Skip to content
Product
AI visibilityAI referralsHumans-only analyticsWeb analyticsGoals and revenuecomingFunnelsAI analystcomingMCP serverIntegrations
PricingDocsBlog
Sign inStart free trial
ProductAI visibilityAI referralsHumans-only analyticsWeb analyticsGoals and revenuecomingFunnelsAI analystcomingMCP serverIntegrationsPricingDocsBlogSign in
Home/Legal/Privacy Policy

Legal

Privacy Policy

Last updated 13 June 2026

1. Who we are2. Two roles: controller and processor3. Data we process as a controller (account & billing)4. Data we process as a processor (website analytics)5. What we do not do6. AI-generated digests7. How long we keep data8. Sub-processors and third parties9. International transfers10. Your rights11. Security12. Children13. Changes to this policy14. Contact

Last updated: 13 June 2026 Effective date: 4 July 2026

This Privacy Policy explains how Rocket Venture Labs B.V. ("Voris", "we", "us", "our") handles personal data in connection with the Voris analytics platform at voris.ai (the "Service").

We are committed to a privacy-by-design product. Voris is built so that, in its default mode, it collects no personal data at all, no cookies, no visitor IDs, no cross-page tracking.

1. Who we are#

Legal entityRocket Venture Labs B.V.
Legal formBesloten vennootschap (private limited company)
Registered officePlantage Middenlaan 42 A, 1018 DH Amsterdam, the Netherlands
Chamber of Commerce (KVK)99793237
Establishment number (vestigingsnummer)000064841049
VAT (BTW)NL869135284B01
Privacy / legal contactlegal@voris.ai
Supportsupport@voris.ai

We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. You can reach our privacy contact at legal@voris.ai.

2. Two roles: controller and processor#

Voris handles personal data in two distinct roles, and which one applies determines who is responsible:

  • As a controller, for data about our own customers: the account holders, team members, and billing contacts who use the Voris dashboard. We decide why and how this data is processed. This Privacy Policy governs that processing.
  • As a processor, for the analytics data we collect on our customers' websites and apps on their behalf. Here, our customer is the controller: they decide what to measure and they are responsible for the lawful basis and for informing their own visitors. We only process this data on their documented instructions, under our Data Processing Agreement.

If you are a visitor to a website that uses Voris and have questions about how your data is used, the website operator (our customer) is your first point of contact. We will support them in responding to you.

3. Data we process as a controller (account & billing)#

When you create and use a Voris account, we process:

CategoryExamplesPurpose
Identity & accountEmail address, organization name, team roleCreate your account, authenticate you, manage your team
AuthenticationMagic-link login tokens, session recordsSign you in securely (we do not use passwords)
BillingPlan, subscription status, customer/subscription IDsManage your subscription
Usage & supportSettings you configure, sites you add, messages you send usOperate the Service and help you

We do not collect payment-card details. Payments are handled by Paddle, which acts as Merchant of Record (see Section 8 and the Terms of Service).

Legal bases (controller data)

  • Performance of a contract (Art. 6(1)(b) GDPR), to provide the Service you signed up for.
  • Legitimate interests (Art. 6(1)(f)), to secure, maintain, and improve the Service, and to prevent abuse. We balance these against your rights.
  • Legal obligation (Art. 6(1)(c)), to keep financial records.

4. Data we process as a processor (website analytics)#

When our customers install the Voris tracking script, we collect analytics events about their websites. What we collect depends on the privacy mode the customer has set for each site. See the privacy modes guide for the plain-English version.

What is collected in every mode

For each event we may process:

  • Page context, URL, hostname, page path, and the referring URL/hostname.
  • Marketing attribution, UTM parameters present in the URL (source, medium, campaign, content, term).
  • Device information, derived from the User-Agent string, device type (desktop / mobile / tablet), operating system, and browser.
  • Coarse location, derived from the IP address, country, region, and city. The IP address itself is never stored. It is used only to look up location at the moment of collection and is then immediately discarded.
  • Performance metrics, Core Web Vitals (LCP, INP, CLS, TTFB, FCP), if the customer enables them.
  • Custom event properties and revenue, optional values the customer chooses to send. Customers are contractually prohibited from putting personal data in custom properties, and the SDK warns about this in development.

Identity, by privacy mode

  • Mode A, Aggregated (default, and currently the only live mode). No cookies, no browser storage, no visitor or session identifiers. Events cannot be linked to an individual or across pages. In our view, Mode A data is not personal data once stored.
  • Mode B, Balanced. A short-lived visitor_id is derived server-side by hashing a daily secret salt together with the site, IP, and User-Agent. The salt is generated fresh each day and destroyed after 48 hours, after which re-identifying a visitor across days is not possible. No identifier is stored in the visitor's browser.
  • Mode C, First-party. The customer supplies their own opaque user_id (for example, for signed-in users of their product). This enables cross-session product analytics. Mode C requires the customer to have a lawful basis and to use it under our DPA.

