Privacy Policy — Virtosic
Effective Date: 9 August 2026
Last Updated: 9 August 2026
This Privacy Policy explains how Virtosic ("we," "us"), based in Houston, Texas, collects, uses, and discloses information in connection with the Virtosic platform (the "Service").
This document distinguishes between Account Information (information about the people who use the Service, where we act as data controller) and Customer Data (your company profile, risk register, policies, vendor data, and uploaded documents, where we act as a data processor / service provider acting on your instructions).
1. Information We Collect
1.1 Account Information
Name, work email, role, authentication data, and support communications.
Authentication today uses an email and password held by Virtosic: your password is stored only as a hash, and your session is a server-side record we can revoke. Amazon Cognito is supported by the Service as an identity provider but is not active in this deployment, so no authentication data is currently held by Cognito. We will update this section before that changes.
We do not currently collect billing information, because payment processing is not enabled — see Section 3 of the Terms of Service.
1.2 Company Profile and Customer Data
- Company profile details you provide at onboarding: industry, size, your intended data region, and flags indicating whether you handle payment data, health data, or operate legacy/operational-technology equipment. These are used to tailor risk assessments and framework recommendations. The flag about legacy/OT equipment informs which frameworks the Service recommends; a dedicated OT/legacy assessment module is not available in the Service.
- Risk register entries, draft and published policies, framework/control assessment status, vendor information, and questionnaire responses.
- Documents and photographs you upload (including specification sheets, vendor questionnaires, and compliance evidence), which may be processed using multimodal AI extraction as described in Section 4.
- Public DNS and email-authentication records for a domain you nominate, read directly from public records. This is the only connector available in the Service; it uses no credentials, and connectors for cloud and identity providers are not available. If we add one, we will update this section before it processes anything.
1.3 Usage Data
Server log data, and operational metrics about the Service's own behaviour — including how many AI model calls your organization's work required and what they cost us. There is no third-party product-analytics tool in the Service, and no behavioural tracking of individual users.
2. How We Use Information
We use Account Information to provide, secure, and improve the Service, provide support, and communicate with you. We use Customer Data solely to provide the Service to you: generating your risk register, draft policies, compliance gap analysis, vendor risk assessments, and reports. We do not use Customer Data for independent purposes or to train models for the benefit of any party outside your organization.
3. Legal Basis for Processing (EEA/UK Users)
Where GDPR applies, our legal bases are performance of a contract, legitimate interests, and legal compliance. Where we process personal data within your Customer Data on your behalf, we act as a processor; a data processing agreement is available on request at [email protected].
4. AI Processing Disclosure
The Service uses AI models provided by Anthropic to generate risk assessments, draft policies, compliance gap analyses, and to extract structured data from uploaded documents and photographs (multimodal/vision processing). Anthropic is the only model provider the Service uses.
4.1 As of the date of this Policy, data submitted to Anthropic via its API/enterprise offering is not used to train its general-purpose models. We will update this section if that changes.
4.2 Document Intelligence extraction from uploaded photographs and files is reviewed and confirmed by you before being applied to your risk register or compliance records — see the Disclaimers. The Service has no path that applies extracted data without your confirmation.
4.3 If your organization requires specific restrictions on AI processing (exclusion of specific categories, or a request to disable multimodal document processing), contact [email protected].
5. Health Information (HIPAA)
This Privacy Policy does not, by itself, satisfy the requirements applicable to Protected Health Information ("PHI") under HIPAA. If your organization is a HIPAA Covered Entity or Business Associate and intends to submit PHI to the Service, you must first execute a Business Associate Agreement with us, available on request at [email protected]. Do not submit PHI to the Service unless a BAA is in place, per Section 5 of the Terms of Service. Where a BAA is in place, its terms govern the handling of PHI to the extent they conflict with this Policy.
6. Data Retention
What the Service does today:
- Account Information: retained while your account is active and for a reasonable period after, for legal and dispute-resolution purposes.
- Customer Data (risk register, policies, compliance records, vendor data): retained for as long as your organization exists in the Service. There is no automatic deletion schedule.
- Uploaded documents: retained as long as referenced by an active risk item, control, or vendor record, to preserve evidence traceability for audit purposes.
