Privacy Policy
What we collect, why we have it, who else sees it, and how long it stays. Every category below corresponds to something the system actually stores.
Effective 7 September 20261Who this is about
Vectorbea provides a hosted workflow platform. For your account, we are the controller. For the data you put THROUGH a workflow — inputs, outputs, and anything a step reads — we are a processor acting on your instructions, and the Data Processing Addendum governs.
2What we collect
Account data. Your email address, your name if you give one, your workspace memberships and role, and authentication metadata — sign-in times, session tokens, password reset state. Passwords are handled by our authentication provider and we never see them.
Workflow data. The workflows you build, every version of them, the agents and tools you register, and the connections you configure.
Run data. For each run: an immutable event timeline, execution spans, node inputs and outputs, tool call requests and responses, model prompts and completions, token counts, timings, retries and errors. This is the record that makes a run debuggable, and it necessarily contains whatever your workflow processed.
Credentials. API keys and connection strings you store are encrypted at rest with AES-256-GCM, bound cryptographically to your workspace. They are never returned by the API, never written to logs, and are decrypted only in memory at the moment a step needs them.
Operational data. Request logs, error traces and usage counters, used to run the service, enforce quotas and bill accurately.
3Why we have it
To provide the service you asked for — running workflows is the whole product.
To let you debug: the run record is the reason a failure can be explained rather than guessed at.
To enforce quotas and bill accurately.
To keep the service secure and to investigate abuse.
To contact you about your account, and about material changes to these documents.
In the EEA and UK, our lawful bases are performance of a contract for the first three, and legitimate interests for security and service communications.
4Model providers see what your workflow sends them
When a workflow calls a model, the assembled prompt is sent to that model provider. The prompt contains whatever your workflow put in it — including the run's input and any data an earlier step fetched. If that includes personal data, that personal data goes to the provider.
The call is made from our infrastructure using the API key you supplied on the connection. That means you are the account holder with that provider, and their agreement with you governs how long they retain the request and whether it may be used for training. We do not override it and cannot see it.
Every provider we can reach is named on the subprocessor list, alongside what is sent to each.
6How long it is kept
Run data is retained for the window your plan grants — currently between 3 and 365 days depending on the plan and the surface — and is then deleted. Deletion means removed from the database, not hidden behind a filter; there is no flag that brings it back. The exact windows are on the pricing page.
Account data is kept while your account exists. After you close it, we delete your workspace data within 30 days, except anything we must keep for legal or accounting reasons.
7Where it is processed
Primarily in the United States, on the infrastructure named in the subprocessor list. One model provider (Mistral) is in France, and a custom model connection sends data wherever you point it. Transfers out of the EEA and UK rely on Standard Contractual Clauses where applicable.
8Your rights
Access — ask for a copy of what we hold about you.
Correction — have inaccurate data fixed.
Deletion — have your account and its data removed.
Portability — receive your workflows and run history in a machine-readable form.
Objection and restriction, where the law provides them.
Write to susmit@vectorbea.com and we will answer within 30 days. If you are exercising a right on behalf of someone whose data went through a workflow you run, address it to your own organisation first — for that data, they are the controller and we act on their instructions.
9Security, stated honestly
Data is encrypted in transit with TLS. Connection secrets are encrypted at rest with AES-256-GCM and bound to their workspace, so a ciphertext moved between tenants fails to decrypt rather than decrypting for the wrong one. Cross-workspace access is refused at the same boundary for every resource type, and fails closed if the check itself errors. Privileged actions are recorded in an audit log.
We hold no SOC 2, ISO 27001 or equivalent certification, and no third-party security audit has been performed. Everything above describes controls we implemented; none of it has been independently verified.
10Children
The service is not for anyone under 16. We do not knowingly collect their data; tell us if you believe we have and we will delete it.
11Changes and contact
We will give at least 30 days' notice of a material change, by email to the account owner. Questions: susmit@vectorbea.com.