Last updated 27 August 2026
INKASEC Ltd operates VitroVault ("we", "us"). This notice explains what personal data we hold and how we handle it. How we process the documents you upload, including our processor obligations, residency and retention, is set out in full in our Terms and Conditions of Service (clause 13, which is also the Data Processing Agreement). This notice is a separate document and does not form part of the Terms; where it and clause 13 differ as to our data-handling obligations to you, clause 13 prevails.
Which of us is responsible for what
VitroVault hosts a trust page that your buyers visit, so there are two relationships here rather than one.
For you, our customer, meaning the people who sign in and run a trust centre, we hold your account data and we are the controller of it. This notice is about that.
For everything you put into your trust centre, and for everyone who visits your trust page, you are the controller and we act as your processor under clause 13. If you are a buyer who verified an email address or accepted an agreement on a supplier's trust page, that supplier decides what happens to your details. Their own privacy notice is linked on their page where they have given us one, and a request about your data belongs with them; if you send it to us, we will pass it on and tell you we have.
Personal data we collect
Information that could identify you, including your name, company, email address, telephone number, and IP address. The documents you upload are your business information; to the extent they contain personal data, you are the controller and we act as your processor under the Terms.
How we use your data
- To provide the service you request: hosting your trust page, presenting what you publish, and
operating the access and agreement ceremonies your buyers complete.
- To send important service information, such as confirmations, invoices, renewal notices and the
prompts that keep your page current.
- To associate your email with your account for support purposes.
- To secure, operate and improve the service, including preventing misuse, fraud and abuse.
- To keep the record of what happened on your trust page, which is the part of the service you and
your buyers rely on: who accepted what, when, and what they were then able to read.
Lawful bases
- Contract: to perform our obligations in providing the service to you.
- Legitimate interests: to provide quality support, to secure, operate and improve the service,
and to keep records of consent and access that either of us may need to establish, exercise or defend a legal claim, where this is not overridden by your rights.
- Legal obligation: to retain financial and transaction records as required by law.
Sharing your data
We do not sell your data. We may share personal data with sub-processors and service providers (including our cloud and payment providers), our professional advisers and auditors, and courts or authorities where required by law or to protect vital interests. Sub-processors are engaged only on terms consistent with this notice and the DPA, and each one is named, with its location and what it receives, in Schedule 1 of the Terms.
International transfers and residency
Your materials are stored and processed within the EU (Ireland) region of our cloud infrastructure and do not leave the UK/EEA except where a lawful transfer mechanism is in place. We will tell you if we propose any such transfer. Two things are worth stating plainly rather than leaving to be discovered: trust pages are delivered through a content delivery network whose edge locations we confine to Europe and North America, which carries published page content and the visitor's network address but never a gated document, and our payment processor operates from Ireland with transfers to the United States under the mechanism in its own terms.
Automated processing
On the Managed tier we check, on a documentary basis, whether each expected area of a standard is addressed by a named document in your own material. It produces no score, no grade and no judgement about any person, a named person at your organisation approves the result before any of it reaches a buyer, and the models used run within our cloud provider's EU region and are not trained on your material. No decision with a legal or similarly significant effect on a person is made automatically.
Retention
- Your trust centre, meaning the documents you upload, what you publish, every acceptance by a
buyer and your whole event log, is kept while your trust centre exists and is permanently erased when it closes. There is no archive and no grace copy.
- Acceptance and access records in your event log: where erasure is requested, these are kept
for 18 months from the event, or until closure if that is sooner, because they are the record both you and your buyers rely on.
- Account records: retained for as long as your account is active. Our record that your
organisation accepted a version of our Terms is kept as the evidence of the agreement, and is not a copy of your trust centre.
- Financial records: for the period required by law, currently seven years.
- Operational and security logs (which may include IP addresses): retained to secure the service
and prevent misuse, for up to 18 months, then deleted.
Your rights
You have the right to be informed, to access your data, to rectification, to erasure (where applicable), to restrict or object to processing, to data portability, and to opt out of direct marketing. To exercise any of these, contact us using the details below.
One practical note: if you are an administrator asking us to erase your organisation's data, that is the closure path in the Terms, and it erases everything for everyone in the organisation. One person leaving your team is an offboarding, not a deletion of your trust centre.
Cookies
We do not use analytics or tracking cookies on this site, and we set no cookies at all. Two things are kept in your own browser's storage and neither leaves it: your sign-in tokens while you are using the console, and, on a trust page you have been granted access to, the token for that access and the email address you verified, so that returning does not mean repeating the ceremony. You can clear both by clearing your browser's site data.
Security
We maintain appropriate technical and organisational measures to protect your data, including encryption in transit and at rest, a separate storage container per organisation, access restricted to authorised personnel on a need-to-know basis, and an append-only record of what happens on your trust page. The measures are set out in full in Schedule 1 of the Terms. We require third parties who process data on our behalf to apply equivalent safeguards.
Contact and complaints
To exercise your rights or ask a question, email hello@vitrovault.com, or security@vitrovault.com for anything with a security dimension. We are registered with the Information Commissioner's Office (registration ZA284049). If you are unhappy with how we handle your data you may complain to the ICO: helpline 0303 123 1113, ico.org.uk, Wycliffe House, Water Lane, Wilmslow, SK9 5AF.