Vendian
01Process02Training03Modules04Work05Pricing
Running
EN/ES
Book a call

[LEGAL]

Privacy Policy

Last Updated: June 19, 2026Effective Date: June 19, 2026

This Privacy Policy explains how Zonder Solutions S.L. ("Vendian", "we", "us") collects, uses, shares, stores, and protects personal data when you use our website and our managed automation services.

We apply privacy-by-design principles and process personal data only for defined lawful purposes, with safeguards proportionate to risk and to the maximum extent required by applicable law.

1. Controller identity and contact

Data controller for covered processing activities:

  • Entity: Zonder Solutions S.L. (operating as Vendian)
  • Registered office: Carrer Magarola 36, Sant Cugat del Vallés, Spain
  • Contact email: [email protected]

2. Scope and applicability

This Policy applies to personal data processed in connection with our website, scoping and onboarding, the operation of managed automation Modules within a client's connected systems, customer support, billing, and related professional services.

When we operate a Module on a client's behalf, we typically act as a processor for the personal data within that client's connected systems; the client's instructions and a data processing agreement also apply to that processing.

3. Categories of data collected

  • Contact and enquiry data (business email and the message you submit through our contact form, and details you share on a scoping or discovery call).
  • Client and identity data (names, business emails, roles, and organization details of client contacts and authorized users).
  • Billing and commercial data (subscription and order details, invoice records, payment status, tax identifiers where required).
  • Operational data from delivering Modules (run logs, status, and Outputs produced while operating a Module within the client's connected systems).
  • Support and communications data (tickets, emails, meeting and review records).
  • Integration and credential metadata (service identifiers, token metadata, and scope information for the connected systems we operate on the client's behalf).
  • Website interaction and cookie-related data (preferences, analytics identifiers, and consent signals).

4. Sources of data

  • Directly from you, your organization, or your authorized users, including via our contact form and scoping or discovery calls.
  • From the connected third-party systems a client authorizes us to operate.
  • From payment and accounting providers.
  • From automatic logging and telemetry generated while delivering and operating the services.

5. Purposes of processing

  • Respond to contact-form enquiries and scope potential engagements.
  • Scope, build, operate, monitor, and maintain managed automation Modules within a client's connected systems.
  • Authenticate authorized users and enforce security controls, including preview → confirm review of sensitive actions.
  • Manage subscriptions, billing, invoicing, and payment administration.
  • Provide onboarding, implementation, and customer support.
  • Prevent abuse, detect incidents, investigate misuse, and enforce legal terms.
  • Improve service reliability, performance, and quality.
  • Comply with legal obligations and respond to lawful requests.

6. Legal bases (GDPR/UK GDPR mapping)

  • Performance of contract: to provide the requested services and administer engagements.
  • Legitimate interests: to respond to enquiries, secure the services, prevent abuse, and improve quality.
  • Consent: where required, such as non-essential cookies or specific marketing communications.
  • Legal obligation: for compliance, accounting, tax, sanctions, and lawful disclosure duties.

7. AI processing disclosure

Our services use AI to help build and operate Modules, for example to classify data, generate drafts, summarize content, and support automated workflows.

AI-generated Outputs may contain errors or uncertainty. Sensitive actions run on a preview → confirm basis with a named human accountable, and clients remain responsible for appropriate review of outcomes.

8. AI improvement and training (de-identified/aggregated only)

We do not use identifiable client content for broad AI model training by default.

We may use de-identified and aggregated usage signals, telemetry, and performance metadata to improve service quality, security, and reliability, to the maximum extent permitted by applicable law.

9. Sharing and recipients (processors, subprocessors, legal disclosures)

We share personal data only where necessary to provide the services, protect legitimate interests, or comply with legal obligations.

  • Infrastructure and cloud hosting providers (including our website host, Vercel).
  • Product analytics providers used on our website (Vercel Web Analytics and Speed Insights), only where you have consented.
  • Payment, invoicing, and accounting service providers.
  • Communication, support, and incident management tools.
  • The connected third-party systems a client authorizes us to operate, as needed to deliver the Module.
  • Professional advisers (legal, financial, compliance) under confidentiality obligations.
  • Authorities and courts where required by law or to protect rights and safety.

10. International transfers (EU-first, SCC fallback, safeguards)

We prioritize processing and storage in the EEA where operationally feasible.

When data must be transferred outside the EEA/UK, we implement appropriate safeguards such as Standard Contractual Clauses (SCCs) or equivalent lawful mechanisms, with supplementary technical and organizational controls where appropriate.