Modes B and C are not yet generally available. This policy describes them so the data practices are transparent ahead of launch.

Legal basis (analytics data)

Our customer (the controller) is responsible for the lawful basis for analytics collected on their site. Because Mode A uses no cookies or device storage and collects no personal identifiers, it generally does not require consent under the ePrivacy/cookie rules, but the customer remains responsible for their own compliance.

Connected accounts (Google Search Console)

If a customer chooses to connect Google Search Console, we access that account's Search Console data on a read-only basis (the webmasters.readonly scope). We read the site's search-performance data, such as queries, pages, clicks, impressions, and average position, solely to correlate it with the customer's site analytics. This connection is optional, the access is read-only (we never modify the Search Console account), and the customer can disconnect it at any time from site settings or revoke it from their Google Account permissions. We do not access Gmail, Drive, or contacts, and we never sell this data or use it for advertising.

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

5. What we do not do#

  • We never store IP addresses.
  • We do not sell personal data.
  • We do not use the data to build cross-site advertising profiles.
  • We do not use third-party advertising or tracking cookies.
  • Our AI features never read raw event content, the AI digest is generated only from pre-aggregated, anonymous statistics (see Section 6).

6. AI-generated digests#

If a customer enables AI digests, we generate a weekly or daily summary of statistically significant changes in a site's analytics. To protect privacy:

  • The AI model receives only pre-aggregated, typed query results, never raw events, never custom properties, never anything that could identify a visitor.
  • Every numeric claim the model makes is cross-checked against the source data; if it cannot be verified, we fall back to a template.

The AI processing is performed by Anthropic (see Section 8).

7. How long we keep data#

DataRetention
Website analytics eventsDefault 365 days, configurable per site by the customer. A hard platform maximum of 3 years (1095 days) applies, data is automatically deleted after that at the latest.
Mode B daily salt48 hours, then permanently destroyed.
Account dataFor as long as your account is active, then deleted or anonymized within a reasonable period after closure.
External & connected-source signals (incl. Google Search Console)Follows the site's analytics retention, to a hard maximum of 2 years (730 days).
Financial records (invoices, billing)7 years, to meet Dutch tax-law retention obligations.

8. Sub-processors and third parties#

We use a small set of vetted providers to run the Service. The current list:

ProviderPurposeLocation
HostingerHosting / virtual serversEU (with safeguards as applicable)
Bunny CDNContent delivery and edge geolocation headerGlobal edge network
MaxMindGeo-IP lookup (fallback for location)United States
PaddlePayment processing, billing, tax (Merchant of Record)EU / global
ResendTransactional email (login links, digests)United States
AnthropicAI digest generation (aggregated data only)United States

A current sub-processor list for analytics data is maintained in the Data Processing Agreement.

9. International transfers#

Some sub-processors are located outside the EEA (notably MaxMind, Resend, and Anthropic in the United States). Where we transfer personal data outside the EEA, we rely on appropriate safeguards under Chapter V GDPR, primarily the European Commission's Standard Contractual Clauses, and take additional measures where needed. Note that, by design, the data sent to these providers is minimal and, in the case of analytics, typically not personal data.

10. Your rights#

If you are in the EEA/UK, you have the right to:

  • Access the personal data we hold about you;
  • Rectify inaccurate data;
  • Erase your data ("right to be forgotten");
  • Restrict or object to processing;
  • Data portability; and
  • Withdraw consent where processing is based on consent.

To exercise these rights for account data, email legal@voris.ai. For data collected on a website you visited, contact that website's operator (our customer); we will assist them.

You also have the right to lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or your local supervisory authority.

11. Security#

We protect data with industry-standard measures, including encryption in transit, strict tenant isolation (every query is scoped to the authenticated customer's data), least-privilege access, and the privacy-by-design choices described above. No system is perfectly secure, but security is a core design constraint of the platform.

12. Children#

The Service is intended for business use and is not directed at children. We do not knowingly collect personal data from children. See the eligibility clause in the Terms of Service.

13. Changes to this policy#

We may update this policy from time to time. We will post the new version here and update the "Last updated" date. For material changes, we will give reasonable notice (for example, by email or an in-app notice).

14. Contact#

Questions about this policy or your data:

Rocket Venture Labs B.V. Plantage Middenlaan 42 A, 1018 DH Amsterdam, the Netherlands legal@voris.ai

More legal documents

Terms of ServiceCookie PolicyData Processing Agreement

Privacy-first analytics for the AI-influenced web.

product

AI visibilityAI referralsHumans-only analyticsIntegrationsPricingWeb analytics

compare

vs Google Analytics 4vs Plausiblevs Simple Analytics

free tools

AI citation checkerwaitlistAgent Readiness Scorellms.txt generatorwaitlistAI crawler directory

company

AboutBlogContactStatuscoming

legal

Privacy approachPrivacy policyTermsCookiesDPA

Made in the EU. Your analytics data stays here.

We track this site with Voris and nothing else, which is rather the point.

© 2026 Voris