VINCIS Limited (“VINCIS”, “we”, “us” or “our”) takes your privacy and the security of your personal data seriously.
This Privacy Policy explains how we collect, use, store, disclose and protect your personal data when you access or use the VINCISGPT website, applications, enterprise knowledge features, AI Employee, connectors, automation tools and other related services (collectively, the “Services”), and how you may exercise your rights.
Please read this Policy carefully before using the Services. If you do not agree with this Policy, please do not submit personal data to the Services or continue using the relevant features.
01Scope
This Policy applies to personal data processing activities controlled by VINCIS.
Where an enterprise customer uses VINCISGPT to process data relating to its employees, customers, partners or other individuals, that enterprise customer is generally responsible for determining the purposes and means of processing, and VINCIS may process such data as a service provider or data processor acting on the customer’s instructions.
This Policy does not apply to websites, applications, model services or platforms operated independently by third parties. Their processing of data is governed by their own privacy policies.
02Data We Collect
Depending on the features you use, we may collect the following categories of data.
2.1Account and Identity Data
- name, display name and profile image;
- email address and telephone number;
- account, user and organisation identifiers;
- login records, authentication status and technical identifiers of security credentials;
- enterprise or organisation affiliation;
- system-confirmed permission and authorisation records.
Sensitive authentication information such as passwords, access tokens and keys is handled under corresponding security measures. We do not display complete secret credentials in any public interface.
2.2Content You Submit
- conversations, questions, instructions and feedback;
- uploaded documents, images, spreadsheets, audio, video or other files;
- enterprise knowledge, project materials, work records and internal data;
- content you ask AI to generate, analyse, organise or process;
- data you authorise the Services to access through connectors.
Do not submit personal data or confidential information that you have no right to use, disclose or process.
2.3AI Employee and Work Data
- AI Employee configuration, name, responsibilities and available capabilities;
- Work items, tasks, plans, status and assignment records;
- user confirmation, approval, rejection and revocation records;
- tool invocations, execution attempts and error information;
- Evidence, read-back results and Outcome;
- event records relating to security, audit and accountability.
AI, models and automated systems cannot themselves constitute a real human identity, nor can they generate human authorisation on their own.
2.4Usage and Device Data
- IP address and approximate location;
- browser, device, operating system and language;
- access times, pages, features and operation records;
- performance data, error logs and crash reports;
- information generated by cookies, session identifiers and similar technologies.
2.5Payment and Subscription Data
If you purchase paid Services, we may collect:
- subscription plans, orders and transaction records;
- billing contact and billing address;
- payment status, refunds and tax information;
- service usage actually incurred.
Full payment card details are generally handled by an engaged payment service provider. VINCIS does not ordinarily store complete card numbers or security codes.
2.6Data from Third-Party Sources
Where you authorise it or the law permits, we may obtain data from:
- enterprise customers or organisation administrators;
- identity authentication providers;
- third-party platforms you choose to connect;
- model, search, storage, payment and other service providers;
- publicly accessible data sources;
- anti-fraud, security and compliance providers.
03How We Use Data
We may use data to:
- create, authenticate and manage accounts;
- provide conversation, research, knowledge management and AI features;
- create and manage Work, AI Employees and execution flows;
- process user confirmations, Owner approvals and permission determinations;
- carry out operations you expressly request or authorise;
- retain Evidence, Outcome and necessary audit records;
- provide customer support and handle complaints;
- calculate service usage and fees actually incurred;
- detect fraud, abuse, privilege escalation and security incidents;
- debug errors, maintain systems and improve reliability;
- perform contractual, legal and regulatory obligations;
- send product or marketing communications where the necessary consent has been obtained;
- produce aggregated, anonymised or otherwise non-identifiable analytics.
We do not grant Owner or administrative rights to an account automatically because it uses a particular email address, displayed role or job title.
04AI Processing and Model Providers
When you use AI features, your instructions, relevant context and necessary User Content may be sent to the model or infrastructure providers used by VINCIS for processing.
We limit the scope of data sent according to functional necessity, product configuration, contractual arrangements and applicable law.
AI output may contain errors, omissions or inferences. Model-generated content does not by itself constitute a confirmed enterprise fact, a formal approval, or a completed execution result.
We do not use an enterprise customer’s non-public content to train general models serving other customers, unless we have obtained your express authorisation and have an appropriate legal basis.
Whether a third-party model provider retains inputs, for how long, and whether it uses them to improve its own services, depends on the product configuration and contractual terms adopted between VINCIS and that provider. We will, so far as reasonably practicable, select services that offer enterprise data protection options.
05Local and Cloud Processing
Some features may run on your device, in a local environment or in a private deployment; others may require VINCIS servers or engaged cloud services.
We will not describe a cloud-processed feature as fully local without technical substantiation.
The actual processing location depends on:
- the features you use;
- the deployment model you select;
- the models or connectors invoked;
- the enterprise customer’s configuration;
- the applicable order or service agreement.
Where a feature is expressly marked “local processing only”, its data boundary is determined by the corresponding technical documentation and configuration.
06Legal Bases for Processing
Where required by applicable law, we process personal data on one or more of the following bases:
- performance of a contract with you;
- provision of the Services at your request;
- your consent;
- compliance with legal or regulatory obligations;
- protection of the legitimate interests of users, VINCIS or third parties;
- maintaining service security, preventing fraud and improving the Services;
- establishing, exercising or defending legal claims;
- any other basis permitted by applicable law.
You may withdraw consent given as a basis for processing; withdrawal does not affect the lawfulness of processing carried out beforehand.
07How We Share Data
We may disclose data to the following recipients, to the extent necessary.
