Privacy Policy (UK)
Effective date: 28 July 2026
Version: 2.1 (UK production)
Controller: VETRO.AI LIMITED (Company No. 17366338; trading as VetroCheck)
Law: UK GDPR (UK General Data Protection Regulation) and the Data Protection Act 2018
Supervisory authority: Information Commissioner's Office (ICO)
1. Who we are (data controller)
VETRO.AI LIMITED
Company number: 17366338
Registered office: 128, City Road, London, EC1V 2NX, UNITED KINGDOM
VAT number: not yet issued — registration in progress
We operate an AI-assisted document and contract analysis platform for UK users. For the purposes of UK GDPR, we are the data controller for personal data processed when you use VetroCheck as an individual consumer (B2C). VetroCheck is operated by VETRO.AI LIMITED. VetroCheck is a trading name of VETRO.AI LIMITED.
We have conducted a Data Protection Impact Assessment (DPIA) for our processing of personal data using AI-powered document analysis. The DPIA is available upon request.
Privacy contact: via [email protected] (subject: Privacy enquiry)
Support: [email protected]
ICO registration number: ZC208889
Data Protection Officer: We have assessed our obligation to appoint a DPO under UK GDPR Article 37 and currently do not appoint a DPO (group processing volume and core activities assessment). Privacy enquiries should be sent to the privacy contact above. You may also contact the ICO.
2. Scope of this notice
This Privacy Policy explains how we collect, use, store, share, and protect personal data when you:
- visit our website or use our apps;
- create an account or sign in (email, magic link, Google, or other providers);
- upload documents for analysis;
- purchase unlocks via Stripe;
- manage consents and account settings;
- contact support.
It applies to the UK deployment of Vetro. If you access Vetro from outside the UK, different terms may apply.
3. Personal data we process
Depending on how you use Vetro, we may process:
| Category | Examples |
|---|---|
| Account data | Email address, authentication identifiers, session tokens, account preferences |
| Uploaded documents | PDFs/DOCX and extracted text, which may include names, addresses, dates of birth, National Insurance numbers, financial figures, tenancy details, health information, and other identifiers |
| Analysis outputs | Structured facts, reports, draft letters, scores, and audit metadata |
| Consent records | Cookie consent, preview consent, Article 9 explicit consent, early-performance consent for digital content |
| Payment data | Transaction IDs, billing email, payment status (processed by Stripe; we do not store full card numbers) |
| Technical data | IP address, browser/device metadata, security logs, error diagnostics |
| Communications | Support emails and in-product messages |
Special category data: Some documents may contain special category personal data, such as health information, family details, immigration information, or other sensitive personal data. If your document includes such data about yourself or about other people, you confirm that you have the right to share it with us for analysis. We process such data only to generate your Report and do not use it for any other purpose. We process such data only with explicit consent where required, or on another lawful Article 9 basis if applicable.
4. Purposes and lawful bases
We process personal data only where we have a lawful basis under UK GDPR Article 6 (and Article 9 where relevant):
| Purpose | Lawful basis | Details |
|---|---|---|
| Account creation, authentication, paid unlock delivery | Art. 6(1)(b) — performance of a contract | Necessary to provide the service you request |
| Free preview analysis | Art. 6(1)(a) — consent | You opt in to preview processing in-product |
| Special category document content (e.g. health) | Art. 9(2)(a) — explicit consent | Separate Art. 9 consent screen where required |
| Payment processing | Art. 6(1)(b) contract / Art. 6(1)(c) legal obligation | Stripe processes payments; we retain transaction records |
| Security, fraud prevention, abuse detection | Art. 6(1)(f) — legitimate interests | Protecting users, platform integrity, and our systems |
| Service improvement and debugging | Art. 6(1)(f) — legitimate interests | Measured diagnostics; no profiling for marketing |
| Legal compliance and claims | Art. 6(1)(c) / Art. 6(1)(f) | Records required by law or to defend legal claims |
| Marketing emails (if enabled in future) | Art. 6(1)(a) — consent | Only with opt-in; not currently used for cold outreach |
We apply data minimisation and PII masking/redaction before sending content to AI model providers where configured.
