Comment COLVO, un produit de VLN Technologies, traite les données personnelles : ce que nous collectons, pourquoi, pendant combien de temps, qui y a accès, et vos droits au titre du RGPD.
La version française de ce document est en préparation et sera publiée après relecture juridique. Le texte anglais ci-dessous fait foi.
The data controller for colvo.app and for account data in the COLVO service is:
VLN Technologies, Italy (“VLN”, “we”). Website: https://vln-network.it/. Contact: [email protected].
For personal data your organisation puts through COLVO (end-customer records inside mandates, operations, scenarios and evidence), your organisation is the controller and VLN is the processor under a Data Processing Agreement (Article 28 GDPR). Privacy questions: [email protected].
Mandates, connections, operations, approvals, scenarios, test runs, evidence, guardrail hits, incidents and exports may contain your end customers’ identifiers, emails, subscription and payment references and conversation text. We process this only on your instructions to provide the service: to evaluate proposals against mandates, to execute allowed actions through your provider connection, to verify results and to produce the reports you request. Testing uses simulated data by default. Guardrails can redact personal data in inputs and outputs before it reaches a model or the logs.
Deterministic checks decide every verdict and need no AI. Where you enable AI features (semantic judge, guardrail judges, Test Architect, red team), the relevant text is sent to the provider you configured: your own OpenAI or Anthropic account (BYOK), or — when you choose “Managed by COLVO” — COLVO’s own AI gateway, withConflux, which is operated by VLN Technologies itself (not a third party) and forwards the request to OpenAI or Anthropic under VLN’s account. We meter every call (tokens, model, cost) and never send provider secrets, API keys or full evidence records to a model.
VLN staff with the superadmin role can access account and organisation data to operate the service; every such access path is logged. We do not sell personal data and we do not share it with advertisers.
Some processors are established outside the EEA. Transfers rely on adequacy decisions or the EU Standard Contractual Clauses, with supplementary measures where needed. The current list of sub-processors and their locations is available on request.
Test artefacts (sandbox worlds, attempt data) are deleted by an automated 30-day retention job. Evidence and usage records are append-only for the life of the organisation and deleted with it. Account data as stated above. Backups expire within 35 days.
Row-level tenant isolation in the database, encrypted secrets, an egress allowlist, append-only evidence, hashed API keys and exclusive administrator roles. Details on the security page. Report a vulnerability to [email protected].
Under the GDPR you may request access, rectification, erasure, restriction, portability and object to processing based on legitimate interest, and withdraw consent where processing relies on it. Write to [email protected]; we answer within one month. You may lodge a complaint with the Italian supervisory authority (Garante per la protezione dei dati personali) or your local authority. If you are an end customer of one of our clients, please contact that organisation first; we will assist them.
The console uses strictly necessary cookies for sign-in and your language choice. Our page-view counter is cookieless. Google Analytics cookies are set only if you accept them in the cookie banner, and you can change your choice at any time. No third-party advertising cookies. The full list is in the cookie policy.
COLVO is a business tool and is not directed at children under 16. We do not knowingly collect their data.
We will post changes here and, for material changes affecting account holders, notify organisation owners by email before they take effect.