Privacy Policy
Last updated: April 13, 2026
Vedion ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Execution Risk Audit platform (the "Service").
1. Information We Collect
1.1 Information You Provide
- Account Information: Name, email address, organization name, and password when you register.
- Company Profile: Company logo, website, employee count, funding stage, industry, and team structure.
- Survey Responses: Answers submitted by survey respondents during Execution Risk Audits.
- Payment Information: Billing address and payment method details (processed securely by Stripe; we do not store card numbers).
- Communications: Messages you send to us via email or support channels.
1.2 Information Collected Automatically
- Usage Data: Pages visited, features used, timestamps, and interaction patterns.
- Device Information: Browser type, operating system, screen resolution, and device identifiers.
- Log Data: IP address, access times, referring URLs, and error logs.
- Cookies: See our Cookie Policy for details.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service.
- Process survey responses and generate audit scores, gap analyses, and recommendations.
- Process payments and manage subscriptions.
- Send transactional emails (survey invitations, audit reports, account notifications).
- Provide AI-powered recommendations and insights based on aggregated, anonymized data.
- Detect and prevent fraud, abuse, and security incidents.
- Comply with legal obligations.
3. How We Share Your Information
We do not sell your personal data. We may share information with:
- Service Providers: Third-party vendors who help us operate the Service (e.g., Stripe for payments, SendGrid for email, Google Cloud for hosting).
- Within Your Organization: Audit results and scores are shared with authorized members of your organization as configured by you.
- Legal Requirements: When required by law, court order, or to protect our rights and safety.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, with prior notice.
We do not share individual survey responses with the subscribing organization in a way that identifies specific respondents, unless explicitly consented to by the respondent.
4. Data Security
We implement industry-standard security measures to protect your data, including:
- Encryption in transit (TLS/SSL) and at rest.
- JWT-based authentication with RSA-signed tokens.
- Brute-force login protection (account lockout after failed attempts).
- Regular security audits and vulnerability assessments.
- Access controls limiting employee access to personal data on a need-to-know basis.
While we strive to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
5. Data Retention
- Account Data: Retained as long as your account is active, plus 30 days after deletion.
- Audit Data: Retained for the duration of your subscription and up to 12 months after expiration to allow for renewal.
- Survey Responses: Retained as part of audit data. Anonymized aggregate data may be retained indefinitely for benchmarking purposes.
- Payment Records: Retained as required by tax and financial regulations (typically 7 years).
- Usage Logs: Retained for up to 90 days for security and debugging purposes.
6. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data (subject to legal retention requirements).
- Portability: Request your data in a structured, machine-readable format.
- Objection: Object to processing of your data for certain purposes.
- Withdrawal of Consent: Withdraw consent where processing is based on consent.
To exercise any of these rights, contact us at hello@vedion.co. We will respond within 30 days.
7. International Data Transfers
Your data is primarily processed and stored in the United States via our cloud infrastructure providers. If you are accessing the Service from outside the United States, your information will be transferred to and processed in the U.S. We ensure appropriate safeguards are in place for any international data transfers in compliance with applicable laws (including, where relevant, the EU Standard Contractual Clauses and the UK International Data Transfer Addendum).
8. Children's Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we learn that we have collected data from a child, we will delete it promptly.
9. Third-Party Services
The Service integrates with the following third-party services:
- Stripe: Payment processing (Stripe Privacy Policy)
- Google Cloud: Infrastructure and storage (Google Cloud Privacy)
- SendGrid: Email delivery (Twilio Privacy Policy)
- Microsoft Azure AD: Single sign-on authentication
- Google OAuth: Single sign-on authentication
- OpenAI: AI-powered recommendations (no personal data is sent; only anonymized, aggregated scores)
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Platform at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
11. Contact Us
For privacy-related inquiries or to exercise your data rights, contact us at:
- Email: hello@vedion.co
- Organization: Vedion
