Privacy Policy
Last Updated: April 03, 2025
Introduction
Welcome to VectorForgeAI's Privacy Policy. Your privacy is critically important to us, and we are committed to being transparent about how we collect, use, and share your information. This Privacy Policy is designed to comply with applicable data protection laws, including the General Data Protection Regulation (GDPR) for users in the European Union.
Information We Collect
1. User Account Information
When you register for a VectorForgeAI account, we collect:
- Full name
- Email address
- Company affiliation (through the Teams feature)
2. Billing Information
We process your payment information through Stripe, our third-party payment processor. We don't store your full credit card details on our servers.
3. Usage Data
We collect information about how you use our service, including:
- API call frequency and patterns
- Features used
- System performance metrics
4. Content Data
We store the following content that you provide to our services:
- Documents you upload (e.g., helpdesk content, documentation, business information)
- Conversation messages (both user inputs and LLM responses)
- Vector embeddings (stored as SHA256 values to protect the original search terms)
How We Use Your Information
We use your information to:
- Provide, maintain, and improve our services
- Process transactions and send related information
- Send technical notices, updates, and support messages
- Respond to your comments and questions
- Monitor and analyze usage patterns and trends
Data Retention
We automatically delete conversations and LLM completion data after 30 days or when a user stops subscribing to our service. Documents and their embeddings are retained until explicitly deleted through our API or when a user unsubscribes from our service.
End User Data
We do not store any personal data about your end users (your users' users/clients) except if explicitly sent by you. It is your responsibility to ensure that you do not set identifiers to real personal data but rather use database IDs, UUIDs, or similar non-personal identifiers.
Third-Party Services
We use OpenAI's API for our underlying LLM infrastructure. We may change to other providers if we determine it necessary, in which case we will notify all users 14 days in advance of such a change. These third-party services have their own privacy policies that govern how they use your information.
Data Security
We implement appropriate security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. Conversation messages and LLM responses are stored securely until deleted.
Your Rights
Depending on your location, you may have rights regarding your personal information. These may include:
- Access to your personal information
- Correction of inaccurate information
- Deletion of your personal information
- Restriction or objection to processing
- Data portability
Legal Basis for Processing
We process your personal data only where we have a legal basis to do so, such as your consent, the necessity to perform a contract, compliance with a legal obligation, or our legitimate interests in providing and improving our services.
International Data Transfers
Your information may be transferred to and processed in countries outside of your own, including countries that may not provide the same level of data protection. Where required by law, we ensure appropriate safeguards are in place for such transfers.
GDPR Compliance
For users in the European Union, we comply with the General Data Protection Regulation (GDPR). This includes:
- Lawful Basis: We process your data based on contract necessity (for service provision), legitimate interest (for service improvement), or with your explicit consent.
- Data Subject Rights: We respect your rights to access, rectify, erase, restrict processing, object to processing, and data portability.
- Data Protection Officer: We have appointed a DPO to oversee our compliance with data protection regulations.
- Data Processing Agreements: We maintain appropriate data processing agreements with all third-party processors.
- Data Protection Impact Assessments: We conduct DPIAs for processing operations that may result in high risks to your rights and freedoms.
- Data Breach Notification: We have procedures in place to detect, report, and investigate personal data breaches within 72 hours.
- Records of Processing: We maintain records of our processing activities as required by Article 30 of the GDPR.
- Privacy by Design: We implement appropriate technical and organizational measures to ensure data protection principles are integrated into our processing activities.
To exercise your GDPR rights or for more information about our GDPR compliance, please contact our Data Protection Officer at privacy@vectorforgeai.com.
Children's Privacy
Our services are not directed to children under 16. We do not knowingly collect personal information from children under 16. If you become aware that a child has provided us with personal information, please contact us and we will take steps to remove such information.
How to Exercise Your Rights
To exercise your rights regarding your personal information, please contact us at privacy@vectorforgeai.com. We may need to verify your identity before fulfilling your request.
Data Protection Officer
If you have questions about our data protection practices, you may contact our Data Protection Officer at privacy@vectorforgeai.com.
Complaints
If you are located in the European Economic Area and believe your data protection rights have been violated, you have the right to lodge a complaint with your local supervisory authority.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on our website and, if the changes are significant, we will provide a more prominent notice.
Contact Us
If you have questions about this Privacy Policy, please contact us at: privacy@vectorforgeai.com