Skip to main content
Virent

Legal

Privacy Policy

This policy explains how Virent collects, uses, discloses, and protects personal information across our websites, applications, analytics SDK, and related services.

Effective July 22, 2026

01

Scope and our role

This Privacy Policy applies to Virent’s websites, waitlist, applications, software development kits, APIs, support channels, and related services (collectively, the “Services”). “Virent,” “we,” “us,” and “our” refer to the provider of the Services identified in an applicable order form or agreement.

When we handle account, website, waitlist, sales, or support information for our own purposes, Virent acts as a controller, including a controlador under Brazil’s LGPD, or a business where those terms apply. When a customer uses Virent to collect or analyze information from its own websites, applications, prompts, or users, Virent generally acts as a processor, operador under the LGPD, or service provider on that customer’s instructions. The customer remains responsible for its own notices, choices, lawful basis, and instructions.

02

Information we collect

Information you provide

  • Account and profile details, such as name, business email, authentication details, workspace, and role.
  • Waitlist and business details, such as name, email, phone number, and website.
  • Billing and transaction details handled by us or our payment providers when paid services are available.
  • Communications, feedback, support requests, and any files or context you choose to provide.

Information generated through the Services

  • Service and device data, including log events, browser or device type, timestamps, referring pages, and approximate network context.
  • Human analytics selected by a customer, such as pageviews, sessions, referral context, pseudonymous identifiers, events, and conversion goals.
  • Crawler analytics, such as requested URL, bot classification, user-agent, response status, timing, and pseudonymous or derived network signals. Network addresses may be processed transiently for security, rate limiting, or derivation where configured.
  • LLM visibility and prompt-tracking data, including prompts, model or provider, generated answers, mentions, rankings, citations, comparison results, and run history.
  • Product usage and configuration data, including integrations, monitored domains, filters, saved views, and feature interactions.

Information from other sources

  • Information a workspace administrator or teammate provides about authorized users.
  • Publicly available website, domain, company, and citation information needed to perform requested visibility analysis.
  • Information from integrations that a customer chooses to connect, subject to that integration’s settings and terms.
03

How we use information

Depending on context and applicable law, we rely on performance of a contract or pre-contractual steps, legitimate interests in operating and protecting the Services after considering necessity and individual rights, consent where required, compliance with legal or regulatory obligations, and the establishment or defense of legal claims. We do not use Customer Data to train general-purpose AI models unless the customer expressly agrees.

  • Provide, operate, secure, troubleshoot, and improve the Services.
  • Create accounts, manage workspaces, process waitlist requests, and communicate about access.
  • Measure human activity, classify crawler traffic, run prompt and visibility analyses, and generate customer-requested reports.
  • Personalize settings, maintain service integrity, prevent abuse, enforce terms, and comply with law.
  • Understand feature performance and develop new functionality using aggregated, de-identified, or otherwise lawfully processed information.
04

How we disclose information

We disclose information only as needed for the purposes described in this policy. We do not sell personal information or share it for cross-context behavioral advertising.

  • Vendors and subprocessors that provide hosting, storage, security, authentication, communications, payments, analytics infrastructure, or AI model access under contractual safeguards.
  • Workspace administrators and authorized users according to the customer’s settings.
  • Integration providers when a customer directs us to connect or transmit data.
  • Professional advisers, authorities, or other parties when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or complete a corporate transaction.
05

Cookies and similar technologies

We may use cookies or local storage that are necessary for authentication, security, preferences, and reliable operation. We do not use the Virent website for cross-context behavioral advertising. A customer that deploys Virent analytics on its own property controls that deployment and is responsible for any consent or notice required by law.

06

Retention

We retain personal information only as long as reasonably necessary to provide the Services, satisfy the purposes described here, meet contractual or legal obligations, resolve disputes, and protect the Services. Retention depends on the data type, workspace settings, agreement, and whether the information can be safely deleted or de-identified. Customer Data is returned or deleted as described in the applicable agreement and Data Processing Addendum.

07

Security

We use administrative, technical, and organizational safeguards designed for the nature and risk of the information we process. These include access controls, data minimization, encryption in transit, protected secrets, logging, and incident response practices where appropriate. No system can guarantee absolute security. Please report suspected security issues privately to our contact email and do not include secrets or unnecessary personal information.

