VectorMachines
ProductContact
Book a demo
ProductContactBook a demo
Privacy

Privacy Notice.

How VectorMachines collects, uses, discloses and protects personal information. Published notice — GDPR Articles 13 and 14, and applicable US state privacy law.

Version 1.2·Effective 30 August 2026

Contents

  1. 1Summary
  2. 2Two Different Roles
  3. 3Information We Collect as a Controller
  4. 4Why We Use It, and On What Basis
  5. 5How We Share Information
  6. 6International Transfers
  7. 7How Long We Keep Information
  8. 8Your Rights
  9. 9Cookies and Similar Technologies
  10. 10Artificial Intelligence
  11. 11How We Protect Information
  12. 12Contact Us
  13. 13Changes to This Notice
Contents
  1. 1Summary
  2. 2Two Different Roles
  3. 3Information We Collect as a Controller
  4. 4Why We Use It, and On What Basis
  5. 5How We Share Information
  6. 6International Transfers
  7. 7How Long We Keep Information
  8. 8Your Rights
  9. 9Cookies and Similar Technologies
  10. 10Artificial Intelligence
  11. 11How We Protect Information
  12. 12Contact Us
  13. 13Changes to This Notice

This notice is published by VectorMachines, Inc. (“VectorMachines”, “we”, “us”). It is written to be read by customers, prospective customers, vendor risk reviewers and members of the public.

1Summary

VectorMachines builds a source-available, in-perimeter agentic artificial intelligence platform for enterprise business processes. Our customers are organizations, not consumers. The great majority of the personal information we handle does not come from individuals directly — it arrives inside business records belonging to a customer, which we process on that customer’s instructions and under that customer’s control.

Three commitments frame everything below:

  • We do not sell personal information, and we do not use it for advertising. We operate no advertising business and participate in no data brokerage.
  • We do not use customer data to train, fine-tune or improve any artificial intelligence model. We operate no model training pipeline.
  • We do not need to hold your data to serve you. Our platform is designed to be deployed inside the customer’s own perimeter as a single-tenant stack, and there is no shared VectorMachines cloud endpoint through which customer data flows. Where a pilot runs in a dedicated cloud account operated by VectorMachines before the platform moves inside the customer’s perimeter, that account is single-tenant and the location is agreed in advance.

2Two Different Roles

This notice covers two distinct situations, and your rights differ between them.

2.1 Where VectorMachines is a controller

We determine the purposes and means of processing for a limited set of information: visitors to our website, business contacts at prospective and current customers, individuals who correspond with us, job applicants, and our own personnel. Sections 3 to 9 of this notice apply.

2.2 Where VectorMachines is a processor

When we deliver our platform and services to a customer, personal information contained in that customer’s records is processed by us only on the documented instructions of that customer, who acts as the controller. We do not determine why that data is processed, and we do not use it for our own purposes.

If your personal information reaches us in this way — for example, because you are named as a purchase order approver, an expense requestor or a vendor contact in a customer’s finance systems — the customer is responsible for the notice given to you and for responding to your rights requests. Please direct requests to that organization. We will support them in responding. Section 10 describes the safeguards that apply to this category of data.

3Information We Collect as a Controller

CategoryExamplesSource
Business contact informationName, employer, job title, business email address, business telephone numberProvided by you, or by your employer, in the course of a commercial discussion
CorrespondenceEmails, meeting requests, questionnaire responses, notes of calls and meetingsProvided by you
Website usage informationPages requested, referring page, browser and device type, approximate location derived from IP addressCollected automatically when you visit our website
Recruitment informationCV or résumé, work history, references, correspondence about an applicationProvided by you or by a recruiter acting for you

Records generated when a user authenticates to a deployed platform — identity claims received from the customer’s identity provider through OpenID Connect, and the IP address recorded in the audit log — are processed as a processor on the customer’s instructions, not as a controller. Section 10 applies to them.

We do not knowingly collect special categories of personal data, and we do not collect personal information from children. Our services are not directed at individuals under 18.

4Why We Use It, and On What Basis

PurposeLegal basis (GDPR / UK GDPR)
Responding to enquiries and conducting commercial discussionsLegitimate interests — operating and developing our business
Performing a contract with a customer, including support and deliveryPerformance of a contract; legitimate interests where the counterparty is an organization
Sending operational and, where requested, occasional business communicationsLegitimate interests, or consent where consent is required in the relevant jurisdiction
Securing our systems, investigating incidents and maintaining audit recordsLegitimate interests; compliance with legal obligations
Assessing job applicationsSteps taken at the request of the data subject prior to entering into a contract
Meeting legal, regulatory, tax and accounting obligationsCompliance with legal obligations

Where we rely on legitimate interests, we have assessed that our interest is not overridden by the rights and interests of the individuals concerned. You may ask us for that assessment.

