Legal
Version 1.0 · Effective 14 August 2026 · Corvair Pte. Ltd. (UEN 202551453H)
A Data Processing Agreement for business, organisation and educational customers is in preparation and will be published before those customers are onboarded.
The previous version of this page named sub-processors that are no longer accurate and referred to reports that are not yet available. It has been withdrawn rather than left in place, because an inaccurate compliance document is worse than none.
Controller. Corvair Pte. Ltd. (UEN 202551453H) is the controller of personal data processed through the platform for individual customers. Where we process personal data on behalf of an organisation, we act as processor and a Data Processing Agreement will govern that relationship.
Sub-processors. The current list is published in our Privacy Policy and is maintained there. It is the authoritative list.
Security measures. Described in the Privacy Policy. Encryption in transit and at rest, multi-factor authentication, per-project isolation, an authorisation decision point that denies by default, step-up re-authentication for sensitive actions, no standing operator access to customer content, an append-only audit ledger, daily backups replicated to redundant storage, and malware scanning of uploads.
Independent assurance. A SOC 2 implementation programme, including third-party penetration testing, begins in November 2026. No SOC 2 report exists today and none is claimed. We will publish the position as it changes.
International transfers. Infrastructure is hosted in the United States. Standard Contractual Clauses are relied on where a transfer restriction applies.
Business, organisation and educational customers who need a Data Processing Agreement before that date should contact privacy@corvair.ai and we will provide the current draft for review.