← Back to VANTA
Privacy Policy
Effective date: July 2026 · Last updated: July 2026
This Privacy Policy describes how Voltify Agency ("Voltify," "we," "us," or "our") collects, uses, stores, shares, and protects your personal information when you use the VANTA platform ("the Service"), including the web application at voltifyagency.com, all API endpoints, and any associated dashboards, tools, or documentation. By using the Service, you consent to the practices described in this policy.
1. Information We Collect
1.1 Account Information
When you create an account (free or paid), we collect: your full name, email address, company or organization name, and optional phone number. If you subscribe to a paid plan, Stripe (our payment processor) collects your billing address and payment card details. We never store full credit card numbers, CVV, or magnetic stripe data on our servers. Stripe tokenizes your card and stores it in their PCI DSS Level 1 compliant infrastructure.
1.2 Analysis Data
The queries, prompts, business questions, uploaded files (PDFs, spreadsheets, Word documents, images), and generated analysis results you submit through the Service are stored in our database. This includes: the full text of your query, any documents or files you attach, the complete analysis output generated by VANTA (including all specialist responses, financial models, risk assessments, and executive summaries), timestamps of each analysis, and metadata such as analysis duration, model used, and specialist domains activated.
1.3 Usage & Technical Data
We automatically collect: API call logs (endpoint, method, status code, response time), feature interactions (which buttons you click, which pages you visit, which features you use), session duration and frequency, browser type and version, operating system, screen resolution, referring URL, and approximate time zone.
1.4 Communication Data
If you contact us via email, support forms, chat, or any other channel, we collect: your message content, your email address, any attachments you send, and the date and time of communication.
1.5 Billing & Transaction Data
We store: subscription plan type, subscription start and end dates, payment history (amounts, dates, statuses), credit balance and usage, invoice records, and refund requests. Payment card details are handled exclusively by Stripe.
1.6 Onboarding Data
If you complete the onboarding questionnaire, we collect: your industry, company size, annual revenue range, primary business challenges, strategic priorities, competitors, and other contextual information you voluntarily provide. This information is used to tailor VANTA's analysis to your specific business context.
1.7 Team & Enterprise Data
If you use the enterprise/team features, we collect: invited team members' names and email addresses, per-member usage and budget data, organization-wide settings, and role assignments. You are responsible for obtaining consent from team members before inviting them.
2. How We Collect Your Information
We collect information through the following methods:
- Directly from you — when you create an account, submit analyses, fill out forms, upload files, contact support, or communicate with us.
- Automatically — through cookies, server logs, API request logging, and analytics tools when you interact with the Service.
- Third-party services — from Stripe (payment verification), Supabase (authentication and database), and IP intelligence providers (IPQualityScore, IPinfo) for free-plan abuse prevention only.
3. How We Use Your Information
We use your personal information for the following purposes:
- Service delivery — to provide, operate, maintain, and deliver the VANTA analysis engine, including running your queries through our 9-specialist pipeline, generating reports, and returning results.
- Account management — to create and manage your account, authenticate your identity, track your subscription, manage credits and billing, and provide customer support.
- Payment processing — to process subscription payments, issue refunds, generate invoices, and detect fraudulent transactions through Stripe.
- Service improvement — to analyze usage patterns, identify bugs, optimize performance, develop new features, and improve the accuracy and quality of AI-generated analyses.
- Machine learning & system improvement — to train, fine-tune, evaluate, and improve AI models and algorithms, as described in our Terms of Service (Section 10).
- Abuse prevention — to detect, prevent, and mitigate fraud, unauthorized access, multi-account abuse, and other violations of our Terms of Service, particularly for free-tier accounts.
- Communications — to send service-related emails (account confirmations, security alerts, billing notifications, policy changes), and, with your consent, marketing communications.
- Legal compliance — to comply with applicable laws, regulations, legal processes, or enforceable governmental requests.
