Legal
Privacy Policy
How Vimiana handles the data you provide as an account holder, and the data that flows through invocations.
Last updated 22 June 2026 · Draft
Draft — pending review
This is a working draft, not final or legally binding wording. It is published so the platform's real behaviour can be reviewed; final wording is pending operator and counsel review before the public launch.
1. Who we are and scope
This policy explains how the operator of Vimiana (“Vimiana”, “we”) handles personal data as the controller for account and operational data, and how data flows through the invocations you make or serve. It covers the website, the console and the API.
Provisional — pending the tax / merchant-of-record rulingThe identity and registered address of the controlling legal entity, and any EU/UK representative, are being confirmed and will be stated here before public launch.2. What we collect
- Account data — your email, organisation, role and authentication details.
- Billing and wallet data — top-ups, balances, ledger entries, payouts and, when real payments are enabled, limited payment metadata from our payment processor (we do not store full card numbers).
- Operational logs — records of API requests for metering, rate-limiting, security, billing and support. Logs are structured and PII-redacted by default.
3. Invocation data
The inputs and outputs of a call are processed to fulfil and meter that call, including passing the request to the relevant supplier capability. We do not sell invocation data. Suppliers receive only what a call requires to run — a consumer's identity is not exposed to suppliers beyond that, and supplier economics are never exposed to consumers.
4. Legal bases for processing
5. Sharing and sub-processors
We share data with the processors that run the service (hosting, database, authentication and, when enabled, payments) only as needed to operate it. We do not sell personal data. Our current processors are listed on the sub-processor list, and our terms for business-customer data are described in the data processing addendum.
6. International transfers
7. Retention
We retain account, billing and operational records for as long as needed to provide the service and to meet legal, tax and accounting obligations, after which they are deleted or anonymised. Specific retention periods will be confirmed with counsel before public launch.
8. Your rights
Subject to applicable law, you may request access to, correction of, deletion of, or a copy of your personal data, and you may object to or restrict certain processing. To exercise a right, email privacy@vimiana.com. You also have the right to complain to your local data-protection authority.
9. Security
Access is authenticated and rate-limited. Outbound calls made on your behalf are constrained to prevent server-side request forgery and secret egress, and request sizes are bounded. We restrict internal access to personal data and log administrative actions. No system is perfectly secure; report concerns to security@vimiana.com.
10. Cookies and changes
The website uses a small number of cookies, described in the cookie policy. We may update this policy; material changes will be reflected by the “last updated” date above and, where appropriate, additional notice.
Questions about this document? Email privacy@vimiana.com or read the docs before relying on these terms.