7.1Service Providers
Engaged providers of:
- cloud computing and data storage;
- AI models and inference;
- identity authentication;
- payment and billing;
- email, notifications and customer support;
- security monitoring, error analysis and fraud prevention;
- search, connector and automation infrastructure.
Service providers may process the relevant data only in accordance with their contract and applicable law.
7.2Your Organisation
If your account is provided, administered or paid for by a company or organisation, that organisation may access or manage:
- account and member data;
- content within the enterprise workspace;
- permission, work and audit records;
- usage and subscription data.
Before permitting an organisation administrator to access personal content, we determine the applicable boundaries in accordance with product functionality, the authorisation relationship and applicable law.
7.3Third Parties You Authorise
When you connect to, or ask us to perform an operation on, a third-party platform, we may send the necessary data in accordance with your instructions.
7.4Legal and Security Disclosure
We may disclose data as permitted by law where we reasonably consider it necessary to:
- comply with law, a court order or regulatory requirement;
- protect life, safety or legitimate interests;
- investigate fraud, attacks, abuse or unlawful conduct;
- establish, exercise or defend legal rights.
7.5Corporate Transactions
In the event of a merger, acquisition, financing, reorganisation or transfer of business, relevant data may be transferred to the relevant parties subject to appropriate confidentiality and protection measures.
08We Do Not Sell Personal Data
VINCIS does not sell your personal data for monetary consideration.
Where applicable law defines certain advertising, analytics or cross-platform disclosures as a “sale” or “sharing”, we will provide notice and an opt-out mechanism as required by law.
We do not use sensitive personal data for targeted advertising unrelated to providing the Services without appropriate consent.
09Cookies and Similar Technologies
We may use strictly necessary cookies and similar technologies to:
- maintain your login session;
- prevent cross-site request forgery and other attacks;
- remember language and basic settings;
- analyse service performance;
- diagnose errors and prevent abuse.
Non-essential cookies will be subject to your consent where required by applicable law.
You may manage your preferences through your browser or cookie settings, though disabling strictly necessary cookies may render certain features unusable.
10International Data Transfers
VINCIS and its service providers may process data outside your country or region.
Data protection laws differ between jurisdictions. In accordance with applicable law, we protect cross-border transfers through contractual safeguards, risk assessments, access controls, encryption or other appropriate measures.
If you use an enterprise or private deployment, the applicable data regions and cross-border arrangements may be separately agreed in the order documentation or a data processing agreement.
11Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, perform a contract, resolve disputes, maintain security or comply with law.
Retention periods may depend on:
- whether the account remains active;
- the enterprise customer’s configuration and contractual requirements;
- the category and sensitivity of the data;
- whether a dispute, security incident or legal hold exists;
- whether the data forms a necessary transaction or audit record.
The principal retention periods are:
On expiry of the retention period we will delete, anonymise or otherwise securely handle the data, except where continued retention is required by law.
12Data Security
We apply technical and organisational measures proportionate to risk, including:
- authentication and access control;
- least-privilege permissions;
- encryption in transit or at rest;
- security logging and anomaly monitoring;
- tenant and data isolation;
- backup, recovery and business continuity measures;
- confirmation, approval and audit for sensitive operations;
- appropriate management of service providers.
Nevertheless, no system can guarantee absolute security. You are also responsible for protecting your account, devices and credentials, and for reporting suspicious activity promptly.
13Your Rights
Depending on your location and applicable law, you may have the right to:
- ask whether we hold personal data about you;
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request deletion of data;
- restrict or object to certain processing;
- withdraw consent;
- obtain a portable copy of your data;
- opt out of certain marketing, sale or sharing activities;
- object to significant decisions based solely on automated processing;
- lodge a complaint with a competent supervisory authority.
Certain rights may be limited by identity verification, the rights of others, contractual, audit, security and statutory retention obligations.
To exercise your rights, please submit a request using the contact details in this Policy. We may ask for reasonable information to verify your identity, but we will never grant account or organisation permissions based on a displayed email value alone.
14Enterprise Accounts
If you use the Services through an enterprise account, your organisation may bear corresponding data controller responsibility for data in the enterprise workspace.
Please consult your organisation’s internal privacy policy first. For data whose purposes and means of processing are determined by an enterprise customer, VINCIS may need to refer your request to that customer.
An enterprise administrator or responsible person may not obtain access beyond the system authorisation record on the basis of a job title, role label or email address alone.
15Children and Minors
The Services are intended primarily for enterprises and users with full legal capacity, and are not designed specifically for children.
If you are below the age of independent consent under the laws of your jurisdiction, please use the Services with the consent and supervision of a guardian.
If we discover that a child’s personal data has been collected without appropriate authorisation, we will take reasonable steps to delete it or restrict its processing.
16Automated Decision-Making
VINCISGPT may assist in analysing data, making recommendations or carrying out authorised tasks.
Unless permitted by applicable law and subject to appropriate safeguards, we do not make final decisions producing legal or similarly significant effects on an individual based solely on automated processing.
AI output cannot itself constitute a human approval, a formal enterprise fact, or valid authorisation.
17Data Breaches and Security Incidents
If a security incident occurs that may affect your personal data, we will investigate, contain the risk and take reasonable remedial measures.
Where required by applicable law, we will notify the relevant supervisory authority, enterprise customers or affected individuals.
18Third-Party Links
The Services may contain links to third-party websites or services. We do not control third-party privacy practices.
Please review their privacy policies and terms of service before submitting data to them.
19Changes to This Policy
We may update this Policy to reflect product, technical, legal or business changes.
Where a change may materially affect your rights, we will notify you through the website, in-product notice, email or another reasonable method.
The updated Policy takes effect on the date published or the date stated in the notice.
20Contact Us
If you have any questions about this Policy, our processing of personal data, or a rights request, please contact:
You may also lodge a complaint with the data protection authority having jurisdiction over you.