Document Directory
    Add a header to begin generating the table of contents
    Scroll to Top

    edoro Privacy and Cookie Policy

    ENTITY: Clavis Technologies Private Limited (“Company”, “edoro”, “We”, “Us”, or “Our”)

    1. Introduction and Overview

    Welcome to edoro (accessible at www.edoro.ai), an Agentic Content Orchestration Platform developed and operated by Clavis Technologies Private Limited. edoro provides enterprise-grade content life-cycle orchestration, multi-format visual proofing, AI-assisted compliance, automated workflows, project timeline management, and system integrations (collectively, the “Service” or “Services”).

    This Privacy and Cookie Policy (“Policy”) governs all data processing activities across our website (www.edoro.ai), the edoro web application, mobile interfaces, API endpoints, webhooks, and single sign-on (SSO) login portals.

    We recognize that Personal Data requires rigorous protection practices. We are committed to processing your data transparently, securely, and in full compliance with applicable privacy laws worldwide, including but not limited to the General Data Protection Regulation (GDPR – EU 2016/679), the UK Data Protection Act 2018 (UK GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), state-level US privacy frameworks (including VCDPA, CPA, CTDPA, UCPA), the Indian Digital Personal Data Protection Act (DPDP Act 2023), and other applicable global data protection frameworks (“Privacy Laws”).

    By accessing our website, creating an account, connecting third-party integrations, or using our Services, you acknowledge the data collection, use, and disclosure practices described in this Policy.

    2. Definitions

    • “Customer” / “Subscriber”: Any business entity, organization, or natural person contracting with Us to utilize the edoro Service.
    • “Customer Content”: Any digital assets, manuscripts, videos, images, graphics, audio, dynamic HTML files, documents, project schemas, briefs, metadata, annotations, comments, and task logs uploaded, imported, or generated within the Service by a User.
    • “Personal Data”: Any data relating to an identified or identifiable natural person, whether the person identified is an employee, contractor, applicant, consumer, customer, partner, or other individual. An identifiable person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, identification number, location data, online identifier, or factors specific to their physical, physiological, mental, economic, cultural, or social identity.
    • “Processor” / “Service Provider”: The entity processing Personal Data on behalf of a Data Controller (as defined under GDPR/CCPA).
    • “Controller” / “Business”: The entity determining the purposes and means of processing Personal Data.
    • “Integration Partners” / “Third-Party Services”: External software platforms, cloud storage providers, project management tools, CRM/ERP engines, and communication channels connected to edoro via OAuth 2.0, API keys, webhooks, or developer integrations.

    3. Core Privacy Principles

    1.You Own Your Data: We do not acquire any ownership or intellectual property rights to Your Personal Data or Customer Content, except the limited license strictly necessary for Us to perform Our obligations under Our agreement with You or as required by law.
     
    2.No Commercial Exploitation: We will not sell, rent, monetize, modify, or merge Your Personal Data with other data sources, nor take any actions that adversely affect its security or confidentiality.
     
    3.Strict Purpose Limitation: Your data will only be processed to provide, maintain, secure, and optimize the edoro Service as directed by You.
    1. No Unsanctioned AI Model Training: Your Personal Data and Customer Content processed within edoro are never used to train, retrain, fine-tune, or improve generalized public artificial intelligence (AI) or machine learning (ML) models without Your explicit, opt-in written consent.

    4. Data We Collect

    We collect Personal Data directly from you, automatically through your interaction with the Service, and through authorized Third-Party Integration Partners.

    4.1. Information You Provide Directly

    • Account & Registration Data: Name, business email address, job title, company name, phone number, password, profile picture, and authentication credentials when you sign up, log in, or update your account.
    • Billing & Subscription Data: Payment contact details, billing address, tax identification numbers, and transaction history. (Note: Credit card processing is handled securely by PCI-DSS compliant payment gateways; edoro does not store raw payment card credentials).
    • Customer Content & Working Assets: Text, comments, media, metadata, Job Jacket schemas, brand guidelines, audio transcripts, and feedback pins uploaded or created in the workspace.
    • Support & Communication Data: Messages, support tickets, feedback, and inquiries sent to legal@edoro.ai or customer success channels.

    4.2. Information Collected Automatically

    • Usage & Interaction Telemetry: Features used, workflow stages completed, clickstream data, proofing interactions, time spent on tasks, performance metrics, and dashboard query logs.
    • Device & Connection Information: IP address, browser type and version, operating system, device hardware models, preferred language, access timestamps, and referring URLs.
    • Cookies & Tracking Data: Collected via cookies, local storage, and similar technologies (see Section 12: Cookie Policy).

