Privacy Policy
Last updated
June 2026 update: Switched the marketing site from PostHog to Cloudflare Web Analytics, a cookieless analytics service that stores nothing in your browser and does not track you across sites.
August 2026 update: Named every sub-processor individually, added dedicated sections for US state privacy rights and the UAE Personal Data Protection Law, and documented automated decision-making, breach notification, and marketing-email consent.
1. Who We Are
VenturOS is operated by Venture Operating Systems - FZCO ("VenturOS," "we," "us," or "our"), a Free Zone Company registered at DTEC, Dubai Silicon Oasis, Dubai, United Arab Emirates. We are the data controller for the personal data processed through our platform at ventur-os.com and associated services.
For any privacy-related questions, contact us at: hello [at] ventur-os.com
2. What Data We Collect
Account & Authentication Data
When you create an account, we collect: full name, email address, display name, profile photo (optional), account ID, hashed password, and authentication tokens.
Workspace & Business Data
In the course of using VenturOS, you and your team may upload or input: company information (name, stage, industry), financial data you choose to share (revenue, expenses, projections), pitch decks and documents, GitHub repository contents (read-only when you connect a repo), OKRs and milestones, team member information, and other business data you choose to enter.
Technical & Usage Data
We automatically collect limited technical and usage data: IP address, browser type and version, device type and operating system, pages visited, selected product events, and sanitized referrer data when available. On the marketing site, we use Cloudflare Web Analytics, a cookieless, privacy-first service: it does not set cookies or store identifiers in your browser, it does not track you across sites, and it reports only aggregate metrics such as page views and referrers.
Payment Data
If you subscribe to a paid plan, our payment processor collects billing information. We do not store full credit card numbers on our servers.
3. What We Do NOT Collect
We do not collect: biometric data, health or medical information, religious or political affiliations, racial or ethnic origin, sexual orientation, genetic data, data from minors (our service is not directed at anyone under 18), or contacts, calendars, or social graphs from your device.
4. How We Use Your Data
- Service delivery: To operate, maintain, and improve VenturOS and provide you with the features you use.
- Authentication & security: To verify your identity, protect your account, and detect fraud or abuse.
- AI features: To power AI-assisted features within the platform. Your business data may be sent to AI providers for processing your specific requests. We do not use your data to train third-party AI models.
- Communication: To send you service-related notices, respond to support requests, and (with your consent) send product updates.
- Analytics: To understand how VenturOS is used, diagnose issues, and improve the product.
- Legal compliance: To comply with applicable laws, regulations, and legal processes.
5. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), the United Kingdom, or another jurisdiction where GDPR or similar legislation applies, we process your data on the following legal bases:
- Contract performance: Processing necessary to provide you the VenturOS service you signed up for (Article 6(1)(b) GDPR).
- Legitimate interests: Cookieless analytics, security, fraud prevention, and product improvement, where these interests are not overridden by your rights (Article 6(1)(f) GDPR).
- Consent: Marketing communications and any optional cookies or browser storage we may introduce in the future, which you can withdraw at any time (Article 6(1)(a) GDPR).
- Legal obligation: Where we are required to process data by law (Article 6(1)(c) GDPR).
6. AI Data Processing
Ownership of inputs and outputs
You retain full ownership of everything you bring into VenturOS (your idea, repo context, uploaded documents, and conversations with your Team) and of all AI-generated outputs produced for you. We do not share, sell, license, or expose your inputs or outputs to other users or third parties, except sub-processors strictly required to deliver the service. We do not use your data, code, or conversations to train, fine-tune, or evaluate any AI model - ours or our providers'. See our Trust & Data page for the plain-language version.
VenturOS uses artificial intelligence to provide features such as automated analysis, content generation, and strategic recommendations. When you use AI-powered features:
- Your data is sent to third-party AI providers solely to process your specific request.
- We do not permit AI providers to use your data for training their models.
- AI outputs are generated based on your inputs and are not shared with other users.
- You retain full ownership of your inputs and the AI-generated outputs.
We contractually require our AI providers to maintain confidentiality and not retain your data beyond what is necessary to fulfill the request.
