Privacy Policy
Corveria ehf. ("Corveria", "we", "us") operates Anna, an AI customer-service assistant available at annasvarar.is. We respect your privacy and process personal data in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR", which applies in Iceland through the EEA Agreement) and the Icelandic Act on Data Protection and the Processing of Personal Data nr. 90/2018.
This policy explains how we handle personal data as a controller: data about our business customers and their account users, billing data, support correspondence, and visitors to our website at annasvarar.is.
Our two roles
It helps to distinguish two situations:
- As a controller. For account, billing, support, and website-visitor data, we decide why and how the data is processed. That is what this policy covers.
- As a processor. When our business customers use Anna to answer their own customers (end users), the messages and any contact details exchanged in those conversations are processed by us on behalf of the customer, who is the controller of that data. That processing is governed by our Data Processing Agreement with the customer and by the customer's own privacy notice, not by this policy. See our Data Processing Agreement and the end-user privacy notice.
Who is responsible
The controller is:
- Corveria ehf., kt. 590526-1260
- Hringbraut 58, 101 Reykjavík, Iceland
- [email protected]
We have not appointed a data protection officer, because our processing does not meet the thresholds in Article 37 GDPR. For any privacy question you can reach us at [email protected].
What we collect, why, and on what legal basis
| Data | Purpose | Legal basis |
|---|---|---|
| Account and user data (name, email, password (hashed), company, kennitala, role) | Create and operate your account, authenticate you, provide the service | Performance of a contract (Art. 6(1)(b)) |
| Billing data (company, kennitala, VSK number, billing contact, usage and amounts) | Issue invoices, take payment, keep accounts | Contract (Art. 6(1)(b)) and a legal obligation for accounting records (Art. 6(1)(c)) |
| Support correspondence (messages you send us and our replies) | Answer questions and provide support | Legitimate interests in supporting our customers (Art. 6(1)(f)) |
| Website-visitor data (waitlist email, and any analytics or cookies on annasvarar.is) | Respond to sign-ups, keep the site secure, understand site usage | Consent for non-essential cookies and marketing (Art. 6(1)(a)); legitimate interests for security and basic measurement (Art. 6(1)(f)) |
| Technical and security logs (IP address, request metadata, error diagnostics) | Keep the service secure and reliable, detect and fix faults, prevent abuse | Legitimate interests (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. You can object at any time (see "Your rights").
Cookies
Beyond the essential session cookies that keep you signed in, the app remembers a few choices you make with first-party functional cookies (your language, colour palette, and dashboard layout). The embeddable chat widget sets no cookies, and the annasvarar.is website currently sets no cookies and no non-essential trackers. We use no analytics, advertising, or tracking cookies, so no consent banner is required. See our Cookie notice for details.
Bot protection (Cloudflare Turnstile)
To protect the chat interface against automated abuse, we use Cloudflare Turnstile, a security service from Cloudflare, Inc. Turnstile runs an invisible check in the browser (Invisible mode) while the chat is used and never asks you to solve a puzzle.
During the check, Cloudflare processes limited signals from your browser: IP address, TLS fingerprint, User-Agent header, the page's Turnstile sitekey, and the page origin. The signals are used solely to detect and block bots, not to identify you, profile you, or target you with marketing. In our configuration Turnstile sets no cookies.
Cloudflare processes these signals as a processor for us when providing the service, and as an independent controller when improving its bot detection, as described in the Cloudflare Turnstile Privacy Addendum: https://www.cloudflare.com/turnstile-privacy-policy/
The legal basis for this processing is our legitimate interest in keeping the service secure and preventing abuse (Art. 6(1)(f)). For transfers outside the EEA, see "International transfers" below.
Connected Google services (Google Calendar)
If you connect a Google account to Anna (for example, Google Calendar), you grant Anna access to specific Google data through Google's OAuth consent screen. We request only the scopes needed to provide the feature you connect:
- See and download events on your calendars (the
calendar.readonlyscope): so Anna can check your availability and answer your customers' questions about open appointment times. - Create and edit events on your calendars (the
calendar.eventsscope): so Anna can add a booking to your calendar when a customer schedules an appointment through the chat.
We store the resulting Google OAuth tokens encrypted at rest with AES-256-GCM using a versioned key ring, and we access your calendar only to provide the features above. We do not sell Google user data, do not use it for advertising, and do not use it to train generalized artificial-intelligence or machine-learning models. We share it only with the sub-processors needed to operate the feature, as listed in our Sub-processor list.
