Legal

Version 1.1-business-conformed-attorney-review-draft · Effective 2026-08-07

COVU Feature-Specific Consent

Template version: 1.1 business-conformed attorney-review draft - July 28, 2026 Provider: COVU Inc., a Delaware corporation Status: INTERNAL SOURCE - NOT ACTIVE UNTIL COMPLETED AND ACCEPTED

This Feature-Specific Consent supplements the COVU OS Lite Terms of Service, Privacy Notice, Data Processing Addendum, and Security Exhibit for the Agency account identified below. The Agency-level Terms/DPA/Security gate must be satisfied first. This Consent authorizes only the feature and processing expressly selected here. It does not authorize a paid module, Service Network work, or a materially different data source or purpose.

Activation summary

  • Agency legal name / Agency ID: [AGENCY / ID]
  • Feature: [GMAIL / OUTLOOK / ATTACHMENT REVIEW / MESSAGING / OTHER]
  • Business purpose: [SPECIFIC PURPOSE]
  • Selected account or mailbox scope: [NAMED MAILBOXES / USERS / FOLDERS / LABELS]
  • All-current-and-future scope: No, unless separately selected here with explicit affirmation: [ ]
  • Supported document or content classes and version: [ALLOWLIST / VERSION]
  • Data read or created: [CONTENT / ATTACHMENTS / METADATA / FINDINGS / LOGS]
  • COVU processing: [COLLECT / PARSE / EXTRACT / SUMMARIZE / CITE / STORE]
  • Material providers receiving content: [NONE - LOCAL PROCESSING ONLY / PROVIDER, PURPOSE, LOCATION]
  • Human access: [AGENCY ROLES / TIME-LIMITED COVU SUPPORT EXCEPTION]
  • Raw/temporary-content retention: [PERIOD / EVENT]
  • Finding and citation retention: [PERIOD / EVENT]
  • Audit/consent record retention: [PERIOD / EVENT]
  • Revocation path: [SETTINGS PATH / CONTACT]
  • Effective version: [VERSION / HASH / DATE]
  • Messaging Terms (messaging only): [TITLE / VERSION / HASH - DISPLAYED AND ACCEPTED]

Consent

> I represent that I am a current owner or administrator authorized to act for [AGENCY LEGAL NAME]. I instruct COVU to enable the feature only for the selected scope and purpose above. I understand what data COVU will access or create, which material providers will receive content, how long the listed records are retained, who may access them, and how to revoke this authorization. I understand that ordinary OS Lite signup or connecting a mailbox does not by itself authorize this processing.

Required checkbox:

> I authorize this feature for the selected scope.

Button:

> Authorize feature

The checkbox must not be preselected. The selected scope and provider list must appear on the final review screen.

Product boundaries

Unless a separately accepted feature schedule expressly and lawfully states otherwise:

  1. Outputs are review aids and may be incomplete or inaccurate.
  2. A qualified Agency human must verify every finding against the cited source before use.
  3. The feature does not send communications, bind or alter coverage, write to an agency-management or carrier system, route work to the Service Network, create a charge, or make a coverage, underwriting, claims, fraud, identity, employment, credit, legal, deadline, signature-validity, legal-sufficiency, compliance, or bind-readiness decision.
  4. A failed, unsupported, encrypted, malformed, sensitive, or uncertain item fails closed to human review and does not block ordinary intake.

For ALI-728 attachment review, display:

> AI-assisted review aid. Verify every finding against the cited source before use.

Every candidate must be phrased as an observation about the scan, not an assertion about the document. State what was or was not found and where; never state or imply that a document is unsigned, incomplete, expired, invalid, insufficient, ineffective, or defective. Approved patterns include:

> We didn't find text in the area where a signature usually appears. Open the cited source to check.

> We didn't find date text in the expected area. Open the cited source to check.

> We couldn't read text in the identified field or area. Open the cited source to check.

Revocation

Revocation must:

  • stop new and queued feature processing immediately;
  • fence in-flight output from becoming visible or actionable;
  • revoke or disable relevant COVU access tokens where the connection is also removed;
  • begin deletion of analysis-only copies, temporary extraction/OCR content, and unreviewed findings under the displayed retention schedule;
  • preserve only records lawfully required for security, billing, legal hold, or proof of consent/revocation, subject to access and purpose limits; and
  • leave unrelated OS Lite access active where technically and legally feasible.

Revocation is prospective and does not invalidate actions the Agency previously confirmed or charges it previously authorized. Provider-level disconnection may require an additional Google, Microsoft, carrier, or platform action, which the product must identify.

A revoked consent is not re-prompted at login. The feature remains off until the Agency affirmatively re-initiates activation.

Changes

A materially different purpose, data category, mailbox expansion, document-class expansion, content processor, retention period, or automated action requires a new disclosure and affirmative acceptance before activation. Nonmaterial clarifications may be communicated through versioned notice.

Records

COVU will retain the Agency, accepter identity and role, authority representation, selections, exact displayed language, document version/hash, timestamp, provider authorization reference, revocation event, and downloadable copy as part of the agreement ledger. IP address and user-agent/device evidence may be retained only under the Security- and Privacy-approved evidence-retention policy.

Required review

This template is an attorney-reviewable first draft, not legal advice. Before publication, licensed counsel must approve the final feature-specific wording, consent granularity, retention periods, revocation/deletion promises, state privacy implications, and provider disclosures. Security and Product must verify that the product exactly implements every displayed scope and revocation control.