11. Retention schedule (by category)

Where data is no longer needed, we delete, anonymize, or securely isolate it according to our retention and deletion controls.

  • Contact and enquiry data: retained to follow up and for a limited period thereafter, unless you ask us to delete it.
  • Client and account data: retained while the engagement is active and for a limited post-termination period required for legal, audit, or dispute purposes.
  • Billing and tax records: retained for legally required retention periods.
  • Operational data within connected systems: retained per the engagement and the client's instructions or data processing agreement.
  • Security and audit logs: retained according to security policy and risk requirements.
  • Support communications: retained for service continuity, quality, and legal defensibility.
  • Cookie and analytics data: retained based on consent choices and configured retention settings.

12. Security measures (technical/organizational)

  • Encryption in transit and at rest where appropriate.
  • Access controls, least-privilege permissions, and role separation.
  • Preview → confirm review and named accountability for sensitive actions such as money movements and outbound messages.
  • Logging, monitoring, and anomaly detection for security events.
  • Secure development and change-management practices.
  • Vendor due diligence and contractual data protection commitments.

13. Incident response and breach notification

We maintain incident response processes to identify, contain, investigate, and remediate security events.

Where required by applicable law, we notify affected parties and competent authorities within legally mandated timeframes.

14. Data subject rights (GDPR + UK GDPR + CCPA-style rights with jurisdiction qualifiers)

Depending on applicable law and your location, you may have rights including access, correction, deletion, portability, restriction, objection, and withdrawal of consent.

Where we process data on behalf of a client as processor, we will direct your request to that client (the controller) where appropriate and support them in responding.

  • Right to know/access the personal data we process about you.
  • Right to request correction of inaccurate personal data.
  • Right to request deletion, subject to legal and contractual exceptions.
  • Right to data portability where applicable.
  • Right to object to or restrict processing in defined cases.
  • Right to non-discrimination for exercising privacy rights.

15. Verification process and response timelines

To protect security and prevent unauthorized disclosure, we may verify requester identity before processing rights requests.

We respond within timeframes required by applicable law and may extend where legally permitted for complex requests, with notice to the requester.

16. Cookies and similar technologies

We use a consent-first model for non-essential tracking. On first visit, analytics and performance tracking remain blocked until you choose "Accept all." If you choose "Accept none," non-essential tracking stays disabled. We do not run advertising or cross-context behavioral tracking.

You can change your choice anytime from the "Cookie settings" control in the footer. Blocking non-essential cookies may limit analytics-based improvements but does not disable core site functionality.

  • Strictly necessary cookies: required for core functionality and security.
  • Preference cookies: store interface settings and your cookie choice.
  • Analytics cookies: privacy-friendly product analytics (Vercel Web Analytics and Speed Insights) that help us measure usage and performance.

17. Do Not Sell/Share and targeted advertising

We do not sell personal data for money, and we do not use it for cross-context behavioral advertising.

Where applicable law defines certain disclosures as "sharing," you may exercise opt-out rights through available controls and by contacting [email protected].

18. Children's data (18+ service use)

Our services are intended for adults and business users. We do not knowingly collect personal data from individuals under 18 for use of the services.

If you believe underage data was provided in violation of this Policy, contact [email protected] for prompt review and removal where required.

19. Automated decision-making and profiling

We use automated systems to support routing, scoring, detection, and workflow automation as part of operating the Modules. These systems are designed to assist operations with named human accountability, not to replace legally required human judgment in sensitive contexts.

Where applicable law grants rights regarding automated decision-making, you may request review through [email protected].

20. Third-party links and services

Our website may contain links to third-party sites, and our Modules operate within clients' third-party systems. Those third parties' privacy practices are governed by their own policies and terms.

21. Complaints and supervisory authority rights

If you believe your data has been processed unlawfully, you may contact us first at [email protected] so we can investigate and resolve the issue.

You may also lodge a complaint with a competent data protection authority in your jurisdiction.

22. Policy changes and effective dates

We may update this Policy to reflect legal, technical, or operational changes. Updated versions will show a revised effective date.

Where required by applicable law, we will provide additional notice or obtain consent before material changes take effect.

23. Contact and data subject request channel ([email protected])

For privacy, data subject rights, legal notices, and compliance inquiries, contact [email protected].

Reference your organization and the email address you use with us to accelerate verification and response.

Vendian

The AI adoption partner for established firms. We work out with your leadership what AI can do, then build and run the systems that prove it.

Book a call →
Modules
AI RevOpsAI OutreachAI Finance
Company
TrainingWorkProcessAboutPricing
Legal
PrivacyTerms
© 2026 VendianWe teach. We build. We stay.