    4.3. Information Collected via Integration Partners & APIs

    When you choose to connect third-party software tools to edoro (e.g., cloud storage, task boards, communication platforms, or CRM/ERP systems), we collect information necessary to facilitate seamless data synchronization, including:

    • OAuth tokens, access scopes, and user identification keys.
    • File metadata, folder structures, and workspace identifiers.
    • Task names, statuses, assignees, and due dates required for timeline and Kanban synchronization.

    5. Third-Party Integrations and API Data Handling

    edoro is designed as an agentic orchestration platform that deeply integrates with third-party software environments. To ensure compliance with global developer policies, API Limited Use requirements, and security frameworks:

    5.1. Compliance with Third-Party API User Data Policies

    • Strict Scope Compliance: edoro accesses, reads, writes, and modifies data from third-party APIs strictly to execute user-requested features—such as importing assets from external storage, syncing project statuses, posting review alerts, or exporting finalized deliverables.
    • Limited Use Disclosure: Our use and transfer to any other app of information received from third-party APIs will adhere to the applicable integration provider’s Limited Use requirements and developer policies.
    • No Unrelated Transfers: Personal Data or Customer Content retrieved through third-party APIs is never transferred to third parties except:
      1. As strictly necessary to provide or improve user-facing features that are prominent in the edoro user interface;
      2. To comply with applicable law; or
      3. As part of a merger, acquisition, or asset sale with explicit customer notice.
    • Prohibition on Advertising: Data accessed through third-party integration APIs is never used to serve targeted advertisements or retargeting campaigns.
    • Human Inspection Restrictions: Human personnel are prohibited from reading data accessed via third-party APIs unless:
      1. You give explicit consent for troubleshooting or support purposes;
      2. It is necessary for security investigations (e.g., analyzing software bugs or security incidents);
      3. It is required to comply with applicable law; or
      4. The data is aggregated and anonymized for internal technical performance monitoring.

    6. How We Use Your Personal Data (Purposes & Legal Bases)

    We process Personal Data under valid legal bases under Privacy Laws, as outlined below:

    Purpose of Processing Categories of Personal Data Involved Legal Basis (GDPR / Global Standards)
    Service Provision & Contract Execution Account Data, Customer Content, Integration Tokens, Telemetry. Performance of Contract (Art. 6(1)(b) GDPR)
    AI Processing & Automation Customer Content, Workflow Logs, User Prompts. Performance of Contract / Legitimate Interests
    Customer Support & Success Account Data, Support Communications, System Logs. Performance of Contract / Legitimate Interests
    Platform Security & Infrastructure Safety Device Data, IP Addresses, Audit Logs, Auth Tokens. Legal Obligation (Art. 6(1)(c)) / Legitimate Interests
    Billing & Financial Records Billing Data, Transaction History, Account Data. Legal Obligation / Performance of Contract
    Communications & Updates Account Data, Usage Telemetry. Legitimate Interests / Consent (where required)

    7. AI And Co-pilot Data Processing & No Automated Decision-making

    edoro incorporates cognitive AI processing, OCR (Optical Character Recognition) text analysis, audio transcription, and natural language query tools (“AI Services”) to automate content orchestration.

    1. Context-Bound Processing: Customer Content processed by AI utilities is analyzed strictly in temporary runtime environments to deliver real-time outcomes (e.g., highlighting text discrepancies, checking brand guidelines, or answering dashboard queries).
    2. No Model Training: Neither edoro nor its underlying infrastructure subprocessors use Customer Content, Personal Data, or private integration data to train, fine-tune, or retrain public or foundational machine learning models.
    3. Data Isolation: All AI operations respect edoro’s logical data segregation architecture, ensuring your inputs, prompt queries, and outputs remain strictly isolated within your tenant workspace.
    4. Human-in-the-Loop & No Solely Automated Decision-Making (GDPR Art. 22): edoro’s AI features function strictly as assistive tools to optimize human workflows. edoro does not engage in solely automated decision-making or profiling that produces legal effects or similarly significant consequences for data subjects without human review and intervention.

    8. Data Sharing, Subprocessors, And Third Parties

    We do not sell, rent, or trade Personal Data. We share Personal Data only with trusted third parties under strict contractual data protection agreements:

    8.1. Authorized Subprocessors and Change Notifications

    We engage third-party service providers (“Subprocessors”) to provide cloud infrastructure, database hosting, customer support systems, payment gateways, and security services. All Subprocessors are:

    • Contractually required to adhere to data security standards at least as stringent as those set forth in this Policy;
    • Restricted from using Personal Data for any purpose other than providing services to edoro; and
    • Subject to periodic vendor security risk assessments.

