Privacy Policy
Last updated: May 31, 2026
1. Introduction
vAssistant ("we", "us", "our") is a product of Violtech. This Privacy Policy explains how we collect, use, store, share, and protect information when you use the vAssistant platform, website, and related services (collectively, the "Service").
By using the Service, you agree to the practices described in this policy. If you do not agree, please do not use the Service.
2. Information We Collect
2.1 Account information
When you create an account, we collect: name, email address, password (hashed), workspace and organization details, and billing information processed by our payment processor.
2.2 Authentication data from third-party providers
When you connect a third-party service (such as Google Workspace), we receive your profile information (name, email, and account identifier) and OAuth access and refresh tokens scoped to the permissions you explicitly grant. Tokens are stored encrypted at rest and used only to perform the actions you have authorized.
2.3 Content you create
Agents you configure, prompts, knowledge base content, channel settings, and other content you create or upload to the Service.
2.4 Usage and technical data
Log data including IP address, browser type, device class, pages accessed, timestamps, and basic interaction events. We use this for security, debugging, and product analytics.
2.5 Data your agents collect
When end users interact with agents you deploy (chat conversations, form submissions, channel messages), the data they provide is processed and stored according to your workspace configuration. You are the data controller for end-user data; we are the processor.
3. How We Use Information
- To provide and maintain the Service
- To authenticate you and your connected third-party accounts
- To perform actions you authorize through connected integrations (e.g., write rows to a Google Sheet you connected)
- To process payments and manage your subscription
- To respond to support requests and communicate updates
- To detect, prevent, and respond to security issues and abuse
- To improve the Service through aggregated analytics
4. Google API Services User Data — Limited Use
vAssistant's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We only request the OAuth scopes needed to perform the actions you explicitly enable.
- Files we access in your Google Drive are limited to files vAssistant creates on your behalf (using the
drive.filescope). We do not have visibility into any other files in your Drive. - We do not use Google user data to train generalized AI or machine learning models.
- We do not transfer Google user data to third parties except as required to provide the Service (e.g., our cloud hosting provider), for security purposes, or to comply with applicable law.
- We do not use Google user data for advertising purposes.
- Human access to Google user data is restricted to: (a) you and your authorized workspace members; (b) Violtech engineers for security investigation or with your explicit permission; (c) as required by law.
5. How We Share Information
We do not sell your personal information. We share data only with:
- Subprocessors that help us operate the Service (cloud hosting, database, payment processing, email delivery, error monitoring, analytics). All subprocessors are bound by data protection agreements.
- Third-party services you connect (e.g., Google Workspace) — strictly as needed to fulfill your authorized actions.
- Legal authorities when required by valid legal process.
- Successors in the event of a merger, acquisition, or asset sale, with notice to you.
6. Data Retention
We retain account and content data for as long as your account is active. When you delete your account, we delete or anonymize your data within 90 days, except where retention is required by law (e.g., tax records) or to resolve disputes.
OAuth tokens for connected integrations are deleted immediately when you disconnect the integration. Tokens are also revoked with the third-party provider where supported.
7. Security
We implement industry-standard technical and organizational measures to protect your data, including encryption in transit (TLS) and at rest, access controls, audit logging, and regular security reviews. No method of transmission or storage is 100% secure, but we work continuously to protect your data.
8. Your Rights
You have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your account and associated data
- Export your data in a portable format
- Withdraw consent for processing where consent is the basis
- Disconnect any third-party integration at any time
- Lodge a complaint with your local data protection authority
To exercise these rights, contact hello@violtech.com.
9. International Data Transfers
Your data may be processed in countries other than your country of residence. We use appropriate safeguards (such as standard contractual clauses) where required to ensure your data receives adequate protection.
10. Children
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have collected such data, contact us and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-product notice at least 14 days before taking effect. Continued use of the Service after changes take effect constitutes acceptance.
12. Contact
Questions about this Privacy Policy or our data practices:
Violtech
Email: hello@violtech.com
Website: vassistant.viol.tech