5. AI processing and automated analysis
Vetro uses automated systems (including large language models and rules engines) to extract and structure information from documents you upload.
Important: Vetro provides information-only analysis. We do not make solely automated decisions producing legal or similarly significant effects about you within the meaning of UK GDPR Article 22. Outputs are intended to assist your review; decisions remain with you and, where appropriate, a qualified adviser.
AI outputs may be inaccurate. Do not rely on them as a substitute for professional advice.
6. Cookies and similar technologies
We use cookies and similar storage for authentication, security, and (during checkout) payment session integrity. Preference choices for the cookie banner are stored in the browser’s local storage (`vetro_cookie_consent`), not as an HTTP cookie. See our Cookie Policy (PECR) for details.
Non-essential analytics or advertising cookies are not enabled by default on the UK deployment unless you opt in where offered.
7. Recipients and sub-processors
We use carefully selected service providers (processors) who process personal data on our instructions under Article 28 UK GDPR terms:
| Provider | Role | Usage status | Location | Transfer safeguards |
|---|---|---|---|---|
| Mistral AI | Primary AI text analysis | Active | EU | EU hosting; DPA in place |
| Stripe Payments Europe Ltd. | Payment processing | Active | EU (Ireland) | Stripe DPA |
| Resend Inc. | Transactional email | Active | USA | DPA / UK transfer tools (in place) |
| Google Ireland Ltd. | Google Sign-In (OAuth) | Active | EU / USA | Google DPA; UK IDTA / SCCs where applicable |
| Hetzner Online GmbH | Hosting, database, encrypted storage | Active | EU (Germany/Finland) | DPA in place |
| Cloudflare Inc. | CDN, DDoS protection, edge security | Active | Global / EU edge | Cloudflare DPA; UK IDTA / SCCs where applicable |
| Google LLC (Gemini API) | Fallback AI analysis (code path only) | Fallback only — not currently active for UK users | USA / EU region | Transfer tools required before any UK enablement; DPA execution pending verification |
| Anthropic PBC | Fallback AI analysis (code path only) | Fallback only — not currently active for UK users | USA | Transfer tools required before any UK enablement; DPA execution pending verification |
Providers that are not currently in use for UK end-user document analysis are disclosed in our Data Processing Disclosure and related privacy notices.
An up-to-date processor list is published in our Data Processing Disclosure and in-product privacy settings.
We may disclose data to professional advisers, courts, regulators, or law enforcement where required by law or to protect rights and safety.
We do not sell your personal data.
8. International data transfers
Primary hosting and our preferred AI provider are located in the UK/EU. Where personal data is transferred outside the UK, we implement appropriate safeguards, including:
- UK International Data Transfer Agreement (UK IDTA);
- UK Addendum to EU Standard Contractual Clauses (SCCs);
- provider Data Processing Agreements (DPAs) and supplementary measures where required by ICO guidance.
US-based AI fallbacks are not used on the UK deployment unless a compliant transfer mechanism and signed DPA are in place. See also our Data Processing Disclosure.
9. Retention
We retain personal data only as long as necessary for the purposes above:
| Data type | Retention period |
|---|---|
| Preview analysis results | 24 hours |
| Paid analysis reports and outputs | 30 days |
| Consent records | Up to 365 days (longer if required for legal claims) |
| Upload staging files | Short-lived (typically up to 60 minutes, then purged) |
| Account data | While your account is active and for a reasonable period thereafter |
| Payment records | As required for tax, accounting, and fraud prevention (typically up to 6–7 years where law requires) |
| Security logs | 90 days rolling retention for abuse investigation |
You may request earlier deletion subject to legal exceptions (see section 10).
