Cordiva
    ES

    Privacy Policy

    Last updated: August 17, 2026

    Cordiva AI is a trade name of Javier Tabarovsky. This policy applies to all new and ongoing relationships.

    Cordiva ("we," "us," or "our") operates the website cordiva.ai and provides AI-powered voice receptionist services for medical spas ("Services"). Cordiva AI is a trade name of Javier Tabarovsky, an individual, based in Madrid, Spain. This Privacy Policy describes how we collect, use, disclose, and protect information when you visit our website or use our Services.

    Cordiva's policy is to treat each Service client as a HIPAA Covered Entity for purposes of the Services and to execute a Master Services Agreement and a Business Associate Agreement ("BAA") before processing Protected Health Information ("PHI") on that client's behalf. This policy does not constitute a legal determination that a particular client is, in fact, a Covered Entity under HIPAA. When Cordiva processes PHI under an applicable BAA, Cordiva acts as a Business Associate on the client's behalf. The applicable client's Notice of Privacy Practices, rather than this Privacy Policy, governs that client's relationship with its patients and its use and disclosure of PHI.

    If you have entered into a Master Services Agreement ("MSA"), BAA, Order Form, or other written agreement with Cordiva, that agreement controls to the extent of a conflict with this Privacy Policy concerning the Services. This Privacy Policy does not expand Cordiva's contractual obligations or alter any limitation of liability, disclaimer, or allocation of responsibility under those agreements.

    This policy is governed by the laws of Spain; disputes are resolved by arbitration in Madrid, Spain; provided that an executed MSA governs the law and dispute-resolution provisions applicable to a client relationship.

    1. Information We Collect

    Information you provide directly:

    When you fill out our contact form, we collect your full name, email address, phone number, business name, estimated monthly call volume, and optionally a description of the call problem you want to solve. This information is used solely to evaluate your business needs and contact you about our Services.

    Please do not submit patient health information, medical-record information, payment-card information, or other sensitive personal information through a general Site contact form.

    This instruction applies to Cordiva's public website contact form only. It does not apply to Cordiva's designated support channel, which may receive PHI from authorized Client personnel where reasonably necessary for support and is subject to the applicable BAA. Client personnel should nevertheless limit support submissions to the minimum information reasonably necessary to describe and resolve the issue.

    Information collected through our Services:

    When we provide AI voice receptionist services to our clients (medical spas), our system processes inbound and outbound phone calls. Call recordings, transcripts, caller phone numbers, appointment details, and related data are processed by our voice-infrastructure provider, engaged under the Business Associate Agreement policy described in Section 4. Call transcripts and recording URLs may also be transmitted through an Amazon Web Services, Inc. ("AWS") Lambda function to make them available through the applicable Client dashboard. We do not ordinarily persistently store call recordings or transcripts in Cordiva-controlled systems.

    Cordiva's systems are designed to minimize persistent storage of PHI. However, PHI may be processed, transmitted, temporarily cached, logged, or transiently retained in Cordiva-controlled systems or authorized Subcontractor systems where reasonably necessary to provide, secure, maintain, support, troubleshoot, or improve the reliability and quality of the Services.

    Support tickets submitted through Cordiva's designated support channel may contain PHI. Support-ticket content may be stored in AWS DynamoDB, and attachments may be stored in AWS S3, under Cordiva's BAA with AWS. Retention periods for support-ticket content and attachments are described in Section 5.

    Onboarding and customization chats may be processed through Amazon Bedrock under Cordiva's direct BAA with AWS. These chats concern Client business configuration, and information submitted in them may be incorporated into the applicable agent configuration, scripts, workflows, or other Service settings.

    Call recordings and transcripts are retained for thirty (30) calendar days through the applicable voice-infrastructure platform, subject to the applicable BAA, technical limitations, applicable law, and a different period expressly agreed in writing.

    Automatically collected information:

    We use limited local storage on your device to remember functional preferences, such as your cookie-consent choice and your language selection. Our hosting and infrastructure providers generate standard server logs, which may include IP address, request time, pages requested, referring URL, browser type, and device information, and which we use to operate and secure the Site and to prevent abuse.

    We do not operate advertising pixels or other advertising or cross-context behavioral-advertising trackers on the Site. We do not send PHI or other sensitive health information to advertising or analytics platforms.

