Vensta Logo

Privacy Policy

Effective Date: January 1, 2026 · Last Updated: January 1, 2026

Vensta ("we," "our," or "us") is committed to protecting the privacy and security of our users, clients, and visitors. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Vensta venture development operating system and related services at vensta.io (collectively, the "Services").

1. Information We Collect

1.1 Information You Provide Directly

We collect information you voluntarily provide when you register, use our platform, or contact us. This includes:

  • Full name, job title, and company or venture name
  • Email address and phone number
  • Account credentials (username and hashed password)
  • Billing and payment information (processed securely through Stripe)
  • Business plans, financial models, and other venture content you create in the platform
  • Communications with our support and sales teams

1.2 Automatically Collected Information

We automatically collect certain technical and usage data when you use our Services:

  • IP address and approximate geographic location
  • Browser type, version, and device information
  • Operating system and hardware identifiers
  • Pages visited, features used, and time spent on platform sections
  • Interaction logs and usage patterns
  • Error logs and performance metrics

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and improve the Vensta platform and its venture development tools
  • Authenticate users and maintain account security
  • Process subscription payments and manage billing cycles
  • Send transactional communications including account updates, security alerts, and invoices
  • Send marketing communications with your consent where required by law
  • Analyze usage patterns to improve platform features and user experience
  • Detect, investigate, and prevent fraudulent or unauthorized activity
  • Comply with legal obligations and enforce our Terms of Service
  • Provide customer support and respond to your inquiries

3. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area, our legal bases for processing personal data include:

  • Contract Performance: Processing necessary to deliver your subscription services
  • Legitimate Interests: Improving our Services, security monitoring, and fraud prevention
  • Legal Compliance: Meeting applicable legal and regulatory obligations
  • Consent: Where you have provided explicit consent for marketing communications

4. Information Sharing and Disclosure

We do not sell, rent, or trade your personal information. We may share it in the following limited circumstances:

  • Service Providers: Trusted third-party vendors who assist us in operating our platform (cloud hosting, payment processing, analytics, email delivery), bound by confidentiality and data processing agreements
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, subject to appropriate confidentiality protections
  • Legal Requirements: When required by law, court order, or governmental authority
  • Protection of Rights: To protect the rights, property, or safety of Vensta, our users, or others

5. Data Security

We implement enterprise-standard security measures to protect your information:

  • AES-256 encryption at rest for all stored data
  • TLS 1.3 encryption in transit for all data transmission
  • Role-based access controls and multi-factor authentication
  • Continuous security monitoring and regular penetration testing
  • SOC 2 Type II compliant infrastructure

6. Data Retention

We retain personal information for as long as necessary to provide our Services, unless a longer retention period is required by law. Account data is retained for the duration of your subscription and up to 7 years thereafter for legal and audit purposes. Venture content (business plans, models) is retained per your account settings and deleted within 30 days of account closure upon request.

7. Your Privacy Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete information
  • Request deletion of your personal information (right to erasure)
  • Restrict or object to certain processing activities
  • Receive your data in a portable format
  • Withdraw consent at any time where processing is consent-based
  • Lodge a complaint with your local data protection authority

To exercise these rights, contact us at privacy@vensta.io.

8. Cookies

We use cookies and similar tracking technologies as described in our Cookie Policy. You can manage your cookie preferences through our cookie consent manager or your browser settings.

9. International Data Transfers

Your information may be processed in countries outside your own. We ensure appropriate safeguards for all cross-border transfers, including Standard Contractual Clauses for transfers from the European Economic Area.

10. Children's Privacy

Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, please contact us immediately.

11. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email or a prominent notice on our platform at least 30 days before taking effect. Your continued use of the Services after the effective date constitutes acceptance.

12. Contact Us

For privacy-related inquiries:

  • Privacy Officer: privacy@vensta.io
  • General: hello@vensta.io
  • Website: vensta.io