Skip to content

Privacy Policy

Last updated: June 2026

1. Introduction

VANCORE ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our website, AI business analysis tools, and services (collectively, the "Service").

By using our Service, you consent to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.

2. Data Controller

VANCORE, Bulgaria
Email: hello@vancoresys.com
Website: vancoresys.com

3. Information We Collect

We collect the following types of personal data:

  • Account Information: Name, email address, company name, phone number when you register or use our lead capture forms.
  • Conversation Data: Messages exchanged with our AI assistant (Vera), including business information you share during consultations.
  • Usage Data: Information about how you interact with our Service, including pages visited, features used, and timestamps.
  • Technical Data: IP address, browser type, device information, cookies, and similar technologies.
  • Payment Information: When you subscribe to our paid plans, payment is processed through Revolut. We do not store your full payment card details.

4. How We Use Your Information

We use the collected information for the following purposes:

  • Providing and improving our AI business analysis service
  • Personalizing your experience and delivering relevant insights
  • Processing subscriptions and payments
  • Communicating with you about your account and service updates
  • Analyzing usage patterns to improve our Service
  • Complying with legal obligations
  • Preventing fraud and ensuring security

5. Legal Basis for Processing (GDPR)

We process your personal data under the following legal bases:

  • Consent: When you opt in to marketing communications or accept non-essential cookies
  • Contract: To provide the services you have requested
  • Legitimate Interest: To improve our Service and communicate with you about relevant offerings
  • Legal Obligation: To comply with applicable laws and regulations

6. Data Sharing and Disclosure

We share personal data only with processors necessary to deliver the Service, under agreements that protect your data. None of these processors are located outside the EU in a way that would bypass GDPR transfer rules.

  • Supabase — authentication and database hosting, EU region. DPA
  • Vercel — frontend hosting and edge delivery. DPA
  • DigitalOcean — backend API hosting and file storage, Frankfurt region. DPA

We do not sell your personal data. We do not share data for advertising purposes.

7. Data Retention

We retain your personal data for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law. Account data is retained for 12 months after your last activity. You may request deletion of your data at any time.

8. Your Rights (GDPR)

Under GDPR, you have the following rights:

  • Right of Access: Request a copy of your personal data
  • Right to Rectification: Correct inaccurate personal data
  • Right to Erasure: Request deletion of your personal data
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive your data in a portable format
  • Right to Object: Object to processing of your personal data
  • Right to Withdraw Consent: Withdraw consent at any time

To exercise these rights, contact us at hello@vancoresys.com.

9. Cookies

We use cookies and similar tracking technologies to track activity on our Service and hold certain information. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.

For more information, please see our Cookie Policy.

10. Data Security

We implement technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction. Specific controls include:

  • Encryption in transit: All external connections use TLS 1.2 or higher through our hosting and CDN providers.
  • Authentication: Portal and API access require authenticated sessions using JWT. Role-based access controls are applied where team environments are enabled.
  • Audit logging: Administrative actions, booking changes, and document upload events are logged with timestamp, actor, and action.
  • Backups: System and database backups are stored according to configured retention schedules. Backup integrity is verified periodically to support restoration within realistic timeframes.
  • Security headers: The site applies security headers such as HSTS, CSP, and X-Frame-Options consistent with deployment platform capabilities.

11. International Transfers

Your information may be transferred to and processed in countries other than your country of residence. We ensure that such transfers comply with applicable data protection laws.

12. Children's Privacy

Our Service is not intended for individuals under the age of 16. We do not knowingly collect personal data from children under 16.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.

14. Contact Us

If you have any questions about this Privacy Policy, please contact us:
Email: hello@vancoresys.com
Website: vancoresys.com/contact