Comtech Solutions Limited

Corbiere privacy notice

v2.0, 5 September 2026

This notice is issued under Article 12 of the Data Protection (Jersey) Law 2018, with equivalent transparency under sections 12–13 of and Schedule 3 to the Data Protection (Bailiwick of Guernsey) Law, 2017, Articles 13–14 of the UK GDPR and Articles 13–14 of the EU GDPR.

1.Who we are and what this notice covers

Corbiere is a data subject access request (DSAR) management platform operated by Comtech Solutions Limited, a company registered in Jersey with registered number 101874 and registered office at 9 Hope Street, St Helier, Jersey (“we”, “us”, “Comtech Solutions”). You can contact us about anything in this notice at dpo@comtech-solutions.co.uk or by post to our registered office. Our data protection officer, appointed under Article 24 of the Data Protection (Jersey) Law 2018, can be contacted at the same address.

This notice is issued primarily under the Data Protection (Jersey) Law 2018 (“DPJL 2018”). Because Corbiere supports cases governed by other frameworks, and because our customers and the individuals whose data passes through the platform may be located outside Jersey, we also observe the Data Protection (Bailiwick of Guernsey) Law, 2017, the UK GDPR and Data Protection Act 2018, and the EU GDPR, whichever applies to you. References below are to the DPJL 2018 unless stated otherwise; the equivalent provisions of the other frameworks apply in parallel.

We act in two distinct capacities, and it matters which one applies to you.

Where we are the controller

For the personal data we hold about our customers’ staff (platform accounts), billing contacts, website enquiries and platform security records, Comtech Solutions decides why and how the data is processed and is the controller. Sections 3 to 10 of this notice explain that processing in full.

Where we are a processor

The content of DSAR cases, that is the requester’s details, identity documents, uploaded evidence, review decisions, redactions and correspondence, belongs to the organisation running the case (or the controller that organisation advises). That organisation is the controller of the case content; Comtech Solutions processes it only on that organisation’s documented instructions under Articles 19, 22 and 23 of the DPJL 2018. Section 2 explains what this means for you if your data appears inside a case.

2.If your personal data is inside a DSAR case

If you have made a subject access request to one of our customers, or your personal data appears in documents a customer has uploaded as evidence, the customer organisation, not Comtech Solutions, is the controller of that data. Their privacy notice, not this one, governs the purposes, legal bases and retention of that processing, and your data subject rights in respect of it are exercisable against them. We will refer any rights request we receive about case content to the relevant controller without undue delay.

For full transparency, we describe here what the platform does with case content on our customers’ behalf. Case content may include any category of personal data and routinely includes special category data (such as health information), criminal offence data and legally privileged material; the platform is designed on that assumption.

  • Evidence files are held in private storage accessible only to the customer organisation’s own users. The platform has no administrative role and no route by which anyone outside that organisation, including Comtech Solutions personnel, can read case content through the application.
  • Text extraction and OCR of evidence run in the user’s own browser rather than being sent to an extraction service. Case content is not emailed by the platform.
  • Where, and only where, a customer organisation has expressly enabled the optional AI assistance, the passage or document a reviewer is working on is sent to the AI provider that organisation’s administrator has selected, to generate a suggestion. Whole case files are never uploaded to a provider, the password vault is never included, and material already marked out of scope is not sent. Organisations that have not enabled the feature make no AI calls at all, and AI can also be switched off for a single case with a recorded reason.
  • The administrator selects both the model and the region it runs in, from a fixed list of four options: Claude on Amazon Bedrock in Ireland, the direct Anthropic API in the United States, or Azure OpenAI in UK South or Sweden Central. Requests go to the selected option and to nothing else, and are never routed elsewhere for capacity or failover. Anthropic does not offer a European regional endpoint, so the direct Anthropic option is a transfer to the United States and is described as one. No broker, router or evaluation service sits between the platform and the provider. Section 6 sets out each option in full, and the AI data residency and subprocessor policy gives the detail behind it.
  • We retain nothing sent to the AI layer: prompts and responses pass through to produce the suggestion and are not stored by Corbiere. What the provider itself keeps depends on the option chosen and is set out in section 6; it is not zero in every case. No option permits the provider to train a model on the content. Our records show that a request was made, by whom, against which case and on which model and region, never its content. A suggestion is only ever a suggestion; a person accepts or rejects each one, and no decision about an individual is made by the model alone.
  • Where a customer organisation invites a requester, a data controller or a data processor to a secure portal, we process the contact name and email address that organisation supplies, so that the invitation and the letters selected for that recipient can be delivered. Access is granted by one-time codes sent by email, which are stored only as a hash, expire after ten minutes and are locked after five failed attempts, or by an authenticator application the recipient sets up. Each grant is limited to the case and the documents chosen for it, lasts only for the period the organisation sets, and can be withdrawn at any time.
  • Use of a portal is recorded: sign-ins, the documents opened or downloaded, replies and uploads, together with the time and the recipient. These entries form part of the case audit trail, and the platform emails the case owner and the organisation’s administrators to alert them to that activity. The record exists so the controller can evidence what was sent, when it was received and by whom.
  • Deletion of a case removes its associated records. Retention scheduling is operated by the customer organisation, which sets and applies its own retention periods to case content.

