Legal
Privacy policy
What VVDex collects, why, who else handles it, how long it is kept, and what you can ask of us under the EU General Data Protection Regulation (GDPR).
1. Who is responsible
The controller for vvdexops.com and the VVDex service is:
Vamsi VenkateshRobert-Seitz-Straße 1
39108 Magdeburg, Germany
vamsi@vamsivenkatesh.com
Write to this address for any question about your data or to use any of your rights.
2. What we process, and why
Visiting the website
When you open a page, your browser sends your IP address, the address requested, the time, your browser’s user agent and the referring page. We and our network provider (see section 3) process this to deliver the page, keep the service secure and find errors. Legal basis: our legitimate interest in a working and secure website (Art. 6(1)(f) GDPR).
Sign-in forms and free exam runs count requests per IP address in time windows of up to one day to stop abuse. These counters are deleted after one day.
The bot check before a free exam run and on the Book a call form is Cloudflare Turnstile: Cloudflare checks your browser before the run starts or the message is sent, and processes your IP address and browser characteristics to do so. Legal basis: our legitimate interest in keeping the free runs and the form for people (Art. 6(1)(f) GDPR).
Your account
- Email address and a display name taken from it, the time you signed up and last signed in.
- Sign-in codes, stored only as a keyed hash, valid for 10 minutes, deleted after one day.
- Sessions: a session cookie, and with each session the IP address and browser user agent at sign-in. Sessions last up to 30 days and are deleted 7 days after they expire or you sign out.
- If you sign in with Google or GitHub, where offered, we receive your verified email address from that provider and nothing else we store.
- API keys: their name, first characters and a keyed hash; the key itself is shown to you once and never stored.
Legal basis: providing the service you signed up for (Art. 6(1)(b) GDPR).
What you put into your workspace
- Connections: provider, label, address, and your provider keys and custom headers, encrypted with AES-256-GCM. Keys are never shown again, never written to logs and never put in receipts; only their last four characters are displayed.
- Datasets, playground runs, evaluation runs and their results: the prompts, expected answers, the models’ answers, grades, timings, token counts and costs.
- The full record of each Forge exam attempt: the whole conversation between the exam and your model (the task, every message your model sent and every tool result it got back), the commands it ran, the files it read and changed, the change it submitted, the timeline and the grading. The record also holds the exam’s own content, so it is never shown to other users or published; we can go through it with you.
- Human labels you add to judge answers, and the workspace’s audit log (who did what and when).
- Daily usage counters used to apply your plan’s limits.
Legal basis: Art. 6(1)(b) GDPR. Please do not put personal data of other people into prompts or datasets unless you are allowed to.
Prompts sent to the models you choose
When you run the playground, an evaluation or a connection check, VVDex sends your prompts and dataset rows to the model provider or address you selected, using your key, and stores the answer. That provider processes the data under its own terms and privacy policy, and it may be outside the EU. You decide which providers receive your data and are responsible for having a legal basis to send it there.
For a model on your own machine connected through the VVDex connector, requests are relayed through our database to the connector program you run; relay records are deleted after one hour.
Things you make public
If you share a run by link, or publish a Forge exam result, everyone with the link, or everyone, can see what it shows: prompts, answers, grades and the models’ public names. Receipts contain the same content and never contain keys or the address of a custom endpoint (only its host name).
Evaluations you ask us to run
When you ask for an evaluation, we store what you enter in the request form (your name; your company and role if you give them; what to test and why; the exams, models and deadline you name; your notes), the messages on the request and its history. We use this to plan the evaluation, run it and write your report. We start the runs in your own workspace, on the model connections saved there, so your provider key is used and your provider bills you for those calls. We see the names and providers of the models saved in your workspace, never the keys. The report we deliver is stored with the request. Legal basis: Art. 6(1)(b) GDPR.
