||

Privacy Policy

Last Updated: December 19, 2024

1. Introduction

Welcome to VARDA ("we," "our," or "us"). VARDA is an AI-powered review management platform that helps businesses detect policy violations in Google Business reviews and facilitates the removal of inappropriate content.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service. By using VARDA, you agree to the collection and use of information in accordance with this policy.

We are committed to protecting your privacy and ensuring compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR) and other relevant privacy legislation.

2. Data We Collect

2.1 Google Account Information

When you sign in with Google OAuth, we collect the following information from your Google account:

  • Email address
  • Full name
  • Profile picture (if provided)
  • Google account ID (unique identifier)
  • Google OAuth access and refresh tokens (encrypted)

2.2 Business Profile Data

When you connect your Google Business Profile to VARDA, we collect:

  • Business name and legal name
  • Business address (street, city, postal code, country)
  • Phone number
  • Website URL
  • Google Business account ID and location ID
  • Business category and type

2.3 Review Data

We import and store reviews from your connected Google Business Profile:

  • Review text content
  • Star ratings (1-5)
  • Reviewer names
  • Review dates (creation and update timestamps)
  • Google review IDs
  • AI analysis results including:
    • Policy violation detection (violation types, confidence scores)
    • Sentiment analysis (positive, neutral, negative)
    • Theme extraction (service, pricing, staff, etc.)
    • Detected language

2.4 Payment Information

Payment processing is handled securely by Stripe. We collect and store:

  • Stripe customer ID
  • Payment method ID (encrypted token, not full card details)
  • Payment history and transaction records
  • Payment amounts and timestamps
  • Removal request IDs associated with payments

Important: We do not store your full credit card numbers, CVV codes, or expiration dates. All sensitive payment data is securely handled by Stripe, a PCI-DSS compliant payment processor.

2.5 Usage and Technical Data

We automatically collect certain technical information when you use VARDA:

  • IP address
  • Browser type and version
  • Device information
  • Session cookies and authentication tokens
  • Log data (access times, pages viewed)

3. How We Use Your Data

3.1 Review Analysis and Violation Detection

We use AI-powered analysis to scan your Google Business reviews for policy violations. Review text is sent to Mistral AI's API for analysis against Google's official review policies and European legal frameworks. This includes detecting spam, fake content, harassment, off-topic reviews, defamation, commercial disparagement, and other violations.

3.2 Removal Request Processing

When you request removal of a review, we generate legal arguments citing specific policy violations and facilitate the submission process to Google on your behalf. We track the status of removal requests and notify you of updates.

3.3 Billing and Payment Processing

We process payments using Stripe. Audit fees are charged immediately upon purchase. Subscription fees for ongoing monitoring and AI tools are billed monthly in advance. We maintain payment records for accounting and tax compliance purposes.

3.4 Service Communication

We use your contact information to send you updates about:

  • Removal request status changes
  • Account activity and security notifications
  • Service updates and feature announcements
  • Payment confirmations and receipts

3.5 Service Improvement

We analyze usage patterns and anonymized data to improve our AI models, enhance service quality, and develop new features. Personal identifiers are removed before analysis.

3.6 Legal Compliance

We may use your data to comply with legal obligations, respond to legal requests, enforce our Terms of Service, and protect our rights and the rights of our users.

4. Third-Party Services

4.1 Google APIs

VARDA integrates with Google's APIs to access your Business Profile and reviews:

  • Google OAuth 2.0: For secure authentication and authorization
  • Google Business Profile Management API: To fetch business account and location information
  • Google My Business API: To retrieve reviews from your connected business locations

Your data shared with Google is subject to Google's Privacy Policy. We only request the minimum permissions necessary to provide our service.

4.2 Mistral AI

We use Mistral AI's API to analyze review content:

  • Mistral Large 2: For review analysis, violation detection, and generating detailed legal arguments for removal requests
  • EU Data Residency: Mistral AI is a French company with EU data residency, ensuring GDPR compliance and better understanding of French legal frameworks

Review text is sent to Mistral AI for analysis. Mistral AI processes your data according to their data usage policies and does not use your data to train their models. As a French company, Mistral AI ensures full GDPR compliance and EU data residency.

4.3 Stripe

Stripe processes all payments securely:

  • Payment Processing: Secure credit card transactions
  • Payment Method Storage: Encrypted storage of payment method tokens
  • Invoice Generation: Automated receipt and invoice creation

Stripe is PCI-DSS Level 1 certified and handles all sensitive payment data. We only store payment method IDs and transaction records, not full card details.

4.4 Resend

Resend handles all transactional emails (account verification, removal status notifications, receipts):

  • Email Delivery: Sends transactional emails on our behalf
  • Data Processed: Email addresses, message content

4.5 Sub-Processor Summary (RGPD Art. 28)

Sub-ProcessorPurposeData LocationData Processed
Mistral AIReview analysis & AI reply generationEU (France)Review text, rating, reviewer name
StripePayment processingEU / USPayment method, billing details
ResendTransactional emailsUSEmail address, message content
Google APIsAuthentication & business dataEU / USOAuth tokens, business profile data

4.6 Data Processing Agreements

All third-party service providers are bound by data processing agreements (DPAs) that ensure they handle your data in compliance with GDPR and other applicable privacy laws. We regularly audit our third-party providers to ensure continued compliance.

5. Data Storage

5.1 Hosting Infrastructure

VARDA's application and data are hosted on Microsoft Azure cloud infrastructure. Azure provides enterprise-grade security, compliance certifications (including ISO 27001, SOC 2, GDPR compliance), and redundant data centers to ensure high availability and data protection.