3.Personal data we process as controller

  • Account data, collected when a customer organisation invites you as a user: your name, email address, role within the organisation and account status, together with your sign-in credentials (your password is hashed and handled by our authentication provider; we never store or log it in plain text) and, where used, second-factor and trusted-device records.
  • Billing data: the billing contact’s name, email address and subscription details, collected through our payment provider, Stripe. We never receive or store card numbers.
  • Platform security and usage records, including an audit trail of actions taken in the platform (who did what and when; the audit log deliberately records actions and identifiers only, never document text or case content), session records, and, where AI assistance is used, metering records limited to the model, the processing region, the user, the organisation and the timestamp, never the content of a prompt or a response.
  • Correspondence you send us, such as support requests.

4.Purposes and legal bases

We process account data to create and administer your access to the platform, on the basis that the processing is necessary for the performance of, or entry into, our contract with your organisation (paragraph 2 of Schedule 2 to the DPJL 2018) and, in respect of access controls, session security and the audit trail, on the basis of our legitimate interests (paragraph 5 of Schedule 2) in keeping the platform and our customers’ cases secure, demonstrating accountability, and preventing and detecting misuse.

We process billing data because it is necessary for the performance of the contract and to comply with our legal obligations in respect of accounting and tax (paragraph 3 of Schedule 2).

We process correspondence on the basis of our legitimate interests in responding to and supporting our users. Where any processing relies on legitimate interests, we have balanced those interests against your rights and freedoms and concluded they are not overridden; you may request a copy of that assessment.

5.Who receives your data

We use a small, fixed set of service providers, each acting as our processor (or, for case content, sub-processor) and each bound by contract. No other outbound transfers are made from the application. We do not sell personal data, and we do not share it with anyone else except where the law requires us to. The table below lists each provider, what it does, whether the data it handles leaves the European Union, and the transfer mechanism we rely upon; where data stays within the EU, the transfer is to an adequate jurisdiction from a Jersey perspective and no additional mechanism is required.

ProviderWhat it does for usData transferred outside the EU?Transfer mechanism relied upon
Supabase (provisioned through Lovable Cloud)Database, authentication and file storage for the platformNo, all data stored in the EUAdequacy
LovableApplication hosting, edge functions and the gateway through which transactional email is sentNo, all data stored in the EUAdequacy
ResendTransactional email delivery: invitations, verification codes and notifications; case evidence is never emailedYes, United StatesStandard contractual clauses in the vendor’s data processing agreement / UK Addendum
StripeSubscription billing and payment processing; we never receive or store card numbersYes, Stripe processes payment data in the United StatesStandard contractual clauses in Stripe’s data processing agreement
Amazon Web Services EMEA SARL (Amazon Bedrock, Claude)Optional AI assistance, where an administrator has selected Claude on Amazon Bedrock: receives only the passage or document a reviewer is working on; the model runs inside the Bedrock service, Anthropic does not receive the request, prompts and outputs are not stored after the response and are not used for trainingNo, inference runs in the AWS Ireland region (eu-west-1); AWS support access may occur from outside the EUAdequacy (European Union), with standard contractual clauses in the AWS Data Processing Addendum covering support access
Anthropic, PBC (direct Anthropic API)Optional AI assistance, where an administrator has selected the direct Anthropic API: receives only the passage or document a reviewer is working on. Anthropic does not offer a European regional endpoint, so this option processes in the United StatesYes, United StatesStandard contractual clauses in Anthropic’s data processing addendum; Anthropic self-certifies under the EU-US Data Privacy Framework and its UK extension. A transfer risk assessment is required of the controller
Microsoft (Azure OpenAI Service), Microsoft Ireland Operations Limited for customers contracted in EuropeOptional AI assistance, where an administrator has selected an Azure region: the model runs inside Microsoft’s own tenancy and OpenAI does not receive the data. Prompts and generated content are stored for up to 30 days for abuse monitoring, with review of flagged content by authorised Microsoft staff, unless Microsoft has approved modified abuse monitoring for the resourceNo, processing is pinned to UK South or Sweden Central, whichever region the administrator selected; Microsoft support access may occur from outside the regionAdequacy (United Kingdom or European Union), under the Microsoft Products and Services Data Protection Addendum, which incorporates standard contractual clauses for support access

