Data & Privacy Policy
Last Updated: September 13, 2026
What Corda Stores, Why We Use It, How Long We Keep It, And How You Control It.
Effective: 15th September, 2026
This policy explains how Corda AI (“Corda”, “we”, “us”, or “our”) collects, uses, stores, discloses, and protects personal data across https://corda.marketing/, the Corda web and mobile applications, APIs, integrations, and related services. It applies to customers, workspace users, website visitors, prospects, publishers, partners, and individuals who interact with us.
Please note: Local laws and regulations may provide you with additional rights. Please review the Regional Compliance & Privacy Rights section below to understand specific rights applicable to your jurisdiction.
1. Scope, Compliance Framework & Corda’s Role
Corda is committed to international standards of data privacy, legal compliance, and security. Our parent company is Viacon FZCO. The data practices we follow, comply with applicable data protection regulations, including:
- European Union & UK General Data Protection Regulation (GDPR / UK GDPR)
- United Arab Emirates Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL)
- United States Federal and State Privacy Laws (including the California Consumer Privacy Act / CCPA, as amended by the CPRA, and applicable state privacy statutes).
Data Controller vs. Data Processor
- Data Controller / Business: For account management, marketing, analytics, sales, website operations, and customer relationship data, Corda acts as a Data Controller (or “Business” under US law) and determines the purpose and means of processing personal data.
- Data Processor / Service Provider: For Customer Data submitted to and processed within a customer’s workspace (including documents, prompts, campaign parameters, and workspace files), Corda acts strictly as a Data Processor (or “Service Provider”) operating under customer instructions, the Master Subscription Agreement, and our Data Processing Addendum (DPA). If your personal data resides within a customer’s workspace, please contact that organization directly.
2. Information We Collect
Customer-Provided Data
- Account & Identity Data: Name, business email address, company name, role, authentication credentials, workspace permissions, and billing/tax information.
- Workspace & Campaign Configuration: Domains, target pages, keywords, topics, geographic target parameters, competitor tracking lists, campaign instructions, files, uploaded assets, and integration credentials.
- Communications: Demo requests, support logs, survey responses, sales correspondence, and event registrations.
- AI Inputs: Prompts, queries, instructions, context documents, feedback, and user inputs provided to AI-assisted tools.
Generated Data & AI Outputs
- Website & Authority Analysis: Page quality signals, brand mentions, citations, topic coverage, competitor benchmarks, publisher matches, authority scores, and strategy reports.
- Campaign & Fulfillment Activity: Placement status, content approvals, link tracking, and performance metrics.
- AI Outputs: Summaries, copy drafts, topic classifications, content suggestions, and metadata generated for your workspace.
- Usage & Analytics: Feature usage logs, clickstream data, search queries within the platform, and aggregated usage metrics.
Operational & Technical Data
- Device & Connection Information: IP address, approximate geographic location, browser type, operating system, unique device identifiers, and HTTP referrers.
- Audit & Service Logs: Authentication history, API request logs, audit trails, system performance metrics, error trace logs, and security event indicators.
- Cookies & Tracking Identifiers: Essential operational tokens, preferences, analytics identifiers, and performance cookies (subject to consent preferences).
Sensitive Data Notice: Do not upload government identification numbers, financial account credentials, health/biometric data, precise geolocation data, or children’s data to Corda unless explicitly agreed to in a executed agreement or addendum.
3. How We Use Data & Lawful Bases for Processing
We process personal data for specific, lawful purposes in accordance with GDPR (Article 6) and UAE PDPL principles:
| Purpose | Lawful Basis (GDPR / UAE PDPL) |
| Operating, delivering, and maintaining the Services | Performance of a Contract |
| Generating SEO scores, campaign analytics, publisher matches, and strategy reports | Performance of a Contract / Legitimate Interests |
| Operating requested AI features and third-party integrations | Performance of a Contract |
| Invoice processing, subscription management, and payment collection | Performance of a Contract / Legal Obligation |
| System security, fraud prevention, vulnerability mitigation, and threat detection | Legitimate Interests / Legal Obligation |
| Product improvement, service optimization, and aggregated performance benchmarking | Legitimate Interests |
| Marketing, news, and promotional communications | Consent (where required) / Legitimate Interests |
4. Artificial Intelligence, Data Use & Model Training
- Inputs & Outputs: AI features process your inputs and workspace data solely to generate the requested results for your account.