    2. How We Use Your Information

    We use the information we collect to:

    • Respond to your inquiries and provide the Services you request
    • Monitor, diagnose, and improve the reliability and quality of the Services using operational telemetry, such as latency, error, completion, success-rate, and sentiment-score data; provided that Cordiva does not use call recordings or transcripts for routine agent diagnosis or improvement and does not use PHI to train a general-purpose artificial-intelligence or language model unless the PHI has first been de-identified in accordance with applicable law or another valid legal permission applies
    • Send you information about our Services (only if you opted in)
    • Analyze website traffic and improve our website
    • Comply with legal obligations, including HIPAA
    • Operate, secure, maintain, support, troubleshoot, and prevent fraud, abuse, security incidents, and unlawful activity in connection with the Site and Services

    We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are used in the California Consumer Privacy Act, as amended. We do not sell PHI, and we do not use PHI for advertising or marketing.

    When Cordiva processes PHI through the Services, Cordiva uses and discloses PHI only as permitted by the applicable BAA, the client's instructions, and applicable law. Cordiva may use de-identified information for lawful purposes, including analytics, benchmarking, security, product development, and service improvement, consistent with the applicable BAA.

    Cordiva may process PHI submitted through the designated support channel or onboarding and customization chats as necessary to provide, configure, secure, maintain, support, or troubleshoot the Services, as permitted by the applicable BAA.

    3. HIPAA Compliance

    Cordiva's policy is to treat each Service client as a HIPAA Covered Entity for purposes of the Services and to execute a Master Services Agreement and a BAA before processing PHI on the client's behalf. This policy does not constitute a legal determination that a particular client is, in fact, a Covered Entity under HIPAA. When Cordiva processes PHI under an applicable BAA, Cordiva acts as a Business Associate on the Client's behalf. Cordiva's policy is to execute a Business Associate Agreement with each client and with every Subcontractor that creates, receives, maintains, or transmits PHI on Cordiva's behalf, and not to enable a Subcontractor to process PHI before that agreement is in place.

    Call recordings and transcripts are stored by our voice-infrastructure provider (currently Retell AI, Inc.) or another authorized Subcontractor engaged under the Business Associate Agreement policy described above. Cordiva may also process PHI through AWS for Client-dashboard delivery, support-ticket content and attachments, onboarding and customization chats, and related technical functions, as permitted by Cordiva's BAA with AWS and the applicable Client BAA.

    Cordiva's own systems are designed primarily to store business configuration data, such as service catalogs, pricing, scheduling rules, scripts, and workflows, rather than persistently storing recordings or transcripts. Nonetheless, Cordiva-controlled systems and authorized Subcontractor systems may process, transmit, temporarily cache, log, or transiently retain PHI where reasonably necessary to provide, secure, support, maintain, or troubleshoot the Services.

    Cordiva's designated support channel is covered by the applicable BAA and may receive PHI from authorized Client personnel where reasonably necessary for support. Support-ticket content may be stored in AWS DynamoDB, and attachments may be stored in AWS S3. Onboarding and customization chats are also covered by the applicable BAA; those chats concern Client business configuration, and submitted information may be incorporated into the applicable agent configuration, scripts, workflows, or other Service settings.

    Cordiva processes PHI only as permitted by the applicable BAA, the client's instructions, and applicable law. Cordiva does not sell PHI, use PHI for marketing, or intentionally disclose PHI to advertising or Site analytics platforms.

    Suspected security or privacy incidents and suspected unauthorized use or disclosure of PHI are reported to security@cordiva.ai, as described in Sections 7 and 11.

    For more details on how we handle health information, see our HIPAA Compliance Statement (cordiva.ai/hipaa). If there is a conflict between this Privacy Policy and the applicable BAA concerning PHI, the BAA controls.

    4. Data Sharing and Subprocessors

    Cordiva's policy is to execute a Business Associate Agreement with every vendor that creates, receives, maintains, or transmits PHI on Cordiva's behalf, and not to enable a vendor to process PHI before that agreement is in place.

    We share information only with the following categories of service providers, each under a written agreement appropriate to its role:

    • Voice infrastructure: Retell AI, Inc. (call processing, recordings, transcripts; processed in the United States)
    • Cloud infrastructure and artificial-intelligence services: Amazon Web Services, Inc. (AWS), including AWS Lambda for Client-dashboard delivery; DynamoDB and S3 for support-ticket content and attachments; and Amazon Bedrock for onboarding and customization chats (processed in the United States)
    • Email and communications: Google LLC / Google Workspace, including the support@cordiva.ai mailbox, which may receive PHI from authorized Client personnel
    • Payment processing: Stripe, Inc. (subscription billing, payment processing)
    • Other operational providers: cloud-hosting, storage, backup, security, communications, customer-support, and technical-infrastructure providers, as reasonably necessary to operate, secure, support, and improve the Site and Services.