- Analytics — to understand how users interact with the Service through privacy-respecting analytics (Plausible Analytics, which does not use cookies or collect personal data).
4. IP & Network Data (Free Plan Only)
For users on the Starter (Free) plan, we collect and process the following data at the time of account creation and analysis submission:
- IP address — your public IPv4 or IPv6 address as received by our servers.
- Browser user agent — the string your browser sends identifying its type, version, and operating system.
- Device fingerprint hash — a SHA-256 truncated hash of a lightweight device identifier sent by the browser. This is used to group multiple account attempts from the same device.
- Approximate geographic location — country and region derived from your IP address via third-party IP intelligence.
- Network classification — whether your IP is classified as residential, datacenter, VPN, proxy, Tor exit node, or hosting provider.
- IP risk/fraud score — a numerical score (0–100) provided by IPQualityScore indicating the likelihood that the IP is associated with fraudulent activity.
- ISP / ASN information — the name of your Internet Service Provider and Autonomous System Number.
This data is collected exclusively through IPQualityScore (ipqualityscore.com) and IPinfo (ipinfo.io). It is used solely to enforce our one-free-analysis-per-user policy and to prevent multi-account abuse. IP risk data is cached for up to 24 hours and then permanently purged from memory. This data is not shared, sold, licensed, or disclosed to any third party beyond the IP intelligence providers necessary for the lookup itself.
Paid plan users (API Access, Installation, Integration, Enterprise) are not subject to IP-based abuse prevention. Your IP is not stored or analyzed for abuse purposes if you have an active paid subscription.
5. AI Providers & Data Processing
When you submit an analysis, your query and any uploaded documents are sent to third-party AI language model providers for processing. The specific providers depend on the analysis complexity and routing configuration:
- Z.ai (Zhipu AI) — for standard and complex analysis tasks.
- Qwen (Alibaba Cloud) — for supplementary analysis and language tasks.
- OpenAI (GPT-4o / GPT-4o-mini) — for smart model tiering on simpler queries and specific specialist domains.
Your data is sent to these providers solely for the purpose of generating your analysis output. These providers are contractually bound not to use your data for training their models. However, data handling practices may vary by provider and plan tier. We recommend reviewing each provider's privacy policy for details.
For Installation and Integration enterprise plans, AI processing may occur within your own infrastructure, in which case your data does not leave your environment.
6. Data Sharing & Third Parties
We do not sell your personal information. We do not rent your personal information. We may share your data only in the following circumstances:
6.1 Service Providers
We share data with the following categories of service providers, each contractually bound to use your data only for the services they provide to us:
- Stripe, Inc. (payments) — processes payment card data, manages subscriptions, handles invoicing. Stripe's privacy policy: stripe.com/privacy.
- Supabase, Inc. (database & authentication) — stores account data, manages user authentication, hosts the backend database. Supabase's privacy policy: supabase.com/privacy.
- Upstash (caching) — provides Redis-compatible caching for rate limiting and session management.
- Vercel, Inc. (hosting) — hosts the frontend application and serverless functions. Vercel's privacy policy: vercel.com/legal/privacy-policy.
- Plausible Insights OÜ (analytics) — provides privacy-respecting, cookie-free website analytics. Plausible does not collect or store personal data. Plausible's privacy policy: plausible.io/privacy.
- IPQualityScore / IPinfo (IP intelligence) — used only for free-plan abuse prevention. Data is not retained beyond the lookup.
6.2 Legal Requirements
We may disclose your information if required to do so by law, regulation, legal process, or governmental request; to enforce our Terms of Service; to detect, prevent, or address fraud, security vulnerabilities, or technical issues; or to protect the rights, property, or safety of Voltify, our users, or the public.
6.3 Business Transfers
In the event of a merger, acquisition, bankruptcy, or sale of assets, your personal information may be transferred to the acquiring entity. We will notify you via email and/or a prominent notice on the Service before your data is subject to a different privacy policy.
