Privacy and Cookie Notice
Last updated 22 September 2026
This notice explains how Vinza Ltd uses personal information when people visit VINZA.AI, answer questions, receive reports, use PromptCheck, subscribe to Clarity, contact us or interact with communications. It also explains cookies, similar technologies and individual rights.
1 Who is responsible
1.1 VINZA.AI is operated by Vinza Ltd, registered in England and Wales under company number 17366609. Our registered office is 2nd Floor College House, 17 King Edwards Road, Ruislip, London, HA4 7AE, United Kingdom. Vinza Ltd is the controller of personal information described in this notice.
1.2 Our Privacy Lead can be contacted at contact@vinza.ai. Put Privacy request in the subject line when exercising a right. You may also write to the registered office. Do not send identity documents unless we ask for proportionate information needed to verify a request.
1.3 VINZA.AI is for adults aged 18 and over. We do not knowingly provide accounts or paid products to children.
2 Information we collect
2.1 Information you provide may include name, email address, account and sign-in information; answers to Snapshot, Momentum and Advisory questions; AI platforms and tools used; goals, priorities, experience and working preferences; prompts submitted to PromptCheck; business enquiries; support and complaint messages; optional refund feedback; product feedback; and communication choices.
2.2 We create information from those inputs, including profiles, opportunity areas, classifications, tool or capability suggestions, prompts, action steps, report content, PromptCheck improvements and Clarity relevance matching. When linked to you, these outputs may be personal information.
2.3 Technical and usage information may include IP address, device and browser information, session identifiers, authentication events, pages and features used, timestamps, referral information, product and report identifiers, checkout and entitlement events, error logs, security signals, cookie choices and sharing-link activity.
2.4 Paddle collects payment-card, billing, tax, fraud and transaction information as authorised reseller and Merchant of Record. Vinza normally receives transaction references, product, amount, currency, tax or country indicators, payment and subscription status, refund state and contact information needed to provide access and support. We do not need your complete payment-card number.
2.5 Do not submit passwords, complete payment-card data, government identification numbers, private keys, credentials, detailed bank information, medical records, biometric or genetic information, criminal-offence information, legally privileged material, or unnecessary confidential or personal information about another person.
3 How and why we use information
| Purpose | Information | UK GDPR basis |
|---|---|---|
| Create and deliver outputs | Answers, prompts, profile and account information | Contract or requested pre-contract steps |
| Operate accounts and entitlements | Identity, sign-in, purchase and usage records | Contract and legitimate interests in secure operation |
| Provide PromptCheck and Clarity | Prompts, report priorities, subscription and interaction records | Contract |
| Payments and refunds | Identity, transaction, entitlement and support information | Contract, legal obligations and fraud-prevention interests |
| Support and complaints | Contact details, messages, product and transaction records | Contract, legitimate interests and legal obligations |
| Security and debugging | Device, account, content, event and log information | Legitimate interests and legal obligations |
| Improve product quality | Feedback, de-identified quality measures and limited interaction data | Legitimate interests after minimisation; consent where required |
| Measure website use | Consent-controlled cookie and event information | Consent unless a specific lawful exception applies |
| Marketing | Email address and communication choices | Explicit consent at launch |
| Legal and financial records | Transactions, consent, complaints and rights records | Legal obligations and legal claims |
3.1 Where we rely on legitimate interests, we consider necessity, reasonable expectations and the effect on individual rights. You may ask for information about a relevant balancing assessment.
3.2 We do not sell personal information or share it for cross-context behavioural advertising. Behavioural advertising and retargeting are not used at launch.
4 Artificial intelligence and personalisation
4.1 We use contracted AI systems to analyse answers and prompts and to generate or assist with personalised classifications, explanations, suggestions, prompts and reports. A report may be generated without individual human review.
4.2 VINZA.AI outputs do not determine legal rights and are not used by us to make solely automated decisions having legal or similarly significant effects concerning employment, credit, insurance, health, education or essential services.
4.3 Information needed for generation may be sent securely to a contracted model provider acting for us. Our contracts and technical settings must prevent the provider from using customer answers, prompts or outputs to train its general models. We minimise direct identifiers in model requests where practicable.
4.4 We do not use identifiable customer answers, prompts or reports to train general-purpose models. We may use aggregated or genuinely de-identified performance information, error measures and voluntarily supplied feedback to improve the Services. Any future use of identifiable customer content for model development would require a separate lawful basis, clear notice and any required consent.
5 PromptCheck sharing
5.1 PromptCheck results are private by default. A sharing link is created only when the user deliberately uses the designated sharing function.
5.2 Before sharing, the user should see the selected content and must avoid sharing personal, confidential or sensitive material without authority. The sharing page should exclude account details and unrelated report answers. Anyone with an active link may be able to view it.
5.3 We process the selected PromptCheck content, a random sharing identifier, creation and revocation records, and limited security logs to operate the sharing feature. Where offered, the user may disable the link. Shared pages should not be indexed by search engines.
6 Who receives information
6.1 We use service providers for database and authentication, hosting, AI processing, payment and tax, email delivery, support, analytics, security and error monitoring. They receive only information reasonably needed for their function and must protect it contractually where they act as processors.