08

International data transfers

Virent and its providers may process information in countries other than where it was collected. For information protected by European or UK law, we use a lawful transfer basis where required, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, or the UK International Data Transfer Agreement or Addendum, together with transfer-risk assessments and supplementary measures where appropriate.

For personal data transferred from Brazil, we apply the mechanisms required by the LGPD and ANPD Resolution CD/ANPD No. 19/2024. Depending on the transfer, this may include an ANPD adequacy decision, the Brazilian standard contractual clauses, approved specific contractual clauses, global corporate rules, or another mechanism expressly permitted by the LGPD. EU or foreign adequacy decisions do not by themselves authorize a Brazilian transfer.

09

Your privacy rights

Depending on where you live, you may have rights to confirm whether we process your information; access, correct, anonymize, block, restrict, object to, or delete it; receive a portable copy where technically and legally available; withdraw consent; obtain information about disclosures and the consequences of withholding consent; opt out of certain processing; or appeal a denied request. You may also have rights concerning solely automated decisions that produce legal or similarly significant effects.

To make a request, email virent.app@gmail.com. Requests may be submitted in English or Portuguese. Describe the request and the account, workspace, or email involved. We may verify your identity and authority before acting. We will respond within the period required by applicable law. If Virent processes the information for a customer, we may direct you to that customer or assist it with the request.

10

European, UK, and Swiss disclosures

If the GDPR, UK GDPR, or Swiss Federal Act on Data Protection applies, you may exercise the applicable rights described above and lodge a complaint with the supervisory authority where you live, work, or believe an infringement occurred. You may withdraw consent without affecting processing that was lawful before withdrawal and object to processing based on legitimate interests.

Virent is not designed to make decisions about individuals based solely on automated processing that produce legal or similarly significant effects. If a customer uses Virent output in such a process, that customer is responsible for the decision, required safeguards, human review, and notice. Where legally required, Virent will designate an EU or UK representative or data protection officer and publish the relevant details.

11

Brazil disclosures

If the Lei Geral de Proteção de Dados Pessoais, Law No. 13,709/2018 (LGPD), applies, Virent processes personal data in accordance with the LGPD principles of purpose, adequacy, necessity, free access, data quality, transparency, security, prevention, nondiscrimination, and accountability.

Brazilian data subjects may request confirmation and access; correction; anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed data; portability as regulated; deletion of data processed on consent, subject to legal retention; information about public and private entities with which data was shared; information about the consequences of withholding consent; consent withdrawal; review of qualifying automated decisions; and an explanation of the criteria used, subject to lawful protections for trade and industrial secrets.

Virent provides virent.app@gmail.com as its channel for Brazilian data subjects and the ANPD. Where Virent is an operador for a customer, the customer is the controlador responsible for the request. You may petition the Autoridade Nacional de Proteção de Dados (ANPD) after first raising the matter with the relevant controlador, as applicable.

12

Additional United States disclosures

During the preceding 12 months, we may have collected the categories described above: identifiers and contact information; internet or electronic activity; commercial and account information; approximate geolocation derived from network information; professional information; and inferences related to product or visibility analytics. We collect and disclose these categories for the business purposes described in this policy.

We do not sell personal information, share it for cross-context behavioral advertising, or use sensitive personal information to infer characteristics about individuals. Where applicable, authorized agents may submit requests, and eligible users may appeal a decision by replying to our response.

13

Children

The Services are designed for businesses and are not directed to children under 16. We do not knowingly collect personal information from children through the Services. If you believe a child has provided information, contact us so we can review and delete it where appropriate.

14

Changes and contact

We may update this policy to reflect changes to the Services, law, or our practices. We will post the revised policy with a new effective date and provide additional notice when required.

Questions, privacy requests, security reports, and other contacts should be sent to virent.app@gmail.com. This is also Virent’s privacy contact channel for data subjects, supervisory authorities, and the ANPD. If law requires Virent to appoint and publicly identify a data protection officer, representative, or encarregado, we will update this section with that person’s or representative’s details.