Draft for review — not yet legal advice. Contact: sales@corematrix.it

Legal

Privacy & GDPR notice

This notice explains what personal data Qoveris processes, why, and what rights you have under the EU General Data Protection Regulation (GDPR). The data controller is Core Matrix s.r.l., Italy.

Last updated: 4 July 2026

1. Data controller

Core Matrix s.r.l. (Italy) is the controller for the personal data described below. For any privacy request, contact sales@corematrix.it.

2. Data we process

  • Account data — your email address, display name and profile photo, collected through Firebase Authentication (email/password or Google sign-in).
  • Workspace content — the datasets, problem definitions, experiments, results and reports you create in your workspaces.
  • Provider keys (BYOK) — third-party API credentials you choose to store, kept only in encrypted form (see Section 10) and never displayed back in full.
  • Usage metering — counts of runs per workspace per billing period, used to enforce plan limits.
  • Audit logs — records of security-relevant actions (e.g. key changes, gateway runs) kept for accountability and abuse prevention.

3. Purposes & legal bases

  • Performance of a contract (Art. 6(1)(b) GDPR) — providing the platform: authentication, workspaces, solver runs, reports, billing.
  • Legitimate interest (Art. 6(1)(f)) — security, abuse prevention, rate limiting, audit logging and service integrity.
  • Consent (Art. 6(1)(a)) — where applicable, e.g. optional communications; you can withdraw consent at any time.

4. Sub-processors & where data lives

Qoveris is EU-hosted by default. We use a small set of sub-processors:

  • Google Cloud / Firebase EU

    Hosting and data storage. Application services run on Cloud Run / Firebase App Hosting in europe-west4 (Netherlands); Firestore data is stored in europe-west8 (Milan, Italy). Firebase Authentication handles sign-in.

  • Stripe EU/US under SCCs

    Payment processing for paid plans. Stripe receives your billing details directly; we never store card numbers.

  • Anthropic US under SCCs

    AI model provider — used only when you invoke the AI agent. Your prompts and relevant workspace context are processed to provide the feature. Requests use the API key configured for your workspace (BYOK where you supplied your own key).

Anthropic is engaged only when you invoke the AI agent; if you never use the agent, no data is sent to Anthropic. Quantum-hardware providers you connect via your own BYOK credentials (e.g. D-Wave, IBM, AWS) receive only the problem data required to execute the runs you request, under your own account with them.

5. No training on customer data

We do not use your workspace content, prompts or results to train machine-learning models, and we do not sell or share your data for advertising or profiling.

6. Retention

Your data is retained for the lifetime of your account. When content is deleted (or your account is closed), residual copies persist only in database backups — 7 days of point-in-time recovery (PITR) — after which they are gone. Audit and metering records may be kept longer where needed for security, billing or legal obligations.

7. Your GDPR rights

You have the right of access, rectification, erasure, data portability and objection (as well as restriction of processing and withdrawal of consent). To exercise any of them, email sales@corematrix.it. You may also lodge a complaint with your supervisory authority — in Italy, the Garante per la protezione dei dati personali.

8. Cookies

Qoveris uses no advertising or tracking cookies. Only functional cookies and local storage strictly required for authentication (Firebase session state) and remembering your workspace selection are used. Because these are strictly necessary, no cookie consent banner is required.

9. International transfers

The platform is EU-hosted by default (Netherlands and Milan regions). Limited transfers outside the EU occur only through Stripe (payments) and Anthropic (AI agent, when invoked), in each case under the European Commission's Standard Contractual Clauses (SCCs) or other valid transfer mechanisms where applicable.

10. Security

  • KMS envelope encryption for stored provider keys (Google Cloud KMS); plaintext keys are never returned after saving.
  • Deny-all Firestore security rules — data is only reachable through explicitly allowed, per-member paths.
  • Fail-closed gateway — hardware and agent runs are proxied server-side and refused when entitlements or credentials are missing.
  • Audit logs of security-relevant operations.
  • Transport encryption (TLS) for all traffic.

Contact

Core Matrix s.r.l. — Italy. Privacy requests and questions: sales@corematrix.it. See also our Terms of Service.