6.4 Data Submitted to AI Providers
As described in Section 5, your analysis queries and uploaded documents are transmitted to third-party AI providers for processing. This constitutes data sharing necessary for service delivery.
7. Cookies & Tracking Technologies
7.1 VANTA Platform
The VANTA platform (app, dashboard, and API) uses no tracking cookies. We use a single essential cookie for session management and authentication (e.g., maintaining your logged-in state). This cookie is strictly necessary for the Service to function and does not track your browsing behavior.
7.2 Marketing Website
The Voltify marketing website (voltifyagency.com) may use analytics cookies through Plausible Analytics. Plausible is a privacy-first analytics tool that does not use cookies, does not collect personal data, and is fully compliant with GDPR, CCPA, and ePrivacy. You may opt out through our cookie banner.
7.3 Browser Do Not Track
We respect Do Not Track (DNT) browser signals. When a DNT signal is detected, we disable all non-essential data collection.
8. Data Retention
We retain your data for the following periods:
- Account data (name, email, company) — retained for the lifetime of your account, plus 30 days after deletion to allow for recovery.
- Analysis data (queries, uploads, results) — retained for 12 months after your last analysis, or until you request deletion, whichever comes first. After this period, analysis data is permanently deleted from both active databases and backups.
- Billing records (invoices, payment history) — retained for 7 years as required by tax and accounting regulations.
- API request logs (endpoint, status, response time) — retained for 90 days for debugging and performance monitoring, then purged.
- Onboarding questionnaire responses — retained for the lifetime of your account to personalize your experience.
- Communication records (support emails, messages) — retained for 24 months after the last communication.
- IP risk data (free plan) — cached in memory for up to 24 hours, then permanently purged. Not stored in any persistent database.
- Device fingerprint hashes (free plan) — stored in memory for up to 30 minutes (the cooldown window), then purged. Not persisted to disk.
When you request account deletion, we delete or anonymize all personal data within 30 days, except where retention is required by law (e.g., billing records).
9. Data Security
We implement industry-standard security measures to protect your personal information:
- Encryption in transit — all data transmitted between your browser/device and our servers is encrypted using TLS 1.3.
- Encryption at rest — all data stored in our databases is encrypted using AES-256.
- API key hashing — API keys are stored as one-way hashes; the plaintext key is shown to you once at creation and never stored.
- Authentication — user authentication is managed through Supabase Auth with JWT tokens, optional OAuth (Google, GitHub), and optional two-factor authentication.
- Access controls — database access is restricted by Row Level Security (RLS) policies ensuring tenant isolation by API key. No user can access another user's data.
- Infrastructure security — hosted on Vercel (frontend) and Supabase (database) with SOC 2 Type II compliance, automatic backups, and DDoS protection.
- Payment security — all payment processing is handled by Stripe, a PCI DSS Level 1 certified processor. We never handle, store, or transmit raw card data.
However, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security. If you discover a security vulnerability, please report it to security@voltifyagency.com.
10. International Data Transfers
Voltify is based in the United Kingdom. Your data may be transferred to, stored, and processed in the following locations depending on which services process it:
- United States — Supabase (database), Vercel (hosting), Stripe (payments), and AI providers may process data in US-based data centers.
- European Union — Supabase and Vercel have EU-based infrastructure options. Some processing may occur in EU data centers.
- Asia-Pacific — AI providers (Z.ai, Qwen) may route certain queries to Asia-Pacific data centers for processing.
For transfers from the EU/EEA/UK to countries without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, and/or the UK International Data Transfer Agreement (IDTA), as applicable. You may request a copy of these transfer mechanisms by contacting privacy@voltifyagency.com.
11. Your Rights Under GDPR (EU/EEA/UK Users)
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR) and the UK GDPR:
- Right of access (Article 15) — you have the right to obtain confirmation that we process your personal data and to receive a copy of that data.
- Right to rectification (Article 16) — you have the right to correct inaccurate personal data or complete incomplete data.
