Privacy Policy
Effective and last updated: 8 August 2026
Operator: STRIATUM AI LTD (company number 17306880), incorporated in England and Wales
Privacy contact: [email protected]
At a glance
Corvus is an AI-powered business platform for construction businesses. We use personal information to provide accounts, communications, AI assistance, scheduling, billing, security and customer support. AI providers may receive prompts, call context and outputs as described below; their retention and training practices depend on the applicable service and contract. Some information is processed internationally by the providers listed in this policy.
1.About this policy
This Privacy Policy explains how STRIATUM AI LTD ("Striatum", "we", "us" or "our") collects, uses, stores and shares personal information through Corvus, our websites, applications and related services (together, the "Services"). Corvus is the product name; STRIATUM AI LTD is the legal operator. This policy applies wherever the Services are offered.
Our initial markets are the United Kingdom and Australia. Mandatory local law continues to apply, and we may provide country-specific notices or supplements as we enter additional markets. A local supplement will prevail to the extent that it expressly addresses a local requirement or conflicts with this policy.
This policy is not part of an employment contract and does not govern information processed solely for our own staff or job applicants, which may be covered by a separate notice.
2.Our role and our customers' role
For account administration, billing, our own marketing, website operation, security and service improvement, Striatum generally decides why and how personal information is used. In UK terminology, we act as a controller.
Our business customers may upload or generate information about their leads, clients, suppliers, subcontractors, workers, site visitors and other contacts. For that customer content, the customer normally decides why the information is processed, and Striatum processes it on the customer's instructions to provide Corvus. In UK terminology, the customer is normally the controller and Striatum is its processor. In Australia and other jurisdictions, equivalent concepts may be described differently.
Customers are responsible for having an appropriate legal basis, giving required notices, honouring individual rights and configuring call recording, messaging, AI and location features lawfully. If your information was entered by one of our customers, please contact that customer first. We will assist the customer where required.
3.Personal information we collect
- Account and identity information:Name, business name, job title, username, email address, telephone number, profile details, authentication identifiers and OAuth account identifiers.
- Business and verification information:Australian Business Number (ABN), UK Companies House company number, legal and trading names, business address, registration status, trade or service details and related information collected during onboarding to identify a customer, verify its business and reduce fraud or misuse.
- Billing information:Subscription, invoice, transaction status, billing contact and limited payment details. Stripe processes full card or bank details; we generally receive tokens, status and limited payment metadata.
- Communications:SMS, voice-call metadata, email, calendar entries, WhatsApp messages when that feature launches, and the content of communications sent through or connected to Corvus.
- Voice and AI content:Prompts, agent instructions, responses, call audio where audio recording is enabled, and transcripts, summaries and extracted action items. VAPI voice calls are automatically transcribed and summarised.
- CRM and customer content:Lead and client contact details, enquiry history, notes, appointments, quotes, job information, tasks, files and other information a customer chooses to enter.
- Workforce and site information:Names and contact details of workers, subcontractors or site visitors; roles, schedules, job assignments, attendance, progress notes, permits, incidents and related operational information entered by a customer.
- Location and site data:Site addresses and, when future features are enabled, device or worker location, timestamps, geofencing events, routes or other site-related location information. We will provide additional in-product notice and controls before collecting precise location data.
- Device, log and security information:IP address, browser and device type, operating system, access times, diagnostic logs, authentication events and information used to detect fraud, abuse or security incidents.
- Support and feedback:Support requests, complaint details, survey or feedback responses and related correspondence.
Corvus does not require sensitive or special-category information as a standard part of the Services. Depending on what a customer enters, customer content may nevertheless include health and safety, injury, accessibility, union, religious, criminal-offence or other sensitive information. Customers must not submit that information unless it is necessary and lawful. For information governed by UK data-protection law, the customer is responsible for identifying and documenting an applicable condition under Article 9 UK GDPR and, where required, Schedule 1 to the Data Protection Act 2018, or an appropriate legal authority and safeguards for criminal-offence information. Equivalent requirements apply under other relevant laws.
4.How we collect information
- Directly from you when you register, subscribe, contact us, connect an integration or use the Services.
- From our business customers and their authorised users when they enter or import information.
- From communications and integrations you connect, including Twilio, VAPI, Google Calendar, Gmail and, once live, WhatsApp.