What is intended but not yet implemented, and which we therefore do not commit to here: a self-service export window following termination, automatic deletion after that window, and a minimum seven-year retention schedule for compliance-evidence and audit-log data on the Regulated tier. Until these exist in the Service, export and deletion are handled on request — contact [email protected] and we will action it.
7. Subprocessors and Third-Party Disclosure
These are the subprocessors in use in the deployed Service:
| Subprocessor | Purpose |
|---|---|
| Amazon Web Services | Compute (Lightsail instance) and database backups (S3) |
| Anthropic | AI model inference, including multimodal document extraction |
| Resend | Transactional and notification email |
| Sentry | Application error tracking |
What Sentry receives. When something goes wrong in the Service, the error is
reported to Sentry so that we find out from our own systems rather than from
you. We remove sensitive material before the report leaves our servers rather
than relying on the vendor's own filtering: credentials, session identifiers and
authentication headers are replaced with a redaction marker, and your content —
risk justifications, policy drafts, questionnaire answers, extracted document
data — is replaced with a description of its shape, such as
`[customer content: 412 chars]`. What is sent is the error itself, where in our
code it happened, and your organization identifier so we can tell whose problem
it is. If you would rather we did not use error tracking for your organization
at all, contact [email protected].
One further subprocessor is supported by the Service but is not in use today:
| Subprocessor | Purpose | Status |
|---|---|---|
| Stripe | Payment processing | Not in use; billing is not enabled |
We will update this section before it becomes active. We do not sell Customer Data or Account Information.
8. MSP Data Handling
If your organization is managed by a Managed Service Provider ("MSP") through the Service, your data is isolated from other clients of that MSP at the database level, and the MSP's access is limited to client organizations it has been explicitly granted access to. If you have questions about what your MSP can access, contact the MSP directly or [email protected].
9. Data Security
We maintain administrative, technical, and physical safeguards designed to protect Account Information and Customer Data, including role-based access controls throughout the Service.
Traffic to and from the Service is encrypted in transit with TLS. At rest, data sits on AWS-managed storage and depends on AWS's default storage encryption; Virtosic does not add an application-level encryption layer on top of it, and we would rather say so than imply one. Passwords are stored only as hashes.
Tenant isolation is enforced by PostgreSQL row-level security rather than by application code alone — a query that omits a tenant filter returns nothing rather than another organization's data. The same enforcement covers the MSP hierarchy described in Section 8. This is covered by an automated test suite that runs against a real database.
No method of transmission or storage is 100% secure.
10. Data Location and International Transfers
The Service runs in a single AWS region, us-west-2, in the United States. Account Information and Customer Data are stored there regardless of where your organization is located.
The data-region field in your company profile does not pin your storage to a region. It is a profile setting that informs which compliance frameworks the Service recommends to you — selecting "EU," for example, causes the Service to recommend GDPR. Region-pinned data residency is not offered.
Where data is transferred internationally, we rely on appropriate safeguards including Standard Contractual Clauses where applicable.
11. Cookies and Tracking
The Service sets one cookie: the session cookie that keeps you signed in. It is strictly necessary, HTTP-only, and not used for tracking. There are no analytics cookies, no advertising cookies, and no third-party trackers on the marketing site or in the application. We will update this section before that changes.
12. Your Privacy Rights
You may have rights to access, correct, delete, or port your Account Information, and to object to or restrict certain processing, depending on your location. California residents have rights under the CCPA/CPRA; we do not sell Account Information or Customer Data as defined under that law. To exercise these rights, contact [email protected]. For Customer Data, including risk register entries, policies, or vendor records about individuals, requests should generally be directed to the Customer organization, since Virtosic acts as a processor for that data.
13. Children's Privacy
The Service is intended for business use by adults and is not directed to children under 18.
14. Changes to This Policy
We may update this Policy; material changes will be notified via the Service or email at least 30 days before taking effect.
15. Contact Us
Virtosic
Houston, Texas, United States
Privacy inquiries: [email protected]
HIPAA/BAA inquiries: [email protected]
General inquiries: [email protected]
If you are located in the EEA/UK, you have the right to lodge a complaint with your local data protection authority.
</content>