← Back to platform

Privacy Policy (UK)

Effective date: 28 July 2026
Version: 2.1 (UK production)
Controller: VETRO.AI LIMITED (Company No. 17366338; trading as VetroCheck)
Law: UK GDPR (UK General Data Protection Regulation) and the Data Protection Act 2018
Supervisory authority: Information Commissioner's Office (ICO)

1. Who we are (data controller)

VETRO.AI LIMITED
Company number: 17366338
Registered office: 128, City Road, London, EC1V 2NX, UNITED KINGDOM
VAT number: not yet issued — registration in progress

We operate an AI-assisted document and contract analysis platform for UK users. For the purposes of UK GDPR, we are the data controller for personal data processed when you use VetroCheck as an individual consumer (B2C). VetroCheck is operated by VETRO.AI LIMITED. VetroCheck is a trading name of VETRO.AI LIMITED.

We have conducted a Data Protection Impact Assessment (DPIA) for our processing of personal data using AI-powered document analysis. The DPIA is available upon request.

Privacy contact: via [email protected] (subject: Privacy enquiry)
Support: [email protected]
ICO registration number: ZC208889

Data Protection Officer: We have assessed our obligation to appoint a DPO under UK GDPR Article 37 and currently do not appoint a DPO (group processing volume and core activities assessment). Privacy enquiries should be sent to the privacy contact above. You may also contact the ICO.

2. Scope of this notice

This Privacy Policy explains how we collect, use, store, share, and protect personal data when you:

  • visit our website or use our apps;
  • create an account or sign in (email, magic link, Google, or other providers);
  • upload documents for analysis;
  • purchase unlocks via Stripe;
  • manage consents and account settings;
  • contact support.

It applies to the UK deployment of Vetro. If you access Vetro from outside the UK, different terms may apply.

3. Personal data we process

Depending on how you use Vetro, we may process:

CategoryExamples
Account dataEmail address, authentication identifiers, session tokens, account preferences
Uploaded documentsPDFs/DOCX and extracted text, which may include names, addresses, dates of birth, National Insurance numbers, financial figures, tenancy details, health information, and other identifiers
Analysis outputsStructured facts, reports, draft letters, scores, and audit metadata
Consent recordsCookie consent, preview consent, Article 9 explicit consent, early-performance consent for digital content
Payment dataTransaction IDs, billing email, payment status (processed by Stripe; we do not store full card numbers)
Technical dataIP address, browser/device metadata, security logs, error diagnostics
CommunicationsSupport emails and in-product messages

Special category data: Some documents may contain special category personal data, such as health information, family details, immigration information, or other sensitive personal data. If your document includes such data about yourself or about other people, you confirm that you have the right to share it with us for analysis. We process such data only to generate your Report and do not use it for any other purpose. We process such data only with explicit consent where required, or on another lawful Article 9 basis if applicable.

4. Purposes and lawful bases

We process personal data only where we have a lawful basis under UK GDPR Article 6 (and Article 9 where relevant):

PurposeLawful basisDetails
Account creation, authentication, paid unlock deliveryArt. 6(1)(b) — performance of a contractNecessary to provide the service you request
Free preview analysisArt. 6(1)(a) — consentYou opt in to preview processing in-product
Special category document content (e.g. health)Art. 9(2)(a) — explicit consentSeparate Art. 9 consent screen where required
Payment processingArt. 6(1)(b) contract / Art. 6(1)(c) legal obligationStripe processes payments; we retain transaction records
Security, fraud prevention, abuse detectionArt. 6(1)(f) — legitimate interestsProtecting users, platform integrity, and our systems
Service improvement and debuggingArt. 6(1)(f) — legitimate interestsMeasured diagnostics; no profiling for marketing
Legal compliance and claimsArt. 6(1)(c) / Art. 6(1)(f)Records required by law or to defend legal claims
Marketing emails (if enabled in future)Art. 6(1)(a) — consentOnly with opt-in; not currently used for cold outreach

We apply data minimisation and PII masking/redaction before sending content to AI model providers where configured.

5. AI processing and automated analysis

Vetro uses automated systems (including large language models and rules engines) to extract and structure information from documents you upload.

Important: Vetro provides information-only analysis. We do not make solely automated decisions producing legal or similarly significant effects about you within the meaning of UK GDPR Article 22. Outputs are intended to assist your review; decisions remain with you and, where appropriate, a qualified adviser.

AI outputs may be inaccurate. Do not rely on them as a substitute for professional advice.

6. Cookies and similar technologies

We use cookies and similar storage for authentication, security, and (during checkout) payment session integrity. Preference choices for the cookie banner are stored in the browser’s local storage (`vetro_cookie_consent`), not as an HTTP cookie. See our Cookie Policy (PECR) for details.

Non-essential analytics or advertising cookies are not enabled by default on the UK deployment unless you opt in where offered.

7. Recipients and sub-processors

We use carefully selected service providers (processors) who process personal data on our instructions under Article 28 UK GDPR terms:

ProviderRoleUsage statusLocationTransfer safeguards
Mistral AIPrimary AI text analysisActiveEUEU hosting; DPA in place
Stripe Payments Europe Ltd.Payment processingActiveEU (Ireland)Stripe DPA
Resend Inc.Transactional emailActiveUSADPA / UK transfer tools (in place)
Google Ireland Ltd.Google Sign-In (OAuth)ActiveEU / USAGoogle DPA; UK IDTA / SCCs where applicable
Hetzner Online GmbHHosting, database, encrypted storageActiveEU (Germany/Finland)DPA in place
Cloudflare Inc.CDN, DDoS protection, edge securityActiveGlobal / EU edgeCloudflare DPA; UK IDTA / SCCs where applicable
Google LLC (Gemini API)Fallback AI analysis (code path only)Fallback only — not currently active for UK usersUSA / EU regionTransfer tools required before any UK enablement; DPA execution pending verification
Anthropic PBCFallback AI analysis (code path only)Fallback only — not currently active for UK usersUSATransfer tools required before any UK enablement; DPA execution pending verification

Providers that are not currently in use for UK end-user document analysis are disclosed in our Data Processing Disclosure and related privacy notices.

