracy, quality and legality of Customer Personal Data and for its users, communications, call-transcription notices, automated workflows and connected integrations.

4.Documented instructions

Striatum will process Customer Personal Data only on Customer's documented instructions, including instructions concerning international transfers, unless applicable law requires other processing. The Service Agreement, Orders, Customer's configuration and use of Corvus, support requests, and written directions accepted by Striatum constitute documented instructions.

If law requires processing outside Customer's instructions, Striatum will inform Customer before processing unless the law prohibits notice. Striatum will promptly inform Customer if, in its reasonable opinion, an instruction infringes Data Protection Laws and may suspend the affected processing until the parties resolve the issue.

Striatum will not sell Customer Personal Data, share it for cross-context behavioural advertising, or use it for targeted advertising. Striatum will not use Customer Personal Data to train its own general-purpose AI model. Customer instructs Striatum to route relevant data only to the providers and features that Customer enables or uses. External AI providers may retain or use submitted information for improvement or model training under their applicable account and contractual terms, as disclosed in the Service Agreement and Privacy Policy. Customer must not enable or instruct use of a provider whose terms are unsuitable for Customer's data or purposes.

5.Personnel and confidentiality

Striatum will limit access to personnel and contractors who need Customer Personal Data to provide, secure or support Corvus. Anyone authorised to process it must be bound by confidentiality obligations or an appropriate statutory duty and receive relevant privacy and security instructions.

Striatum is responsible for ensuring authorised personnel process Customer Personal Data only as permitted by this DPA, subject to applicable law.

6.Security

Taking account of the state of the art, implementation costs, the nature, scope, context and purposes of processing, and risks to individuals, Striatum will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

The current measures are described in Schedule 2. Striatum may update them provided the overall level of protection is not materially reduced. Customer must implement appropriate security for its users, devices, credentials, permissions, exports, integrations and configurations.

7.Personal data breaches

Striatum will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Notification will be sent to the account contact or another contact designated by Customer.

As information becomes reasonably available, Striatum will describe the nature of the breach, affected data and individuals where known, likely consequences, measures taken or proposed, and a contact point. Striatum may provide information in phases and will take reasonable steps to contain, investigate and remediate the incident.

Notification is not an admission of fault. Customer is responsible for deciding whether to notify regulators or individuals. Taking account of the processing and information available, Striatum will reasonably assist Customer with UK/EU breach obligations and Australia's Notifiable Data Breaches scheme.

8.Data-subject requests

Taking account of the nature of processing, Striatum will provide appropriate technical and organisational assistance, insofar as reasonably possible, for Customer to respond to requests for access, correction, deletion, restriction, objection, portability, withdrawal of consent or review of automated decisions.

If Striatum receives a request relating to Customer Personal Data, it will not respond substantively except on Customer's instructions or where law requires. It will direct the requester to Customer where practicable and notify Customer unless prohibited. Customer is responsible for verifying identity, deciding the response and meeting statutory deadlines.

Routine self-service tools and reasonable assistance are included in the Services. Striatum may charge reasonable documented costs for unusual, repetitive or extensive assistance where permitted by law and agreed in advance.

9.Compliance assistance

Taking account of the nature of processing and information available, Striatum will reasonably assist Customer with security obligations, data-protection impact assessments, prior regulatory consultation, records of processing, and demonstrations of compliance required by applicable Data Protection Laws.

Striatum will provide information reasonably necessary for Customer to assess Corvus. Customer remains responsible for its own assessment, legal bases, transparency, automated-decision analysis and consultation duties.

10.Subprocessors

Customer gives general written authorisation for Striatum to use the Subprocessors in Schedule 3 and others appointed under this section. Striatum will impose written data-protection obligations that provide protection materially equivalent to this DPA for the processing performed and will remain responsible to Customer for a Subprocessor's performance of those obligations, subject to the Service Agreement and applicable law.

Striatum will give at least 15 days' prior notice of a new Subprocessor that will materially process Customer Personal Data, normally by email to the account owner or through an in-product notice. Striatum may also maintain an updated online list. Customer may object during that period on reasonable, documented data-protection grounds.

The parties will work in good faith on a commercially reasonable solution. If none is available, Striatum may avoid the Subprocessor, permit Customer to stop the affected feature, or allow termination of the affected Service without penalty and refund prepaid fees for the unused affected period. An objection does not excuse payment for Services already supplied.

Self-hosted software does not itself constitute a Subprocessor. Hermes is operated on Striatum-controlled Vultr infrastructure, and n8n is operated by Striatum on AWS. Nous Research is a conditional recipient when Customer Personal Data is routed to a Nous-hosted endpoint. It is a Subprocessor only to the extent it processes that data solely on Striatum's instructions; any independent use permitted by Nous Research's terms is disclosed separately in the Service Agreement and Privacy Policy.