6.AI processing, subprocessors and data residency

AI assistance is switched off unless a customer organisation turns it on. When it is on, an administrator chooses one of four fixed model-and-region combinations, and that choice decides where personal data in a request is processed and which organisation acts as our subprocessor. Nothing outside this list can be selected, so the residency position is always one of the four below.

Claude Sonnet 4.5, EU (Ireland)

Amazon Bedrock (Claude by Anthropic), through the Amazon Bedrock runtime endpoint in eu-west-1

Where processing happens
European Union — Ireland (eu-west-1)
Contracting entity
Amazon Web Services EMEA SARL (Luxembourg)
Subprocessors
Amazon Web Services EMEA SARL, Hosts the model and runs the request inside its own Bedrock service. Ireland (European Union)
What makes the transfer lawful
Inference runs in the AWS Ireland region under the AWS Data Processing Addendum, so no transfer mechanism is engaged for an EU or UK controller. For a Jersey controller the European Union is a jurisdiction the Commissioner treats as adequate, and the transfer is made on that footing under Article 66 of the Data Protection (Jersey) Law 2018. AWS support and its own subprocessors may be located outside the EU; the AWS Data Processing Addendum incorporates standard contractual clauses for that support access, so a controller relying on adequacy alone should note that support access sits under those clauses.
Retention by the provider
Amazon Bedrock does not store prompts or model outputs after the response is returned, and does not use them to train any model. Anthropic does not receive the request: the model weights run inside AWS. Bedrock model invocation logging is a separate feature and is not switched on for Corbiere, so no prompt or response is written to a log in the customer's or our account.
Onward transfers and human review
Anthropic receives no request content under this route. AWS personnel do not access content in the ordinary course; where support access occurs it is governed by the AWS Data Processing Addendum and its standard contractual clauses.

Claude Sonnet 4.5, United States

Anthropic (direct API), through the Anthropic Messages API (api.anthropic.com)

Where processing happens
United States — Anthropic does not offer a regional endpoint
Contracting entity
Anthropic, PBC (San Francisco, United States)
Subprocessors
Anthropic, PBC, Runs the model and returns the response. United StatesAnthropic's own infrastructure subprocessors, Compute and hosting used by Anthropic to serve the API, as listed in its published subprocessor list. United States
What makes the transfer lawful
This is a transfer to the United States. Anthropic Ireland, Limited exists as the group's European company, but the seller on Claude API invoices remains Anthropic, PBC in San Francisco, so the controller is contracting with a United States entity and the transfer analysis is a transfer to a third country — not an intra-EU or adequacy case. For a Jersey controller that engages Articles 66 and 67 of the Data Protection (Jersey) Law 2018 and requires appropriate safeguards: Anthropic's data processing addendum incorporates standard contractual clauses, and Anthropic self-certifies under the EU-US Data Privacy Framework and its UK extension. A controller choosing this option should complete and record a transfer risk assessment.
Retention by the provider
Zero data retention is not the default. By default Anthropic automatically deletes API inputs and outputs within 30 days. Zero data retention is a separate negotiated agreement, available only for eligible APIs and products. Even under such an agreement there are carve-outs: under Anthropic's Covered Models policy in force from June 2026, prompts and outputs for certain models are retained for 30 days on every platform including for zero-retention customers, and content flagged by trust and safety processes may be held considerably longer.
Onward transfers and human review
Anthropic personnel do not read request content in the ordinary course, but retained content exists and may be reviewed where trust and safety processes flag it, or where an investigation or legal obligation requires it. It is not accurate to say there is nothing to read: the accurate statement is that retained data is not read by personnel by default.

