Effective date: August 6, 2026 · Last updated: August 6, 2026
Scope
This policy covers personal data we process as a controller through:- our websites (https://vessl.ai, https://docs.cloud.vessl.ai);
- the VESSL Cloud service (https://cloud.vessl.ai); and
- our communications and support channels,
Who is responsible (controller)
The controller of your personal data depends on the processing:- VESSL AI KOREA Inc. (주식회사 베슬에이아이코리아), based in Seoul, Republic of Korea, is the controller for any processing of personal data where VESSL AI KOREA Inc. is the contracting entity.
- VESSL AI, Inc., based in the United States, is the controller for any processing of personal data where VESSL AI, Inc. is the contracting entity.
1. Personal data we collect
We collect only what we need to provide and secure the Services. We do not seek to collect special-category data (e.g., health, biometrics, political opinions). Please do not submit such data in free-text fields.
Where you access the Services through our command-line interface (CLI) or software development kits (SDKs), we also collect limited diagnostic and usage telemetry — such as the command invoked, CLI/SDK and runtime versions, operating-system type, and error or crash reports — to maintain, secure, and improve those tools. You can limit this collection as described in our CLI documentation.
2. Why we use your data, and our legal bases
We may use each of the categories of information that we collect for the business purposes described in the table below. Where such concept is recognized under applicable privacy laws, we process personal data based on the following legal bases:
Where we rely on legitimate interests, we have balanced those interests against your rights; you may object at any time (see “Your rights”). Where we rely on consent, you may withdraw it at any time without affecting prior processing.
3. Marketing and your choices
We send marketing communications in accordance with applicable law including with your consent where it is required by law. To opt out of email marketing communications, please click on the unsubscribe link or follow the directions within the email marketing communications you have received from us. You also can opt out via your account settings or by emailing privacy@vessl.ai. Transactional and service messages (e.g., security, billing, service announcements) are not marketing and are sent as part of the Service.4. Who we share your data with
We may share the categories of personal data listed above with the following entities:- Group company. We may share personal data between group entities (VESSL AI KOREA Inc. and VESSL AI, Inc.) for service delivery, customer support, product improvement, compliance, and internal reporting.
- Sub-processors / service providers. We use the vendors listed in our Sub-processor List (e.g., AWS for hosting, Stripe for payments, SendGrid/Resend for email, HubSpot for CRM, Sentry/Datadog for monitoring). They act on our instructions under data-protection contracts.
- Advertising & analytics partners. Subject to your cookie consent, we use third-party providers — Google (Google Analytics and Google Ads / DoubleClick), LinkedIn (Insight Tag), Amplitude (product-usage analytics), HubSpot (website visitor tracking and campaign measurement), Mintlify (documentation-site analytics), and Arcade (interactive product demos in the documentation) — for website analytics, advertising, and campaign measurement. These providers are listed in our Sub-processor List.
- Payment processing. Card payments are handled by Stripe, contracted through VESSL AI, Inc.
- Legal and safety. We may disclose data to comply with law, respond to lawful requests by public authorities, enforce our terms, or protect rights, property, and safety.
- Corporate transactions. In a merger, acquisition, asset sale, or other substantial corporate transaction, data may be transferred.
5. International data transfers
VESSL AI KOREA Inc. is based in the Republic of Korea, and VESSL AI, Inc. is based in the United States. The primary hosting region for account and operational data is AWS Seoul (Republic of Korea), but many of our sub-processors are based in the US. When we transfer personal data originating from the EEA or the UK to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses (SCCs) and the UK Addendum to the SCCs, with supplementary measures where appropriate. You can request a copy of the relevant safeguards by emailing privacy@vessl.ai.6. How long we keep your data
We keep personal data only as long as necessary for the purposes above, then delete or anonymise it:- Account data — for the life of the account. Following a voluntary account-deletion request, ordinary access ends immediately and, unless the account holder gives an action-specific instruction for earlier irreversible deletion, account data may be retained for up to fourteen (14) days solely to permit controlled account recovery. It is then deleted or anonymised unless a longer period is required by law. Customer Content processed on a customer’s behalf remains governed by the DPA rather than this Policy.
- Billing, tax, and transaction records — for the periods required by applicable commercial and tax law.
- Security/access logs — for the period required to operate and secure the Services and to meet legal obligations.
- Marketing data — until you withdraw consent or object.
7. Your rights
Subject to applicable laws, you may have the right to:- access your personal data and obtain a copy;
- rectify inaccurate or incomplete data;
- erase your data (“right to be forgotten”);
- restrict processing;
- data portability — receive your data in a portable format;
- object to processing based on legitimate interests, and to direct marketing at any time; and
- withdraw consent at any time where processing is based on consent.
8. Cookies
We use cookies and similar technologies as described in our Cookie Policy. Every cookie and browser-storage key we use is identified individually — with its provider, category, host, purpose, and duration — in our Cookie List. You can manage non-essential cookies through our cookie banner. Analytics, advertising, and other non-essential cookies are set only with your consent. A small number of strictly necessary cookies are used without consent as permitted by applicable law, including some set by providers on our behalf for sign-in and payment fraud prevention.9. Security
We maintain technical, organisational, and physical safeguards appropriate to the risk — including encryption in transit (TLS), hashing of passwords, encryption of secrets, access controls with multi-factor authentication, logging, and storage with certified cloud providers (e.g., ISO 27001 / SOC 2). No method of transmission or storage is perfectly secure, but we work to protect your data and to notify you and regulators of breaches as required by law.10. Region-specific provisions
California (CCPA). If you are a California resident, you have rights to know, access, correct, and delete your personal information, and not to be retaliated against for exercising any of these privacy rights. You or your authorized agent may exercise these rights as described in Section 7, and we do not discriminate against you for exercising them. We do not sell personal information for money. To the extent our use of Targeting cookies constitutes “sharing” or targeted-advertising processing under California or other applicable law, you may opt out at any time through the “Manage cookies” control or a recognized Global Privacy Control signal. See our Cookie Policy Section 5. We do not collect or share sensitive information except in ways permitted under the CCPA. To exercise these rights, email privacy@vessl.ai. General Data Protection Regulation (GDPR) – European Representative Pursuant to Article 27 of the General Data Protection Regulation (GDPR), VESSL AI Korea Inc. and VESSL AI Inc. has appointed European Data Protection Office (EDPO) as its GDPR Representative in the EU. You can contact EDPO regarding matters pertaining to the GDPR:- by using EDPO’s online request form: https://edpo.com/gdpr-data-request
- by writing to EDPO at Avenue Huart Hamoir 71, 1030 Brussels, Belgium
- by using EDPO’s online request and complaint form: https://edpo.com/uk-gdpr-data-request/
- by writing to EDPO UK at Unit 33, Waterside, Schooner Court, 44-48 Wharf Road, London, N1 7UX, United Kingdom