    We do not share PHI with analytics providers or marketing platforms, and we do not use PHI for cross-context behavioral advertising.

    Cordiva accesses language models used for voice interactions through Retell AI and the applicable downstream written arrangements. Cordiva uses Amazon Bedrock under its direct BAA with AWS for non-voice product features, including onboarding and customization chats. Cordiva does not use PHI to train a general-purpose artificial-intelligence or language model unless the information has first been de-identified in accordance with applicable law or another valid legal permission applies.

    Where a provider creates, receives, maintains, or transmits PHI on Cordiva's behalf, Cordiva requires a written agreement containing the HIPAA protections applicable to that provider's role. A current list of material PHI-handling Subcontractors is available to a client upon reasonable written request, subject to Cordiva's reasonable protection of confidential, proprietary, and security-sensitive information.

    We may also disclose or transfer information in connection with an actual or proposed financing, merger, acquisition, reorganization, formation of a controlled affiliate, sale of assets, bankruptcy, or similar transaction. Any successor that handles PHI will be required to enter into any agreement required by HIPAA before receiving or handling PHI.

    We may disclose information where reasonably necessary to comply with applicable law, legal process, governmental requests, or contractual obligations; enforce our agreements; detect or prevent fraud, abuse, or security incidents; or protect the rights, property, safety, or security of Cordiva, our clients, callers, or others.

    5. Data Retention

    • Website form submissions: retained up to 24 months after last contact, unless a longer period is reasonably necessary for legal claims, compliance, security, or business records.
    • Call recordings and transcripts: retained for thirty (30) calendar days through the applicable voice-infrastructure platform, subject to the applicable BAA, technical limitations, applicable law, and a different period expressly agreed in writing.
    • Support-ticket content: stored in AWS DynamoDB and retained for the duration of the client agreement, then returned or destroyed as provided in the applicable BAA, subject to applicable law, backups, security records, and technical limitations. Support-ticket attachments: retained in AWS S3 for up to ninety (90) days, with non-current object versions generally purged after seven (7) days, subject to applicable law, backups, security records, and technical limitations.
    • Onboarding and customization chats: retained only as reasonably necessary to provide, configure, support, secure, and maintain the Services, subject to the applicable BAA, applicable law, and the retention practices of the applicable provider.
    • Client business configuration data: retained for the duration of the service agreement plus 12 months, unless a longer period is required or permitted by law, the applicable client agreement, or legitimate legal, security, or accounting needs.
    • Payment records: retained as required by applicable tax and accounting laws and as reasonably necessary for fraud prevention, dispute resolution, and legal compliance.

    Cordiva does not provide medical-record storage, legal-record retention, or archival services unless expressly agreed in a written client agreement. Each medical spa is responsible for determining and satisfying its own patient-record, clinical-record, professional-licensing, insurance, litigation-hold, and other retention obligations, including by exporting and preserving information in systems it controls.

    Information may remain in backups, archival systems, security logs, audit trails, or disaster-recovery systems for a limited period until overwritten or deleted under ordinary retention practices. Where PHI remains because return or destruction is infeasible, Cordiva will continue to protect it and limit its use as required by the applicable BAA.

    6. Your Rights

    Depending on your jurisdiction, you may have the right to:

    • Access the personal information we hold about you
    • Request correction of inaccurate information
    • Request deletion of your information
    • Opt out of marketing communications
    • Request a copy of your data in a portable format
    • Withdraw consent where processing is based on consent, subject to applicable legal or contractual limitations
    • Object to or request restriction of certain processing where applicable law provides that right

    To exercise any of these rights, contact us at privacy@cordiva.ai. We may request information necessary to verify your identity or authority to act for another person before responding. These rights are not absolute and may be subject to legal exceptions and other limitations.

    If you are a patient or caller seeking access to, correction of, restriction on, or other rights concerning PHI processed through Cordiva's Services, please contact the medical spa or other healthcare provider directly. Cordiva processes PHI as a Business Associate on behalf of that client and will assist the client as required by the applicable BAA and HIPAA.

    You may opt out of promotional emails by using the unsubscribe link in the message or contacting us at privacy@cordiva.ai. We may continue to send non-promotional account, transaction, security, legal, and service-related communications.

