Skip to content
ProductsServicesApproachCompanyContact

Product & technology

Appearance

Language

DEDeutschENEnglishESEspañol
Open Viaora
Main navigationviaora.ai
01Products02Services03Approach04Company05Contact
Open Viaora

Privacy

Contact form privacy notice

This notice covers the contact form on viaora.ai and our subsequent handling of your enquiry. Section 8 also explains the corporate website's local appearance setting. It is not a general privacy notice for the Viaora guest app, partner contracts or payment services.

Published
26 September 2026
Version
contact-2026-09-26-v1
  1. 1. Controller and contact
  2. 2. Data we use
  3. 3. Purposes and legal bases
  4. 4. Transmission and recipients
  5. 5. International processing
  6. 6. Retention and deletion
  7. 7. Your rights
  8. 8. The corporate website's local appearance setting

1. Controller and contact

The controller is VIAORAAI, SOCIEDAD LIMITADA (ViaoraAI S.L.), NIF B93875417, Carrer de ses Roges, 35, Oficina B, 07590 Cala Ratjada, Illes Balears, España.

For questions about this processing and to exercise your data protection rights, contact info@viaora.ai.

2. Data we use

The form requires your email address, a topic to route the enquiry and your message. Your name and company are optional. Without a reply address and message, we cannot handle an enquiry through this form. The selected language and version of this privacy notice are also transmitted. The version records which information accompanied the submission; it is not a consent record.

Opening and submitting the form may generate IP addresses, timestamps, requested resources and technical status, error and security data. These support delivery, troubleshooting and protection against spam or abuse, including request limits.

For our technical abuse prevention, we store a pseudonymous identifier generated using HMAC-SHA256, together with counters and timestamps, in Supabase. This record contains neither the plain IP address nor the contents of your enquiry. This does not mean that no IP address is processed when a connection is established or that the data are anonymous.

Our own structured gateway logs record technical event and service identifiers, a request identifier, the HTTP method, a normalised route, the response status, the number of forwarding attempts and duration. Workers Logs is configured with ten per cent sampling; automatic invocation logs are disabled. Our own logs contain no raw URL query parameters; upstream failures are logged only by error class, not raw error text. These settings do not mean that all infrastructure or security logging is disabled.

The form does not accept attachments or payments. Please do not send passwords, identity-document copies, health information or other sensitive data. You may alternatively contact us directly by email.

3. Purposes and legal bases

We use your details to understand your enquiry, reply and carry out the business communication you request.

  • If the enquiry concerns a contract with you personally, or steps you request before entering into it, we process the necessary data under Article 6(1)(b) GDPR.
  • If you write as a contact or representative for another contracting party, or with another substantive enquiry to which Article 6(1)(b) does not apply, necessary processing is based on Article 6(1)(f) GDPR. Our legitimate interest is to answer incoming enquiries and manage the business relationship you have asked about. Overriding competing interests are taken into account.
  • We process technical security and abuse-prevention data under Article 6(1)(f) GDPR in our legitimate interest in maintaining a secure and available contact channel.
  • Where we meet legal obligations, particularly handling data protection rights or retaining required records, Article 6(1)(c) GDPR applies together with the relevant obligation. Necessary defence of legal claims may rely on Article 6(1)(f) GDPR.

Contacting us does not subscribe you to marketing. Viaora does not use form contents for advertising profiles, automated decisions with legal or similarly significant effects, its AI features or model training. Submitting the form does not conclude a service or partner contract or trigger a payment.

4. Transmission and recipients

Vercel hosts the website. The form sends the enquiry through Cloudflare to Viaora's service hosted on RunPod. That service uses Microsoft Graph and Exchange Online to send it to Viaora's info@viaora.ai mailbox. Your address is used as the reply address; the automated message has a fixed sender and recipient.

4. Transmission and recipients
ServiceRole in the contact process
VercelWebsite delivery and associated technical request data
CloudflareNetwork, API gateway and protection of the request path
RunPodHosting Viaora's server that processes and forwards the enquiry
SupabaseStorage of pseudonymised abuse-prevention data and database backups; no form contents in this process
Microsoft 365 / Microsoft Graph / Exchange OnlineDelivery, mailbox storage and subsequent email communication

Access is limited to authorised Viaora personnel handling the enquiry and the service providers needed for that purpose. Where legally required or specifically necessary for a legal matter, relevant information may also be disclosed to competent authorities or professional advisers.

