Vedora
Legal & Compliance

Privacy Policy

How Vedora Technologies handles data security, client intellectual property protection, and privacy compliance.

Last UpdatedJuly 6, 2026
Effective DateJuly 6, 2026
Policy Versionv1.0.0
Reading Time4 Mins

1. Scope & Commitment

At Vedora Technologies, privacy is not a mere compliance exercise—it is a core engineering principle. We act as both a data processor for the software platforms we build for our enterprise clients, and a data controller for the information collected during our business engagement and website operations.

We strictly adhere to zero-telemetry defaults in the systems we design unless explicitly instructed and configured by our clients. Your source code, blueprints, and data schema diagrams are treated with absolute confidentiality.

2. Information We Collect

We collect information necessary to deliver premium design, technical consulting, and software engineering services. This falls into three categories:

  • Client Business Data: Names, corporate emails, telephone coordinates, billing information, repository access credentials, project specifications, and architectural documentation shared during onboarding.
  • Usage Telemetry: Anonymized analytical metadata collected when visiting our website (browser user-agent, IP hashes, referral channels, and page interaction timestamps).
  • Communication Records: Email messages, Slack communications, and meeting video recordings (captured only with verbal consent for project reference).

3. How We Use Information

The collected information is solely processed for delivery of our consulting agreements. We do not engage in data brokering or ad-targeting networks.

Data TypeUse CaseLegal Basis
Credentials & SchemasRepository setup & backend deploymentContractual Necessity
Billing AddressesInvoicing and corporate taxation auditsLegal Obligation
Anonymized IPsWeb service telemetry and threat intelligenceLegitimate Interest

4. Cookie & Tracking Policies

We use minimalist cookies to run the Vedora platform. We do not use third-party behavioral retargeting pixels (e.g., Facebook Pixel, TikTok Tracker).

Essential Cookies

Necessary for load balancing, caching parameters, and ensuring secure connection handshakes via Cloudflare. Cannot be disabled.

Analytical Metrics

We use server-side tracking and privacy-focused Google Analytics setup with strict IP anonymization enabled. This gathers platform usage trends without creating user profiles.


5. Third-Party Data Sharing

We utilize reliable third-party infrastructure (subprocessors) to build, deploy, and host our services. They process data strictly in accordance with our instructions under written agreements:

Vercel Inc.Hosting & SSR Processing

Hosts our frontend app and processes edge functions securely.

Cloudflare Inc.WAF, CDN, and Security DNS

Filters malicious web requests and mitigates DDoS threats.

Google AnalyticsWeb Traffic Analysis

Anonymized user trends to audit platform load requirements.


6. Security & Encryption Standards

All client workspaces, configuration setups, and codebases are secured following enterprise security standards:

  • TLS & Encryption: All data in transit uses TLS 1.3 encryption. Internal data caches are encrypted at rest with AES-256 keys.
  • Strict IAM Roles: Access permissions to codebase repositories are tightly controlled using multi-factor authenticated Identity Access Management (IAM) matrices.
  • Secure Terminals: Development terminals are configured with compliance software to prevent automated copy-leaks of client code bases.

7. Your Rights & Access

Regardless of geographical boundaries (GDPR, CCPA, or regional legislation), we recognize the following foundational data controls for all clients:

Right to Deletion (Erasure)

Request removal of your credentials, database access variables, and repository history upon project completion.

Right to Correction & Access

Obtain copy exports of all configuration files, wireframe documents, and development notes gathered during sprint phases.


8. Data Retention Policies

We retain client project assets (such as initial layout frames, code drafts, and meeting updates) only for the duration of the operational agreement.

Upon service termination, code caches are deleted within **30 business days**, with the exception of structural invoices and legal contracts which we retain for **7 years** to satisfy regional audit frameworks.


9. Contact & Inquiries

If you have questions regarding data privacy safeguards or wish to exercise your data controls, contact our compliance representative directly:

Direct Contact Channels

Email: privacy@vedora.tech

Company: Vedora Technologies

Compliance Officer: Corporate Compliance Team

Location: Ahmedabad, Gujarat, IN