Privacy Notice
This notice covers Founder applications, accounts, licences, billing, downloads, support and AI features. It will be updated if the scope of processing or the service providers changes.
1. Controller
The controller is the owner identified in the Legal notice. Contact [email protected] for data-protection requests and [email protected] for relevant security incidents.
2. Data we process
Applications: name, work email, company, role, message, selected market, locale, consent version, submission time, limited security data and application status. Account: name, email, company, country and identifiers. Billing: legal name, tax ID, billing address, plan, subscription status, Stripe identifiers, amounts and invoices. Licence and device: plan, status, device limit, release channel, version and activation dates. Technical use: errors, downloads, security IP addresses and user agent. AI: instructions, responses, usage and content voluntarily submitted when using those features. Support: emails, tickets and files voluntarily provided by the user.
3. Purposes and legal bases
We use application data to review and respond to Founder applications with your consent, which you may withdraw at any time. We process account, licence, download, support and subscription data to perform a contract; billing data to comply with legal obligations; and limited logs for our legitimate interests in security and fraud prevention. Optional marketing, non-essential cookies and optional telemetry rely on consent. Content sent to AI or support features is processed at your instruction to provide the requested feature.
4. Service providers
Vectoria Civil uses Supabase for authentication and database services, Stripe for payments and subscriptions, Google Cloud for backend hosting, storage, downloads and AI features through Vertex AI, Resend for transactional email, and Cloudflare for the public website, DNS, protection and—only when enabled with consent—cookieless analytics. Information about purpose, processing region, applicable data-processing terms and international-transfer mechanisms is maintained and made available on reasonable request.
5. Retention
Open Founder applications are retained while they are under review and for a reasonable follow-up period. Rejected, cancelled or withdrawn applications are deleted or minimised when no longer needed for consent evidence, security, legal claims or an applicable legal duty. Contract, tax and billing data is kept for the periods required by Spanish and applicable law. Account and licence data is kept during the subscription and for a reasonable post-cancellation support period. Security logs are kept only as long as needed to detect and investigate incidents. AI prompts and files are minimised by default and are not stored unless a controlled diagnostic mode is explicitly enabled.
6. Engineering data
User files, drawings, models, prompts, measurements, technical documents and results are not used to train our own or third-party models without separate, explicit consent. See AI and professional review.
7. Security
We use reasonable technical and organisational safeguards against unauthorised access, loss, alteration or disclosure. Measures include encryption in transit, separation of credentials from source code, role-based access, audit records for critical actions, temporary signed installer URLs, log minimisation and automatic redaction of tokens and sensitive values. Controls are reviewed as the product and its risks evolve.
8. International transfers
Some providers may process data outside the European Economic Area. Where required, the controller relies on an applicable European Commission adequacy decision, Standard Contractual Clauses or another lawful mechanism, and assesses supplementary measures according to the provider and data involved.
9. Record of processing
The controller maintains an internal record of processing activities covering purposes, data categories, legal bases, retention, processors, international transfers and safeguards. It may be provided to the competent supervisory authority on request.
10. Your rights
You may request access, rectification, erasure, restriction, objection, portability or withdrawal of consent by emailing [email protected]. Withdrawal does not affect processing carried out before withdrawal. Erasure does not apply to information that must be retained by law or for the establishment, exercise or defence of legal claims. You may lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es) or another competent supervisory authority.
11. Children
The Service is intended for professionals, sole traders, practices and technical companies. It is not intended for children, and we do not knowingly collect children's personal data.