11.International processing and transfers

Customer authorises processing in the countries and by the recipients identified in Schedule 3 and the Privacy Policy. Current core locations include the United Kingdom, Japan, Singapore and the United States. Provider subprocessors may operate in additional disclosed locations.

For a restricted transfer governed by UK or EU data-protection law, the parties will ensure an applicable lawful mechanism. This may include adequacy regulations or decisions, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, the EU Standard Contractual Clauses, or another approved mechanism, together with required assessments and supplementary measures. The parties will execute or incorporate the necessary module and information if the transfer is not otherwise lawfully covered.

Where Australian law applies, Striatum will take reasonable steps within its role to ensure overseas Subprocessors handle Customer Personal Data consistently with applicable Australian Privacy Principles, including through enforceable contractual restrictions, security requirements and oversight where reasonable. Customer remains responsible for its APP 5 collection notices, APP 8 assessment and any accountability imposed on it by section 16C of the Privacy Act.

12.United States state privacy terms

To the extent a United States state privacy law applies to Customer Personal Data, Striatum will act as Customer's processor, service provider or contractor for the limited and specified business purposes in Schedule 1. Striatum will provide the same level of privacy protection required of that role and will comply with obligations applicable directly to it.

Striatum will not sell or share Customer Personal Data; retain, use or disclose it outside the direct business relationship or the purposes in Schedule 1; or combine it with personal information received from another person or collected through Striatum's own interaction with an individual, except as permitted by applicable law. Customer may take reasonable and proportionate steps to confirm that Striatum uses Customer Personal Data consistently with Customer's legal obligations and may require Striatum to stop and remediate unauthorised use.

Striatum will notify Customer if it determines that it can no longer meet an applicable obligation under this section. Striatum certifies that it understands and will comply with these restrictions.

13.Return and deletion

During the subscription, Customer may use available export and deletion functions. On termination, Customer may request return of Customer Personal Data in a reasonably available format before account closure. Unless Customer validly instructs otherwise, Corvus currently keeps the closed account in a 30-day deletion period and then schedules Customer Data for permanent deletion.

At Customer's choice, Striatum will delete or return Customer Personal Data after the Services end and delete remaining copies, unless applicable law requires retention. Customer must communicate its choice before the end of the 30-day period; otherwise deletion is the default instruction.

Data in access-restricted backups or provider-controlled systems may remain beyond primary deletion until the applicable secure overwrite or deletion cycle. Supabase database backups are retained for 7 days before being overwritten. During any backup retention period, data will remain protected under this DPA and will not be processed except for security, disaster recovery or legal compliance. Striatum will ensure deletion when the applicable cycle completes unless law requires longer retention.

14.Information, audits and inspections

Striatum will make available information reasonably necessary to demonstrate compliance with this DPA and applicable processor obligations. It may satisfy requests through current policies, security summaries, independent reports, certifications, questionnaires or other appropriate evidence.

If that information is insufficient, Customer may conduct an audit itself or through an independent qualified auditor, normally no more than once in any 12-month period, on at least 30 days' notice, during business hours and without unreasonably disrupting operations. Greater frequency is permitted after a material breach, on a regulator's direction or where law requires.

The auditor must not be a competitor and must protect confidentiality and other customers' information. Customer bears its audit costs; Striatum may charge reasonable time and expenses for unusually burdensome support unless the audit identifies a material breach by Striatum. Audits may not require access that would compromise security, privilege, trade secrets or another customer's data.

Striatum will inform Customer if it believes an instruction or audit demand infringes Data Protection Laws. Nothing prevents either party from cooperating with a competent regulator.

15.Government and legal requests

If Striatum receives a legally binding request for Customer Personal Data, it will, where lawful, notify Customer before disclosure and provide reasonable information so Customer may seek protection. Striatum will disclose only what it reasonably believes is legally required and will document the request as required by law.

16.Liability

The liability exclusions and aggregate cap in the Service Agreement apply to this DPA. They do not limit an individual's rights, a regulator's statutory powers, or liability that cannot lawfully be limited. Regulatory fines and third-party liabilities between the parties will be allocated according to each party's responsibility for the event, subject to applicable law.

17.Duration and changes

This DPA begins when it becomes binding and continues while Striatum processes Customer Personal Data. Provisions concerning confidentiality, deletion, audits, transfers and liability survive as necessary.

Striatum may update this DPA to reflect legal requirements, regulator guidance, transfer mechanisms, Subprocessors or Service changes. Material changes will be notified under the Service Agreement. An update will not materially reduce Customer's data-protection rights during a current paid term unless required by law or agreed by Customer.

