This summary describes how Korevra Technologies Limited processes personal data on behalf of a RecFlow customer. It forms part of the terms of service. Enterprise customers receive a signed Data Processing Agreement on these terms with their order form.
The customer is the controller of the personal data in its workspace: the names and work emails of its members, and any personal data in the files it loads. Korevra is a processor for member and billing data only. Files loaded into RecFlow are processed in the customer's browsers and are never transmitted to Korevra; Korevra therefore does not process the personal data within them.
Korevra processes member and billing data only to provide, secure, bill and support the service, and as the law requires. It does not sell data or use it for its own marketing beyond service notices.
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud / Firebase | Hosting, authentication, database, secrets | EU multi-region (database), global edge (hosting) |
| Flutterwave | Naira payments and recurring billing | Nigeria |
| Stripe | US dollar payments and recurring billing | USA / EU |
| Google Workspace | Transactional email | EU / global |
| Meta (WhatsApp Business) | Billing reminders with the recipient's agreement | Global |
We will give 30 days' notice before adding a sub-processor that handles member or billing data; a customer may object on reasonable grounds and, if unresolved, terminate for that reason.
Korevra notifies the customer's workspace owner without undue delay, and within 72 hours of becoming aware, of a personal data breach affecting member or billing data, with what is known about its nature, scope and the steps taken.
Korevra assists the customer with data-subject requests and regulatory enquiries that concern data it processes. Once a year, and after any breach, the customer may request a written description of the controls above and evidence of their operation.
When a workspace closes, member data is deleted within 90 days and billing records are retained for seven years as financial records require. Reconciliation data never left the customer's devices, so there is nothing for Korevra to return.
Member and billing data is stored in Google's European multi-region. Where a sub-processor is outside Nigeria, transfers rely on the sub-processor's contractual commitments and adequate safeguards recognised under the Nigeria Data Protection Act.