Vorentus

Privacy & data protection

This notice explains what personal data Vorentus processes, why, for how long, and how you can exercise your rights under the GDPR (EU 2016/679).

Controller

Vorentus operates this workspace and is the controller for account data. For the organisational material you upload (documents, statements, evidence), your organisation is the controller and Vorentus acts as processor on your instructions.

Data we process

  • Account data: email address, password hash, sign-in timestamps and IP metadata; profile fields provided by Google when you use Google sign-in.
  • Organisation data: the company name you enter at sign-up and your membership role.
  • Content you upload: source materials, evidence files, statements and notes, which may contain names of individuals (for example authors or people mentioned in documents).
  • AI observations: prompts sent to language models and the responses received, stored to measure recognition over time.
  • Audit logs: which account performed which validation or evidence action, and when.

Purposes and legal bases

  • Providing the service and your account — performance of a contract (art. 6(1)(b)).
  • Analysing your organisational material and measuring AI recognition — legitimate interests of your organisation (art. 6(1)(f)), on your instructions.
  • Security, audit trails and abuse prevention — legitimate interests (art. 6(1)(f)).

Subprocessors

Vorentus relies on the following providers. Some process data outside the EEA under the EU Standard Contractual Clauses.

  • Hosting, database, authentication and file storage — Lovable Cloud (Supabase infrastructure).
  • Language model providers used by the Recognition and Engine modules — Anthropic, Google, OpenAI and Perplexity. Prompts and the organisational text they contain are transmitted to these providers to produce a response.
  • Google — only when you choose Google sign-in.

Retention

Account and organisation data are kept while your account exists. Content, AI observations and audit logs are kept while the organisation exists, because they are the historical record the methodology depends on. When you delete your account, everything belonging to organisations where you were the last remaining member is erased immediately and irreversibly.

Your rights

  • Access, rectification and erasure of your personal data (arts. 15–17).
  • Restriction of and objection to processing (arts. 18 and 21).
  • Data portability (art. 20).
  • Lodging a complaint with your supervisory authority — in Portugal, the CNPD.

You can erase your account and its data yourself in Settings. For any other request, contact the workspace owner.

Security

Data is isolated per organisation and enforced in the database with row-level security: a query can only ever return rows of organisations you belong to. Evidence files are stored in a private bucket scoped to your organisation. Access is over TLS and passwords are checked against known breach databases.

This page is maintained by the Vorentus workspace owner and is not an independent certification.Back to sign in