1. Introduction
Welcome to Vantro. We operate an AI agent platform that enables businesses to deploy autonomous agents for sales, support, research, and operations. By accessing or using our services, you agree to the collection and use of information in accordance with this policy.
This policy applies to all users of the Vantro platform, website visitors, trial users, and paying customers. It covers information collected through our website at vantro.ai, our web application, and any associated APIs or integrations.
If you have questions about this policy, please contact us at privacy@vantro.ai before using our services.
2. Information We Collect
Information You Provide Directly
- Account information: When you create an account, we collect your name, email address, company name, job title, and password.
- Payment information: Billing details are processed by our payment processor (Stripe). We store only the last 4 digits of your card and billing address for record-keeping. We never store full card numbers.
- Business information: During onboarding, you may provide company size, industry, and use-case details to personalise your agent configuration.
- Communications: When you contact support, submit a form, or email us, we retain those communications and any information contained within them.
- User content: Any prompts, instructions, or data you provide to configure your AI agents, including brand guidelines, tone-of-voice documents, and training examples.
Information Collected Automatically
- Usage data: Pages visited, features used, agent interactions, session duration, and click patterns within the platform.
- Device information: Browser type and version, operating system, screen resolution, and device identifiers.
- Network information: IP address, approximate geolocation (country/city level), ISP, and referring URL.
- Performance data: Page load times, error rates, and API response times to help us improve reliability.
Information from Third Parties
- Integrations: If you connect Vantro to third-party services (CRMs, helpdesks, communication platforms), we receive data from those services as necessary to fulfil the integration's purpose.
- Single Sign-On (SSO): If you authenticate via Google, Microsoft, or another OAuth provider, we receive your name, email, and profile picture from that provider.
- Analytics partners: Aggregated, anonymised data from services such as Google Analytics to understand overall site performance.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service delivery: To provision, operate, maintain, and improve the Vantro platform and your AI agents.
- Account management: To create and manage your account, authenticate you, and process payments.
- Customer support: To respond to your enquiries, troubleshoot problems, and provide technical assistance.
- Product improvement: To understand how users interact with the platform, identify bugs, and prioritise feature development. We use anonymised and aggregated data wherever possible.
- Communications: To send transactional emails (password resets, invoices, security alerts) and, with your consent, product updates and marketing communications. You can unsubscribe from marketing emails at any time.
- Security and fraud prevention: To detect, prevent, and respond to fraud, abuse, security incidents, and other harmful activities.
- Legal compliance: To meet our obligations under applicable law, respond to legal process, and enforce our terms of service.
- Personalisation: To tailor your experience, including suggested agent configurations based on your industry and use case.
4. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data under the following legal bases as defined by the General Data Protection Regulation (GDPR):
- Contract performance: Processing your account data and payment information is necessary to provide the services you have signed up for.
- Legitimate interests: We process usage data and improve our platform based on legitimate interests in operating a reliable, secure, and improving service. We balance these interests against your privacy rights.
- Consent: Where we send marketing communications or deploy non-essential cookies, we rely on your consent. You may withdraw consent at any time.
- Legal obligation: Where applicable law requires us to retain or disclose information (e.g., tax records, responses to legal process).
To exercise any rights under GDPR, or to raise a concern, please contact privacy@vantro.ai. You also have the right to lodge a complaint with your national supervisory authority.
6. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this policy, unless a longer retention period is required by law.
- Active accounts: We retain your account data for as long as your account is active and for a reasonable period thereafter in case you wish to reactivate.
- Deleted accounts: When you request account deletion, we delete or anonymise your personal data within 30 days, except for data we are legally required to retain (e.g., billing records retained for 7 years for tax compliance).
- Usage logs: Raw usage logs are retained for 90 days and then aggregated or deleted.
- Support communications: Support tickets and related communications are retained for 3 years after resolution.
- Marketing data: If you unsubscribe from marketing communications, we retain a record of your preference to ensure we do not contact you again.
7. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal data:
- Right of access: You can request a copy of the personal data we hold about you.
- Right to rectification: You can request correction of inaccurate or incomplete data.
- Right to erasure: You can request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
- Right to portability: You can request your data in a machine-readable format (e.g., JSON or CSV) to transfer to another provider.
- Right to restrict processing: You can request that we limit how we use your data in certain circumstances.
- Right to object: You can object to processing based on legitimate interests, including profiling.
- Right to withdraw consent: Where processing is based on consent, you can withdraw at any time without affecting prior lawful processing.
- CCPA rights (California residents): You have the right to know what personal information is collected, to request deletion, to opt out of the sale of personal information (we do not sell personal information), and to non-discrimination for exercising your rights.
To exercise any of these rights, email privacy@vantro.ai with the subject line "Privacy Rights Request". We will respond within 30 days. We may ask you to verify your identity before processing your request.
9. Security
We implement industry-standard technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, and destruction. These measures include:
- Encryption of data in transit using TLS 1.2 or higher
- Encryption of sensitive data at rest using AES-256
- Access controls and principle of least privilege for internal systems
- Regular security assessments and penetration testing
- SOC 2 Type II certified infrastructure
- Audit logging of all data access events
Despite these measures, no method of internet transmission or electronic storage is 100% secure. In the event of a data breach that is likely to result in a risk to your rights, we will notify you and relevant authorities as required by applicable law, within 72 hours of becoming aware of the breach.
10. International Data Transfers
Vantro is based in the United States. If you access our services from the EEA, UK, or other regions, your information may be transferred to and processed in the US and other countries where our servers and service providers are located.
For transfers from the EEA or UK to the US, we rely on the EU-US Data Privacy Framework and Standard Contractual Clauses (SCCs) approved by the European Commission to ensure your data receives adequate protection. A copy of the applicable SCCs is available upon request.
11. Children's Privacy
Our services are not directed to individuals under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If you believe we have inadvertently collected information from a child, please contact us immediately at privacy@vantro.ai and we will promptly delete the information.
12. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will:
- Post the updated policy on this page with a revised "Last updated" date
- Notify registered users by email at least 14 days before changes take effect (for material changes)
- Where required by law, obtain your consent before applying changes
Your continued use of our services after the effective date of any changes constitutes your acceptance of the updated policy. We encourage you to review this page periodically.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: privacy@vantro.ai
- Post: Vantro Inc., Attn: Privacy Team, 123 Market Street, San Francisco, CA 94105, USA
- Response time: We aim to respond to all privacy enquiries within 5 business days.
For EU/UK residents, our EU Representative is available at eu-privacy@vantro.ai.
Note: This Privacy Policy is provided as a template and should be reviewed by a qualified legal professional before publication to ensure compliance with all applicable laws and regulations in your jurisdiction.