- Right to erasure / "right to be forgotten" (Article 17) — you have the right to request deletion of your personal data, subject to legal retention obligations.
- Right to restriction of processing (Article 18) — you have the right to request that we limit how we use your data in certain circumstances.
- Right to data portability (Article 20) — you have the right to receive your personal data in a structured, commonly used, machine-readable format (JSON or CSV).
- Right to object (Article 21) — you have the right to object to processing based on legitimate interests, including profiling.
- Right not to be subject to automated decision-making (Article 22) — VANTA does not make automated decisions with legal effects about you. AI-generated analyses are informational outputs, not automated decisions affecting your legal rights.
- Right to withdraw consent (Article 7) — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint — you have the right to lodge a complaint with your local data protection supervisory authority.
To exercise any of these rights, email privacy@voltifyagency.com. We will respond within 30 days. We may ask you to verify your identity before processing your request.
12. Your Rights Under CCPA/CPRA (California Residents)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you the following rights:
- Right to know — you have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collection, and the categories of third parties with whom we share it.
- Right to delete — you have the right to request that we delete your personal information, subject to certain legal exceptions.
- Right to correct — you have the right to request that we correct inaccurate personal information.
- Right to opt out of sale or sharing — we do not sell your personal information and do not share it for cross-context behavioral advertising. No opt-out is necessary.
- Right to limit use of sensitive personal information — we do not use sensitive personal information (such as financial account details, precise geolocation, or health data) for purposes other than those permitted by law.
- Right to non-discrimination — we will not discriminate against you for exercising your privacy rights.
To exercise these rights, email privacy@voltifyagency.com or call our privacy line. We will verify your identity and respond within 45 days. You may also designate an authorized agent to make requests on your behalf.
We have collected the following categories of personal information from California residents in the past 12 months: identifiers (name, email), commercial information (subscription and billing records), internet/electronic network activity (API logs, usage data), and inferences drawn from the foregoing. We have not sold personal information in the preceding 12 months.
13. Your Rights Under Other Jurisdictions
We extend the core GDPR rights (access, rectification, erasure, portability, objection) to all users worldwide, regardless of jurisdiction. If you are located in a jurisdiction with specific privacy legislation not listed above (e.g., Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act, South Korea's PIPA), you may exercise equivalent rights by contacting privacy@voltifyagency.com. We will honor your request in accordance with applicable law.
14. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal data from a child under 18 without parental consent, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact privacy@voltifyagency.com.
15. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33.
- Notify affected individuals without undue delay when the breach is likely to result in a high risk to your rights and freedoms, providing: a description of the nature of the breach, the categories and approximate number of individuals affected, the likely consequences, and the measures taken or proposed to address the breach.
- Maintain a breach log documenting all breaches, regardless of whether they trigger notification requirements.
16. Do Not Track Signals
We honor Do Not Track (DNT) signals sent by your browser. When a DNT signal is detected, we disable all non-essential data collection and analytics tracking. The VANTA platform's core functionality is unaffected, as session authentication cookies are strictly necessary for the Service to operate.
17. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes:
- We will notify you via email at the address associated with your account.
- We will display a prominent notice on the Service for at least 30 days.
- For material changes affecting how we process your data, we will obtain your affirmative consent where required by law.
The "Last updated" date at the top of this page reflects the most recent revision. Your continued use of the Service after the effective date of any changes constitutes acceptance of the updated policy.
18. Contact & Data Controller
Data Controller:
Voltify Agency
Email: privacy@voltifyagency.com
Security reports: security@voltifyagency.com
General inquiries: patricio@voltifyagency.com
EU/UK Representative (Article 27 GDPR):
If required under applicable law, we will appoint an EU/UK representative. Contact us for current representative details.
Response time: We will respond to all privacy-related requests within 30 business days (or within the timeframe required by applicable law, whichever is shorter).
VANTA — Voltify Analytical Network & Tactical Advisor. A product of Voltify.