7. Third-Party Service Providers
We name every sub-processor that may process personal data on our behalf. This list is current as of the “Last updated” date at the top of this page; we update it whenever a provider changes.
| Sub-processor | Purpose | Data processed | Data region |
|---|---|---|---|
| Microsoft Azure (Microsoft Corporation) | Application hosting, compute, object storage, cache and sessions | Account, workspace and technical data | EU / US |
| Supabase, Inc. | Database, authentication and serverless functions | Account credentials, waitlist and access-request records | EU |
| Cloudflare, Inc. | CDN, DNS, DDoS protection and cookieless web analytics | IP address and request metadata; analytics reported in aggregate only | Global edge |
| Brevo (Sendinblue SAS) | Transactional and product-update email delivery | Email address, name, message content | EU |
| GitHub, Inc. | Read-only repository context when you connect a repo | Repository content you authorise | US |
| Anthropic, PBC | AI inference for AI-powered features | Prompt and context content you submit | US |
| OpenAI, L.L.C. | AI inference for AI-powered features | Prompt and context content you submit | US |
| Google LLC (Gemini API) | AI inference for AI-powered features | Prompt and context content you submit | US |
| OpenRouter, Inc. | AI model routing and inference gateway | Prompt and context content you submit | US |
| Resend (Plus Five Five, Inc.) | Transactional email delivery | Email address, name, message content | US / EU |
| Stripe, Inc. | Payment and subscription processing on paid plans | Billing details, collected and stored by Stripe | US / EU |
All sub-processors are bound by data processing agreements that require them to process your data only on our instructions, maintain appropriate security measures, and comply with applicable data protection laws. Our AI providers are contractually prohibited from training models on your data.
8. International Data Transfers
Your data may be transferred to and processed in countries outside the UAE, EEA, or your country of residence. When we transfer data internationally, we ensure appropriate safeguards are in place, including: Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions where applicable, and contractual commitments with service providers requiring equivalent protection.
9. Data Retention
- Account data: Retained for the duration of your account, plus 30 days after deletion request to allow recovery.
- Workspace data: Retained for the duration of your account. Deleted within 90 days of account closure.
- Usage and analytics data: Event-level analytics retained for up to 12 months; aggregate analytics may be retained indefinitely.
- Payment records: Retained for 7 years as required by UAE and international accounting regulations.
- Support correspondence: Retained for 3 years after resolution.
- Waitlist and access-request records: Retained for up to 24 months from signup, then deleted automatically by a scheduled job. The job skips any record tied to an open data-subject request, so evidence is never destroyed mid-request.
- Data-subject request records: Retained for 3 years from the date the request is closed, as compliance evidence, and excluded from the scheduled deletion above.
10. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data ("right to be forgotten").
- Portability: Request your data in a structured, machine-readable format.
- Restriction: Request that we limit processing of your data.
- Objection: Object to processing based on legitimate interests.
- Withdraw consent: Where processing is based on consent, withdraw it at any time.
- Lodge a complaint: You have the right to lodge a complaint with a supervisory authority.
To exercise any of these rights, use our data request form, which timestamps your request and returns a reference ID so our response deadline is on the record. You can also contact us at hello [at] ventur-os.com.
Before we act on a request, we verify your identity in proportion to the sensitivity of the data — usually by confirming control of the email address on the account. An authorised agent may submit a request on your behalf with written permission that we can verify. Exercising your rights is free and never results in degraded service or different pricing.
| Where you are | Framework | Our response deadline |
|---|---|---|
| EEA / UK / Switzerland | GDPR, UK GDPR | 1 month, extendable by 2 months for complex requests |
| United States (state privacy laws) | CCPA/CPRA and comparable state laws | 45 days, extendable once by a further 45 days |
| United Arab Emirates | Federal Decree-Law No. 45 of 2021 (PDPL) | 1 month, extendable where the law allows |
| Everywhere else | Local law, or our default | 30 days |
11. United States State Privacy Rights
Notice at collection (California)
If you are a California resident, this section serves as our notice at collection under the California Consumer Privacy Act as amended by the CPRA. In the past 12 months we have collected the following categories of personal information:
| CCPA category | Examples | Purpose | Disclosed to |
|---|---|---|---|
| Identifiers | Name, email address, account ID, IP address | Account creation, authentication, support, waitlist | Hosting, database, email and analytics sub-processors |
| Commercial information | Subscription plan, billing records | Billing and account administration | Payment processor |
| Internet or network activity | Pages visited, referrer, device and browser type | Aggregate analytics, security, diagnostics | Analytics and hosting sub-processors |
| Professional or employment information | Company, role, stage, business data you enter | Service delivery and AI features | Hosting, database and AI inference sub-processors |
| Inferences | AI-generated summaries and recommendations from your inputs | Service delivery | Hosting and AI inference sub-processors |
No sale or sharing
We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA. We have not done so in the preceding 12 months, and we do not sell or share the personal information of anyone under 16. Because we do not sell or share, there is no “Do Not Sell or Share My Personal Information” opt-out to submit — but our marketing site also honours Global Privacy Control signals for analytics.
