Skip to content
Coberturia
Menu

Data processing

Draft pending legal review. This text is not final yet and is not legal advice. The Spanish version prevails.

Last updated: Oct 09, 2026

This document governs how SolvyX, as processor, processes the personal data of the clients and prospects that you, the agent or broker and data controller, load into Coberturia. It is part of the Terms and conditions.

1. Roles

You decide which of your clients’ data you load and what you use it for: you are the controller. You must have a legal basis to process it (for example, their consent or the brokerage relationship) and inform them about the processing.

SolvyX is the processor: it processes that data only to provide the service to you.

2. Instructions

SolvyX processes the data only on your instructions, which are those you give when using the platform and those set out in the Terms and conditions. It does not use the data for its own purposes, does not sell it and does not share it except with the sub-processors listed here.

3. Data subjects and data types

Data subjects: your clients, prospects, insured persons and beneficiaries. Data: identification, contact details, policy and premium payment data, documents, recordings, transcripts and notes. It may include health data.

4. Confidentiality

SolvyX people who can access the data are bound by confidentiality. The support team only enters your account with your permission, and every access is logged in your organization’s audit trail.

5. Security measures

Per-organization data isolation with a double barrier in the database, encryption in transit and at rest, private files behind short-lived signed links, role-based access control, an audit log (who viewed, created, changed, exported or deleted what and when) and daily backups kept for 30 days.

6. Sub-processors

We use these kinds of providers: cloud hosting and database [provider pending], file storage [provider pending], transactional email [provider pending], SMS or WhatsApp for verification codes [provider pending] and artificial intelligence providers (Google, Mistral, Groq, OpenAI and Anthropic), always on paid plans that do not train with the data and receiving only the minimum data.

We will notify any change of sub-processors at least 15 days in advance so you can object.

7. Security breaches

If we detect a breach affecting your clients’ data, we will notify you without undue delay and within [time limit pending legal review], with the information you need to notify the authority and the data subjects.

8. Data subject rights

The platform lets you view, correct, export and delete your clients’ data to handle their requests. If a data subject writes to us directly, we will forward the request to you.

9. End of the service

When the service ends, you can export your data for 30 days. After that we delete it, including backups once their retention cycle ends, except what we must keep by law.

10. Demonstrating compliance

Upon reasonable request, we will provide the information needed to demonstrate compliance with this document.