    A current list of edoro Subprocessors is maintained and available to Subscribers upon request via legal@edoro.ai. We will notify enterprise account administrators prior to engaging any new Subprocessor, allowing customers an opportunity to object on reasonable data protection grounds.

    8.2. Third-Party Integration Partners

    When you explicitly enable an integration (e.g., connecting a cloud drive or project management board), edoro transmits relevant data to that partner on your command. You are governed by the privacy statements of those third-party services for data residing in their environments.

    8.3. Legal Disclosures & Compliance

    We may disclose Personal Data to regulatory authorities, law enforcement, or courts only if required by law, subpoena, or legal process, and to the extent necessary to defend edoro’s legal rights or prevent imminent physical or financial harm.

    9. International Data Transfers & EU/UK Representation

    edoro operates globally. Personal Data may be transferred to, stored, and processed in servers located outside your country of origin (including the United States, European Union, and India).

    Whenever we transfer Personal Data across international borders, we ensure appropriate safeguards are established in compliance with Privacy Laws:

    • Standard Contractual Clauses (SCCs): Incorporating EU/UK Standard Contractual Clauses for transfers out of the EEA/UK.
    • Adequacy Decisions & Data Privacy Frameworks: Relying on European Commission adequacy decisions and international transfer frameworks where applicable.
    • Cross-Border Statutory Compliance: Ensuring data processing complies with local cross-border storage and transfer mandates (including the India DPDP Act 2023).

    Where required under GDPR Article 27 / UK GDPR, customers or regulatory authorities within the European Union or United Kingdom may direct data protection inquiries to our designated privacy office at legal@edoro.ai.

    10. Security And Encryption Standards

    Personal Data is a sensitive asset that requires rigorous protection. We implement state-of-the-art technical, physical, and organizational security measures to protect your data:

    10.1. Encryption Standards

    • Data Transmission (In Transit): All connections to edoro computing environments, web applications, APIs, and integrations are encrypted using industry-recognized cryptographic protocols (IPSec, TLS 1.2/1.3, SSH/SCP, PGP) utilizing robust hashing algorithms. Internal or proprietary cryptography algorithms are strictly prohibited.
    • Data Storage (At Rest): Storage, backups, databases, and retention environments are protected using bank-grade encryption algorithms (AES-256 bit encryption).

    10.2. Logical and Physical Data Segregation

    • Virtual Segregation: We maintain software-defined capability to isolate and disable functionality of applications using Personal Data, ensuring data can be segregated, extracted, or returned upon request.
    • Logical Isolation: Personal Data and Customer Content are logically isolated from third-party data and our internal corporate systems via application controls, logical tenant boundary locks, firewalls, and air-gapped virtual private clouds (VPCs) so that data is never commingled or corrupted.

    10.3. Access Control & System Changes

    • Restricted Access: Access to systems containing Personal Data is strictly limited to authorized employees, contractors, and officers with a verified “need-to-know” business role, guarded by multi-factor authentication (MFA), role-based access control (RBAC), and centralized audit logging.
    • System Changes: We will not knowingly make any system changes that degrade or adversely affect the security or integrity of Your Personal Data.

    10.4. Security Incident & Breach Notification

    Should you become aware of a security vulnerability or potential breach in edoro or an integrated system, you must notify us immediately at legal@edoro.ai.

    In the event of a confirmed security incident impacting Your Personal Data, edoro will notify affected account administrators without undue delay (and within statutory deadlines under Privacy Laws, such as 72 hours under GDPR) detailing the nature of the breach, potential impact, and corrective action taken.

    11. Data Retention And Deletion

    1. Retention Period: We retain Personal Data and Customer Content only as long as an account remains active, or as required to fulfill the operational purposes set forth in this Policy, or as mandated by legal, tax, or accounting requirements.
    2. Account Termination: Upon termination or expiration of your subscription, Customer Content and associated Personal Data will be retained for a standard grace period of 30 days to permit account recovery, after which it will be permanently deleted or anonymized from active databases, and purged from backup systems in accordance with standard backup rotation schedules.
    3. Data Extraction: Subscribers may export their Customer Content, decision logs, and project metadata prior to contract termination using edoro’s native export tools or API endpoints.
    4. Data Retention After Account Deletion: When your account is deleted we remove your profile, projects, files, comments and settings. Two records are deliberately kept on the basis of our legitimate interest in preventing abuse and in respecting your communication preferences, which are as follows:
      1. A one-way fingerprint of your email address, so a single address cannot claim more than one free trial. It cannot be used to contact you or to recover any of your data, and is kept for one year for that purpose alone.
      2. Your email address, if you have unsubscribed, so that we continue to honour your choice. Deleting this record would cause us to start emailing you again, which is the outcome unsubscribing exists to prevent.

