vaaya / privacy policy
Privacy Policy · vaaya
Last updated 21 May 2026
How Vaaya Inc. collects, uses, discloses, processes, and protects information across our website, products, APIs, and agentic AI systems.
1Introduction
Vaaya Inc. ("Vaaya", "Company", "we", "our", or "us") is committed to protecting the privacy, security, and confidentiality of information entrusted to us.
This Privacy Policy describes how we collect, use, disclose, process, and protect information through our website, products, APIs, agentic AI systems, and related services.
2Information We Collect
Information you provide
- Name
- Business email address
- Company name
- Job title
- Phone number
- Account credentials
- Communications and support requests
Information collected automatically
- IP address
- Browser and device information
- Usage logs
- Session information
- Diagnostic and telemetry information
Customer Data
Customers may provide information for processing through the Services. Customers retain ownership of Customer Data.
3Agentic AI Processing
Vaaya provides AI systems that may retrieve information, execute workflows, call APIs, generate content, and perform tasks on behalf of authorized users.
Customers are responsible for configuring permissions, approval workflows, and governance controls.
4How We Use Information
We use information to:
- Provide and improve Services
- Authenticate users
- Secure accounts
- Operate AI agents
- Provide support
- Detect fraud and abuse
- Comply with legal obligations
5Customer Data and Model Training
Unless expressly agreed in writing:
- Customer Data is not used to train public or shared foundation models.
- Customer Data is not sold.
- Customer Data is not licensed to third parties.
Vaaya may use aggregated, anonymized, or de-identified information to improve security, reliability, and performance.
6Third-Party Providers
We may use third-party cloud, infrastructure, analytics, security, communications, and AI model providers.
7Security
We maintain administrative, technical, and organizational safeguards including:
- Encryption in transit
- Encryption at rest
- Access controls
- Audit logging
- Security monitoring
- Incident response procedures
8Data Retention
We retain information only as long as necessary for service delivery, legal obligations, and legitimate business purposes. In practice that means:
- Transaction records (the call, its price, the provider, the outcome) are retained for the life of the account and thereafter as required for accounting and tax obligations.
- Call parameters and results are retained with the account so results can be re-read instead of re-purchased, and are deleted when the account is deleted.
- Consult conversations are retained with the account and deleted when the account is deleted.
- Uploaded files are retained until you delete them, or until the account is deleted.
- Company memory is retained until you clear it, or until the account is deleted.
- GitHub scoring data (public profile signals and the computed score) is retained while GitHub is connected and removed when you disconnect it.
A per-data-type summary of what is stored and what is forwarded to providers is published on our security and data page.
9International Transfers
Information may be processed in jurisdictions outside your country of residence subject to appropriate safeguards.
10Your Rights
Subject to applicable law, individuals may have rights to:
- Access
- Correction
- Deletion
- Restriction
- Portability
- Objection
Requests: privacy@vaaya.ai
11Security Incidents
Where required by law or contract, Vaaya will provide notice of confirmed security incidents affecting Customer Data.