Privacy
Corporate website privacy notice
As of: 26 September 2026
This privacy notice covers visits to the corporate website viaora.ai, its local appearance setting and our handling of your enquiries, including the contact form. It does not cover separate use of the Viaora guest app at viaora.app, Studio, or separate contractual and payment services.
1. Controller and contact
The controller is VIAORAAI, SOCIEDAD LIMITADA (ViaoraAI S.L.), NIF B93875417, Carrer de ses Roges, 35, Oficina B, 07590 Cala Ratjada, Illes Balears, España.
For questions about this processing and to exercise your data protection rights, contact info@viaora.ai.
2. Data we use
Website visits
Visiting the corporate website involves processing the connection and request data needed to deliver and protect it, including IP address, access time, requested resources and technical status, error and security data. Vercel hosts the website. Sections 4 to 6 describe provider roles, international processing and retention criteria. You do not have to enter a message or contact details in the form simply to visit the website.
Contacting us
If you email us directly, we process your sender address, message contents and the details you provide to handle your enquiry. The following also applies to the contact form:
The form requires your email address, a topic to route the enquiry and your message. Your name and company are optional. Without a reply address and message, we cannot handle an enquiry through this form. The selected language and version of this privacy notice are also transmitted. The version records which information accompanied the submission; it is not a consent record.
Opening and submitting the form may generate IP addresses, timestamps, requested resources and technical status, error and security data. These support delivery, troubleshooting and protection against spam or abuse, including request limits.
For our technical abuse prevention, we store a pseudonymous identifier generated using HMAC-SHA256, together with counters and timestamps, in Supabase. This record contains neither the plain IP address nor the contents of your enquiry. This does not mean that no IP address is processed when a connection is established or that the data are anonymous.
Our own structured gateway logs record technical event and service identifiers, a request identifier, the HTTP method, a normalised route, the response status, the number of forwarding attempts and duration. Workers Logs is configured with ten per cent sampling; automatic invocation logs are disabled. Our own logs contain no raw URL query parameters; upstream failures are logged only by error class, not raw error text. These settings do not mean that all infrastructure or security logging is disabled.
The form does not accept attachments or payments. Please do not send passwords, identity-document copies, health information or other sensitive data. You may alternatively contact us directly by email.
3. Purposes and legal bases
We base the technically necessary delivery and protection of the corporate website on Article 6(1)(f) GDPR. Our legitimate interest is to make understandable company information available and ensure the website operates securely. The local appearance you explicitly select serves only your requested display; it is not expanded into a usage profile.
We use your details to understand your enquiry, reply and carry out the business communication you request.
- If the enquiry concerns a contract with you personally, or steps you request before entering into it, we process the necessary data under Article 6(1)(b) GDPR.
- If you write as a contact or representative for another contracting party, or with another substantive enquiry to which Article 6(1)(b) does not apply, necessary processing is based on Article 6(1)(f) GDPR. Our legitimate interest is to answer incoming enquiries and manage the business relationship you have asked about. Overriding competing interests are taken into account.
- We process technical security and abuse-prevention data under Article 6(1)(f) GDPR in our legitimate interest in maintaining a secure and available contact channel.
- Where we meet legal obligations, particularly handling data protection rights or retaining required records, Article 6(1)(c) GDPR applies together with the relevant obligation. Necessary defence of legal claims may rely on Article 6(1)(f) GDPR.
Contacting us does not subscribe you to marketing. Viaora does not use form contents for advertising profiles, automated decisions with legal or similarly significant effects, its AI features or model training. Submitting the form does not conclude a service or partner contract or trigger a payment.
4. Transmission and recipients
Vercel hosts the website. The form sends the enquiry through Cloudflare to Viaora's service hosted on RunPod. That service uses Microsoft Graph and Exchange Online to send it to Viaora's info@viaora.ai mailbox. Your address is used as the reply address; the automated message has a fixed sender and recipient.
| Service | Function on the website or in the contact process |
|---|---|
| Vercel | Website delivery and associated technical request data |
| Cloudflare | Network, API gateway and protection of the request path |
| RunPod | Hosting Viaora's server that processes and forwards the enquiry |
| Supabase | Storage of pseudonymised abuse-prevention data and database backups; no form contents in this process |
| Microsoft 365 / Microsoft Graph / Exchange Online | Delivery, mailbox storage and subsequent email communication |
Access is limited to authorised Viaora personnel handling the enquiry and the service providers needed for that purpose. Where legally required or specifically necessary for a legal matter, relevant information may also be disclosed to competent authorities or professional advisers.
