Who this policy covers
This Privacy Policy explains how Vedric ("Vedric," "we," "us") collects, uses, discloses, and protects personal data. It applies to three audiences:
- Website visitors - anyone browsing vedric.io or related public properties.
- Customer personnel - administrators, analysts, and other users at organizations that have purchased our Services.
- End-users of monitored endpoints - employees, contractors, and other personnel of our Customers whose workstation activity is observed by the Vedric agent. Important: Vedric does not have a direct relationship with these individuals. See Section 4.
Data we collect from website visitors
When you visit vedric.io, we collect basic web analytics: IP address, browser type, pages requested, referring URL, and approximate geographic region. We use this to operate the website and understand which content is useful. We do not use third-party advertising trackers, cross-site identifiers, or sell visitor data.
If you contact us through the demo form or by email, we collect the information you provide (typically name, work email, company, role, and message contents) to respond to your inquiry.
Data we collect from customer accounts
When a customer organization creates an account, administrators provide names, work email addresses, and role designations for users who will access the Vedric platform. We use this information to authenticate users, deliver service notifications, and provide support.
We collect operational telemetry from the Vedric platform (logins, audit events, support tickets) to maintain the service, investigate incidents, prevent abuse, and improve product quality.
Endpoint telemetry and the controller / processor relationship
The Vedric agent runs on endpoints owned or managed by our Customers and collects behavioral metadata about activity on those endpoints. For this telemetry, Vedric acts as a "data processor" (or equivalent role under applicable law). The Customer is the "data controller." This means:
- The Customer determines the purposes and means of processing.
- The Customer is responsible for establishing the lawful basis for monitoring (typically employer's legitimate interest in security, or consent), and for providing notice to monitored individuals as required by law.
- Vedric processes endpoint telemetry only as instructed by the Customer through configuration of the Services and as necessary to deliver the Services.
- Requests from monitored individuals (access, correction, deletion, portability, objection) should be addressed to the Customer organization, who controls the data. Vedric will assist Customers in responding to such requests as required by Article 28 GDPR or equivalent law.
For Customers subject to GDPR or similar regulations, we offer a Data Processing Addendum (DPA) governing this relationship. Request a copy at legal@vedric.io.
What endpoint telemetry actually contains
The agent captures behavioral metadata - characteristics of activity, not the content of activity.
What is collected
- Process and command-line metadata.
- Authentication and privilege-change events.
- Network destination and DNS query metadata.
- File-system activity metadata (extension, size, location - never contents).
- Removable-media activity.
- Persistence-mechanism inventory.
- Decoded script-block content where host logging is enabled.
- Kernel-level process metadata where available.
What the agent does not collect
- File contents.
- Keystrokes.
- Screenshots.
- Browser history or page content.
- Email or chat message bodies.
- Clipboard data.
- Microphone or camera input.
- Location-services data.
These code paths are not present in the agent. End-user identifiers from the endpoint are anonymized at the source through a one-way cryptographic transformation before transmission.
How DNS observation works
DNS query metadata - the domain strings your endpoints resolve - is retained as observed within your tenant. We keep the domain string itself rather than a hash because behavioral detection compares domains against the endpoint's own history and against published threat-indicator feeds; both require the original string to be meaningful.
We do not record the IP addresses returned by DNS responses beyond aggregate counts, the data subsequently transferred to or from those domains, the bodies of any web requests, or any client-side DNS cache contents beyond the queries actually made by monitored processes. Domain telemetry is isolated to the customer's tenant and is never shared cross-customer or used to train cross-customer models without express consent.
How we use personal data
- Provide, maintain, secure, and improve the Services.
- Generate behavioral baselines and security alerts for the Customer organization.
- Authenticate users and enforce access controls.
- Communicate about accounts, service changes, security notices, and support.
- Comply with legal obligations and respond to lawful government requests.
- Investigate suspected violations of our terms or applicable law.
- Defend Vedric's legal rights, property, and the safety of others.
We do not sell, rent, or share personal data with third parties for their marketing purposes. We do not use endpoint telemetry to train cross-customer models without the Customer's express consent.
Lawful bases for processing (GDPR / UK GDPR)
Where Vedric is the controller of personal data (e.g., for visitor analytics, customer account administration, payment processing), our lawful bases include:
- Performance of a contract - to deliver the Services to our Customers.
- Legitimate interests - to operate, secure, and improve our Services and protect against abuse.
- Legal obligation - to comply with tax, accounting, audit, and other legal requirements.
- Consent - where applicable, such as marketing communications you can opt out of at any time.