- Automatically from devices, servers, essential cookies and service logs.
- From public business registers or verification sources when necessary to verify a business or prevent misuse.
5.Why we use personal information
The UK lawful bases below apply where Striatum acts as controller. Where we process customer content as a processor, the customer determines and documents the applicable lawful basis and we process the information on its instructions, subject to law.
| Purpose | What this includes | UK lawful basis |
|---|---|---|
| Provide and administer the Services | Create accounts, collect ABNs and UK Companies House company numbers during onboarding, identify and verify business customers, authenticate users, operate CRM, communications, calendars, workflows and site tools, and deliver customer-requested functionality. | Contract; legitimate interests. |
| AI assistance and automation | Process prompts and customer content, generate responses, summaries and actions, route tasks and maintain permitted workspace memory. | Contract; legitimate interests; consent where required. |
| Communications | Send and receive calls, SMS and email and, once launched, WhatsApp messages; provide transactional notices and respond to enquiries. | Contract; legitimate interests; consent where required by communications or recording law. |
| Billing | Manage subscriptions, payments, invoices, refunds and accounting records. | Contract; legal obligation; legitimate interests. |
| Security and integrity | Authenticate users, monitor availability, prevent fraud and abuse, investigate incidents, enforce terms and protect users and the Services. | Legitimate interests; legal obligation. |
| Support and improvement | Resolve problems, understand feature performance and improve reliability and usability using feedback, logs and de-identified or aggregated information where practicable. | Legitimate interests; consent where required. |
| Legal and corporate purposes | Comply with law, respond to lawful requests, establish or defend claims, conduct audits and support a merger, financing or business reorganisation. | Legal obligation; legitimate interests. |
Where we rely on legitimate interests, those interests include operating and securing a useful business service, preventing misuse, supporting customers and improving reliability. We consider the impact on individuals and do not rely on this basis where their rights and interests override ours. Where consent is the basis, it may be withdrawn without affecting earlier lawful processing.
6.AI systems and Hermes memory
Corvus uses Anthropic's Claude for CRM chat, Google's Gemini for auxiliary AI tasks, and OpenAI's gpt-4o for VAPI voice-agent responses. For a voice call, OpenAI may receive a system prompt and relevant lead context such as the person's name, pipeline stage and active job title.
The self-hosted Hermes gateway orchestrates some AI interactions on Striatum-controlled infrastructure in Singapore and may route conversation messages to Anthropic or, when configured, to a Nous Research hosted model endpoint.
Striatum does not itself use customer content to train a general-purpose AI model. Information sent to an external AI provider is handled under that provider's applicable account terms and settings. When a Nous Research hosted endpoint is selected, prompts, inputs, outputs, usage data and related information may be processed under Nous Research's public terms, which permit certain information to be used to develop, improve or train its services unless different contractual terms apply. Customers should avoid placing unnecessary personal or sensitive information in prompts.
Data obtained through Google Workspace APIs (Calendar and Gmail) is excluded from any Nous Research training and is never processed by a Nous Research endpoint.
Hermes may maintain personalised operational memory for a particular customer, account or workspace, including useful context, preferences, prior actions or outcomes. This memory may contain personal information included in interactions and is separate from an external provider's model-training practices. Its retention is determined by the life of the relevant account or workspace, whether the information remains necessary for the configured service and any valid deletion instruction, subject to technical, security, contractual and legal retention requirements.
Corvus uses computer programs and automated workflows to assist with appointment reminders, dormant-lead re-engagement, pipeline and job-status monitoring, and invoice-overdue escalation messages at configured stages, including 7, 14, 21 and 30 days after the due date. These processes may use names, contact details, appointment and communication history, job or pipeline status, invoice status, amount and due date. They may determine whether and when to send a message, which escalation stage applies, or whether to flag or update a workflow item. Customers configure and control these workflows and must provide human review where a process could materially affect a person's rights or interests.
AI output may be inaccurate. Corvus is not intended to make solely automated decisions with legal or similarly significant effects unless expressly agreed, lawfully configured and accompanied by required safeguards and notices. Affected individuals may contact the relevant Corvus customer or [email protected] to ask about a process or request human review where applicable.
