Privacy Policy — Corevia Software
Effective Date: 13 July 2026
Last Updated: 13 July 2026
1. Who We Are
Corevia Software ("Corevia", "we", "us") develops and sells digital products, Excel-based business systems, and software services through coreviasoftware.com (the "Website"). For the purposes of Qatar's Law No. 13 of 2016 Concerning Personal Data Protection (the "PDPPL"), Corevia is the controller of personal data collected through the Website.
Controller details: Corevia for Software Solutions (trading as "Corevia Software"), License No. 331584, Doha, State of Qatar. Privacy contact: info@coreviasoftware.com.
2. Scope of This Policy
This Policy applies to personal data we process when you visit the Website, create an account, purchase or download products, subscribe to services, or contact support. It does not apply to third-party websites or services linked from the Website (including payment gateways), which have their own privacy policies.
3. Information We Collect
(a) Registration information. Name, email address, password (stored only as a one-way cryptographic hash — we cannot read your password), and optional profile details such as company name and country.
(b) Customer profile and account activity. Account settings, email verification status, support correspondence, and preferences you set.
(c) Orders. Products ordered, order dates, amounts, currency, order status, and billing details you provide (e.g., billing name and country). We do not collect or store payment card numbers (see Section 7).
(d) Payments. Payment status and transaction references returned to us by the payment gateway (e.g., confirmation codes, masked identifiers). The gateway — not Corevia — collects your card or bank details.
(e) Downloads and entitlements. Records of which products you are entitled to, download events, timestamps, and technical logs used to protect products against unauthorized access. IP addresses in our audit and download logs are stored in a pseudonymized (HMAC-hashed) form.
(f) Device and technical information. Browser type, operating system, referring pages, approximate region, and similar technical data generated when you use the Website, collected through server logs and essential cookies.
(g) Cookies. See Section 6 and our separate Cookie Policy (COR-LEG-004).
(h) Communications. Emails and support messages you send us.
We do not intentionally collect data of "special nature" under the PDPPL (such as data relating to ethnic origin, health, religious beliefs, or criminal records), and we ask that you do not submit such data to us.
4. How We Use Your Information
We use personal data to:
(a) create and administer your account, including email verification and login security;
(b) process orders, deliver digital products, create entitlements, and enable protected downloads;
(c) provide customer support and respond to your requests;
(d) send service communications (order confirmations, receipts, license and security notices, material changes to terms or policies);
(e) secure the Website — including fraud prevention, abuse detection, rate limiting, and audit logging;
(f) comply with legal obligations, including accounting, tax, and lawful requests by competent authorities;
(g) analyze aggregate, non-identifying usage to improve products and the Website;
(h) with your consent where required, send marketing communications (see Section 15).
We do not sell personal data. We do not use personal data for automated decision-making that produces legal effects concerning you.
5. Legal Basis for Processing
Under the PDPPL, we process personal data:
(a) with your consent — for example, when you create an account or opt in to marketing;
(b) where processing is necessary to perform a contract with you — such as delivering products you have purchased;
(c) where processing is necessary for our legitimate purposes as permitted by the PDPPL — such as securing the Website and preventing fraud — balanced against your rights;
(d) where processing is necessary to comply with a legal obligation.
6. Cookies and Analytics
The Website currently uses essential cookies only — session, authentication, and security (CSRF) cookies necessary for the Website to function. We do not currently operate third-party analytics or advertising cookies.
If we enable analytics tools in the future (such as Google Analytics or Microsoft Clarity), we will update this Policy and the Cookie Policy first, and where required we will request your consent before activating non-essential cookies. Full details, including retention periods and browser controls, are in the Cookie Policy (COR-LEG-004).
7. Payments
Payments are processed by licensed third-party payment gateways through hosted payment pages (which may include Qatar-licensed providers such as Sadad or other gateways identified at checkout). Corevia never receives or stores your full card number, CVV, or banking credentials. The gateway processes your payment data under its own privacy policy and applicable financial regulations. We receive only the transaction outcome and reference data needed to fulfil your order and maintain accounting records.
8. Downloads and Entitlements
To protect paid products, downloads are tied to your account entitlements. We log download events (product, time, pseudonymized IP) for security, licensing enforcement, and fraud prevention. These logs are retained per Section 12.
9. Third-Party Processors
We share personal data only with service providers who process it on our behalf and under contractual obligations of confidentiality and security, limited to:
- Hosting and infrastructure providers (application and database hosting);
- Payment gateways (as independent controllers of the payment data they collect);
- Email delivery providers (for transactional emails such as verification and receipts);
- Professional advisers and authorities where legally required.
