Legal

Privacy Policy

Effective date: 28 July 2026

1. Who we are

Vioscale (“Vioscale”, “we”, “us”) operates the independent, evidence-based software-intelligence platform at www.vioscale.ai and the separate vendor portal at account.vioscale.ai. We are the controller of the personal data described in this policy.

  • General and privacy contact: support@vioscale.ai
  • Registered company: Vioscale Technologies Ltd (registered in England and Wales, company number 14751646)
  • Registered office: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
  • Data protection contact: you can reach us on any data protection matter at support@vioscale.ai. We have not appointed a statutory Data Protection Officer; data protection matters are handled by our privacy team.
  • Article 27 representative: Vioscale Technologies Ltd is established in the United Kingdom, so a representative under Article 27 of the UK GDPR is not required.

2. What we collect, how, and why

We keep data collection deliberately narrow. We process four categories of personal data:

a. Account data

For developer and API accounts, and separately for vendor accounts, we store your email address, an optional display name, a scrypt hash of your password (we never store the password itself), and the timestamp at which your email was verified. We collect this directly from you when you register, to create and secure your account.

b. Vendor claim and submission data

When a vendor claims a software listing, we process the software being claimed, domain-verification tokens used to prove control of the associated domain, and an append-only audit log of profile edits. This lets us verify legitimate control and preserve the integrity and provenance of the record.

c. API-consumer data

For API access we store a hash of each API key (never the key in clear text), your credit balance, and usage events. This is needed to authenticate requests, meter usage, and bill or rate-limit fairly.

d. Analytics and measurement data

When you view public pages or call the API, our servers receive your IP address and User-Agent string as part of the request. We do not retain the raw IP address: before storage it is combined with the User-Agent and replaced with a keyed hash (HMAC-SHA256, truncated), so the stored identifier cannot be reversed to your IP. Alongside that hash we record page-view and API-usage events. When you click through to a vendor’s own website, we also record a server-side outbound-click event (the same pseudonymised identifier plus the product), which sets no cookie and reads nothing from your device; it measures aggregate buyer interest. Analytics capture on public page views is gated on your consent (see our Cookie Policy). Our lawful basis for this measurement is our legitimate interest in understanding aggregate usage, keeping the service secure, and improving the product.

3. Legal bases (UK GDPR, DPA 2018, and EU GDPR)

Our lead data protection framework is the UK GDPR together with the Data Protection Act 2018. Where the UK GDPR, or the EU GDPR for individuals in the EU or EEA, applies, we rely on the following legal bases:

  • Performance of a contract (Article 6(1)(b)): creating and operating your developer, API, or vendor account, providing the vendor portal, and delivering API access you have requested.
  • Legitimate interests (Article 6(1)(f)): maintaining aggregate analytics, securing the platform against abuse and attack, and improving the product. We have weighed these interests against your rights and freedoms; because the IP address is stripped before storage and the data is used in aggregate, we consider the impact on you to be low and not to override your interests. You may object at any time (see Section 6).
  • Consent (Article 6(1)(a)): non-essential analytics cookies and the associated measurement capture. You can withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
  • Legal obligation (Article 6(1)(c)): where we must retain or disclose data to comply with applicable law, such as tax, accounting, or a lawful request from an authority.

4. How long we keep it (retention)

We keep personal data only as long as necessary for the purpose it was collected. Our retention policy is as follows.

  • Account and profile data: retained for the life of the account and for 24 months after the account is closed, after which it is erased or anonymised. During the period following closure the data supports recovery and helps prevent abuse.
  • Analytics and consent-log data: retained for 14 months, after which events are deleted or further aggregated.
  • Transactional email logs: retained for 12 months to support deliverability, security, and account-related record-keeping.
  • Vendor claim and edit audit logs, raw crawl snapshots, and published source evidence: retained for as long as the related fact remains published, since provenance is part of the product and preserves the integrity of the public record.
  • Hashed API keys: retained until the key is revoked, after which the hash is removed subject to any short reconciliation window for billing and security logs.

5. Sharing and processors

We do not sell your personal data and we do not share it for cross-context behavioural advertising. We run no third-party advertising trackers, and we take no vendor payment that affects data handling or ranking. We use a small number of service providers acting as processors on our instructions, including our email provider (Resend, when configured) to send transactional and verification email, and our payment processor (Stripe) to take and manage API and subscription payments. Card details are handled by Stripe and never reach our servers. Processors are bound by contract to protect the data and use it only as we direct.

6. Your rights

Depending on your location, you may have the right to: access a copy of your data; rectify inaccurate data; erase your data; restrict processing; port your data to another provider; object to processing based on legitimate interests; and withdraw consent at any time. Where the UK or EU GDPR applies, you also have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the UK Information Commissioner’s Office (ICO), ico.org.uk. If you are in the EU or EEA, you may also lodge a complaint with your local supervisory authority.

To exercise any of these rights, use our data request page or email support@vioscale.ai. We will respond within the timeframe required by applicable law and will not discriminate against you for exercising your rights.

7. California privacy rights (CCPA/CPRA)

If you are a California resident, this section applies to you. In the preceding 12 months we have collected the following categories of personal information: identifiers (such as email address and a keyed hash derived from your IP address and User-Agent); internet or network activity (page-view and API-usage events, User-Agent); and account credentials in hashed form. We collect these for the business purposes described above.

We do not sell or share your personal information. Under the CCPA and CPRA you have the right to know what we collect, to delete it, to correct it, and to limit the use of sensitive personal information. Because we do not sell or share personal information and do not use sensitive personal information for purposes that trigger the limit-use right, there is nothing to opt out of, but you may still exercise your other rights.

Do Not Sell or Share My Personal Information: Vioscale does not sell or share your personal information, so no opt-out action is required. We honour these rights without discrimination.

8. International data transfers

Where personal data is transferred outside the EEA, the UK, or your home jurisdiction, we rely on an approved transfer mechanism, such as an adequacy decision or the Standard Contractual Clauses (with the UK International Data Transfer Addendum where relevant), together with any supplementary measures needed to protect your data.

9. How we protect your data

We apply security measures appropriate to the risk. Passwords are stored as scrypt hashes, never in clear text. Session cookies are httpOnly and HMAC-signed. The raw IP address is stripped and replaced with a keyed HMAC hash (over the IP and User-Agent) before any analytics record is stored. API keys are stored only as hashes. In the event of a personal data breach likely to result in a risk to your rights, we are committed to notifying the relevant supervisory authority and affected individuals without undue delay and in line with applicable law.

10. Children

The service is not directed to children under 16 and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Changes to this policy

We may update this policy from time to time. When we make material changes we will update the effective date above and, where appropriate, notify you. Your continued use of the service after an update constitutes acceptance of the revised policy.

See also our Terms of Service and Cookie Policy.

Privacy Policy · Vioscale