Legal

Privacy policy.

How COLVO, a product of VLN Technologies, processes personal data — what we collect, why, for how long, who sees it, and your rights under the GDPR.

At a glance
Controller
VLN Technologies · Italy
Updated
26 September 2026
Selling data
Never — and not shared with advertisers
Your rights
Access · rectify · erase · port · object

Last updated 26 September 2026 · Applies to colvo.app, the COLVO console and API.

1. Who is responsible

The data controller for colvo.app and for account data in the COLVO service is:

VLN Technologies, Italy (“VLN”, “we”). Website: https://vln-network.it/. Contact: [email protected].

For personal data your organisation puts through COLVO (end-customer records inside mandates, operations, scenarios and evidence), your organisation is the controller and VLN is the processor under a Data Processing Agreement (Article 28 GDPR). Privacy questions: [email protected].

2. What we collect and why

2.1 Website visitors

  • Server logs — IP address, user agent, requested page, time. Purpose: security and operating the site. Legal basis: legitimate interest (Art. 6(1)(f)). Retention: 30 days.
  • Forms (early access, contact, demo) — name, work email, company, your message, the IP address you submitted from and the approximate location derived from it (city, region, country, timezone — from our network edge or an IP-lookup service), and a bot-protection result. Purpose: answering you, provisioning access, scheduling demos and preventing abuse. Legal basis: pre-contractual steps (Art. 6(1)(b)) and legitimate interest in preventing abuse. Retention: until handled plus 24 months, or on request.
  • Bot protection — Cloudflare Turnstile, when enabled, processes a challenge token and connection data. See Cloudflare’s privacy notice. We store only the outcome.
  • Page views — our own cookieless counter records the page, the referring site, campaign (UTM) tags, country and city from our network edge, device type and browser. It does not store your IP address: a keyed, non-reversible hash of IP and browser is kept to count unique visitors. Requests with Do-Not-Track or Global Privacy Control are not counted. Legal basis: legitimate interest (Art. 6(1)(f)). Retention: 13 months.
  • Analytics — Google Analytics is used only if enabled for the deployment, with IP anonymisation. No advertising cookies. We do not track signed-in staff.

2.2 Account holders (console users)

  • Account — name, email, hashed password or magic-link tokens, organisation membership and role, platform role. Basis: contract (Art. 6(1)(b)). Retention: life of the account plus 30 days.
  • Activity log — sign-ins, key and role changes, plan changes, decisions, with a hashed IP. Purpose: security and accountability. Basis: legitimate interest and, for paying organisations, contract. Retention: 24 months.
  • Billing — when subscriptions are enabled, payment is processed by Stripe; we store the customer id, plan, invoices and status, never card numbers.
  • Support — what you send us. Retention: 24 months after the last exchange.

2.3 Data processed on behalf of your organisation

Mandates, connections, operations, approvals, scenarios, test runs, evidence, guardrail hits, incidents and exports may contain your end customers’ identifiers, emails, subscription and payment references and conversation text. We process this only on your instructions to provide the service: to evaluate proposals against mandates, to execute allowed actions through your provider connection, to verify results and to produce the reports you request. Testing uses simulated data by default. Guardrails can redact personal data in inputs and outputs before it reaches a model or the logs.

3. AI providers

Deterministic checks decide every verdict and need no AI. Where you enable AI features (semantic judge, guardrail judges, Test Architect, red team), the relevant text is sent to the provider you configured: your own OpenAI or Anthropic account (BYOK), or the managed gateway operated through withConflux with COLVO’s own key. We meter every call (tokens, model, cost) and never send provider secrets, API keys or full evidence records to a model.

4. Who sees the data (recipients and processors)

  • Hosting — the infrastructure provider running the COLVO deployment (EU region where available).
  • Resend — transactional email (invites, alerts, reports).
  • Cloudflare — Turnstile bot protection, when enabled.
  • Stripe — as your provider when you connect an account under Guard, and as our billing processor when subscriptions are enabled.
  • OpenAI, Anthropic, withConflux — only for AI features you enable, as described above.
  • Google — analytics, only if enabled for the deployment.
  • IP-lookup services (ipwho.is, ip-api.com) — receive the IP address of an early-access or demo request once, to return its approximate location.

VLN staff with the superadmin role can access account and organisation data to operate the service; every such access path is logged. We do not sell personal data and we do not share it with advertisers.

5. International transfers

Some processors are established outside the EEA. Transfers rely on adequacy decisions or the EU Standard Contractual Clauses, with supplementary measures where needed. The current list of sub-processors and their locations is available on request.

6. Retention

Test artefacts (sandbox worlds, attempt data) are deleted by an automated 30-day retention job. Evidence and usage records are append-only for the life of the organisation and deleted with it. Account data as stated above. Backups expire within 35 days.

7. Security

Row-level tenant isolation in the database, encrypted secrets, an egress allowlist, append-only evidence, hashed API keys and exclusive administrator roles. Details on the security page. Report a vulnerability to [email protected].

8. Your rights

Under the GDPR you may request access, rectification, erasure, restriction, portability and object to processing based on legitimate interest, and withdraw consent where processing relies on it. Write to [email protected]; we answer within one month. You may lodge a complaint with the Italian supervisory authority (Garante per la protezione dei dati personali) or your local authority. If you are an end customer of one of our clients, please contact that organisation first; we will assist them.

9. Cookies

The console uses a strictly necessary session cookie and an organisation-selection cookie. The marketing site sets no cookies — our page-view counter is cookieless — unless Google Analytics is enabled, in which case a consent-free, IP-anonymised configuration is used. No third-party advertising cookies.

10. Children

COLVO is a business tool and is not directed at children under 16. We do not knowingly collect their data.

11. Changes

We will post changes here and, for material changes affecting account holders, notify organisation owners by email before they take effect.

Privacy policy — how COLVO handles personal data · COLVO