- No General Model Training: Corda does not use Customer Data (including AI inputs and outputs) to train general-purpose AI models. We contractually mandate that our third-party AI infrastructure providers (e.g., LLM vendors) are prohibited from using your Customer Data to train or fine-tune their public or general-purpose models.
- De-Identified Diagnostics: Corda may use anonymized, aggregated, or de-identified metadata to monitor performance, evaluate prompt accuracy, and improve internal software engineering, provided the data cannot reasonably be re-identified or linked to an individual or customer.
- Human Oversight: Generated content, scores, and recommendations are intended as decision-support tools. They are not intended to make automated decisions that produce legal or similarly significant effects regarding individuals.
5. Data Security, Safeguards & Escrow Protection
Technical & Organizational Security Practices
Corda implements a defense-in-depth security architecture designed to protect personal data against unauthorized access, loss, alteration, or disclosure. Key security measures include:
- Encryption: Data is encrypted in transit using Transport Layer Security (TLS 1.3/1.2) and at rest using AES-256 encryption across storage systems and databases.
- Access Control: Strict Role-Based Access Control (RBAC), multi-factor authentication (MFA), least-privilege access policies, and automated session management.
- Infrastructure Security: Continuous vulnerability scans, automated patch management, network isolation via Virtual Private Clouds (VPC), and regular third-party penetration testing.
- Incident Response: Dedicated security event logging, monitoring, and breach notification procedures compliant with statutory disclosure windows (e.g., GDPR 72-hour notice, UAE PDPL mandates).
Source Code & Data Escrow Protection
To ensure business continuity, system resilience, and risk management for enterprise customers, Corda offers Software and Data Escrow Protection Options:
- Enterprise clients may request inclusion under a formal Software Escrow Agreement with a recognized third-party escrow agent.
- In the event of specified release conditions (such as insolvency or failure to maintain core operations), the escrow protection guarantees designated access to critical assets and system configurations, ensuring uninterrupted operational continuity and compliance oversight.
6. Data Residency, International Transfers & Hosting Regions
Corda offers multi-region deployment infrastructure to meet local data sovereignty and compliance requirements, specifically supporting our primary launch regions:
| Hosting Region | Availability | Regional Compliance & Residency |
| United States | Available (Default / Primary) | Hosted on US-based cloud infrastructure complying with US state and federal standards. |
| United Arab Emirates (UAE) | Available | In-region primary hosting supporting regional data sovereignty requirements under UAE PDPL. |
| Custom / Selected Region | Enterprise Plans | Regional data isolation option for specific workspace records and stored assets. |
Cross-Border Transfers
When personal data is transferred across international borders including transfers out of the European Economic Area (EEA), United Kingdom, or United Arab Emirates Corda ensures appropriate safeguards are applied:
- Standard Contractual Clauses (SCCs): Execution of EU/UK-approved Standard Contractual Clauses for international data transfers.
- UAE International Transfer Safeguards: Adherence to UAE PDPL statutory transfer requirements, relying on adequate level of protection determinations, contractual protections, or explicit consent mechanisms.
7. Retention & Deletion Schedule
We retain personal data only for as long as necessary to fulfill the operational, contractual, legal, and security purposes set out in this policy.
| Data Category | Standard Retention Period |
| Account & Profile Data | Active subscription period + 90 days post-termination |
| Workspace Settings & Uploaded Assets | Active subscription period + 30 days post-termination |
| Campaign & Performance Analytics | 90 days rolling window (or duration of account) |
| AI Inputs, Prompts & Generated Outputs | 90 days |
| Audit, Event & Security Logs | 90 days |
| Operational & Diagnostic Logs | 90 days |
| Billing & Financial Records | 7 years (or as required by statutory tax and accounting laws) |
| Backups & Encrypted Snapshots | Retained up to 180 days before automated rotation and overwrite |
8. Your Privacy Rights & Regional Controls
Depending on your jurisdiction, you possess specific legal rights regarding your personal data:
A. European Economic Area & United Kingdom (GDPR)
- Access & Portability: Request a copy of your personal data in a structured, machine-readable format.
- Rectification: Request correction of inaccurate or incomplete personal data.
- Erasure (“Right to be Forgotten”): Request deletion of your personal data under certain conditions.
- Restriction & Objection: Object to or request restrictions on data processing based on legitimate interests or direct marketing.
- Withdrawal of Consent: Withdraw consent at any time where processing was based on consent.