5How We Share Information

We disclose personal information only as follows:

  • To service providers and sub-processors who provide infrastructure, model inference, communications and business support, under written contracts imposing confidentiality and data protection obligations no less protective than our own commitments. Our current sub-processor list is maintained and made available to customers on request, and is incorporated into the data processing agreement executed with each customer.
  • To professional advisers — legal, accounting and audit — under duties of confidence.
  • Where required by law, or to establish, exercise or defend legal claims.
  • In connection with a corporate transaction, such as a merger, acquisition or financing, subject to confidentiality obligations.

We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not disclose it to data brokers. We have never received a national security request for customer data.

6International Transfers

VectorMachines operates from the United States and processes information there. Where we act as a processor, the processing and storage location for each customer environment is fixed and documented before production data is processed; for the engagements currently in scope, that location is the United States. Whether a copy of customer data comes to rest in infrastructure we operate at all depends on how the customer chooses to supply it: where the platform runs inside the customer’s own environment and reads from there, it does not.

Where personal information is transferred out of the European Economic Area, the United Kingdom or Switzerland, we apply an appropriate transfer mechanism — ordinarily the European Commission’s Standard Contractual Clauses together with the UK Addendum — and record it in the applicable agreement.

7How Long We Keep Information

We keep personal information only as long as we need it for the purpose for which it was collected, and then delete it.

DataRetention
Business contact and correspondence recordsDuration of the relationship, plus 24 months
Customer data processed as a processorDuration of the engagement, plus the period agreed with the customer. Deleted in accordance with the applicable customer agreement. Where that agreement is silent: personal data is returned or destroyed within 30 days of termination, expiry or request; work product within 14 days; and confidential information promptly following termination or on request, with verification of destruction provided. Copies retained in routine backup or archival systems not readily accessible in the ordinary course are deleted on their normal cycle; copies required by law or legal hold, and audit, security and system log records required for our information security program, are retained for as long as that requirement lasts and remain subject to this notice
Security and audit logsSeven years for audit records; 90 days for error logs; 90 days for operational logs. Cache data is not persisted and does not survive a restart. Log classes specific to an engagement are defined in that engagement’s agreement
Unsuccessful job applications12 months, unless you ask us to delete them sooner
Records required for legal, tax or accounting purposesThe applicable statutory period

Deletion of customer data is performed through controlled tooling that operates within a defined tenant scope, requires explicit confirmation and a recorded reason, and writes a mandatory audit record. Where the audit record cannot be written, the deletion fails — so every deletion is evidenced. A deletion is scoped to the user named in the request and covers their conversations and the stored results those conversations drew on, their working directories, their memory entries, their uploaded files and generated artifacts, and their interface keys. It reports what it removed from each store. The audit record that a deletion occurred is deliberately outside its scope, so the record outlives the data it describes.

8Your Rights

Depending on where you live, you may have the right to request access to your personal information; correction of inaccurate information; deletion; restriction of processing; portability; objection to processing carried out on the basis of legitimate interests; and withdrawal of consent where processing is based on consent. You also have the right to complain to a supervisory authority.

Residents of California and of other US states with comprehensive privacy legislation have rights to know, delete, correct and opt out of sale or sharing. We do not sell or share personal information as those terms are defined, and we do not use it for targeted advertising or for profiling that produces legal or similarly significant effects.

To exercise a right, contact us at the address in Section 12. We will verify your identity before acting and will respond within the period required by applicable law — ordinarily one month under the GDPR and 45 days under US state law. We will not discriminate against you for exercising a right.

Where we act as a processor, we cannot act on your request directly. We will forward it to the customer that controls the data without undue delay and support them in responding.

9Cookies and Similar Technologies

Our website sets no cookies at all. Two first-party session-storage entries hold interface state — where you had scrolled to — and are erased when you close the browser tab; neither contains an identifier. We run no analytics, no marketing tags and no tracking code of any kind, and your browser contacts no third party when you load a page: every file the site serves, including its typefaces, comes from infrastructure we operate. A content security policy is enforced at the edge, so a third-party resource could not be introduced without a deliberate change to that policy. If analytics, marketing or embedded third-party content is added to vectormachines.com in future, this section will name it and, where consent is required, a consent mechanism will be in place before it runs.

Within our application, a session cookie is set when a user signs in. The authentication token itself is held server-side rather than in the browser, so it cannot be read by a script running in the page. The cookie is required for the application to work, carries the secure, HTTP-only and same-site attributes, and is not used for tracking. We place no tags, cookies, pixels or widgets on any customer website.

10Artificial Intelligence

Our product is an AI system, and we describe how it works rather than leaving it to inference.

Customer data is not used to train models. Personal information processed through the platform is never used to train, fine-tune or otherwise improve any model, whether ours or a third party’s. We operate no training pipeline. We require the same commitment from every model provider we use. On retention, we state the position as it is rather than as we would like it: the commercial providers we use delete what is sent to them within 30 days, and hold it during that window for their own abuse monitoring and legal compliance rather than for any purpose of ours. We are seeking shorter arrangements where they are offered. Where a deployment is configured to run inference within the customer’s own environment, nothing is sent to a commercial provider at all and none of this arises. These terms are confirmed and recorded before a provider is used in an environment that processes customer data.