Book a call
When you send the form on Book a call, we store your name, email address, company if you give it, the topic and your message, with the IP address it came from, and email them to Vamsi Venkatesh so he can reply to you. Nothing is sent to your address from the form itself. Legal basis: steps you asked for before a possible contract (Art. 6(1)(b) GDPR).
Emails
We send the sign-in code, the notice that a run has finished when you ask for one, and messages about your evaluation requests to your email address, through our email provider (see section 3). Legal basis: Art. 6(1)(b) GDPR.
3. Who else processes data for us
| Provider | What for | Where |
|---|---|---|
| Contabo GmbH, Munich | Servers that run VVDex and hold its database | Germany |
| Cloudflare, Inc. | Network delivery and protection: every request to vvdexops.com passes through Cloudflare; the bot check before free exam runs and on the Book a call form | Worldwide network; USA-based company, certified under the EU–US Data Privacy Framework |
| Zoho | Sending emails: sign-in codes, run notices, messages about requests | EU data centre |
Each processes data on our instructions under a data processing agreement (Art. 28 GDPR). Model providers you connect are not our processors: you choose them and use your own account with them.
4. Cookies and tracking
VVDex sets one cookie, __Host-vvx_session, when you open the app or sign in. Opening the app without signing in creates a private guest workspace tied to this cookie and nothing else: no email address, only the network address and browser name used to limit abuse. The cookie is needed to keep you in your workspace, is not readable by scripts, is sent only to vvdexops.com over HTTPS, and ends when you sign out or after 30 days. Signing in with Google or GitHub also sets a short-lived cookie that protects the sign-in step. Because these cookies are strictly necessary for a service you asked for, no consent is required (§ 25(2) TDDDG).
There are no advertising or analytics trackers, no tracking pixels and no third-party fonts: fonts are served from vvdexops.com.
5. How long we keep data
- Account data, including a guest workspace: until you delete it in Settings.
- Playground and evaluation runs, with their results and share links: for your plan’s retention period (Free: 30 days), then deleted automatically; earlier if you delete your account. The full record of each Forge exam attempt belongs to its run and is deleted with it.
- A Forge exam run you publish: kept, with its page and receipt, while it is published. Unpublishing it, or withdrawing its share link, takes it down; the retention period then applies.
- Evaluation requests, their messages and the delivered report: until you delete your account. The runs started for a request are runs in your workspace, so your plan’s retention period applies to them; the report keeps its figures.
- Messages sent with the Book a call form: 12 months, then deleted automatically.
- Sign-in codes and rate-limit counters: one day. Sessions: 7 days after they end. Connector relay records: one hour.
- Web server logs: only as long as needed for security and error analysis.
6. Deleting your account
In the web app, open Settings → Delete account. This deletes your account and every workspace in which you are the only member, with everything in it: connections and keys, datasets, runs, results, share links and API keys.
7. Your rights
You have the right to access your data (Art. 15 GDPR), to have it corrected (Art. 16), deleted (Art. 17) or restricted (Art. 18), to receive it in a portable format (Art. 20), and to object to processing based on legitimate interests (Art. 21). Where processing is based on consent, you can withdraw it at any time with effect for the future (Art. 7(3)).
You can also complain to a data protection supervisory authority, for example the one for Saxony-Anhalt in Magdeburg, or the one where you live or work.
8. Security
Connections use HTTPS, and vvdexops.com accepts them only through Cloudflare. Provider keys are encrypted with AES-256-GCM and bound to their workspace. Sign-in codes, session tokens and API keys are stored only as keyed hashes. Every workspace has an audit log in which each entry’s hash covers the one before it, so an edited or deleted entry shows. Exams run in sealed sandboxes with no network. To report a security problem, see security.txt.
9. No automated decisions
VVDex makes no decisions about you based solely on automated processing that have legal or similarly significant effects (Art. 22 GDPR). Scores in VVDex are about AI models, not about people.
10. Changes
We will update this policy when the service changes. For material changes that affect data we already hold, we will tell signed-up users by email.