Privacy Policy
Last Updated: February 19, 2026
Table of Contents
1. Introduction
Vessel Tech Inc. ("VXL," "we," "us," or "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the VXL platform and related services (the "Service").
This policy complies with the European Union's General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.
By using our Service, you consent to the data practices described in this policy. If you do not agree with this policy, please do not use the Service.
2. Data Controller
For the purposes of GDPR and other data protection laws, the data controller is:
For privacy-related inquiries, data subject requests, or concerns about how we handle your data, please contact us at the email address above.
3. Data We Collect
We collect several types of information to provide and improve our Service:
3.1 Information You Provide Directly
- Account Information: Name, email address, phone number, company name, job title, billing address
- Authentication Data: Login credentials, OAuth tokens (Google, GitHub)
- Payment Information: Credit card details, billing information (processed by third-party payment providers)
- Configuration Data: Call scripts, greetings, business hours, routing preferences, CRM integration settings
- Support Communications: Messages sent to our support team, feedback, and survey responses
3.2 Information Collected Automatically
- Usage Data: Pages visited, features used, time spent on platform, click patterns, search queries
- Device Information: IP address, browser type and version, operating system, device identifiers
- Log Data: Access times, error logs, API requests, system diagnostics
- Cookies & Tracking Technologies: Session cookies, preference cookies, analytics cookies (see Section 10)
3.3 Call & Conversation Data
- Call Recordings: Audio recordings of calls handled by AI agents (when legally permitted and disclosed)
- Transcripts: Text transcriptions of voice conversations
- Call Metadata: Phone numbers, call duration, timestamps, outcomes, routing information
- Lead Information: Customer names, contact details, preferences, and intent data captured during calls
3.4 Information from Third Parties
- CRM Data: Contact information, deal stages, notes synced from HubSpot or other integrated platforms
- Authentication Providers: Profile information from Auth0, Google, GitHub
- Payment Processors: Transaction confirmations and payment status
4. How We Use Your Data
We use collected data for the following purposes:
4.1 Service Delivery
- Provide, operate, and maintain the VXL platform
- Process and route phone calls through AI agents
- Integrate with your CRM and business systems
- Generate transcripts and conversation summaries
- Schedule appointments and manage calendars
4.2 Improvement & Development
- Train and improve AI models for better accuracy
- Analyze usage patterns to enhance features
- Develop new products and services
- Conduct research and analytics
4.3 Communication
- Send service announcements and updates
- Respond to support inquiries
- Provide technical assistance
- Send billing notifications and invoices
- Deliver marketing communications (with consent)
4.4 Legal & Security
- Comply with legal obligations and regulatory requirements
- Prevent fraud, abuse, and security incidents
- Enforce our Terms of Service
- Protect rights, property, and safety of VXL, users, and the public
- Respond to legal requests and court orders
5. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), UK, and Switzerland, we process personal data based on the following legal grounds:
Contract Performance
Processing necessary to fulfill our contractual obligations to provide the Service (GDPR Article 6(1)(b))
Legitimate Interests
Processing necessary for our legitimate business interests, such as improving the Service, preventing fraud, and ensuring security (GDPR Article 6(1)(f))
Consent
Processing based on your explicit consent, which you may withdraw at any time (GDPR Article 6(1)(a))
Legal Obligations
Processing required to comply with applicable laws and regulations (GDPR Article 6(1)(c))
7. Data Storage & Security
7.1 Where We Store Data
Your data is stored on secure servers provided by Amazon Web Services (AWS) and Vercel, primarily located in the United States. We implement industry-standard security measures to protect your information.
7.2 Security Measures
We protect your data using multiple layers of security:
- Encryption: Data in transit is encrypted using TLS 1.3. Data at rest is encrypted using AES-256.
- Access Controls: Role-based access control (RBAC) limits data access to authorized personnel only.
- Authentication: Multi-factor authentication (MFA) for administrative access.
- Monitoring: Continuous monitoring for security threats and anomalous behavior.
- Auditing: Regular security audits and penetration testing.
- Compliance: Adherence to SOC 2 Type II standards and best practices.