GPT-4.1, UK South

Azure OpenAI Service, through the Azure OpenAI resource pinned to UK South

Where processing happens
United Kingdom — UK South
Contracting entity
The Microsoft entity on the customer's Azure agreement — Microsoft Ireland Operations Limited for customers contracted in Europe
Subprocessors
Microsoft (Azure OpenAI Service), Hosts the Azure OpenAI resource and runs the model in Microsoft's own tenancy. UK South (United Kingdom)
What makes the transfer lawful
Inference runs on a resource pinned to UK South under the Microsoft Products and Services Data Protection Addendum. For an EU controller the UK adequacy decision applies; for a Jersey controller the United Kingdom is adequate under Article 66 of the Data Protection (Jersey) Law 2018; for a UK controller no transfer arises. OpenAI does not receive the data — the model runs in Microsoft's tenancy — though Microsoft support may be provided from outside the region under the standard contractual clauses in the addendum.
Retention by the provider
By default Azure OpenAI stores prompts and generated content for up to 30 days for abuse monitoring, and authorised Microsoft reviewers may examine content flagged by that monitoring. Storage and human review stop only where Microsoft has approved modified abuse monitoring for the resource under its Limited Access programme. Do not assume the exemption: the approval status of the resource behind this option is stated on the AI settings page, and Corbiere shows this option as retaining for 30 days unless the exemption is recorded. Prompts and responses are not used to train OpenAI or Microsoft models in either case.
Onward transfers and human review
No onward transfer of request content to OpenAI. Where modified abuse monitoring has not been approved, Microsoft abuse reviewers may see flagged content; where it has, no Microsoft reviewer sees request content.

GPT-4.1, EU (Sweden Central)

Azure OpenAI Service, through the Azure OpenAI resource pinned to Sweden Central

Where processing happens
European Union — Sweden Central
Contracting entity
The Microsoft entity on the customer's Azure agreement — Microsoft Ireland Operations Limited for customers contracted in Europe
Subprocessors
Microsoft (Azure OpenAI Service), Hosts the Azure OpenAI resource and runs the model in Microsoft's own tenancy. Sweden Central (European Union)
What makes the transfer lawful
Inference runs on a resource pinned to Sweden Central under the Microsoft Products and Services Data Protection Addendum and Microsoft's EU Data Boundary commitment. No transfer mechanism is engaged for an EU or UK controller; for a Jersey controller the European Union is adequate under Article 66 of the Data Protection (Jersey) Law 2018. OpenAI does not receive the data, though Microsoft support may be provided from outside the region under the standard contractual clauses in the addendum.
Retention by the provider
By default Azure OpenAI stores prompts and generated content for up to 30 days for abuse monitoring, and authorised Microsoft reviewers may examine content flagged by that monitoring. Storage and human review stop only where Microsoft has approved modified abuse monitoring for the resource under its Limited Access programme. Do not assume the exemption: the approval status of the resource behind this option is stated on the AI settings page, and Corbiere shows this option as retaining for 30 days unless the exemption is recorded. Prompts and responses are not used to train OpenAI or Microsoft models in either case.
Onward transfers and human review
No onward transfer of request content to OpenAI. Where modified abuse monitoring has not been approved, Microsoft abuse reviewers may see flagged content; where it has, no Microsoft reviewer sees request content.

Whichever option is selected: requests are not routed to another region for capacity, failover or load balancing; the selected provider is the only party that processes the content of a request; no broker, evaluation or analytics service sits in between; and OpenAI never receives content under the Azure options, because those models run inside Microsoft’s own tenancy, and Anthropic never receives content under the Amazon Bedrock option. Comtech Solutions staff do not read prompts or responses. Provider-side retention and any human review of flagged content are as stated against each option above, and are not the same for all four.

Only an administrator can change the model or region, and every change is recorded with the person, the time, the previous value and the new value. The full policy, including the assessment a controller should make before selecting a region, is in the AI data residency and subprocessor policy.

7.International transfers

Our database and file storage are hosted on Supabase infrastructure provisioned through Lovable Cloud in the European Union; Jersey treats that as an adequate jurisdiction. Where personal data is transferred out of Jersey to any other jurisdiction, we do so only in accordance with Articles 66 and 67 of the DPJL 2018, that is, to a jurisdiction providing an adequate level of protection or subject to appropriate safeguards, and with the equivalent transfer provisions of the Guernsey, UK and EU frameworks where they apply. The transfer position and mechanism for each provider are set out in the table in Section 5, and for each AI option in Section 6.

8.How long we keep your data

The table below sets out how long we keep each category of data where we are the controller, and why.

