Privacy Policy
How VAISET ONE handles account data, workspace content, security information, support requests, and payment metadata.
Effective: 20 August 2026
1. Operator and roles
The service is operated by VAISET ONE project operator (details pending confirmation), address pending confirmation, country pending confirmation. Privacy contact: legal contact pending confirmation.
For account administration, security, support, and platform operations, the operator acts as controller. For personal data that a workspace customer uploads about leads, clients, candidates, students, or other contacts, the workspace owner normally decides the purpose and means of processing; the operator processes that content to provide the service.
2. Data we process
We process data that you provide, data created through use of the service, and limited technical data needed to operate and protect it.
- Account and profile data: email, password hash, locale, time zone, optional profile fields, workspace memberships and roles.
- Workspace content: records, contact details, notes, comments, statuses, events, custom fields, files, imports, exports, and integration payloads.
- Optional Telegram integration data: an encrypted customer-provided bot token, target chat identifier, bot username, notification preferences, delivery state, and safe error codes. Contact email or phone is included in a Telegram message only when the workspace manager explicitly enables that option.
- Optional phone and computer notifications: notification preferences, reminder timing, quiet hours, a browser-provided push subscription endpoint and public encryption keys, safe delivery state and error codes. Browser permission is requested only after an explicit user action. The endpoint is used only to deliver requested service notifications and is revoked when the device is disconnected or the provider reports that it is gone.
- Security and usage data: session identifiers, hashed IP information where configured, user agent, audit events, timestamps, correlation identifiers, and rate-limit counters.
- Support and communications: requests, reasons for support access, and correspondence.
- Payment and referral-program data: order identifiers, plan, amount, currency, public blockchain transaction references, confirmation state, referral rewards and commissions, payout amount and status, the destination TRON address supplied by the inviter, and provider events. We do not need and must never receive a wallet seed phrase or private key.
3. Purposes and legal grounds
We use data to create and operate accounts and workspaces, authenticate users, provide CRM functions, import and export data, deliver integrations, prevent abuse, investigate incidents, provide support, maintain backups, comply with law, and improve reliability.
Depending on the context and applicable law, processing is based on performance of a contract, steps requested before a contract, legitimate interests in operating and securing the service, consent where specifically requested, and legal obligations. Workspace customers are responsible for choosing a lawful basis for contact data they upload.
4. Sources and responsibility for CRM data
Data may come directly from account holders, workspace members, spreadsheet imports, or SUPER PREMIUM API clients. A workspace customer must have authority and a lawful basis to upload, use, and share personal data and must give required notices to the people represented in its CRM.
5. Sharing and service providers
We do not sell personal data. Data may be made available to authorized workspace members, infrastructure and security providers acting under instructions, professional advisers where necessary, or authorities when lawfully required. The current production stack uses a hosted server and self-managed application databases, cache, and object storage; the provider list must be maintained as infrastructure changes.
SUPER PREMIUM workspace managers may connect their own Telegram bot. VAISET ONE validates the bot and target chat, encrypts the token at rest, and sends only the configured notification content to Telegram. Telegram is an independent third-party service and may process messages in other countries under its own terms and privacy policy. The workspace customer is responsible for bot and chat access, recipient authorization, a lawful basis for contact data, and disabling contact details when they are unnecessary. Disconnecting deletes the stored encrypted token and cancels pending deliveries, but does not delete messages already delivered to Telegram.
6. International transfers
The service may be accessed internationally and infrastructure or support may involve more than one country. Where transfer rules apply, the operator will use an available lawful transfer mechanism and appropriate safeguards. Final transfer disclosures depend on the confirmed operator location and processor list.
7. Retention and deletion
Active account and workspace data is retained while the service is provided. Deleted CRM records are currently placed in recoverable trash for 30 days before planned purge. Sessions expire or can be revoked. Audit, security, billing, dispute, and backup data may be kept longer when reasonably necessary for security, legal obligations, fraud prevention, recovery, or claims. Backup deletion may follow a delayed rotation cycle.
A workspace owner should export required data before closing an account. Deletion requests may be limited where retention is required by law or to protect rights.
8. Security
Measures include hashed passwords, HTTP-only session cookies, role and workspace checks on the server, hashed API keys, revocation, scoped API permissions, rate limits, validation, audit logs, encrypted transport, and tested backups. No internet service can guarantee absolute security. Users must protect credentials, API keys, devices, and wallet access and must report suspected compromise promptly.
9. Cookies and device storage
The service uses essential session cookies and local device preferences such as theme. These are needed for authentication or requested interface behavior. Advertising cookies are not part of the current product. If analytics or non-essential cookies are added, the notice and consent controls must be updated before activation.
10. Rights and requests
Depending on applicable law, individuals may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent, and may complain to a competent data protection authority. Requests should be sent to the privacy contact. Identity and authority may be verified before acting. Workspace contact-data requests may need to be directed first to the relevant workspace owner.
11. Children and sensitive data
The service is intended for users able to enter a binding agreement and is not directed to children. Do not upload special-category, highly sensitive, medical, biometric, financial-account, government-identifier, or children’s data unless you have a documented lawful basis, necessary safeguards, and the service has been approved for that use.
12. Incidents, changes, and contact
We will assess suspected personal-data incidents and make notifications when legally required. This policy may change when features, providers, or laws change. Material changes will be dated and communicated through an appropriate channel. Questions and rights requests: legal contact pending confirmation.