7.3 No Absolute Security
While we implement robust security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security but continuously work to protect your data using industry best practices.
7.4 Breach Notification
In the event of a data breach that affects your personal information, we will notify you within 72 hours of becoming aware of the breach, as required by GDPR and other applicable laws. Notifications will include the nature of the breach, affected data, and steps we're taking to address it.
8. Data Retention
We retain your data for as long as necessary to provide the Service and fulfill the purposes outlined in this policy:
- Account Data: Retained while your account is active and for 90 days after account closure (unless deletion is requested earlier).
- Call Recordings & Transcripts: Retained for 12 months by default, configurable by customer settings (minimum 30 days, maximum 7 years).
- Usage Logs: Retained for 13 months for analytics and troubleshooting purposes.
- Billing Records: Retained for 7 years to comply with tax and accounting regulations.
- Support Communications: Retained for 3 years to maintain service quality and resolve disputes.
You may request earlier deletion of your data at any time by contacting privacy@vessel.nyc. Note that we may retain certain data to comply with legal obligations or legitimate business purposes.
9. Your Privacy Rights
Depending on your location, you have the following rights regarding your personal data:
Right to Access
Request a copy of the personal data we hold about you.
Right to Rectification
Correct inaccurate or incomplete personal data.
Right to Erasure ("Right to be Forgotten")
Request deletion of your personal data, subject to legal retention requirements.
Right to Restrict Processing
Limit how we use your data in certain circumstances.
Right to Data Portability
Receive your data in a structured, machine-readable format and transfer it to another service.
Right to Object
Object to processing based on legitimate interests or for direct marketing purposes.
Right to Withdraw Consent
Withdraw consent for data processing that was based on your consent.
How to Exercise Your Rights
To exercise any of these rights, please contact us at privacy@vessel.nyc with your request. We will respond within 30 days (or as required by applicable law). We may need to verify your identity before processing your request.
You also have the right to lodge a complaint with a supervisory authority if you believe we have violated your data protection rights.
11. California Privacy Rights (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights:
CCPA Rights
- Right to Know: Request disclosure of the categories and specific pieces of personal information we've collected about you.
- Right to Delete: Request deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out: Opt out of the "sale" of personal information (note: we do not sell personal information).
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
Categories of Personal Information Collected
In the past 12 months, we have collected the following categories under CCPA:
- Identifiers (name, email, phone, IP address)
- Commercial information (purchase history, subscriptions)
- Internet activity (browsing history, usage data)
- Audio/visual information (call recordings)
- Professional information (company name, job title)
We Do Not Sell Personal Information
VXL does not sell personal information as defined by the CCPA. We do not exchange personal information for monetary consideration with third parties.
Exercising CCPA Rights
To exercise your CCPA rights, contact us at privacy@vessel.nyc or call 929-599-6360. We will verify your identity and respond within 45 days.
12. International Data Transfers
If you access the Service from outside the United States, your data may be transferred to, stored in, and processed in the United States and other countries where our service providers operate.
For users in the EEA, UK, and Switzerland, we ensure adequate protection through:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions for specific jurisdictions
- Data Processing Agreements with all third-party processors
- Technical and organizational security measures
By using the Service, you consent to the transfer of your data as described in this policy.
13. Children's Privacy
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information promptly.
If you believe we have collected information from a child, please contact us immediately at privacy@vessel.nyc.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
When we make material changes, we will:
- Update the "Last Updated" date at the top of this policy
- Send you an email notification (if you have an account)
- Display a prominent notice on our website or within the Service
- In some cases, request your explicit consent to the changes
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Vessel Tech Inc.
Privacy Team: privacy@vessel.nyc
Support: support@vessel.nyc
Legal: legal@vessel.nyc
Website: vessel.nyc
We are committed to working with you to resolve any privacy concerns. We typically respond to privacy inquiries within 5 business days.
Compliance Statement: This Privacy Policy is designed to comply with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws. VXL is committed to transparency, accountability, and respecting your privacy rights. This policy should be reviewed by qualified legal counsel to ensure it meets your organization's specific compliance requirements before you use our Service.