A current list of material processors can be requested via the privacy contact in Section 19.
10. International Data Transfers
Our hosting and email infrastructure may be located outside the State of Qatar. Where personal data is transferred across borders, we take measures designed to ensure an adequate level of protection consistent with the PDPPL, including contractual safeguards with providers. Under the PDPPL, transfers must not be made where they would breach the law or cause serious harm to data subjects.
11. Data Security
We apply technical and organizational measures appropriate to the risk, including:
- passwords stored using strong one-way hashing (bcrypt);
- encrypted connections (HTTPS/TLS) across the Website;
- HTTP-only, secure session cookies and CSRF protection;
- role-based access controls and audit logging for administrative actions;
- pseudonymization (HMAC hashing) of IP addresses in logs;
- payment card data never touching our systems;
- download files stored outside the public web directory and gated by entitlements.
No system is perfectly secure. If we become aware of a personal data breach likely to cause serious harm, we will notify the competent authority and affected individuals as required by the PDPPL and NCSA guidance.
12. Data Retention
We keep personal data only as long as needed for the purposes above:
| Data | Indicative retention | Reason |
|---|---|---|
| Account data | Life of the account + up to 12 months after closure | Service delivery; dispute window |
| Order and payment records | Up to 10 years | Accounting, tax, and commercial-record obligations |
| Support correspondence | Up to 24 months after resolution | Service quality and dispute handling |
| Security and download logs | Up to 12 months | Security, licensing enforcement |
| Marketing preferences | Until consent withdrawn | Compliance with your choices |
When retention ends, data is deleted or irreversibly anonymized.
13. Your Rights
Under the PDPPL, you have the right to:
(a) withdraw consent to processing based on consent;
(b) object to processing that is not necessary for the purposes for which data was collected;
(c) access your personal data and request a copy;
(d) correct inaccurate or incomplete data;
(e) request erasure of data that is no longer necessary for the purposes for which it was collected;
(f) be informed of any breach of your personal data likely to cause you serious harm.
To exercise these rights, contact info@coreviasoftware.com. We will respond within a reasonable period and in any event within any timeframe required by law. If you are dissatisfied, you may complain to the competent authority in Qatar (the National Cyber Security Agency's competent department for personal data protection). Rights under other laws (e.g., GDPR for EU residents, where applicable) are addressed in Section 18.
Exercising your rights is free of charge except where the law permits a reasonable fee for repetitive or manifestly unfounded requests.
14. Children's Privacy
The Services are intended for adults and business users. We do not knowingly collect personal data from children under 18. If you believe a child has provided us personal data, contact us and we will delete it. The PDPPL contains specific protections for children's data online; because our Services are not directed at children, we do not operate child-directed features.
15. Marketing Communications
We send marketing emails only with your consent (opt-in) or as otherwise permitted by law. Every marketing email contains an unsubscribe link, and you can also opt out from your account or by contacting us. Opting out does not affect service communications (receipts, security notices), which we must still send.
16. SaaS Business Data
For future hosted SaaS products, data you upload about your own business (which may include personal data of your customers or employees) is processed by Corevia on your behalf and on your instructions. You remain the controller of that data; Corevia acts as a processor. Before launching SaaS products that process third-party personal data at scale, Corevia will make a Data Processing Agreement (DPA) available to business customers.
17. Changes to This Policy
We may update this Policy from time to time. Material changes will be announced on the Website or by email before they take effect, and the "Last Updated" date will be revised. Where a change requires your consent under applicable law, we will seek it.
18. Future Compliance Considerations
Corevia serves customers inside and outside Qatar. As our customer base grows, additional regimes may apply to some processing, including the EU/UK GDPR (for offering goods or services to individuals in the EU/UK), and other national privacy laws. We do not currently claim certification under any privacy framework, and we do not claim GDPR representation arrangements. Before materially targeting such markets, Corevia will assess and implement any required measures (legal bases, representative appointments, transfer mechanisms, notices).
This Policy does not claim any certification (e.g., ISO 27001, SOC 2) that Corevia does not hold.
19. Contact Information
Corevia for Software Solutions (trading as Corevia Software) — Privacy
Website: https://coreviasoftware.com
Privacy contact: info@coreviasoftware.com
Registered address: Doha, Qatar
License Number: 331584