Juridiskā informācija
Privātuma politika
Pēdējoreiz atjaunināts 2026. gada 7. septembris
Šis dokuments ir publicēts angļu valodā. Saistošā ir angļu valodas versija.
1. Who is responsible
The data controller is Flowin, SIA, registration number 40203053267, Miera iela 97 - 26, Rīga, LV-1013, Latvia. For anything about your personal data, write to hello@visiaq.io.
2. What Visiaq is
Visiaq audits how well AI assistants can find, understand and describe a company from its public website. Most of what we process is information companies have already published about themselves. This policy explains the personal data we handle alongside that, and why.
3. The data we process
When you run a free audit. You give us a website address. We fetch publicly available pages of that site and store the pages we read, the facts we extract from them and the resulting report so we can show it to you and let you return to it. If the website contains personal data, for example the names and contact details of the company’s people, that data appears in the report exactly as the site publishes it. Legal basis: our legitimate interest in providing the audit you asked for (Article 6(1)(f) GDPR).
When you ask for the report by email. We store your email address to send you the report and to let you find it again. Legal basis: performance of the service you requested (Article 6(1)(b)). If you tick the separate box agreeing to hear from us, we also use your address for occasional product updates. Legal basis: your consent (Article 6(1)(a)), which you can withdraw at any time using the link in any email or by writing to us.
When you create an account. We store your name, email address and password (as a salted hash) or, if you sign in with Google, the profile Google shares (see section 4). We store the websites you track, your workspace settings, the prompts and competitors you configure, and the results of scheduled scans. Legal basis: performance of our contract with you (Article 6(1)(b)).
When you pay. Payments are handled by a payment provider; we receive confirmation of payment and billing details needed for invoicing, not your full card number. Legal basis: contract and our legal obligation to keep accounting records.
When you use the website. Our servers log requests, including IP address, browser type and the pages requested, to keep the Service secure and working. Legal basis: legitimate interest (Article 6(1)(f)). We also use Google Analytics to understand which pages and features are used; see section 7.
When you write to us. We keep the correspondence for as long as needed to deal with it.
4. Google user data and Limited Use
If you choose Sign in with Google, Google shares your basic profile with us through Google’s sign-in API: your name, email address, profile picture and a unique account identifier. That is the only Google user data Visiaq receives. We do not request access to your Gmail, Drive, Calendar or any other Google service.
We use this data only to create and secure your Visiaq account and to show you who is signed in. We do not use it:
- for advertising of any kind, targeted or otherwise;
- to sell to data brokers or any other third party;
- to develop, improve or train generalised or non-personalised artificial intelligence or machine-learning models;
- to determine credit-worthiness or for lending purposes;
- for any purpose unrelated to providing or improving Visiaq’s own features.
Google user data is stored with the same protections as the rest of your account data (section 11), is never transferred to other apps, and is deleted together with your account (section 8). You can revoke Visiaq’s access at any time from your Google account permissions, or by closing your Visiaq account.
Visiaq’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. AI providers
Paid features send questions about the audited company to third-party AI models (currently OpenAI, Anthropic and Google) and report the answers. What we send is the question, the website address and publicly available information about the company. We do not send your account details or email address. Each provider processes this under its own terms; we use their business APIs, under which submitted content is not used to train their models.
6. Who else sees the data
We use service providers that process data on our behalf and under our instructions:
- Vercel Inc. — hosting and delivery of the website and application;
- Neon Inc. — database hosting;
- Resend Inc. — sending the emails we send you;
- Google LLC — Sign in with Google (if you choose it; see section 4) and Google Analytics;
- OpenAI, Anthropic and Google — AI model queries for paid features, as described above.
Some of these providers are based in the United States. Where data leaves the EU/EEA, transfers rely on the EU–US Data Privacy Framework or the European Commission’s standard contractual clauses. We do not sell personal data and do not share it with advertisers.
We may disclose data if the law requires it, or to protect the rights, safety or property of Visiaq, our users or others.
7. Cookies and analytics
The website uses strictly necessary cookies for things like remembering your language and keeping you signed in to the application. Google Analytics is used to measure how the website is used: pages visited, how long the audit takes, and which steps are reached. It is not used to read the contents of your audit or your email address. A notice on the website explains this when you first visit. You can block analytics cookies in your browser or with the Google Analytics opt-out add-on.
8. How long we keep data
- Free audit reports and the pages fetched for them: 12 months from the last time the report is opened, after which they are deleted.
- Email addresses given to receive a report: until you unsubscribe or ask us to delete them; marketing consent records are kept for as long as the consent is active and three years after.
- Account data: for as long as your account exists, then deleted within 30 days of closure, except data we must keep for accounting (Latvian law requires invoices to be kept for 5 years).
- Server logs: 30 days.
9. Your rights
Under the GDPR you can ask us to:
- tell you what personal data we hold about you and give you a copy;
- correct data that is inaccurate;
- delete your data, where we have no overriding reason to keep it;
- restrict or object to processing based on legitimate interest;
- receive the data you gave us in a portable format;
- withdraw consent at any time, without affecting processing that happened before.
Write to hello@visiaq.io; we answer within one month. You can also complain to the Latvian Data State Inspectorate (Datu valsts inspekcija, dvi.gov.lv) or to the supervisory authority where you live.
10. If your company appears in someone else’s audit
Reports quote what a company’s own website publishes. If a report shows personal data about you that you would like removed, email us with the page address and we will remove it from the report. To keep it out of future audits, remove it from the website itself.
11. Security
Data is transmitted over TLS and stored with providers that hold recognised security certifications. Passwords are stored as salted hashes. Access to production data is limited to people who need it to operate the Service. No system is perfectly secure; if we learn of a breach affecting your data we will inform you and the authorities as the law requires.
12. Children
The Service is for businesses and is not directed at anyone under 16. We do not knowingly collect their data.
13. Changes
We may update this policy. The date at the top shows the current version; account holders are told of material changes by email or in the application.