The form does not create an additional message record in a contact database or CRM and has no message queue of its own. Its draft remains in temporary page memory; Viaora's own server holds the message contents only in request memory during processing until handoff to Microsoft Graph. Our own form code does not write the message text to application logs. Separate abuse-prevention data are stored as described above. The message is then stored and handled in the email mailbox; this does not eliminate technical processing by providers, including any transport copies. The automated transmission does not create an additional Sent Items copy. Replies and other necessary working copies are also subject to the rules below.
The providers process entrusted contents and data under their respective data-processing arrangements. This is distinct from their own technical operational data: Vercel handles personal “Service-Generated Data”, Cloudflare its own “Network Data”, and RunPod personal “Performance Data” partly as independent controllers. Microsoft also distinguishes processing on our behalf from limited purposes of its own business operations. Sections 5 and 6 explain these distinctions and retention.
Acceptance for sending does not confirm mailbox delivery or that a person has read the message.
5. International processing
Our contact server runs in RunPod's EU-RO-1 region in Romania; the abuse-prevention database is in Supabase's eu-central-1 region in Germany. These locations do not mean that all processing takes place in Europe. The providers operate internationally; in particular, operations, technical support and subprocessors may involve processing outside the European Economic Area (EEA), including the United States and, for Supabase, Singapore.
The relevant data-processing agreements apply to data processed on our behalf. They provide the following transfer safeguards:
| Provider | Basis for transfers outside the EEA |
|---|---|
| Vercel | EU standard contractual clauses under DPA, Schedule 3, including independent-controller service-generated data where the relevant role applies |
| Cloudflare | DPA, Section 6: EU-US Data Privacy Framework for transfers covered by that framework; EU standard contractual clauses for the other third-country transfers specified there |
| RunPod | EU standard contractual clauses for third-country transfers covered by DPA, Section 14 |
| Supabase | EU standard contractual clauses with Supabase Pte. Ltd., Singapore, under DPA, Section 12 and Schedule 2 |
| Microsoft | EU standard contractual clauses incorporated into Microsoft's contractual terms for the relevant transfers |
A provider or server location is not a general adequacy decision. In particular, we do not claim that all providers and subprocessors are covered by the EU-US Data Privacy Framework. For the independent-controller processing distinguished in Section 6, the privacy notices linked there also explain the relevant international processing arrangements.
You may request information and a copy of the safeguards applicable to your data at info@viaora.ai, subject to protecting information relating to others where necessary.
6. Retention and deletion
Enquiries that do not lead to a contractual relationship remain in our active enquiry records only as long as justified by handling the matter and necessary follow-up, and no longer than twelve months after the last substantive communication about it. We remove data earlier when it is no longer needed. Internal notes, technical sending acknowledgements or marketing messages do not extend that period.
A 14-day retention period is configured for recoverable mailbox copies. It starts when an item is removed from Deleted Items or moved directly into the recovery area, not when it is first moved to Deleted Items. Service-side cleanup follows expiry. This does not promise simultaneous physical deletion of all provider copies.
If a contractual relationship, legal record-keeping obligation or specific legal matter arises, we transfer only the necessary records to the relevant file. These are retained separately under the applicable obligations and periods, rather than automatically continuing to classify them as an open contact enquiry.
We handle rights requests, content reports and comparable legally relevant matters until the specific procedure is resolved and completed. Afterwards, we retain only the details needed for a statutory record-keeping duty or specific legal claims, separately and with restricted access, until the applicable record-keeping or limitation period ends. Further internal notes alone do not keep these records permanently classified as an open enquiry.
Where Article 32 of Spain's LOPDGDD requires blocking, the affected data are removed from ordinary access and secured exclusively for the authorities and liability-related purposes provided by law until the applicable limitation period expires; they are then destroyed.
The abuse-prevention counting window expires one hour after its first associated request. Further requests within that window do not extend it. Expired records are scheduled for cleanup every five minutes. Expiry and cleanup of the active record are separate from retention in database backups.
