How COLVO, a product of VLN Technologies, processes personal data — what we collect, why, for how long, who sees it, and your rights under the GDPR.
The data controller for colvo.app and for account data in the COLVO service is:
VLN Technologies, Italy (“VLN”, “we”). Website: https://vln-network.it/. Contact: [email protected].
For personal data your organisation puts through COLVO (end-customer records inside mandates, operations, scenarios and evidence), your organisation is the controller and VLN is the processor under a Data Processing Agreement (Article 28 GDPR). Privacy questions: [email protected].
Mandates, connections, operations, approvals, scenarios, test runs, evidence, guardrail hits, incidents and exports may contain your end customers’ identifiers, emails, subscription and payment references and conversation text. We process this only on your instructions to provide the service: to evaluate proposals against mandates, to execute allowed actions through your provider connection, to verify results and to produce the reports you request. Testing uses simulated data by default. Guardrails can redact personal data in inputs and outputs before it reaches a model or the logs.
Deterministic checks decide every verdict and need no AI. Where you enable AI features (semantic judge, guardrail judges, Test Architect, red team), the relevant text is sent to the provider you configured: your own OpenAI or Anthropic account (BYOK), or the managed gateway operated through withConflux with COLVO’s own key. We meter every call (tokens, model, cost) and never send provider secrets, API keys or full evidence records to a model.
VLN staff with the superadmin role can access account and organisation data to operate the service; every such access path is logged. We do not sell personal data and we do not share it with advertisers.
Some processors are established outside the EEA. Transfers rely on adequacy decisions or the EU Standard Contractual Clauses, with supplementary measures where needed. The current list of sub-processors and their locations is available on request.
Test artefacts (sandbox worlds, attempt data) are deleted by an automated 30-day retention job. Evidence and usage records are append-only for the life of the organisation and deleted with it. Account data as stated above. Backups expire within 35 days.
Row-level tenant isolation in the database, encrypted secrets, an egress allowlist, append-only evidence, hashed API keys and exclusive administrator roles. Details on the security page. Report a vulnerability to [email protected].
Under the GDPR you may request access, rectification, erasure, restriction, portability and object to processing based on legitimate interest, and withdraw consent where processing relies on it. Write to [email protected]; we answer within one month. You may lodge a complaint with the Italian supervisory authority (Garante per la protezione dei dati personali) or your local authority. If you are an end customer of one of our clients, please contact that organisation first; we will assist them.
The console uses a strictly necessary session cookie and an organisation-selection cookie. The marketing site sets no cookies — our page-view counter is cookieless — unless Google Analytics is enabled, in which case a consent-free, IP-anonymised configuration is used. No third-party advertising cookies.
COLVO is a business tool and is not directed at children under 16. We do not knowingly collect their data.
We will post changes here and, for material changes affecting account holders, notify organisation owners by email before they take effect.