An up-to-date processor list is published in our Data Processing Disclosure and in-product privacy settings.

We may disclose data to professional advisers, courts, regulators, or law enforcement where required by law or to protect rights and safety.

We do not sell your personal data.

8. International data transfers

Primary hosting and our preferred AI provider are located in the UK/EU. Where personal data is transferred outside the UK, we implement appropriate safeguards, including:

  • UK International Data Transfer Agreement (UK IDTA);
  • UK Addendum to EU Standard Contractual Clauses (SCCs);
  • provider Data Processing Agreements (DPAs) and supplementary measures where required by ICO guidance.

US-based AI fallbacks are not used on the UK deployment unless a compliant transfer mechanism and signed DPA are in place. See also our Data Processing Disclosure.

9. Retention

We retain personal data only as long as necessary for the purposes above:

Data typeRetention period
Preview analysis results24 hours
Paid analysis reports and outputs30 days
Consent recordsUp to 365 days (longer if required for legal claims)
Upload staging filesShort-lived (typically up to 60 minutes, then purged)
Account dataWhile your account is active and for a reasonable period thereafter
Payment recordsAs required for tax, accounting, and fraud prevention (typically up to 6–7 years where law requires)
Security logs90 days rolling retention for abuse investigation

You may request earlier deletion subject to legal exceptions (see section 10).

Backups: Backups are retained for 30 days on a rolling basis. Where you request deletion, your data is removed from live systems immediately and from backups within 30 days; restored backups are re-processed against pending deletion requests.

Account data: Account data is deleted 24 months after your last sign-in, following a reminder email.

What happens when you delete your account: When you delete your account, your personal data is removed from live systems immediately. Payment records required by law are retained for 6–7 years. Data in backups is removed within 30 days.

10. Your rights under UK GDPR

You have the following rights in relation to your personal data:

  • Right of access (Subject Access Request)
  • Right to rectification
  • Right to erasure (“right to be forgotten”) — subject to exceptions
  • Right to restriction of processing
  • Right to data portability (where applicable)
  • Right to object to processing based on legitimate interests
  • Right to withdraw consent at any time (without affecting prior lawful processing)
  • Rights related to automated decision-making — see section 5

To exercise your rights, email [email protected] with subject Privacy enquiry. We respond within one month, extendable where requests are complex.

You may lodge a complaint with the ICO:

We encourage you to contact us first so we can try to resolve your concern.

11. Security measures

We implement appropriate technical and organisational measures, including:

  • encryption in transit (TLS);
  • encrypted storage for staging uploads where configured;
  • access controls and role-based admin permissions (including least-privilege support roles where configured);
  • PII masking/redaction before AI prompts where configured;
  • logging and monitoring;
  • an incident-response process covering containment, assessment, and preparation for regulatory notification (including the UK GDPR expectation to notify the ICO without undue delay and within 72 hours where required — ICO registration number: ZC208889);
  • vendor due diligence and DPAs for sub-processors.

No method of transmission or storage is 100% secure. You use the service at your own risk regarding document sensitivity; do not upload material you are not authorised to share.

12. Third-party data in your uploads

When you upload a document for analysis, that document may contain personal data about other individuals (for example, a landlord, employer, family member, or doctor). These individuals are referred to as "third parties."

What we do:
- All names are automatically masked before processing by our AI (`[NAME_1]`, `[NAME_2]`, etc.).
- Health and medical terms are automatically redacted before AI processing (`[HEALTH-REDACTED]`).
- Third-party names remain masked in your final PDF report.
- We do not use third-party data for any purpose other than generating your requested analysis.
- We do not sell, share, or train models on third-party data.

Your responsibility:
- You must ensure you have a lawful basis for uploading documents that contain third-party data (for example, the document concerns your own legal matter).
- We do not notify third parties that their data has been processed (Article 14 UK GDPR). It is your responsibility to inform them where required by law.
- If a third party contacts us to exercise their data subject rights, we will verify their identity and handle the request in accordance with UK GDPR.

Technical measures:
- PII masking, health-data redaction, and persistent masking in output are applied to every upload regardless of any selection you make during upload.
- If you indicate that your document contains health data, we apply additional keyword-based redaction. This may limit the depth of health-related legal analysis in your report.

Your original document is stored encrypted on our own infrastructure for the retention period set out in section 9. Masking and redaction apply to the text we send to our AI provider — they do not remove data from the copy we hold. This is why we ask for your explicit consent where a document contains special category data.

Further detail on how we process data and which sub-processors we use is in our Data Processing Disclosure.

13. Children

Vetro is not directed at children under 18. We do not knowingly collect personal data from children. If you believe a child has provided data, contact us for deletion.

14. Changes to this Privacy Policy

We may update this notice when processing activities, providers, or legal requirements change. Material changes will be communicated in-product or by email where appropriate. The effective date at the top will be updated accordingly.

15. Contact

VETRO.AI LIMITED
Company number: 17366338
ICO Registration Number: ZC208889
Registered office: 128, City Road, London, EC1V 2NX, UNITED KINGDOM
Privacy: via [email protected] (subject: Privacy enquiry)
Support: [email protected]
Legal: via [email protected] (subject: Legal enquiry)

Related documents: Terms of Service · Cookie Policy · Data Processing Disclosure