The Supabase database is backed up physically each day. These backups have a rolling recovery window of seven days. An abuse-prevention record already removed from the active database may therefore remain in an older backup until that backup leaves the recovery window. In this contact process, the backups do not contain message text. Restoring a backup does not reset the original expiry periods; expired records are cleaned up again before the contact service resumes. The seven-day window does not promise simultaneous physical deletion of every infrastructure copy.
Under the current Cloudflare Workers Free plan, the gateway logs described above are retained in Workers Logs for no more than three days. This statement concerns that log product, not all other provider logs.
For technical email delivery tracing, Microsoft Exchange retains Message Trace data for 90 days and then automatically removes it. This period concerns sending and delivery information, not retention of the message text in the mailbox.
For other data generated by Microsoft in operating the email service, Microsoft's service information specifies a default period of up to 180 days from collection. Longer periods are provided for where required for service security or legal or regulatory obligations. This is not an additional general retention period for message contents.
The following providers may also process technical data as independent controllers where those data are personal. Their privacy notices do not specify one uniform period in days:
- Vercel: Service-generated operational data; retention depends on legal and contractual duties, service development, resolving disputes and enforcing rights. When there is no continuing legitimate need, deletion or anonymisation is provided for; backups that cannot be deleted are stored securely. Vercel privacy notice.
- Cloudflare: Its own network and security data; retention depends on operational purpose, volume and sensitivity, possible harm, less data-intensive alternatives, and legal and contractual requirements. Data are deleted or destroyed when the period ends; where technical obstacles prevent this, further use is prevented. Cloudflare privacy notice, Section 11.
- RunPod: Personal performance and operational data; retention depends on processing purposes, statutory records, legal claims and fraud prevention, volume and sensitivity, and available alternatives. Its policy provides for deletion, anonymisation or isolation from further processing when data are no longer required. RunPod privacy notice, “Retention”.
These criteria concern the specified independent-controller processing; they do not extend our twelve-month maximum. Purely administrative data about our provider accounts are not an additional record of your enquiry.
7. Your rights
Subject to the legal conditions, you may request access, rectification, erasure, restriction and, where applicable, data portability. You may object to processing based on legitimate interests on grounds relating to your particular situation. Any later processing based separately on consent requires its own information; you may withdraw such consent for the future.
Contact info@viaora.ai. We request only the information needed to handle your request and, where necessary, verify your identity. We normally respond within one month; if a legally permitted extension is needed, we explain it and the reasons within that month.
You may complain to the Agencia Española de Protección de Datos (AEPD) or another competent data protection authority. You do not have to wait for our response before contacting an authority.
8. The corporate website's local appearance setting
For a light, dark or system-based appearance, the corporate website uses the local browser entry viaora.site.theme.v2. It contains only the value light, dark or auto, with no personal identifier or timestamp. The website does not transmit this value to Viaora or third parties or use it for analytics, advertising or profiling. In system mode (auto), the appearance follows your device's light/dark setting.
The entry is created or changed only when you explicitly select an appearance. Without a stored choice, the website follows your system without saving that default. Neither the first page visit nor a change in system settings writes the entry. A stored choice is read to set the appearance on later visits. The website sets no automatic expiry period. If the website cannot read a stored choice when it loads, it starts with the system appearance. An appearance you then explicitly select remains usable for the current page even if storage is unavailable, but is not saved persistently.
If there is no valid v2 choice, an earlier light/dark choice in viaora.site.theme.v1 may still be read to set the appearance. An old auto value is not adopted as a stored choice. The old entry is removed when a new choice is successfully saved. Without a new selection, an old entry may remain until the browser's website data is deleted.
You can change the appearance through the website settings and remove the entries using your browser's function for deleting website data. Explicitly selecting system mode does not delete the entry; it stores auto. After deletion, the entry is created again only when you make another explicit selection. This local setting is separate from contact enquiries and technical server logs.
9. Analytics, advertising and linked services
The corporate website sets no cookies of its own and integrates no analytics, advertising or session-replay tools. Vercel Web Analytics and Speed Insights are not enabled for this website. The local appearance setting in Section 8 is distinct from these tools, as are the technical operational and security data described in Sections 2 and 6. This does not mean that visiting the website involves no processing of personal data.
Links may lead to viaora.app or services operated by others. If you open one of those services, its own privacy information applies to processing there. This notice does not attribute the guest app's functions or processing to the corporate website.