This notice explains what personal data Vorentus processes, why, for how long, and how you can exercise your rights under the GDPR (EU 2016/679).
Vorentus operates this workspace and is the controller for account data. For the organisational material you upload (documents, statements, evidence), your organisation is the controller and Vorentus acts as processor on your instructions.
Vorentus relies on the following providers. Some process data outside the EEA under the EU Standard Contractual Clauses.
Account and organisation data are kept while your account exists. Content, AI observations and audit logs are kept while the organisation exists, because they are the historical record the methodology depends on. When you delete your account, everything belonging to organisations where you were the last remaining member is erased immediately and irreversibly.
You can erase your account and its data yourself in Settings. For any other request, contact the workspace owner.
Data is isolated per organisation and enforced in the database with row-level security: a query can only ever return rows of organisations you belong to. Evidence files are stored in a private bucket scoped to your organisation. Access is over TLS and passwords are checked against known breach databases.