You can disconnect Google Calendar at any time from the Connections page (Tengingar) in your dashboard, or through your Google Account permissions at https://myaccount.google.com/permissions. Disconnecting revokes Anna's access.
Anna's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
Connected Meta services (Messenger and Instagram)
If you connect a Facebook Page or Instagram account, Anna sends and receives messages on that channel through Meta's Messenger Platform. To do so, Anna receives the messages people send to your Page or account and the sender's display name, so it can generate and deliver replies on your behalf. When your customers message you on these channels, we process those messages as your processor under our Data Processing Agreement; this section explains the Meta connection for transparency. We store the Meta access tokens encrypted at rest (AES-256-GCM, versioned key ring) and use this access only to operate the channel. We do not use Meta data for advertising or to train generalized artificial-intelligence or machine-learning models, and we share it only with the sub-processors needed to operate the feature, as listed in our Sub-processor list. You can disconnect a Page or Instagram account at any time from the Connections page (Tengingar) in your dashboard; disconnecting revokes Anna's access.
Who we share data with
We use a small number of trusted service providers (sub-processors) to run the service, for example hosting, database, email, and the AI models that generate replies. Each is bound by a data processing agreement. The current list, including what each receives and where it processes data, is in our Sub-processor list. Additional sub-processors apply only to optional features you enable (for example Google Calendar, Messenger, or website scanning); they are also in that list.
We do not sell personal data. We disclose data to public authorities only where we are legally required to.
International transfers
Some of our sub-processors process data outside the European Economic Area (EEA). Where they do, the transfer is protected by an appropriate safeguard:
- OpenAI and Anthropic (United States): the EU Standard Contractual Clauses, with supplementary measures.
- Cloudflare and Resend (United States): the EU-US Data Privacy Framework.
- Amazon Web Services (embeddings and reranking), Hetzner, Supabase, and Sentry: processed within the EEA.
You can ask us for a copy of the relevant safeguard by emailing [email protected].
How long we keep data
| Data | Retention |
|---|---|
| Account and user data | For as long as your account is active, then deleted or anonymized within 90 days of closure |
| Billing and accounting records | 7 years, as required by the Icelandic Act on Bookkeeping nr. 145/1994 |
| Support correspondence | 12 months |
| Website waitlist | 24 months, or until you become a customer |
| Document access log | 2 years |
| Technical and security logs | A limited period appropriate to the purpose, around 90 days for error-diagnostic logs |
End-user conversation data handled on behalf of customers is retained under the customer's instructions and our Data Processing Agreement, not under the table above.
Your rights
Under the GDPR you have the right to: access your data, have it corrected, have it erased, restrict or object to processing, receive it in a portable format, and, where we rely on consent, withdraw that consent at any time. To exercise any of these, email [email protected]. We will respond without undue delay and in any event within one month, as required by Article 12(3).
Complaints
If you believe we have handled your data unlawfully, please contact us first so we can put it right. You also have the right to lodge a complaint with the Icelandic Data Protection Authority:
- Persónuvernd, Laugavegur 166, 105 Reykjavík, [email protected], personuvernd.is
If you live or work in another EEA state, you may instead complain to the supervisory authority there.
Is providing data required
Providing account and billing data is necessary to enter into and perform our agreement with you. If you do not provide it, we cannot give you access to the service.
Automated decision-making
We do not make decisions about our own users that produce legal or similarly significant effects through solely automated means within the meaning of Article 22 GDPR.
Children
The Service is intended for businesses and adults and is not directed at children. Anna is not intended for children under the age of 13, which is the age at which a child can consent to information society services in Iceland under the Icelandic Act nr. 90/2018 (the default age under the GDPR is 16). As a controller, we do not knowingly collect children's personal data. If we become aware that we have, as a controller, inadvertently processed the personal data of a child under this age, we will delete it without undue delay. A parent or guardian can contact us at [email protected].
When our customer uses Anna to answer their own end users, the customer is the controller of that data, as described in "Our two roles". A customer who directs a service at children is therefore itself responsible for obtaining appropriate parental consent and for meeting the data-protection requirements that apply to children in relation to its end users.
Changes
We may update this policy. When we make a material change we will update the version and date below and, where appropriate, notify account holders.
Version 1.1.1. Last updated 2026-08-02.