5.2 Database Storage

Your data is stored in a PostgreSQL database hosted on Azure. The database is:

  • Encrypted at rest using Azure's transparent data encryption
  • Accessible only through encrypted connections (SSL/TLS)
  • Regularly backed up with point-in-time recovery capabilities
  • Protected by network security groups and firewall rules

5.3 Data Location

By default, your data is stored in Azure data centers located within the European Economic Area (EEA) to ensure GDPR compliance. If you are located outside the EEA, your data may be stored in Azure data centers in your region for performance optimization.

5.4 Security Measures

We implement multiple layers of security to protect your data:

  • Encryption in transit (HTTPS/TLS 1.3)
  • Encryption at rest (database and file storage)
  • Regular security audits and vulnerability assessments
  • Access controls and authentication (OAuth 2.0)
  • Intrusion detection and monitoring
  • Regular security patches and updates

6. Your Rights (GDPR)

Under the General Data Protection Regulation (GDPR) and other applicable privacy laws, you have the following rights regarding your personal data:

6.1 Right of Access

You have the right to request a copy of all personal data we hold about you, including account information, review data, and payment records. We will provide this information in a structured, commonly used format within 30 days of your request.

6.2 Right to Rectification

You can request correction of inaccurate or incomplete personal data. You can update most information directly through your account settings, or contact us to request corrections.

6.3 Right to Erasure ("Right to be Forgotten")

You can request deletion of your personal data when:

  • The data is no longer necessary for the original purpose
  • You withdraw your consent
  • You object to processing and there are no overriding legitimate interests
  • The data has been unlawfully processed

Note: We may retain certain data if required by law (e.g., payment records for tax compliance).

6.4 Right to Restrict Processing

You can request that we limit how we process your data in certain circumstances, such as when you contest the accuracy of data or object to processing.

6.5 Right to Data Portability

You have the right to receive your personal data in a structured, machine-readable format (JSON or CSV) and to transmit that data to another service provider.

6.6 Right to Object

You can object to processing of your personal data based on legitimate interests. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests.

6.7 Right to Withdraw Consent

Where processing is based on consent, you can withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

6.8 Right to Lodge a Complaint

You have the right to lodge a complaint with your local data protection authority if you believe we have violated your privacy rights.

How to Exercise Your Rights

To exercise any of these rights, please contact us at contact@vardaprotect.com. We will respond to your request within 30 days. Please include your account email address and a clear description of your request.

7. Cookies and Tracking Technologies

VARDA uses cookies and similar tracking technologies to provide and improve our service:

7.1 Essential Cookies

These cookies are necessary for the service to function:

  • Session Cookies: Maintain your login session and authentication state
  • Security Cookies: Protect against cross-site request forgery (CSRF) attacks
  • Preference Cookies: Remember your language and display preferences

These cookies cannot be disabled as they are essential for service functionality.

7.2 Analytics Cookies

We use analytics cookies to understand how users interact with our service, identify issues, and improve performance. These cookies collect anonymized usage data.

7.3 Cookie Management

You can control cookies through your browser settings. However, disabling essential cookies may limit your ability to use certain features of VARDA. Most browsers allow you to:

  • View and delete cookies
  • Block cookies from specific sites
  • Block all cookies
  • Set preferences for when cookies are set

8. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

8.1 Account Data

We retain your account information (email, name, Google account data) for as long as your account is active. If you delete your account, we will delete or anonymize your personal data within 30 days, except where retention is required by law.

8.2 Review Data

Review data is retained while your account is active and your Google Business Profile remains connected. If you disconnect your business profile, we will delete associated review data within 90 days, unless you have active removal requests.

8.3 Payment Records

Payment records and transaction data are retained for 7 years from the date of transaction as required by tax and accounting laws. This includes invoices, receipts, and payment method tokens.

8.4 Removal Request Records

Records of removal requests are retained for 3 years after resolution to maintain service history and handle potential disputes. After this period, records are anonymized or deleted.

8.5 Deletion Requests

Upon receiving a valid deletion request, we will delete your personal data within 30 days, except where retention is required by law. Some data may be retained in anonymized form for analytics and service improvement.

9. Contact Information

If you have questions, concerns, or wish to exercise your privacy rights, please contact us:

General Privacy Inquiries

contact@vardaprotect.com

Data Protection Officer (DPO)

contact@vardaprotect.com

For GDPR-related inquiries and data subject requests

Support and Account Issues

contact@vardaprotect.com

Response Time

We aim to respond to all privacy-related inquiries within 30 days as required by GDPR. For urgent matters, please mark your email as "URGENT" in the subject line.

10. Updates to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will:

  • Update the "Last Updated" date at the top of this page
  • Notify you of material changes via email to your registered email address
  • Display a prominent notice on our website for significant changes
  • Provide a summary of changes in the notification

Your continued use of VARDA after changes become effective constitutes your acceptance of the updated Privacy Policy. If you do not agree with the changes, you may delete your account and discontinue use of the service.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

Additional Information

Data Controller: VARDA is the data controller responsible for your personal data. Our registered address and contact information are available upon request.

Legal Basis: We process your personal data based on: contract performance (service provision), consent (Google Business Profile connection), and legitimate interests (service improvement, fraud prevention).

International Transfers: Your data may be transferred to and processed in countries outside the EEA. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) and adequacy decisions where applicable.