The form does not create an additional message record in a contact database or CRM and has no message queue of its own. Its draft remains in temporary page memory; Viaora's own server holds the message contents only in request memory during processing until handoff to Microsoft Graph. Our own form code does not write the message text to application logs. Separate abuse-prevention data are stored as described above. The message is then stored and handled in the email mailbox; this does not eliminate technical processing by providers, including any transport copies. The automated transmission does not create an additional Sent Items copy. Replies and other necessary working copies are also subject to the rules below.

The providers process entrusted contents and data under their respective data-processing arrangements. This is distinct from their own technical operational data: Vercel handles personal “Service-Generated Data”, Cloudflare its own “Network Data”, and RunPod personal “Performance Data” partly as independent controllers. Microsoft also distinguishes processing on our behalf from limited purposes of its own business operations. Sections 5 and 6 explain these distinctions and retention.

Acceptance for sending does not confirm mailbox delivery or that a person has read the message.

5. International processing

Our contact server runs in RunPod's EU-RO-1 region in Romania; the abuse-prevention database is in Supabase's eu-central-1 region in Germany. These locations do not mean that all processing takes place in Europe. The providers operate internationally; in particular, operations, technical support and subprocessors may involve processing outside the European Economic Area (EEA), including the United States and, for Supabase, Singapore.

The relevant data-processing agreements apply to data processed on our behalf. They provide the following transfer safeguards:

5. International processing
ProviderBasis for transfers outside the EEA
VercelEU standard contractual clauses under DPA, Schedule 3, including independent-controller service-generated data where the relevant role applies
CloudflareDPA, Section 6: EU-US Data Privacy Framework for transfers covered by that framework; EU standard contractual clauses for the other third-country transfers specified there
RunPodEU standard contractual clauses for third-country transfers covered by DPA, Section 14
SupabaseEU standard contractual clauses with Supabase Pte. Ltd., Singapore, under DPA, Section 12 and Schedule 2
MicrosoftEU standard contractual clauses incorporated into Microsoft's contractual terms for the relevant transfers

A provider or server location is not a general adequacy decision. In particular, we do not claim that all providers and subprocessors are covered by the EU-US Data Privacy Framework. For the independent-controller processing distinguished in Section 6, the privacy notices linked there also explain the relevant international processing arrangements.

You may request information and a copy of the safeguards applicable to your data at info@viaora.ai, subject to protecting information relating to others where necessary.

6. Retention and deletion

Enquiries that do not lead to a contractual relationship remain in our active enquiry records only as long as justified by handling the matter and necessary follow-up, and no longer than twelve months after the last substantive communication about it. We remove data earlier when it is no longer needed. Internal notes, technical sending acknowledgements or marketing messages do not extend that period.

A 14-day retention period is configured for recoverable mailbox copies. It starts when an item is removed from Deleted Items or moved directly into the recovery area, not when it is first moved to Deleted Items. Service-side cleanup follows expiry. This does not promise simultaneous physical deletion of all provider copies.

If a contractual relationship, legal record-keeping obligation or specific legal matter arises, we transfer only the necessary records to the relevant file. These are retained separately under the applicable obligations and periods, rather than automatically continuing to classify them as an open contact enquiry.

Where Article 32 of Spain's LOPDGDD requires blocking, the affected data are removed from ordinary access and secured exclusively for the authorities and liability-related purposes provided by law until the applicable limitation period expires; they are then destroyed.

The abuse-prevention counting window expires one hour after its first associated request. Further requests within that window do not extend it. Expired records are scheduled for cleanup every five minutes. Expiry and cleanup of the active record are separate from retention in database backups.

The Supabase database is backed up physically each day. These backups have a rolling recovery window of seven days. An abuse-prevention record already removed from the active database may therefore remain in an older backup until that backup leaves the recovery window. In this contact process, the backups do not contain message text. Restoring a backup does not reset the original expiry periods; expired records are cleaned up again before the contact service resumes. The seven-day window does not promise simultaneous physical deletion of every infrastructure copy.