    Residents of California and certain other U.S. states may have additional rights under applicable privacy laws, including rights to know, access, correct, delete, or obtain a portable copy of personal information and, where applicable, to opt out of the sale or sharing of personal information. Cordiva does not sell personal information and does not share personal information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act, as amended by the California Privacy Rights Act. Cordiva does not operate advertising trackers on the Site. Cordiva will not unlawfully discriminate against an individual for exercising an applicable privacy right.

    7. Security

    We implement technical and organizational measures appropriate to the applicable system and information, including encryption in transit (TLS), access controls and authentication measures, role-based restrictions, least-privilege practices, logging and audit trails, and contractual restrictions on vendors.

    Cordiva's policy is to implement, for systems that process PHI, the administrative, physical, and technical safeguards required of a Business Associate under the HIPAA Security Rule, appropriate to the nature and scope of the Services, and to require vendors that process PHI on Cordiva's behalf to do the same.

    No method of transmission, processing, or storage is completely secure, and Cordiva cannot guarantee absolute security.

    If Cordiva becomes aware of a security incident involving personal information or PHI, Cordiva will investigate and respond in accordance with applicable law and its contractual obligations. Where PHI is involved, the applicable BAA governs Cordiva's notification and cooperation obligations.

    To report a suspected security or privacy incident, or a suspected unauthorized use or disclosure of PHI, email security@cordiva.ai. A report sent to security@cordiva.ai is deemed received on transmission. Do not use the in-app support channel or support@cordiva.ai to report a security or privacy incident: support submissions are not notices under Section 11.

    8. International Data Transfers

    Cordiva is operated from Spain. Data processed through our Services is stored and handled in the United States by our voice-infrastructure provider (Retell AI, Inc.) or another authorized service provider. Website data may be processed in both jurisdictions and in other jurisdictions where Cordiva, its clients, or its service providers operate. We implement technical and organizational safeguards appropriate to the information we handle and take reasonable steps to require service providers to handle information in a manner consistent with applicable law, Cordiva's contractual obligations, and the nature of the information involved. For PHI, the applicable BAA and HIPAA obligations govern.

    By using the Site or Services, you understand that information may be transferred to and processed in jurisdictions that may have privacy laws different from those in your place of residence.

    If you are located outside the United States, including in the European Economic Area, United Kingdom, or Switzerland, you understand that information may be transferred to and processed in the United States and other jurisdictions that may not provide the same level of data-protection rights as your place of residence.

    9. Children's Privacy

    Our Services are not directed to individuals under 18. We do not knowingly collect information from children under 18 directly through the Site.

    The Services may process information about minors only where a client lawfully provides that information and instructs Cordiva to process it under an applicable BAA or other legally sufficient arrangement. If you believe Cordiva has collected personal information directly from a child through the Site without appropriate authorization, contact privacy@cordiva.ai.

    10. Changes to This Policy

    We may update this Privacy Policy from time to time to reflect changes in the Site, Services, technology, law, or business practices. We will notify you of material changes by posting the updated policy on this page with a new "Last updated" date and, where required by applicable law, through the Site, email, or another legally permitted method.

    Changes to this Privacy Policy do not amend an executed MSA, BAA, Order Form, or other client agreement unless Cordiva and the client agree to an amendment in writing.

    11. Contact and Notices

    For privacy inquiries and to exercise the rights described in Section 6:

    Email is the primary and sufficient channel for notices. Cordiva does not designate a postal address for notices and does not accept notices by postal mail.

    A contractual or legal notice — including notice of termination, breach, non-renewal, or assignment — is given by email to legal@cordiva.ai and is deemed received on the next business day after transmission, provided the sending party does not receive a bounce or other delivery-failure message.

    A security or privacy incident report, and any PHI matter, is given by email to security@cordiva.ai and is deemed received on transmission. That shorter rule is intentional: notification deadlines for a suspected breach of PHI run from discovery, and a next-business-day rule would delay a report made on a Friday evening or before a holiday.

    Cordiva gives notice to a client by email to the notice address the client designated in its Order Form or, if the client designated none, to the email address on the client's account. A client should keep that address current.

    Support requests and change requests submitted through the in-app support channel or support@cordiva.ai are not notices under this section, and submitting one does not satisfy a notice requirement under the applicable MSA, BAA, or Order Form.

    Cordiva AI. Operating as a trade name of Javier Tabarovsky

    For PHI-related questions or requests concerning a medical spa's records, please contact the medical spa directly. A Client may raise a PHI or security matter with Cordiva at security@cordiva.ai.