Legal

Privacy Policy

VAHTOR provides AI governance software for organisations. This policy explains what we collect, how on-device detection works, and what admins can see.

Last updated 22 September 2026·Vahtor Oy

1What we collect

  • Account data (name, email, organisation, role) when you sign up or are invited.
  • Billing and invoicing details when you purchase or redeem a licence.
  • Extension enrolment metadata (browser, platform, version, last seen) for devices you connect.
  • Security alerts from the browser extension: detection type, risk level, application name, and a masked sample only. Prompt text, company documents, and full secrets are not uploaded to our servers.

2On-device processing

Sensitive content is classified on the employee device. Only metadata and masked fingerprints are reported to the organisation’s VAHTOR workspace for admin review.

3Who can see alerts

Organisation owners and admins see alert metadata for their workspace. Individual members see their own personal alerts. We do not sell personal data.

4Retention and control

Workspace owners configure retention and reporting level in Settings. You may request export or deletion of account data by contacting us.

5Contact

Questions: [email protected].

See also the Terms of Service.