Under the current Cloudflare Workers Free plan, the gateway logs described above are retained in Workers Logs for no more than three days. This statement concerns that log product, not all other provider logs.

For technical email delivery tracing, Microsoft Exchange retains Message Trace data for 90 days and then automatically removes it. This period concerns sending and delivery information, not retention of the message text in the mailbox.

For other data generated by Microsoft in operating the email service, Microsoft's service information specifies a default period of up to 180 days from collection. Longer periods are provided for where required for service security or legal or regulatory obligations. This is not an additional general retention period for message contents.

The following providers may also process technical data as independent controllers where those data are personal. Their privacy notices do not specify one uniform period in days:

  • Vercel: Service-generated operational data; retention depends on legal and contractual duties, service development, resolving disputes and enforcing rights. When there is no continuing legitimate need, deletion or anonymisation is provided for; backups that cannot be deleted are stored securely. Vercel privacy notice.
  • Cloudflare: Its own network and security data; retention depends on operational purpose, volume and sensitivity, possible harm, less data-intensive alternatives, and legal and contractual requirements. Data are deleted or destroyed when the period ends; where technical obstacles prevent this, further use is prevented. Cloudflare privacy notice, Section 11.
  • RunPod: Personal performance and operational data; retention depends on processing purposes, statutory records, legal claims and fraud prevention, volume and sensitivity, and available alternatives. Its policy provides for deletion, anonymisation or isolation from further processing when data are no longer required. RunPod privacy notice, “Retention”.

These criteria concern the specified independent-controller processing; they do not extend our twelve-month maximum. Purely administrative data about our provider accounts are not an additional record of your enquiry.

7. Your rights

Subject to the legal conditions, you may request access, rectification, erasure, restriction and, where applicable, data portability. You may object to processing based on legitimate interests on grounds relating to your particular situation. Any later processing based separately on consent requires its own information; you may withdraw such consent for the future.

Contact info@viaora.ai. We request only the information needed to handle your request and, where necessary, verify your identity. We normally respond within one month; if a legally permitted extension is needed, we explain it and the reasons within that month.

You may complain to the Agencia Española de Protección de Datos (AEPD) or another competent data protection authority. You do not have to wait for our response before contacting an authority.

8. The corporate website's local appearance setting

For a light, dark or system-based appearance, the corporate website uses the local browser entry viaora.site.theme.v2. It contains only the value light, dark or auto, with no personal identifier or timestamp. The website does not transmit this value to Viaora or third parties or use it for analytics, advertising or profiling. In system mode (auto), the appearance follows your device's light/dark setting.

The entry is created or changed only when you explicitly select an appearance. Without a stored choice, the website follows your system without saving that default. Neither the first page visit nor a change in system settings writes the entry. A stored choice is read to set the appearance on later visits. The website sets no automatic expiry period. If the website cannot read a stored choice when it loads, it starts with the system appearance. An appearance you then explicitly select remains usable for the current page even if storage is unavailable, but is not saved persistently.

If there is no valid v2 choice, an earlier light/dark choice in viaora.site.theme.v1 may still be read to set the appearance. An old auto value is not adopted as a stored choice. The old entry is removed when a new choice is successfully saved. Without a new selection, an old entry may remain until the browser's website data is deleted.

You can change the appearance through the website settings and remove the entries using your browser's function for deleting website data. Explicitly selecting system mode does not delete the entry; it stores auto. After deletion, the entry is created again only when you make another explicit selection. This local setting is separate from contact enquiries and technical server logs.

Digital products and AI-supported systems.

Product

ProductsInside ViaoraGo to viaora.app

Company

ServicesCompanyContactinfo@viaora.ai

Languages

DeutschEnglishEspañol
PrivacyContact form privacy noticeLocal appearance preference

Preview: complete registry and provider details remain pending document checks and legal approval.

ViaoraAI S.L. · Carrer de ses Roges, 35, Oficina B · 07590 Cala Ratjada · Illes Balears · España · NIF B93875417

© 2026 ViaoraAI S.L.