Sensitive personal information
We do not collect sensitive personal information for the purpose of inferring characteristics, and we do not use or disclose it beyond the purposes permitted under CCPA section 7027(m). We do not need a “Limit the Use of My Sensitive Personal Information” control.
California rights
California residents may request to know, access, delete, and correct personal information, request portability, and opt out of sale/sharing (not applicable here). We will not discriminate against you for exercising any of these rights.
Other US states
If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, or another state with a comprehensive privacy law, you have broadly equivalent rights to confirm, access, correct, delete, and port your personal data, and to opt out of targeted advertising, sale, and profiling with legal or similarly significant effects. We do not conduct targeted advertising, sell personal data, or engage in that kind of profiling. If we decline a request, you may appeal by replying to our decision or emailing hello [at] ventur-os.com with “Privacy appeal” in the subject; we respond to appeals within 45 days and will tell you how to contact your state Attorney General if you remain unsatisfied.
12. UAE Personal Data Protection Law
VenturOS is established in the United Arab Emirates, and processing of personal data is carried out in accordance with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and its implementing rules, alongside the applicable free zone regulations for DTEC / Dubai Silicon Oasis.
- Lawful bases: we rely on your consent, performance of a contract with you, our legitimate interests where these do not override your rights, and compliance with legal obligations — mirroring the grounds in Article 4 PDPL.
- Your PDPL rights: the right to obtain information about processing, request a copy of your data, request rectification or erasure, restrict or object to processing, request that processing stops, and object to automated processing that produces legal effects.
- Cross-border transfers: we transfer personal data outside the UAE only to jurisdictions with an adequate level of protection, or under contractual safeguards that require an equivalent standard of protection, as permitted by Articles 22 and 23 PDPL.
- Complaints: you may complain to us at hello [at] ventur-os.com and, if unresolved, to the UAE Data Office.
13. Automated Decision-Making and AI
VenturOS uses AI models — third-party frontier models and our own runtime — to generate analysis, drafts, plans, and recommendations. These outputs are suggestions for you to review; we do not make decisions that produce legal or similarly significant effects about you by purely automated means within the meaning of Article 22 GDPR. Where you configure the Service to act on your behalf, actions that leave the platform require your approval.
We do not use your venture data, code, or conversations to train, fine-tune, or evaluate any AI model — ours or our providers'. We tell you when you are interacting with AI and we label AI-generated content, aligned with the EU AI Act's transparency requirements. See our AI transparency page for details.
14. Email and Marketing Communications
We distinguish two kinds of email:
- Transactional email — waitlist confirmations, invite and access notifications, security alerts, billing notices, and replies to your support requests. These are sent because you asked for the service or because we are required to send them, and they are not marketing.
- Marketing email — product updates, launches, and occasional founder notes. These are optional and sent only with your consent where consent is required. Every marketing email contains a one-click unsubscribe link and our postal identity, and you can also opt out at any time by emailing hello [at] ventur-os.com. Unsubscribing from marketing never stops transactional email you still need.
15. Data Security
We implement appropriate technical and organisational measures to protect your data, including: hosting on Microsoft Azure with access controls and best-practice security safeguards (encryption is being rolled out), authentication, regular security assessments, employee access limited to need-to-know basis, and incident response procedures.
16. Personal Data Breach Notification
We maintain an incident response process for suspected personal data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it (Article 33 GDPR), and we notify the UAE Data Office in line with PDPL requirements. Where the breach is likely to result in a high risk to you, we notify you directly without undue delay, describing what happened, the likely consequences, and the steps we are taking. Where US state law requires it, we notify affected residents and regulators within the applicable statutory timeframes.
17. Children's Privacy
VenturOS is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a minor, we will take steps to delete it promptly.
18. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and, where appropriate, by email. Your continued use of VenturOS after the effective date of any changes constitutes acceptance of the updated policy.
19. Contact Us
Venture Operating Systems - FZCO
DTEC, Dubai Silicon Oasis
Dubai, United Arab Emirates
Email: hello [at] ventur-os.com