← Back to legal

Website privacy policy

Updated July 22, 2026

Introduction

This policy explains how Vzla.io (“Vzla.io”, “we”, “us”) collects, uses, and protects personal data when you visit this website.

We are a company registered in the United States. Even so, we have chosen to hold this website to the standard of the European Union’s General Data Protection Regulation (GDPR) and European data-protection law, because we believe it is the strongest, clearest privacy standard available and it reflects how we think privacy should work. We apply it to every visitor, wherever you are.

Our approach is privacy by default: we collect the minimum data needed to run the site, we do not sell or rent personal data, we do not use tracking or advertising cookies, and we do not share data for advertising. “You” refers to any visitor or user of this website.

Who is responsible for your data

Vzla.io is the data controller for the personal data described in this policy. Our legal entity name, registered address, and contact details are published in our imprint. For any privacy question or request, see the Contact section below.

Data we collect

We keep data collection deliberately small. We may process the following.

Information you choose to give us:

  • The content of messages you send us, and the email address or contact details you use to send them (for example, when you email us or submit a contact or newsletter form).

Technical data collected automatically to operate and secure the site:

  • IP address and basic connection data recorded in server logs.
  • Browser type and version, and operating system.
  • The pages you request and the date and time of the request.

Cookieless usage statistics:

  • Aggregated, anonymous measurements collected through our analytics (see Cookies and analytics). These do not identify you and are not linked to any other data.

We do not ask for, and do not want, special-category data (such as data about health, ethnicity, religion, or political views). Please do not send it to us.

Lawful bases for processing

Under Article 6 of the GDPR, we process personal data only where we have a lawful basis to do so:

  • Legitimate interests (Art. 6(1)(f)) — to operate, secure, and maintain the website, keep server logs, prevent abuse, and understand aggregate, anonymous usage so we can improve the site. We limit this processing to what is necessary and balance it against your rights.
  • Consent (Art. 6(1)(a)) — where you subscribe to a newsletter or opt in to a specific communication. You can withdraw consent at any time, without affecting processing that already took place.
  • Performance of a contract or steps at your request (Art. 6(1)(b)) — where you contact us about our products or services and we need to respond to your request.
  • Legal obligation (Art. 6(1)(c)) — where we must retain or disclose data to comply with the law.

How we use data

We use the data we collect to:

  • Respond to your messages and requests.
  • Operate, secure, and maintain the website and prevent fraud or abuse.
  • Send you a newsletter or updates you have specifically asked to receive.
  • Understand aggregate, anonymous usage so we can improve content and performance.
  • Comply with legal obligations.

We do not use your data to build advertising profiles, and we do not make decisions about you based solely on automated processing.

Cookies and analytics

Cookies are small text files a website can store on your device. We use them sparingly and honestly.

We use only:

  • Strictly necessary cookies — required for the website to function (for example, security and load balancing). These do not track you.
  • Preference cookies — set only where needed to remember a choice you make, such as your language. These are used to serve you, not to profile you.

We do not use advertising cookies, tracking cookies, cross-site trackers, ad-network tags, or third-party marketing pixels. We do not use Google Analytics.

For usage statistics we use Umami, a privacy-first, cookieless analytics tool that we self-host. Umami sets no analytics or advertising cookies, does not collect personal data, and does not track you across sites or over time. It produces only aggregated, anonymous measurements (such as page views and referring sites) that we cannot trace back to an individual.

You can manage or block non-essential cookies through your browser settings. Blocking strictly necessary cookies may affect how the site works.

Sharing your data

We do not sell or rent your personal data, and we never share it for advertising.

We share personal data only when necessary and only with:

  • Service providers who process data on our behalf under a data-processing agreement (for example, hosting or email delivery), limited to what they need to perform their service.
  • Authorities or advisors where we are required to disclose data by law, or to establish, exercise, or defend legal claims.

International data transfers

We are based in the United States, so operating this website can involve transferring personal data from the European Economic Area (EEA) or the United Kingdom to the United States or to service providers located elsewhere.

We keep such transfers to a minimum and apply appropriate safeguards required by GDPR Chapter V, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission (and the UK International Data Transfer Addendum where relevant) with providers that process data for us.
  • Reliance on the EU–U.S. Data Privacy Framework (and its UK extension) where a provider is certified under it.
  • Data minimisation and, where practical, hosting and processing data within the EEA.

You can contact us for more information about the safeguards that apply to a specific transfer.

Data retention

We keep personal data only for as long as we need it for the purpose it was collected, or as required by law:

  • Messages and contact data — kept for as long as needed to handle your request and for a reasonable period afterward, then deleted.
  • Server logs — kept for a short period for security and troubleshooting, then deleted or anonymised.
  • Newsletter data — kept until you unsubscribe or withdraw consent.
  • Analytics — aggregated and anonymous, so it is not tied to you.

When data is no longer needed, we delete or anonymise it.

Your rights

Under the GDPR you have the following rights over your personal data:

  • Access — to know whether we process your data and to obtain a copy of it (Art. 15).
  • Rectification — to have inaccurate or incomplete data corrected (Art. 16).
  • Erasure — to have your data deleted in the circumstances the law provides (“right to be forgotten”, Art. 17).
  • Restriction — to limit how we process your data in certain cases (Art. 18).
  • Data portability — to receive data you provided in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible (Art. 20).
  • Objection — to object to processing based on our legitimate interests, and to object at any time to any processing for direct marketing (Art. 21).
  • Withdraw consent — at any time, where processing is based on your consent, without affecting prior processing (Art. 7).

To exercise any of these rights, contact us. We respond to requests without undue delay and within one month at the latest, as the GDPR requires. Exercising your rights is free of charge in normal cases.

Security

We use appropriate technical and organisational measures to protect personal data against loss, misuse, and unauthorised access, including encryption in transit and restricted access to data. No method of transmission or storage is completely secure, but we work to keep our safeguards current.

Our website may contain links to third-party sites. This policy applies only to Vzla.io; we are not responsible for the privacy practices of other sites, and we recommend reviewing their policies.

Children’s privacy

This website is not directed at children, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

Changes to this policy

We keep this policy under periodic review. When we make material changes, we update the date at the top of this page and, where appropriate, provide additional notice.

Contact

If you have any questions about this policy or wish to exercise your data-protection rights, contact us at privacy@vzla.io.

Right to lodge a complaint

If you are in the EEA or the UK and believe we have not handled your personal data properly, you have the right to lodge a complaint with your local data-protection supervisory authority. A list of EEA authorities is available from the European Data Protection Board (edpb.europa.eu); in the UK, the authority is the Information Commissioner’s Office (ico.org.uk). We would appreciate the chance to address your concern first, so please consider contacting us before you do.