Where Vedric is the processor (endpoint telemetry from a Customer's environment), the lawful basis is established by the Customer as controller.
Data sharing and subprocessors
We share personal data only as follows:
- With subprocessors who help us operate the Services. We require subprocessors to handle data with at least the same protections required by this Policy. Our current list is available on request, and we provide at least thirty (30) days advance notice before adding a new subprocessor that processes Customer Data, except where prevented by law.
- With our Customers - endpoint telemetry collected from a Customer's environment is shown to that Customer only.
- To comply with law - in response to a valid legal process or to protect rights, property, or safety.
- In connection with a corporate transaction - merger, acquisition, or sale of assets, with notice as required by law.
International data transfers
Vedric is operated from the United States and our infrastructure may store and process data in multiple jurisdictions. For Customers in the European Economic Area, United Kingdom, or Switzerland, we rely on Standard Contractual Clauses (or equivalent legal mechanisms in force from time to time) to provide an adequate level of protection for personal data transferred internationally.
Data retention
We retain personal data only as long as necessary for the purposes outlined in this Policy, or as required by law:
- Visitor analytics: aggregated after a short window; raw logs typically retained for less than ninety (90) days.
- Customer account information: for the duration of the subscription plus a reasonable period thereafter for legal and operational purposes.
- Endpoint telemetry (active tier): retained per the Customer's configured retention windows for live detection and the analyst surface. Default windows are configurable by the Customer; the Customer instructs Vedric on retention through Service settings.
- Forensic cold-archive tier: beyond the active retention window, full endpoint telemetry is moved to a compressed cold archive and retained for up to three hundred sixty-five (365) days to support after-the-fact incident investigation and forensic review. This longer-retained archive is metadata-only (it contains the same behavioral metadata as the active tier - never file contents, keystrokes, or message bodies). The Customer may request earlier deletion of archived telemetry through written notice.
- Audit logs and forensic records: retained as required by the Customer's compliance obligations and our legitimate operational interests; the Customer may request earlier deletion through written notice.
- Backups: retained for a limited operational window after primary data deletion to support disaster recovery.
Security
We implement reasonable and appropriate technical and organizational measures designed to protect personal data, including encryption of data in transit and at rest, multi-factor authentication for administrative access, role-based access controls, payload integrity verification on agent communications, append-only audit trails for sensitive actions, and regular review of access permissions. Third-party security assessments are scheduled.
No system is perfectly secure. While we work to protect personal data, we cannot guarantee absolute security against all threats, including those involving sophisticated or state-sponsored adversaries.
Security incident notification
If Vedric becomes aware of a security incident affecting personal data we process, we will notify affected Customers without undue delay and, in any event, within seventy-two (72) hours of confirming the incident, in accordance with applicable law. Notification will include the nature of the incident, the categories and approximate volume of data affected, the likely consequences, and the measures taken or proposed to address it.
Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, port, or restrict the processing of personal data we hold about you, and to object to certain processing activities. You may also have the right to lodge a complaint with a supervisory authority.
If Vedric is the controller of your data, contact us at legal@vedric.io. If Vedric is processing your data on behalf of a Customer (such as endpoint telemetry from your employer's environment), please direct your request to the Customer organization in the first instance - they control the data and we will support them in responding.
California residents (CCPA / CPRA)
The California Consumer Privacy Act provides specific rights including the right to know what personal information is collected, to access and delete that information, to opt out of "sale" or "sharing" (we do not sell or share personal information as defined under CCPA), and to non-discrimination for exercising your rights. Submit verifiable consumer requests to legal@vedric.io.
Children's privacy
Our Services are designed for use by organizations and their personnel, not by children. We do not knowingly collect personal information from individuals under sixteen (16) (or the age of digital consent in your jurisdiction). If we learn we have collected such information, we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by updating the "Last updated" date and, where appropriate, by notice on our website or to administrators of active Customer accounts. Your continued use of the Services after changes take effect constitutes acceptance of the updated Policy.
Contact
Privacy questions, data-subject requests, and notices under this Policy can be directed to the addresses below.
- PRIVACY + LEGAL
- legal@vedric.io
- SUPPORT
- support@vedric.io
- SALES
- info@vedric.io
- WEBSITE
- vedric.io
- DPA REQUESTS
- Email legal@vedric.io with subject "DPA Request"
For complaints to a supervisory authority, EEA / UK / Swiss residents may contact their local data protection authority directly. A current list is maintained by the European Data Protection Board and, for the UK, by the Information Commissioner's Office.
