1. Who we are and what this policy covers
Covendri [legal entity name and address] ("Covendri", "we", "us") provides an AI-assisted IT support service for businesses. The service includes the Covendri Agent, which a business installs on its Mac and Windows computers; the Covendri menu bar and tray app used by employees; the admin dashboard at dashboard.covendri.com; and the assistant features a Customer chooses to use, such as the email assistant for Microsoft 365 (Outlook) and Gmail, WhatsApp Business, quotes, Teach Covendri, image generation, research and optional screen control (together, the "Service").
This policy explains how we handle information processed through the Service and through our website at covendri.com. The Service is intended for businesses, not for personal or household use.
2. Our role and yours
When a business (our "Customer") uses the Service, the Customer decides which computers to enroll and which people use the Service. For information about the Customer's employees and devices processed through the Service ("Customer Data"), the Customer is the controller and Covendri acts as a processor (or "service provider") that processes Customer Data on the Customer's behalf and according to its instructions.
Customers are responsible for giving their employees any notice required by law, and for having a lawful basis to install the Covendri Agent on the devices they enroll.
Covendri is the controller for information we process for our own business purposes, such as account administration, billing, security of the Service, and our website.
3. Information we process
Account information
Name, email address, company name, role (for example, admin or member), department, and identifiers from the sign-in provider you choose (Microsoft, Google, or email and password). For email and password sign-in, we store only a hashed form of the password.
Device diagnostics
Information the Covendri Agent collects from enrolled computers to diagnose problems and monitor health, including:
- Device name, hardware model, operating system version and the signed-in user's account name.
- Storage usage, including the names and sizes of large folders, and memory and CPU usage.
- Running processes (with command-line secrets redacted), installed software and startup items.
- Network and Wi-Fi diagnostics, such as signal strength, DNS and connection quality.
- Update status, security settings (for example, firewall and disk encryption), backup status, battery health and printer queues.
- Recent system log entries relevant to a problem.
Help requests and support content
The text of help requests and conversations with Covendri, screenshots that users choose to attach, the steps and tool results of each request, and knowledge base articles created from resolved requests.
Email and WhatsApp messages (only if connected)
If a Customer connects Microsoft 365, Gmail or WhatsApp Business, we process messages only in the mailboxes and numbers the Customer's admin allows: sender and recipient names and addresses or phone numbers, subject, dates, message text, and the replies Covendri suggests, edits and sends. We read only new incoming messages from the time of connection, and we don't write replies to newsletters or automatic replies. Covendri sends a message only in the mode the admin chose for that mailbox or number (draft only, or send after a person approves).
Teach Covendri imports
If an admin imports past email or exported chats, we copy the selected messages into a temporary working set, automatically remove personal details we can detect (such as names, email addresses, phone numbers and ID, booking, card and bank numbers), and use the result to propose knowledge articles. Proposed articles are used only after an admin approves them.
Quotes, images and research
Example quotes and templates a Customer uploads, the quotes it creates, images it generates, and the questions it asks the research assistant along with the results and their sources.
Approvals and audit records
Records of actions taken on devices, approval requests, decisions and notes, and who made them and when.
Usage and technical information
Plan and usage information (such as number of devices and AI usage), and technical information about sign-in sessions, such as IP address, browser user agent and timestamps, used for security.
Website
Our website does not use analytics, advertising or tracking tools. Our hosting provider may keep standard server logs (such as IP address and pages requested) for security and operations.
Communications
If you email us, we keep the message and your contact details to respond and provide support.
4. What we don't collect
The Covendri Agent does not use the camera or microphone or read stored passwords. It records the screen and controls the keyboard and mouse only if the customer enables the optional screen-control feature and the user approves a specific task; in that case we keep a step log with downscaled screenshots for the period the customer sets (24 hours by default), and text typed by the agent is stored only as its length. We process the contents of email and WhatsApp messages only in the mailboxes and numbers a Customer connects and allows, as described in section 3; otherwise we do not intentionally collect the contents of users' documents, email or messages. Diagnostic information may incidentally include file, folder or application names.
5. How we use information
- To provide the Service: diagnosing and fixing IT problems, monitoring device health, running proactive health reviews, routing approvals, and keeping the audit log.
- To suggest and, in the mode the Customer chose, send replies to email and WhatsApp messages; to create quotes and images; and to research questions on the web.
- To build the Customer's knowledge base from resolved requests and from imports an admin approves, available only within that Customer's workspace.
- To operate, secure and improve the Service, including preventing abuse, enforcing usage limits, and troubleshooting.
- To communicate with Customers about their account, the Service, and support requests.
- To comply with legal obligations and enforce our Terms of Service.
We do not sell personal information, share it for cross-context behavioral advertising, or use Customer Data for advertising.
6. AI processing
To work on a request, the Service sends the relevant parts of it (such as the request text, attached screenshots, diagnostic results and relevant knowledge base articles) to Microsoft's Azure OpenAI Service for processing. We do not use Customer Data to train AI models. Under Microsoft's terms for the Azure OpenAI Service, customer prompts and outputs are not used to train Microsoft's or OpenAI's foundation models.
Images are generated with an image model on Azure OpenAI Service, subject to Azure's content filters.
When web search is on for a Customer's workspace, search queries are sent through the web search tool in Azure OpenAI Service, which uses Grounding with Bing Search. Bing is a separate Microsoft service that handles queries under its own terms, outside the Azure OpenAI commitments above. Covendri is designed to write search queries without names, contact details or other personal data. The Customer's admin can turn web search on or off.
9. Retention and deletion
We keep Customer Data for as long as the Customer's workspace is active, unless the Customer deletes it sooner or a shorter period below applies. Unconfirmed sign-ups are removed after 7 days.
- Email and message text: the text of messages and suggested replies is deleted after 30 days by default (the Customer's admin can choose from 1 to 365 days). Sender, subject, dates and status are deleted about 90 days after that.
- Teach Covendri working set: deleted when the import ends, and within 48 hours at most. Knowledge articles an admin approves are kept like the rest of the knowledge base.
- Screen-control screenshots: deleted after 24 hours by default (the admin can choose from 1 hour to 7 days).
- Detailed device health metrics: 7 days.
Customers can ask us to delete their workspace's data at any time by emailing support@covendri.com. When a workspace is closed, we delete or de-identify Customer Data within [30] days, except for limited records we must keep for legal, billing or security reasons, and data in backups, which is overwritten on our normal backup cycle.
10. Security
We use technical and organizational measures designed to protect information, including encrypted connections, per-company data isolation, per-device credentials stored only as hashes, server-enforced approvals for high-impact actions, and audit logging. No system is perfectly secure, but we work to protect your data and will notify affected Customers of a security incident as required by law. Learn more on our Security page.
11. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete or export personal information, or to object to or restrict certain processing.
- Employees of a Customer: your employer controls your information in the Service. Please contact your employer first; we will help them respond to your request.
- Customer admins and other individuals: email support@covendri.com. We may need to verify your identity before acting on a request.
We will not discriminate against anyone for exercising their privacy rights.
12. Where data is stored
Covendri is hosted on Microsoft Azure in the United States. If you use the Service from outside the United States, your information will be transferred to and processed in the United States. Where required, we rely on appropriate safeguards for such transfers.
13. Children
The Service is designed for businesses and is not directed to children. We do not knowingly collect personal information from children under 16.
14. Changes to this policy
We may update this policy from time to time. We'll change the "last updated" date above and, for material changes, notify Customer admins by email or in the dashboard before the changes take effect.
15. Contact us
Questions or requests about privacy: support@covendri.com.