Privacy Policy
Last updated: October 6, 2026. How we collect, use, and protect your personal data across venvera.com and the Venvera platform.
1. Who We Are
Venvera is operated by Atlant Security EOOD, registered in Sofia, Bulgaria. In this policy, “Venvera,” “we,” “us,” and “our” refer to Atlant Security EOOD.
We act as the data controller for personal data collected through our website (venvera.com) and marketing activities, and as a data processor for personal data our customers store in the Venvera platform (app.venvera.com).
2. Data We Collect
2.1 Website visitors
- Usage analytics (page views, referring site, country, device and browser type) collected by our own software running on our own servers in the EU. No third party receives it, and your IP address is used to derive a country and then discarded rather than stored
- IP address (truncated, not stored beyond the session)
- Cookies strictly necessary for site functionality, and a record of your cookie choice
- Only if you accept analytics cookies: Google Analytics and Google Ads measurement data (pages visited, the ad click that brought you, device and browser, approximate location, and cookie identifiers), collected by Google. If you decline, Google receives only cookieless signals without identifiers (Google Consent Mode)
2.2 Free Compliance Check
- Email address (if you choose to receive your report)
- Job title and organisation type (optional)
- Assessment answers and resulting score
2.3 Demo requests and contact forms
- Name, email address, company name
- Message content
2.4 Platform users (app.venvera.com)
- Name and business email (from SSO provider: Microsoft Entra ID or Google Workspace)
- Organisation membership and role within the platform
- Audit log of actions taken (for security and compliance)
3. How We Use Your Data
- Service delivery: To provide, maintain, and improve the Venvera platform
- Communication: To respond to enquiries, send assessment reports, and (with consent) share product updates
- Security: To detect, prevent, and respond to security incidents
- Legal compliance: To meet our obligations under GDPR and other applicable laws
- Analytics: To understand how our website and platform are used, in aggregate
- Advertising measurement: With your consent, to measure which of our ads bring visitors and enquiries
4. Legal Basis for Processing
- Contract performance: Processing necessary to deliver our services (Art. 6(1)(b) GDPR)
- Legitimate interest: Analytics, security monitoring, and fraud prevention (Art. 6(1)(f) GDPR)
- Consent: Marketing emails and non-essential cookies, including Google Analytics and Google Ads (Art. 6(1)(a) GDPR). You can withdraw consent at any time with Cookie settings at the bottom of every page
- Legal obligation: Record-keeping required by law (Art. 6(1)(c) GDPR)
5. Data Storage and Security
All data is hosted on EU-based infrastructure in Amsterdam, the Netherlands (DigitalOcean AMS3 region). We implement the following safeguards:
- Encryption at rest using AES-256-GCM with per-tenant encryption keys
- Encryption in transit using TLS 1.3
- PostgreSQL Row-Level Security for tenant data isolation
- Automated encrypted backups every 6 hours (AES-256, 30-day retention)
- Multi-factor authentication for infrastructure access
- Annual penetration testing and continuous vulnerability scanning
6. Data Sharing
We do not sell your personal data. We share data only with:
- Infrastructure providers: DigitalOcean (hosting), all EU-based
- Authentication providers: Microsoft Entra ID and Google Workspace (SSO only, no data stored by them)
- Error monitoring: Sentry (EU region), for application error tracking
- Google Ireland Limited: Google Analytics and Google Ads, only if you accept analytics cookies. Google may process this data in the United States; Google LLC is certified under the EU-US Data Privacy Framework
- Law enforcement: Only when required by law, with appropriate legal process
Apart from Google Analytics and Google Ads data where you have consented, no data is transferred outside the European Economic Area (EEA).
7. Data Retention
- Platform data: Retained for the duration of the customer’s subscription, plus 30 days for data export after termination
- Assessment results: Retained for 12 months, then automatically deleted
- Audit logs: Retained for 3 years as required for regulatory compliance
- Website analytics: Aggregated after 90 days; raw data deleted after 180 days
- Google Analytics: Kept by Google for the retention period set in our Google Analytics property, at most 14 months; the cookies themselves expire as listed in our Cookie Policy
- Marketing contacts: Until consent is withdrawn or the contact is inactive for 24 months
8. Your Rights
Under the GDPR, you have the right to:
- Access your personal data (Art. 15)
- Rectification of inaccurate data (Art. 16)
- Erasure (“right to be forgotten”) (Art. 17)
- Restrict processing (Art. 18)
- Data portability in machine-readable format (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
- Withdraw consent at any time (Art. 7(3))
To exercise these rights, email [email protected]. We will respond within 30 days.
9. Cookies
We use the following categories of cookies:
- Strictly necessary: Session cookies, CSRF protection, authentication tokens
- Analytics and advertising measurement, only with your consent: Google Analytics (_ga, _ga_<id>, up to 2 years) and Google Ads (_gcl_au; _gcl_aw or a similar _gcl_ ad click cookie when you arrive from one of our ads; _gcl_ls in local storage; all 90 days). Our own first-party analytics stay cookieless
On your first visit we ask whether you accept these cookies; rejecting is as easy as accepting, and you can change your choice at any time with Cookie settings at the bottom of every page. We do not use social-media tracking pixels, and we never sell information collected through cookies. Details are in our Cookie Policy.
10. Children’s Privacy
Venvera is a business-to-business service. We do not knowingly collect data from individuals under 16 years of age.
11. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email to registered users and posted on this page with the updated date.
12. Contact
For privacy-related enquiries:
Atlant Security EOOD
Email: [email protected]
Sofia, Bulgaria
You also have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP) at cpdp.bg.