B. United Arab Emirates (UAE PDPL)
- Rights to access, rectify, request erasure, restrict processing, object to automated processing, obtain data copies, and lodge a complaint with the UAE Data Office.
C. United States Residents (CCPA / CPRA & State Laws)
- Right to Know & Access: Details about personal information collected, sold, or shared.
- Right to Delete: Request deletion of personal information held by Corda.
- Right to Correct: Request correction of inaccurate personal data.
- Non-Discrimination: You will not receive discriminatory treatment for exercising your privacy rights.
- Opt-Out of Sale/Sharing/Targeted Advertising: Corda does not sell personal information for monetary consideration. We do not share personal data for cross-context behavioral advertising without explicit consent.
How to Submit a Privacy Request
To exercise any of the above rights:
- Submit a request via our [Privacy Request Portal] or email us at https://corda.marketing/contact/.
- To protect your data, we will verify your identity before processing the request. Authorized agents may submit requests on your behalf provided valid authorization is supplied.
9. Cookies & Tracking Controls
Corda uses essential cookies required for authentication, security, and session management. With your consent (where required by law), we also use performance, analytics, and functional cookies.
- Managing Preferences: You can update or alter your cookie preferences at any time by visiting our Cookie Preference Center.
- Global Privacy Control (GPC): Corda recognizes and honors automated browser opt-out signals, such as the Global Privacy Control (GPC), where legally required.
10. Children’s Privacy
Corda is a business-to-business (B2B) platform. Our Services are not directed to or intended for individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a minor has provided us with personal information, please contact us immediately for deletion.
11. Third-Party Disclosures & Subprocessors
We do not sell personal data. We may disclose personal data to the following categories of recipients solely for operational purposes:
- Subprocessors & Cloud Vendors: Infrastructure, hosting, security, database, and customer support providers listed on our Subprocessor List.
- Payment Processors: PCI-DSS compliant third-party payment gateways for processing billing and renewals.
- Professional Advisors: Lawyers, auditors, insurers, and accountants acting under obligations of confidentiality.
- Corporate Transactions: In the event of a merger, acquisition, reorganization, financing, or sale of company assets, data may be transferred under strict confidentiality agreements.
- Legal Obligations: When required by applicable law, court order, or valid governmental demand.
12. Updates to This Policy
We may update this Data & Privacy Policy periodically to reflect changes in our platform, security practices, legal requirements, or international operational scope. Material changes will be communicated via email or platform notification prior to becoming effective.
13. Data Protection Officer (DPO) & Contact Information
For privacy requests, compliance inquiries, Data Processing Addendum (DPA) execution, or security reports, please reach out to:
- Data Protection Officer / Privacy Team: customer@corda.marketing
- Security & Vulnerability Reporting: support@corda.marketing
- Data Processing Addendum: [DPA REQUEST LINK]
- Subprocessor Directory: [SUBPROCESSOR LIST LINK]
- Legal Entity & Postal Address:
Corda Marketing
IFZA Business Park
Premise No: 39116-001
Makani No: A1-3641379065
Dubai Silicon Oasis
United Arabian Emirates
Table of Contents
1. Information We Collect
We collect account details you provide, such as name, email address, company name, and workspace information needed to operate Corda.
We also collect usage data from the platform, including campaign activity, publisher research, and product interactions that help us deliver and improve the service.
If you contact us, we keep the message content and related details so our team can respond and maintain a record of the request.
2. How We Use Information
We use personal data to create and manage workspaces, run campaigns, provide support, and send service-related notices.
We may also use aggregated or de-identified information to understand product performance and improve authority workflows.
We do not sell personal information to third-party data brokers.
3. Sharing and Disclosure
We share information with trusted processors that help us host the product, send email, process payments, and provide customer support.
We may disclose information if required by law, to protect Corda or our users, or in connection with a merger, acquisition, or similar corporate event.
Team members you invite to a workspace can see the data available inside that workspace according to their assigned role.
4. Data Retention
We retain personal data for as long as your workspace stays active and as needed to provide the service.
When an account is closed, we delete or anonymize personal data within 30 days unless a longer period is required for legal, billing, or security reasons.
Backup copies may persist for a limited period before they are overwritten as part of normal operations.
5. Your Rights
Depending on your location, you may request access, correction, deletion, or export of your personal data.
You may also object to certain processing or withdraw consent where processing is based on consent.
To make a request, contact us using the details below. We may need to verify your identity before completing the request.
Contact Privacy
For privacy questions or data requests, contact privacy@corda.com. or use the contact page.