Privacy Policy
Last updated: June 25, 2026
This Privacy Policy explains how Tnorx Solutions Ltd. (“ventrolic”, “we”, “us”) collects, uses, discloses, and protects information in connection with the ventrolic AI governance and cost-control service (the “Service”), our website at ventrolic.com, and the product at app.ventrolic.com.
1. Our roles: controller and processor
We act in two capacities depending on the data:
- Controller — for the account and website data we collect to run our business (e.g. your name, work email, and how you use the Service).
- Processor — for the data your organization connects to the Service (your AI provider billing/usage, cloud audit logs, and identity/OAuth metadata). Your organization is the controller of that data; we process it on your instructions under our Data Processing Addendum.
2. Information we collect
Account & profile
When you register or are invited: your name, work email, organization name, role, and a securely hashed password. We do not store plaintext passwords.
Connected service data (you authorize)
To deliver the Service, you connect read-only credentials for third-party systems. We then ingest and normalize:
- AI provider cost & usage — spend, projects, models, and usage metrics from providers you connect (e.g. OpenAI, Anthropic, Azure OpenAI, AWS Bedrock, Google Vertex).
- API key & account metadata — key labels, owners, status, and last-used signals (not the content of your AI prompts or completions).
- Cloud audit activity — AI-related events from logs you connect (e.g. AWS CloudTrail) used to detect unsanctioned AI usage.
- Identity / OAuth metadata — where you connect an identity provider, the third-party application grants and scopes used to surface shadow-AI findings.
- Connector credentials — the secrets you provide are encrypted and stored only to operate the connector (see Security).
ventrolic is a read-only, metadata-level tool. We do not sit inline with your AI traffic and do not collect the contents of prompts, responses, or end-user payloads.
Usage & technical data
Standard server logs (IP address, timestamps, request paths, user agent) and a single essential session cookie used to keep you signed in. We do not use advertising or cross-site tracking cookies.
3. How we use information
- Provide, operate, secure, and improve the Service.
- Authenticate users and enforce role-based access.
- Generate cost allocation, budgets, alerts, and shadow-AI findings.
- Send transactional email (verification, password reset, invitations, alerts).
- Respond to support and sales enquiries you submit.
- Comply with legal obligations and enforce our terms.
4. Legal bases (EEA/UK)
Where GDPR/UK GDPR applies, we rely on: performance of a contract (providing the Service), legitimate interests (securing and improving the Service), consent (where required), and legal obligation. For connected service data we process as a processor on your controller’s documented instructions.
5. How we share information
We do not sell personal data. We share it only with:
- Sub-processors who help us run the Service (see Section 6), under contract and confidentiality obligations.
- Legal & safety recipients where required by law, or to protect rights, safety, and the integrity of the Service.
- Corporate transactions — in connection with a merger, acquisition, or asset sale, subject to this Policy.
6. Sub-processors
We host the Service on Amazon Web Services and use AWS managed services as sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (compute, RDS database, Secrets Manager, KMS) | Hosting, database, encrypted secrets storage | US (us-west-2) |
| Amazon SES | Transactional & notification email | US (us-west-2) |
| Resend | Transactional email delivery | US |
We maintain a current list of sub-processors and will provide reasonable notice of changes to customers under the DPA.
7. Security
- Encryption in transit (TLS) and at rest.
- Connector credentials encrypted with AES-256-GCM; infrastructure secrets held in AWS Secrets Manager with KMS.
- Role-based access control, tenant data isolation, and least-privilege IAM.
- Private networking for the database; no public database exposure.
No method of transmission or storage is perfectly secure, but we work to protect your data using industry-standard measures.
8. Data retention & deletion
We retain account data for as long as your account is active and as needed to provide the Service. Connected service data is retained per your configuration and deleted on request or following account termination, subject to legal retention requirements. You can disconnect a connector at any time to stop further ingestion.
9. International transfers
The Service is hosted in the United States. If you access it from outside the US, your information may be transferred to and processed in the US. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (see the DPA).
10. Your rights
Depending on your location (e.g. EEA/UK GDPR, California CCPA/CPRA), you may have rights to access, correct, delete, port, or restrict processing of your personal data, and to object or withdraw consent. To exercise these rights, contact us at the address below. If your data was provided to us by a customer (controller), we will refer your request to that customer.
11. Children
The Service is a business tool not directed to individuals under 16, and we do not knowingly collect their personal data.
12. Changes to this Policy
We may update this Policy from time to time. Material changes will be posted here with an updated “Last updated” date.
13. Contact
Questions or requests: privacy@ventrolic.com. If you are in the EEA/UK and we are required to have a representative, contact details will be provided here.