Legal
Privacy Policy.
We build digital systems for businesses, and we hold our own to the same standard. This policy explains what personal data we collect across vantelyx.dev and Vantelyx Studio, why we collect it, who processes it and the rights you have over it.
Last updated ·
On this page
At a glance
- No analytics, advertising or tracking. The website runs no analytics tools, advertising pixels, session recording or social-media trackers.
- We collect what the service needs. That covers details you give us, records of the work we do together, and technical data needed to run and secure the site.
- We never sell your data. We share it only with the service providers listed below, who process it on our behalf.
- You stay in control. You can export your Studio data yourself, and ask us to correct or delete it at any time.
Who we are
This policy is issued by Vantelyx Technologies Private Limited(“Vantelyx”, “we”, “us”), a company registered in Nepal under registration no. 400359/83/84, with its registered office at Kathmandu Metropolitan City, Ward No. 12, Bagmati Province, Nepal. We decide how and why personal data is processed, so for data-protection purposes we are the controller (the “data fiduciary” under India’s DPDP Act).
It covers:
- the public website at vantelyx.dev, including the free Digital Growth Audit;
- Vantelyx Studio, the signed-in client workspace at /studio;
- our emails and WhatsApp conversations about your projects.
It does not cover the websites and systems we build for clients. For those, we act on the client’s instructions and the client’s own privacy notice applies.
Information we collect
When you browse the website
Our hosting provider records standard server logs: IP address, browser user agent, the page requested and the time. We use them only to operate and secure the service. We also work out your approximate country from your IP address so we can show prices in a suitable currency. That country is saved to your workspace only if you start a project. No analytics profile is built.
When you use the Digital Growth Audit
We collect:
- the website address you submit;
- if you are not signed in, the email address the report should go to;
- the resulting scan scores and findings.
The scan fetches your public website and asks Google PageSpeed Insights to analyse it. Anonymous audits are protected by Cloudflare Turnstile, a bot check that processes your IP address and browser signals. To prevent abuse we keep a shortened, one-way hash of your IP address for about 24 hours.
When you contact us
If you email us or send an enquiry, we keep what you send: your name, email address, company, the service you are interested in, your budget and your message. We use it to reply and to follow up on your enquiry.
When you create a Vantelyx Studio account
- Sign-in details. Your email address and password, or your name, email address and profile image if you sign in with Google. Supabase Auth manages passwords, and we never see them in plain text.
- Identity. Your first and last name, and a mobile number we verify with a one-time SMS code. Google Firebase Authentication sends the code and uses invisible reCAPTCHA to prevent abuse. We keep the verified number and a Firebase reference to it.
- Preferences. Language, currency, which email notifications you receive, and your light/dark theme choice.
- Team members. Email addresses of people you invite to your workspace.
When we work on a project together
- Intake details. Business details, your website address, and the intake conversation (stored as written, together with an English version and the language detected).
- Project records. Briefs, blueprints, domain searches and watchlists, quotes, approvals, change requests, project updates and any files shared through Studio.
- Quote acceptance. When you accept a quote electronically, we record your typed name, your confirmation, a fingerprint of the document, the time, and your IP address and browser user agent, as evidence of the agreement.
- Messages.Replies to project emails (received through Resend) and WhatsApp messages from a number you have verified (through Meta’s WhatsApp Business Platform) are added to your project thread.
- Billing. Invoices and payment records such as amount, method and reference. We do not collect card details on this website.
- Care, monitoring and domains. Care-plan requests, websites you ask us to monitor, and domain details. If we register a domain for you, this includes the registrant contact details the registrar requires.
- Testimonials and referrals. We store the testimonial you submit, with your name and role if you add them. We review every submission and publish it only if you ticked the box giving us permission. For referrals we record the referral code and the credits earned.
Security and accountability records
We keep an activity log of significant account and project actions, such as project submissions, messages sent, account-deletion steps and failed deliveries. It helps us keep the service secure and resolve disputes.
How we use it and why
We use personal data only for the purposes below. Where GDPR-style laws apply, the legal basis is shown for each.
- Delivering our services. We run your account, prepare proposals, deliver projects, invoice, and provide support. Basis: performing our contract with you, or steps you asked for before one.