Backups: Backups are retained for 30 days on a rolling basis. Where you request deletion, your data is removed from live systems immediately and from backups within 30 days; restored backups are re-processed against pending deletion requests.
Account data: Account data is deleted 24 months after your last sign-in, following a reminder email.
What happens when you delete your account: When you delete your account, your personal data is removed from live systems immediately. Payment records required by law are retained for 6–7 years. Data in backups is removed within 30 days.
10. Your rights under UK GDPR
You have the following rights in relation to your personal data:
- Right of access (Subject Access Request)
- Right to rectification
- Right to erasure (“right to be forgotten”) — subject to exceptions
- Right to restriction of processing
- Right to data portability (where applicable)
- Right to object to processing based on legitimate interests
- Right to withdraw consent at any time (without affecting prior lawful processing)
- Rights related to automated decision-making — see section 5
To exercise your rights, email [email protected] with subject Privacy enquiry. We respond within one month, extendable where requests are complex.
You may lodge a complaint with the ICO:
- Website: https://ico.org.uk/
- Complaints: https://ico.org.uk/make-a-complaint/
We encourage you to contact us first so we can try to resolve your concern.
11. Security measures
We implement appropriate technical and organisational measures, including:
- encryption in transit (TLS);
- encrypted storage for staging uploads where configured;
- access controls and role-based admin permissions (including least-privilege support roles where configured);
- PII masking/redaction before AI prompts where configured;
- logging and monitoring;
- an incident-response process covering containment, assessment, and preparation for regulatory notification (including the UK GDPR expectation to notify the ICO without undue delay and within 72 hours where required — ICO registration number: ZC208889);
- vendor due diligence and DPAs for sub-processors.
No method of transmission or storage is 100% secure. You use the service at your own risk regarding document sensitivity; do not upload material you are not authorised to share.
12. Third-party data in your uploads
When you upload a document for analysis, that document may contain personal data about other individuals (for example, a landlord, employer, family member, or doctor). These individuals are referred to as "third parties."
What we do:
- All names are automatically masked before processing by our AI (`[NAME_1]`, `[NAME_2]`, etc.).
- Health and medical terms are automatically redacted before AI processing (`[HEALTH-REDACTED]`).
- Third-party names remain masked in your final PDF report.
- We do not use third-party data for any purpose other than generating your requested analysis.
- We do not sell, share, or train models on third-party data.
Your responsibility:
- You must ensure you have a lawful basis for uploading documents that contain third-party data (for example, the document concerns your own legal matter).
- We do not notify third parties that their data has been processed (Article 14 UK GDPR). It is your responsibility to inform them where required by law.
- If a third party contacts us to exercise their data subject rights, we will verify their identity and handle the request in accordance with UK GDPR.
Technical measures:
- PII masking, health-data redaction, and persistent masking in output are applied to every upload regardless of any selection you make during upload.
- If you indicate that your document contains health data, we apply additional keyword-based redaction. This may limit the depth of health-related legal analysis in your report.
Your original document is stored encrypted on our own infrastructure for the retention period set out in section 9. Masking and redaction apply to the text we send to our AI provider — they do not remove data from the copy we hold. This is why we ask for your explicit consent where a document contains special category data.
Further detail on how we process data and which sub-processors we use is in our Data Processing Disclosure.
13. Children
Vetro is not directed at children under 18. We do not knowingly collect personal data from children. If you believe a child has provided data, contact us for deletion.
14. Changes to this Privacy Policy
We may update this notice when processing activities, providers, or legal requirements change. Material changes will be communicated in-product or by email where appropriate. The effective date at the top will be updated accordingly.
15. Contact
VETRO.AI LIMITED
Company number: 17366338
ICO Registration Number: ZC208889
Registered office: 128, City Road, London, EC1V 2NX, UNITED KINGDOM
Privacy: via [email protected] (subject: Privacy enquiry)
Support: [email protected]
Legal: via [email protected] (subject: Legal enquiry)
Related documents: Terms of Service · Cookie Policy · Data Processing Disclosure