What we holdHow long we keep itWhy we may keep it
Account data (name, work email, role, account status)For the duration of your organisation’s subscription and 12 months afterwardsContract, then legitimate interests in resolving post-termination queries
Sign-in credentials, second-factor and trusted-device recordsWhile the account is active; deleted with the accountContract and legitimate interests in account security
Billing records and invoices8 yearsLegal obligation (accounting and tax)
Audit trail entries (actions and identifiers only, never content)10 yearsLegitimate interests in accountability and demonstrating compliance
AI usage metering (model, region, user, organisation, timestamp)24 monthsLegitimate interests in metering, fair-use enforcement and accountability
AI prompts and responses (held by us)Not retained by us; processed in memory and discarded once the response is returnedNot applicable
AI prompts and responses (held by the provider)Depends on the option the administrator selected: none after the response on Amazon Bedrock; up to 30 days for abuse monitoring on Azure OpenAI unless Microsoft has approved modified abuse monitoring; 30 days by default on the direct Anthropic API, subject to any zero-retention agreement and its carve-outsThe provider’s own terms, as set out in the AI data residency and subprocessor policy
Support correspondence24 months from the last messageLegitimate interests in supporting our users
Security and session records12 monthsLegitimate interests in detecting and investigating misuse
Case content (requester details, evidence, decisions, bundles)Set and applied by the customer organisation as controller; deleted within 30 days of the end of the contractProcessed on the controller’s instructions
Portal recipient contacts and access grants (name, email, invitation and withdrawal dates)For the life of the case, under the customer organisation’s retention schedule; one-time codes are held as a hash and expire after ten minutesProcessed on the controller’s instructions
Portal activity records (sign-ins, documents opened or downloaded, replies)Held with the case audit trailProcessed on the controller’s instructions, in support of its accountability obligations

Please note that deletion and retention of case content is controlled and operated by the customer organisation as controller: the platform provides deletion functions and records their use but does not apply an automatic retention schedule of its own. Your organisation’s own retention policy therefore governs how long case content is kept, and we delete case content within 30 days of the end of that organisation’s contract with us.

9.Security

We protect personal data as required by Article 21 of the DPJL 2018. Key measures include:

  • strict tenant isolation, with no administrative account or route capable of reading another organisation’s data;
  • server-side verification of identity and organisation on every request;
  • row-level security on all application tables;
  • signed, HttpOnly session cookies with a two-stage sign-in requiring a second factor;
  • encryption of all traffic in transit and of stored data at rest, with additional application-layer encryption of reviewer working material;
  • private storage buckets with short-lived signed download links;
  • redactions permanently burned into disclosure documents rather than overlaid; and
  • an append-only, tamper-evident audit trail that records actions without recording content.

No system is perfectly secure, and we will notify the Jersey Office of the Information Commissioner and, where required, affected individuals of any personal data breach in accordance with Article 20 of the DPJL 2018 (and the equivalent duties under the other applicable frameworks).

10.Your rights

Where Comtech Solutions is your controller, you have the right to request access to your personal data (Article 28), rectification of inaccurate data (Article 31), erasure (Article 32), restriction of processing (Article 33), and portability of data you provided to us (Article 34), and to object to processing carried out on the basis of our legitimate interests, including any direct marketing (Articles 35 and 36). We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects (Article 38).

We will respond to a request within four weeks of receiving it, extendable by up to a further eight weeks for complex requests, as provided by Article 27, and we may ask you to verify your identity before acting. Exercising these rights is free of charge except where a request is manifestly unfounded or excessive. If you are in Guernsey, the UK or the EU, the corresponding rights under your framework apply on equivalent terms.

If your data is inside a DSAR case, please direct rights requests to the organisation handling that case, as explained in Section 2.

11.Complaints

If you are unhappy with how we have handled your personal data, please contact us first and we will try to put it right. You also have the right to complain to the Jersey Office of the Information Commissioner (jerseyoic.org) or, as applicable, to the Office of the Data Protection Authority in Guernsey, the Information Commissioner’s Office in the UK, or your EU supervisory authority.

12.Changes to this notice

We will update this notice when our processing changes and will notify account holders of material changes by email. This version, v1.2, was published on 17 September 2026 and replaces v1.1 of 5 September 2026; it describes the secure portals used to send letters to requesters, controllers and processors, the contact details and access codes held for those recipients, and the record kept of portal activity. Version 1.1 added the AI processing, subprocessor and data residency section and the full retention table.