Schedule 1— Processing details

ItemDetails
Subject matterProvision of Corvus CRM, communications, AI assistance, scheduling, site/workforce tools, integrations, automation, support, security and related services.
DurationFor the Service Agreement term, the 30-day account-deletion period, and any limited backup or legally required retention period.
Nature of processingCollection, receipt, hosting, storage, organisation, retrieval, access, transmission, routing to instructed providers, analysis, AI inference, transcription, summarisation, communication, modification, export, restriction and deletion.
PurposesTo provide Customer-configured Corvus functions, including CRM, calls/SMS, AI responses, workflows, appointments, lead and job management, connected Google functions, support, security and account deletion.
Data subjectsCustomer users; leads and prospects; clients; suppliers; subcontractors; workers and crew; site visitors; callers; message recipients; debtors or invoice contacts; and other people whose information Customer submits.
Personal dataNames, contact details, account identifiers, job titles, employer/business information, ABN or company identifiers, CRM records, enquiries, notes, appointments, job/site details, workforce schedules and attendance, communications, SMS, call metadata, transcripts and summaries, prompts and outputs, invoice status and amounts, Google email/calendar data, device/log data, and future location data if enabled.
Special dataNot intentionally required. Customer Data may incidentally contain health and safety, injury, accessibility, union, religious, criminal-offence or other sensitive/special-category information. Customer must not submit it unless lawful, necessary, covered by an identified condition under Article 9 UK GDPR or EU GDPR (or equivalent law), and protected by required safeguards. Customer is responsible for identifying and documenting that condition and satisfying Article 10 requirements for criminal-offence data where applicable.
FrequencyContinuous or event-driven according to Customer's use and configuration.
Customer rightsTo determine purposes and instructions; configure features and access; request assistance, export, correction, restriction, return or deletion; object to new Subprocessors; and obtain compliance information and audits under this DPA.

Schedule 2— Technical and organisational measures

ItemDetails
GovernanceDocumented access responsibilities, confidentiality duties, provider review and incident escalation appropriate to Striatum's size and risk.
Identity and accessAuthenticated access, role or permission controls where available, least-privilege administration, credential protection and removal of access when no longer required.
TransmissionEncryption in transit using current TLS for supported web, API and provider connections.
Hosting separationCustomer records held in Supabase with application-level organisation controls; application and orchestration components hosted on controlled infrastructure.
Logging and monitoringAuthentication, automation, application or provider logs used for security, reliability and incident investigation, with access limited according to operational need.
Secure developmentChange control, dependency and configuration management, testing proportionate to the change, and remediation of identified vulnerabilities according to risk.
Availability and recoveryService monitoring, recovery procedures and provider resilience. Supabase database backups run daily with 7-day retention. Vultr and AWS infrastructure snapshots are maintained on an operational schedule. Backup and snapshot access is restricted, and retained copies remain subject to confidentiality, security and deletion controls.
Incident responseProcedures to identify, contain, investigate, remediate and communicate security incidents, including preservation of relevant evidence.
DeletionAccount soft deletion followed by scheduled permanent deletion after 30 days; access-restricted backup retention until overwrite; provider deletion subject to configured terms.
Subprocessor managementRisk-based provider selection, contractual privacy/security terms where applicable, processing-purpose limits, change notice and ongoing review.

Schedule 3— Current Subprocessors and conditional recipients

SubprocessorPurposeLikely processing location(s)
SupabaseDatabase and authenticationJapan (Tokyo); provider support/subprocessors as disclosed
VultrCorvus application and Hermes gateway hostingSingapore
Amazon Web ServicesInfrastructure for Striatum's self-hosted n8n workflowsSingapore
CloudflareDNS, SSL, content delivery and securityGlobal, including United States
AnthropicClaude AI processing for CRM chatUnited States and disclosed provider locations
OpenAIgpt-4o processing for VAPI voice responsesUnited States and disclosed provider locations
GoogleGemini and connected Gmail, Calendar and OAuth servicesUnited States and global provider infrastructure
TwilioSMS, voice and phone-number servicesUnited States and global communications infrastructure
VAPIAI voice processing, transcription and summariesUnited States and provider subprocessors
Nous Research — conditional recipientHosted model inference only when a Nous Portal endpoint is selected; provider terms may permit independent improvement or training useUnited States and locations identified in applicable provider terms
ZohoTransactional emailConfigured Zoho data centre and disclosed provider locations

Hermes and n8n are self-hosted software operated by Striatum and are not separate Subprocessor entities. Stripe generally processes Corvus customer billing information for Striatum's account administration rather than Customer Personal Data on Customer's behalf; its role is addressed in the Privacy Policy and payment terms. Meta/WhatsApp and analytics services are not included until launched and notified under section 10.

Schedule 4— Party details and acceptance

ItemDetails
Customer / controllerThe company, organisation or sole-trader business identified in the Corvus account or applicable Order.
Customer contactThe account owner, privacy contact or other person designated in the account or Order.
ProcessorSTRIATUM AI LTD, company number 17306880, incorporated in England and Wales.
Processor contact[email protected]
Governing termsThe Corvus Terms of Service and each applicable Order.
AcceptanceAccepted electronically with the Service Agreement, incorporated into an Order, or signed by authorised representatives.