    12. Cookie Policy And Tracking Technologies

    edoro uses cookies, local storage objects (LSOs), web beacons, and similar technologies to ensure core application functionality, store preferences, secure authentication, and analyze service performance.

    12.1. What are Cookies?

    A cookie is a small text file placed on your browser or device by a web server when you visit a website. It allows the platform to recognize your session, remember your preferences, and maintain continuous security.

    12.2. Categories of Cookies We Use

    Cookie Type Purpose Essential vs Optional
    Strictly Necessary / Essential Required for security, user authentication, session state management, canvas proofing rendering, and load balancing. The app cannot function without these. Essential (Cannot be turned off)
    Functional / Preferences Remembers user settings (e.g., preferred dark/light theme, timeline view states, canvas zoom coordinates, and language selection). Optional
    Performance & Analytics Collects anonymous, aggregated metrics on app responsiveness, page load times, error logs, and feature usage to help us optimize system speed. Optional

    12.3. Managing Cookie Preferences & Universal Signals (GPC / DNT)

    When you first visit www.edoro.ai, a cookie consent banner allows you to manage optional cookie preferences. You can update your choices at any time or configure your browser to block cookies.

    Global Privacy Control (GPC): edoro recognizes and respects browser-enabled Global Privacy Control (GPC) opt-out signals. If your browser broadcasts a GPC signal, our systems will automatically process it as a request to opt out of non-essential analytics tracking.

    13. Data Privacy Rights And Choices

    Depending on your geographical location and applicable Privacy Laws (GDPR, CCPA/CPRA, UK GDPR, DPDP Act, US State Laws), you possess specific rights regarding your Personal Data:

    • Right of Access / Know: Request a copy of the Personal Data we hold about you and details regarding its processing.
    • Right to Rectification: Request correction of inaccurate or incomplete Personal Data.
    • Right to Erasure (“Right to be Forgotten”): Request permanent deletion of your Personal Data, subject to statutory retention requirements.
    • Right to Restrict Processing: Request that we temporarily suspend processing of your Personal Data.
    • Right to Data Portability: Receive your Personal Data in a structured, commonly used, and machine-readable format.
    • Right to Object & Opt-Out: Object to data processing based on legitimate interests or direct marketing purposes, and opt out of any potential data sharing.
    • Right to Withdraw Consent: Withdraw previously granted consent for optional data processing at any time without affecting prior lawful processing.
    • Non-Discrimination (CCPA/CPRA): edoro will never discriminate against you (via price adjustments, service denial, or degraded quality) for exercising any of your privacy rights.

    How to Exercise Your Rights

    To exercise any of your privacy rights, please submit a written request to legal@edoro.ai. We will verify your identity and respond within the statutory timeframe mandated by applicable law (typically within 30 days).

    14. Children’s Privacy (Coppa & Global Age Limits)

    edoro is an enterprise business-to-business (B2B) SaaS content orchestration platform. Our Services are intended exclusively for business professionals and are not directed to children under the age of 18 (or under 16 in certain jurisdictions). We do not knowingly collect or solicit Personal Data from children. If we learn that we have collected Personal Data from a child without verified parental or legal guardian consent, we will promptly delete that information.

    15. Data Processing Agreement (Dpa) And Financial Data Privacy

    Where edoro processes Personal Data on behalf of an enterprise customer or corporate Subscriber subject to GDPR, UK GDPR, or US privacy statutes, edoro acts as a Processor (or Service Provider), and the customer acts as the Controller (or Business).

    • Data Processing Agreement (DPA): Data processing is governed by the edoro Data Processing Agreement (DPA), which is incorporated by reference into our Master Services Agreement (MSA) or Terms of Use.
    • Financial & Subscription Data: Transactional billing data, payment gateway logs, and subscription invoices are processed strictly for account management, financial auditing, and tax compliance. Commercial terms, licensing conditions, and refund policies are governed separately under our [Terms of Use / SaaS Service Agreement].

    16. Policy Updates

    We regularly monitor, evaluate, and adjust this Policy in light of changes to applicable laws, emerging technology, enterprise integration requirements, and security practices.

    When we update this policy, we will revise the “Last Updated” date at the top of this document. Material changes will be communicated via email or prominent notifications within the edoro application portal prior to becoming effective. Your continued use of the website or Services after an update constitutes acceptance of the revised Policy.

    17. Contact Information And Data Protection Officer

    If you have questions, concerns, feedback, or requests regarding this Privacy and Cookie Policy, or wish to report a security concern, please contact our Data Protection and Legal team:

    Attention:  Data Protection Officer / Privacy Team

    Website: www.edoro.ai

    Email: legal@edoro.ai

    Parent Entity: Clavis Technologies Private Limited