Legal
Compliance
We state our compliance posture plainly. For the full data-flow and security details, see /security.
Certification status01
Content pendingSOC 2 / GDPR / CCPA / HIPAA status — pending the honest answer
State the true status for each framework (e.g. “SOC 2 in progress, expected [date]” or “not yet”). Claiming compliance you don't have loses everything in diligence.
Data-processing principles02
- Data minimization — we only collect and process data necessary to provide the Service
- Purpose limitation — your data is used exclusively for delivering analytics and visualizations
- Storage limitation — data is retained only as long as needed and deleted promptly upon request
- Integrity & confidentiality — all data is encrypted in transit and at rest
- Accountability — we maintain detailed logs of data processing activities
Subprocessors03
We use a limited number of subprocessors to deliver the Service. All are bound by data processing agreements and regularly assessed.
| Provider | Purpose | Location |
|---|---|---|
| AWS | Cloud infrastructure | US / EU |
| Supabase | Database & authentication | US |
| Resend | Transactional email | US |
| Razorpay | Payment processing | India |
LLM providers that receive schema metadata are named on /security (§14).
Questions04
For compliance inquiries or a Data Processing Agreement, contact compliance@vizkraft.com.