7.Calls, messages and connected services
Corvus uses Twilio for SMS and voice communications and VAPI for AI voice calls. Every call handled by the VAPI-based Sophia agent is automatically transcribed and summarised. VAPI sends the transcript and summary to our workflow system, where they are used to identify the caller and create or update a lead. Corvus does not currently store the transcript as a separate conversation record in Supabase. VAPI may retain call artifacts under its account settings and applicable terms. Call audio may also be recorded where recording is enabled in the relevant assistant configuration.
Before activating voice calls, customers must ensure that callers receive every announcement, consent choice and opt-out required for transcription or recording. Customers must also comply with applicable telemarketing, spam, do-not-call, workplace-monitoring and communications laws.
WhatsApp functionality through Meta is planned but is not live as of the effective date. We will update relevant notices before that functionality processes personal information.
Transactional email is provided through Zoho Mail.
If a customer connects Google, Corvus requests identity confirmation and the account email address, full Google Calendar access to read and write events, and Gmail access to read, modify, label, send and move messages to trash. Users can revoke access through their Google account settings or within Corvus where available. We do not use Google user data for advertising.
8.Cookies, analytics and monitoring
We use cookies or similar local-storage technologies that are necessary for authentication, security, session continuity and core application functions. Where law requires consent for a non-essential cookie, we will request it before use.
We do not currently use product analytics tools. We may use analytics tools in the future to understand and improve the Services. Before doing so, we will update this policy, provide any required cookie information and consent controls, and explain the categories of data and providers involved.
We may also introduce an availability-monitoring service, such as UptimeRobot, which may process limited technical request and incident information.
9.Who receives personal information
We disclose personal information only as reasonably necessary for the purposes described above, on customer instructions, with consent, or where legally required. Recipients may include:
| Provider / category | Role |
|---|---|
| Anthropic | Claude AI processing |
| Gemini, Google OAuth, Gmail API and Google Calendar API | |
| OpenAI | gpt-4o AI processing for VAPI voice-agent responses |
| Hermes gateway | Striatum-operated AI orchestration and workspace memory on Vultr infrastructure in Singapore |
| Nous Research | Hosted model inference when a Nous Portal endpoint is selected |
| Twilio | SMS and voice communications |
| VAPI | AI voice calls and related call processing |
| Meta / WhatsApp | Planned messaging functionality; not yet live |
| Zoho | Transactional email |
| Stripe | Billing and subscriptions |
| Supabase | Database, file-related services where configured, and authentication |
| Vultr | Application and Hermes server hosting in Singapore |
| Amazon Web Services | Singapore hosting for Striatum’s self-hosted n8n workflow system |
| Cloudflare | DNS, SSL, content delivery, performance and security |
| n8n | Striatum-controlled workflow automation running on AWS in Singapore |
We may also disclose information to professional advisers, auditors, insurers, regulators, courts, law-enforcement bodies, prospective purchasers or investors and other parties involved in a corporate transaction, subject to appropriate confidentiality and legal controls.
Striatum does not sell personal information or disclose it for third-party targeted or cross-context behavioural advertising. Our provider list and features may change. We will update this policy before a change materially alters how personal information is used or disclosed.
10.International processing and transfers
STRIATUM AI LTD is established in the United Kingdom and serves customers in the United Kingdom and Australia. Personal information is likely to be disclosed to, accessed from or stored in the United States, Japan and Singapore, as well as the United Kingdom, Australia, countries in the European Economic Area and other countries used by a provider's disclosed subprocessors.
In particular, customer application records are held by Supabase in Tokyo, Japan; the Corvus application servers and Hermes gateway run on Vultr in Singapore; and Striatum's n8n workflow system runs on AWS in Singapore. VAPI, OpenAI and communications providers may process relevant voice or message data in the United States.
For transfers subject to UK data-protection law, we rely on UK adequacy regulations where they cover the destination and recipient. Where they do not, we use an appropriate safeguard where required, such as the UK International Data Transfer Agreement or UK Addendum to approved standard contractual clauses, together with any required transfer assessment and technical or organisational measures.
Overseas recipients of Australian personal information are principally located in the United States, Japan and Singapore. We take reasonable steps required by applicable Australian law before disclosure to an overseas recipient. Contact us for further information about safeguards relevant to a particular transfer.
11.How long we keep information
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, to provide the Services, follow customer instructions, maintain security and business records, and meet legal, tax, accounting and dispute-resolution obligations. Retention depends on the type of information, sensitivity, risk, customer settings and applicable law.