6.2 Supabase supports database and related backend functions. Paddle is the authorised reseller and Merchant of Record for paid transactions. Other material providers are identified by category in this notice and in our internal provider register. We will update public information where naming a provider is legally required or materially helpful to transparency.
6.3 We may disclose information to professional advisers, auditors, insurers, courts, regulators, law-enforcement bodies or an organisation involved in a genuine corporate transaction where lawful and necessary.
7 International transfers
Some providers or authorised support personnel may process information outside the United Kingdom and, for EEA users, outside the EEA. Privacy laws in those places may differ. Where a restricted transfer requires protection, we use an adequacy decision or recognised contractual safeguards, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses or EU Standard Contractual Clauses, together with an appropriate transfer assessment and supplementary measures where needed. You may request information about the applicable safeguard.
8 Retention
| Record | Normal retention |
|---|---|
| Abandoned anonymous or unpaid assessment | Up to 30 days after last activity unless the user asks us to retain it |
| Account answers and purchased report | While the account is active, then delete or anonymise after closure or a valid request, subject to legal records |
| PromptCheck raw prompt and provider request logs | No more than 30 days unless saved as an account output or required for a security investigation |
| PromptCheck sharing link | Until disabled, the underlying output is deleted, or the account retention period ends |
| Clarity profile and briefings | For the subscription and continuing report access, then under account-closure rules |
| Transaction tax and accounting records | Six years after the relevant financial year, or longer where legally required |
| Contract acceptance complaints and disputes | Six years after the transaction or closure of the matter |
| Support records | Two years after closure unless linked to a legal claim or transaction record |
| Security logs | Normally 12 months; longer for an active investigation |
| Product analytics | Normally 14 months before deletion or irreversible aggregation |
| Marketing and consent records | Until opt-out or two years after meaningful engagement; minimal suppression record retained |
| Backups | Removed through the normal backup cycle, targeted within 90 days after live-system deletion |
Purchased reports are intended for ongoing account access, but VINZA.AI is not a permanent archive. Download any report you need to retain.
9 Your rights
Depending on applicable law, you may request access, correction, deletion, restriction or portability, or object to processing. You may withdraw consent without affecting earlier lawful processing and may object to direct marketing at any time. Email contact@vinza.ai. No special form or legal wording is required. We may request proportionate information to verify identity and authority. We normally respond within one month and may extend where law permits for a complex or numerous request, explaining why. Rights are not absolute. We may retain records required for tax, fraud prevention, legal claims or another lawful reason and may protect another person's rights when responding. You may complain to the UK Information Commissioner's Office at https://ico.org.uk. If EU GDPR applies, you may also complain to the supervisory authority where you live, work or believe an infringement occurred.
10 Security and incidents
We use measures designed for the nature of the information and risks, including access controls, encryption in transit, provider due diligence, logging, backups and incident procedures. No internet service can guarantee absolute security. If a personal-data breach is likely to create a high risk to affected people, we will notify them without undue delay where required and explain practical protective steps.
11 Marketing and service communications
At launch, promotional email is sent only where the recipient has actively opted in. Marketing consent is optional, separate from accepting legal terms and may be withdrawn at any time using the unsubscribe link or contact@vinza.ai. We may send messages necessary to operate an account or contract, including report availability, security, billing, renewal, cancellation, policy and service messages. Those messages are not promotional marketing.
12 Cookies and similar technologies
Cookies are small data files stored on or read from a browser or device. Similar technologies include local storage, pixels, SDKs, tags and identifiers. Some are necessary for security, sign-in, checkout and remembering privacy choices. Others support optional functionality, analytics or marketing.
| Category | Purpose | Launch rule |
|---|---|---|
| Strictly necessary | Security, session continuity, sign-in, checkout, fraud prevention and recording privacy choices | May operate without consent only where legally necessary |
| Functional | Remember optional preferences or provide requested optional functionality | Consent unless a specific lawful exception applies |
| Analytics | Measure visits, journeys, interactions, errors and performance | Blocked until consent at launch |
| Marketing | Advertising measurement, retargeting or advertising identifiers | Not used at launch |
12.1 On the first visit, the consent interface must provide equally clear choices to accept or reject optional technologies and offer granular settings. Rejecting optional technologies must not prevent access to Snapshot, reports or paid features.
12.2 Cookie Settings in the website footer provides the current technology names, providers, purposes, categories, first- or third-party status and lifetimes. It also allows choices to be changed. Withdrawing consent must be as easy as giving it and stops future optional storage or access.
12.3 Strictly necessary technologies may include VINZA session and security controls, authentication and Supabase technologies, Paddle checkout technologies and the consent-preference record. Exact names and durations are maintained in Cookie Settings following technical scans of the live site.
12.4 Browser controls can block or delete technologies, but blocking strictly necessary functions may prevent secure sign-in, checkout or account operation.
13 Changes to this notice
We may update this notice when processing, providers, products or law changes. We will publish the update date and give prominent or direct notice of a material change where appropriate. We will not introduce an incompatible new purpose without a lawful basis and any required notice or consent.