- Security and fraud prevention. We verify phone numbers, run bot checks, enforce rate limits and keep activity logs. Basis: our legitimate interest in keeping the service safe, and legal obligations.
- Service communications. We send quotes, updates, invoices and alerts you have switched on. You can turn off non-essential email categories in Studio. Basis: contract and legitimate interests.
- Answering enquiries and audits. We reply to you and send the audit report you asked for. Basis: steps you requested, and legitimate interests.
- Legal and financial records. We keep accounting, tax and signed-agreement records. Basis: legal obligation.
- Testimonials. We publish only what you approve. Basis: your consent, which you can withdraw.
We do not send marketing emails without your permission. We do not use automated decision-making that has legal or similarly significant effects on you.
AI-assisted features
Some Studio features use large language models: the project intake conversation, follow-up questions, scope checks, blueprint drafting and help polishing a testimonial. For these features, the text you provide and relevant project details are sent to AI model providers. The requests go through OpenRouter, or directly to Anthropic. Members’ audit reports get AI commentary based only on the website scan findings.
AI features are available only to signed-in users, are rate-limited, and receive only the content needed for the task. Please don’t include sensitive personal information (such as health or financial account details) in intake conversations.
International transfers
We are based in Nepal and serve clients internationally. Several of our providers process data in other countries, including the United States and the European Union. When data leaves your country, we rely on the safeguards our providers offer, such as standard contractual clauses, and require them to protect it to the standard set out in this policy.
How long we keep it
- Account and project data is kept while your workspace is active, and deleted when we carry out a deletion request.
- Records we must keep are retained even after account deletion, but separated from your account where possible. These are signed quote records, invoices and payment records, and append-only message and activity logs. We keep them for as long as accounting, tax and legal limitation periods require.
- Enquiries and anonymous audit reports are kept for as long as needed to respond and follow up. You can ask us to delete them at any time.
- Rate-limit data (hashed IP addresses) is removed after about 24 hours.
- Phone and WhatsApp verification sessions expire after 10 minutes. Only a hash of each WhatsApp code is ever stored.
- The referral cookie expires after 7 days.
- Server logs are kept only as long as our hosting provider retains them.
How we protect it
Data is encrypted in transit. Database access is restricted with row-level security, so a workspace can see only its own records. Staff access is limited by role, and our admin area can require multi-factor authentication. WhatsApp verification codes and rate-limit keys are stored only as hashes, and we log significant actions. No system is perfectly secure. If a breach is likely to affect you, we will notify you and the relevant authorities as the law requires.
Your rights
We give the following rights to everyone, wherever you live. They reflect Nepal’s Individual Privacy Act, 2075 (2018), the EU and UK GDPR, and India’s Digital Personal Data Protection Act, 2023.
- Access and portability. Get a copy of your data. Signed-in users can download a JSON export from Studio → Account → Data & privacy.
- Correction. Update inaccurate details. Most can be edited directly in Studio.
- Deletion. Ask us to erase your data. Request it in Studio or by email. We confirm before deleting and keep only the records the law requires.
- Objection and restriction. Object to processing based on legitimate interests, or ask us to limit it.
- Withdrawing consent. Where we rely on consent, such as testimonials, you can withdraw it at any time.
- Complaint. Complain to your local data-protection authority or grievance body. We would appreciate the chance to address your concern first.
To exercise a right, email hello@vantelyx.dev from the address linked to your account. We may need to verify your identity, and we aim to respond within 30 days.
Children
Our services are for businesses and are not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.
Links to other sites
Our website links to other services, such as our Instagram, TikTok and Facebook profiles and websites we have built. These are plain links, not embedded trackers. Once you follow one, that service’s own privacy policy applies.
Changes to this policy
We will update this policy when our services or data practices change and revise the date at the top. If the changes are significant, we will tell Studio account holders by email or in Studio before they take effect.
Contact us
For any privacy question, request or complaint, contact us:
- Email: hello@vantelyx.dev
- Post: Vantelyx Technologies Private Limited, Kathmandu Metropolitan City, Ward No. 12, Bagmati Province, Nepal