- Account and CRM content:For the subscription term. When an organisation closes its account, it enters a 30-day deletion period and is then scheduled for permanent deletion, unless law requires us to retain particular records longer.
- SMS and stored conversations:For the life of the customer account and through the 30-day deletion period. No separate age-based deletion rule is currently applied.
- VAPI transcripts, summaries and call artifacts:Transcripts and summaries are processed transiently by our n8n workflow and are not currently stored as separate conversation records in Supabase. VAPI may retain transcripts, summaries and any enabled audio recordings according to the relevant assistant settings, service terms and the period needed to provide and secure the voice service.
- Hermes memory:While the relevant account or workspace is active and the memory remains necessary for the configured service, unless earlier deletion is validly requested. Removal remains subject to technical, security, contractual and legal retention requirements.
- Billing and corporate records:For the period required by tax, accounting, company and limitation laws.
- Automation, security and diagnostic logs:Automation logs currently have no automatic age-based purge and may remain for the account lifetime. Other logs are kept for a period appropriate to investigation, fraud prevention, reliability and security.
- Backups:Deleted information may remain in encrypted or access-restricted backups until it is overwritten. Supabase database backups run daily and are retained for 7 days. Vultr and AWS infrastructure snapshots are maintained on an operational schedule. Backup copies are isolated from ordinary use and retained only for recovery, security and legal purposes.
When retention is no longer necessary, we delete, anonymise or securely isolate the information. Customers may have their own legal retention duties for content they control.
12.Security
We use reasonable technical and organisational measures designed to protect personal information, including access controls, authentication, encryption in transit, provider security controls, logging and measures to prevent abuse. No internet service or storage system is completely secure, and we cannot guarantee absolute security.
Customers must protect credentials, use appropriate user permissions, promptly remove former users, secure connected services and notify us at [email protected] if they suspect unauthorised access.
13.Your privacy rights
United Kingdom
Depending on the circumstances and lawful basis, you may have rights to be informed; request access, correction or erasure; restrict processing; object to processing; receive portable data; withdraw consent; and obtain safeguards in relation to solely automated decisions. Some rights are qualified and exemptions may apply. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
You have an absolute right to object to the use of your personal information for direct marketing. Tell us at [email protected] and we will stop that use.
Australia
Where the Australian Privacy Act 1988 and Australian Privacy Principles apply, you may request access to personal information we hold about you and ask us to correct it. You may also make a privacy complaint. We will acknowledge and investigate complaints and aim to respond within a reasonable period, ordinarily within 30 days. Overseas recipients of Australian personal information are principally located in the United States, Japan and Singapore, as described in section 10. If you are not satisfied with our response to a complaint, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Other countries
Local law may give you additional rights. We will honour applicable mandatory rights and publish local supplements when appropriate as we expand.
To exercise a right, email [email protected]. We may need to verify your identity and authority. If Striatum processes the information only for a customer, we may refer the request to that customer. We will not discriminate against you for exercising a privacy right.
14.Direct marketing
We may send business marketing where permitted by law. You can opt out using the unsubscribe method in the message or by emailing [email protected]. Service, security and billing messages are not marketing and may continue while you use Corvus.
Our customers are responsible for marketing or outreach they conduct through Corvus, including compliance with UK privacy and electronic-communications rules, Australia's Spam Act and Do Not Call Register requirements, and other applicable laws.
15.Children
Corvus is a business service and is not directed to children. We do not knowingly invite children to create accounts. Customers must not use Corvus to collect children's information unless that use is lawful, necessary, covered by an appropriate agreement and accompanied by required notices and consent.
16.Changes to this policy
We may update this policy when our Services, providers, legal obligations or markets change. We will post the updated version with a new effective date and provide additional notice where a change is material or law requires it. We will update this policy before launching material new analytics, WhatsApp processing or new uses of precise location data.
17.Google API Limited Use Disclosure
Corvus's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Corvus does not use data obtained through Google Workspace APIs to develop, improve, or train generalized or foundational AI/ML models.
18.Contact and complaints
STRIATUM AI LTD | Company number 17306880 | England and Wales | [email protected]
Email us with privacy requests or complaints and include enough information for us to understand the matter. We will investigate fairly and respond within the period required by applicable law. Our current registered-office address appears in the public Companies House register under company number 17306880; a postal address or copy of this policy is available on request.