01Who we are and what this covers
Vyorith (“we”, “us”) provides a platform that answers security questionnaires and supports ISO 27001 implementation. This policy covers this website (vyorith.com) and the Vyorith app (app.vyorith.com).
We handle personal data in two roles. For the documents, questionnaires and other content an organisation puts into Vyorith, we act as a processor on that organisation’s behalf: the organisation decides what goes in and why, and our agreement with them governs how we handle it. For account details, security records and people who contact us, we are the controller, and this policy applies directly.
02What we collect
Account information
Your name, work email address and, if you sign in with Google, the profile photo Google provides. We also keep which workspaces you belong to and your role in each. Accounts are created by an administrator; there is no public sign-up.
Two-factor authentication
Every account uses an authenticator app. The enrolment is held by our sign-in provider so that your codes can be checked; we never see the codes themselves.
Customer content
Documents, questionnaires, answers, facts, comments, approvals and their history — whatever your organisation uploads or creates in Vyorith. This may contain personal data, such as names of policy owners or staff.
Your company’s public website
When a workspace is set up, we read the organisation’s own official website to prepare a short brief, and, if the organisation switches it on, to answer questions its documents don’t cover. We read only that organisation’s own site.
Security and usage records
Sign-in events, an audit log of sensitive actions (who did what, and when), IP addresses used for rate limiting and abuse prevention, and technical logs needed to run and fix the service.
When you contact us
Whatever you include in an email to us, such as your name, company and message.
03How we use it
- To provide the service: reading your documents, drafting answers, and keeping your workspace working.
- To keep it secure: authentication, rate limiting, audit logging, and investigating misuse.
- To support you and tell you about changes to the service.
- To meet legal obligations.
We do not sell personal data, we do not use it for advertising, and we do not use customer content to train AI models.
04How AI is used
To draft answers, read documents and make them searchable, parts of your organisation’s content are processed by the AI model providers we use. They process it on our behalf, to return a result to us, under terms that do not allow them to train their models on it.
Everything the AI produces is a draft. Answers, policies and Statement of Applicability entries only count once a person in your organisation approves them.
05Who we share it with
We use a small number of carefully chosen service providers (“sub-processors”) to run Vyorith. Each receives only what it needs for its purpose, under a written agreement that protects it. Customers can request the current list by emailing hello@vyorith.com.
| Category | What it does for us |
|---|---|
| Cloud infrastructure | Hosting, database and encrypted file storage for the Vyorith app and this website. |
| AI model providers | Drafting answers, reading documents and making them searchable. When a customer turns on website lookups, searching that customer’s own official website. |
| Sign-in providers | Signing you in with an existing work account, only if you choose to. |
We may also disclose information where the law requires it, or to protect the rights and safety of our customers, our users or ourselves. Some of these providers process data outside your country, including in the United States; where the law requires it, we rely on recognised safeguards such as standard contractual clauses.
07How long we keep it
Account information is kept while your account is active. Customer content is kept for as long as your organisation’s agreement with us requires, and is deleted or returned when it ends, as that agreement sets out. Security records and logs are kept only as long as needed to protect the service and meet legal obligations.
08How we protect it
Every account uses two-factor authentication, and accounts are created only by administrators. Each organisation’s data is kept in its own workspace, enforced in the application and again in the database. Data is encrypted in transit, and sensitive actions are recorded in an audit log. More on our approach to security.
If you believe you’ve found a security issue, please tell us at hello@vyorith.com.
09Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict how we use it, and to complain to your data protection authority.
To use these rights for your account information, email hello@vyorith.com. If your request is about content your organisation put into Vyorith, please contact your organisation first — they control that content — and we will help them respond.
10Children
Vyorith is a business service and is not intended for anyone under 18.
11Changes to this policy
When we change this policy we update the date at the top. If a change materially affects how we handle your data, we will tell our customers before it takes effect.
12Contact
Questions about this policy or your data: hello@vyorith.com.