What a model provider receives is bounded, and we would rather state the bound than let a summary stand for it. A user’s question is translated into a query plan by the language model, and execution is tool-driven. A set of results passes to the model in full only where it is small — below both a record count and a character limit that are fixed in the software — and anything larger is replaced by a statistical description of the data rather than the data itself. That description is drawn from real records, and any figure the system derives from results forms part of its answer and so reaches the model. So the control bounds how much detail is transmitted; it is not a guarantee that no result data reaches a provider. Two settings can widen this and are decided per deployment rather than by default. Where the optional independent evaluation of an answer is enabled, a second model reads the stored result set in order to judge the answer against it. And where the optional memory feature is enabled, the text of a user’s question is sent to an embedding endpoint on every turn in order to retrieve what is relevant, and stored entries are composed into the prompt. Both are disabled where a customer requires that they be, and on a fully self-hosted path both are served from within the customer’s own environment. Interaction with dashboards, including filtering, pivoting and drilling into a source record, involves no model call at all. Schema enrichment runs on a self-hosted model within the deployment, and a fully self-hosted path is available for customers who require that no third-party model provider participate in processing at all — in which case nothing described in this paragraph leaves their own environment.

Access to customer systems is read-only. The platform reads from source systems and never writes back. This is enforced independently at two layers, and no configuration option enables write access.

Humans remain in the loop. The platform does not take consequential action autonomously. Approval gates suspend execution pending a human decision, plans are presented for approval before they run, and the agent can escalate to a human mid-execution. These gates are exposed through both the user interface and the API so that a customer can enforce review through its own systems.

No decisions about individuals. The platform analyzes vendor, contract and transaction data at the organizational level. It does not score, rank or profile individuals; it performs no systematic monitoring of individuals; and it is not permitted to be used for automated decisions producing legal or similarly significant effects on a person, nor for any practice prohibited by Article 5 of the EU Artificial Intelligence Act. It processes no biometric data.

Outputs are traceable and verified. Generated figures and relational claims are checked deterministically against source records before they are shown; content that cannot be verified is withheld rather than displayed. Every figure can be opened down to the originating record, and the underlying query is available for inspection.

Interactions are logged. Agent runs, query execution and interaction traces are recorded in audit logs, with credentials and personal data masked.

Users know they are using an AI system. The platform is presented as one; there is no scenario in which a user interacts with it unaware that AI is involved.

11How We Protect Information

We operate an information security program documented in the VectorMachines Information Security Policy, aligned to the AICPA SOC 2 Trust Services Criteria and the NIST Cybersecurity Framework 2.0, and available to customers and prospective customers under a non-disclosure agreement.

Controls include federated authentication to your own identity provider, so that the platform holds no store of end-user passwords, role-based access control with record-level authorization, AES-256 encryption at rest and TLS 1.2 or higher in transit, single-tenant deployment with no shared control plane, credential isolation at the connector layer, an isolated agent execution environment with default-deny egress, and audit logging of security-relevant events. Because our platform is source-available, these controls can be verified by inspection of the source code rather than taken on trust.

If a personal data breach occurs, we notify affected customers without undue delay and in any event within 48 hours of becoming aware of the incident, and we notify regulators and individuals where the law requires it of us.

12Contact Us

Privacy enquiries and rights requestsprivacy@vectormachines.com
Privacy accountabilityAnandeep Pannu, Co-founder & Chief Technology Officer — ap@vectormachines.com
Data processing agreementsJaspi Sandhu, Co-founder & Chief Executive Officer — jaspi@vectormachines.com
Postal address5776 Stoneridge Mall Rd, Ste 210, Pleasanton 94588

VectorMachines has not appointed a Data Protection Officer. We are not a public authority, our core activities do not consist of large-scale systematic monitoring, and we do not process special categories of data at scale, so the appointment is not required under Article 37 of the GDPR. Privacy accountability sits jointly with the Chief Executive Officer and the Chief Technology Officer.

If you are in the EEA, the UK or Switzerland and you believe we have not handled your information properly, you may complain to your local supervisory authority. We would prefer the chance to resolve it first.

13Changes to This Notice

We review this notice at least annually and revise it when our processing changes materially. The effective date appears at the top. Where a change materially affects how we handle personal information, we will notify customers directly in accordance with the applicable agreement, and post the updated notice on our website before it takes effect.

© 2026 VectorMachines, Inc. This notice is published and may be reproduced and distributed freely in unaltered form.

Ready to compress days of analyst work into one conversation?

Book a demo
VectorMachines

Product

  • Overview
  • How it works
  • Security

Company

  • Contact
  • Book a demo
  • Privacy Notice
© 2026 VectorMachines, Inc. All rights reserved.