Who processes your data
VIT TEAM is a service that rents AI workers to businesses, a VITON13 brand. The personal data operator (controller) is —, BIN —, address: —.
Questions about data, requests and consent withdrawals go to —. These emails are read by the person responsible for organising personal data processing at our company.
This policy covers the website https://vitteam.tech and the VIT TEAM dashboard. Sign-in works through VITON ID, the shared account of the VITON13 ecosystem.
What we collect
Account. Your VITON ID email, its technical identifier and whether the email is confirmed. Your password is checked by Firebase Authentication (Google): we never see or store it.
Business profile. Name, products and services, audience, tone, what sets you apart, rules, links, customer reviews, geography, goals, time zone and the chosen factory.
Work with the team. Chat messages, tasks, the texts, photos and videos the team makes, approvals, rejections and comments, the dashboard activity log and the team's memory: what it learns from your feedback.
Dashboard team. The emails of the people you invite. If someone invited you, the dashboard owner added your email, and access opens when you sign in with it.
Connections. The Telegram bot token and the channel address where posts are published.
Research. Deep research reports: information from public websites with links to them. Reports may include public business contacts: phones, emails and addresses that companies published themselves.
Gifts. The gift you choose from the VITON13 studio and your notes for it.
Technical data. Cookies and browser storage (see “Cookies and browser storage”), the country code reported by the hosting, and server error logs.
We don't ask for ID numbers, identity documents, face photos or biometrics. Payments are not connected yet, so we hold no card data. When they are, a payment provider will process them and this policy will be updated.
Why we need it
To open your dashboard and keep it safe: the account, the sign-in cookie, error logs.
To let the team work: the business profile, messages, content, memory, research and connections.
To let in the people you invite, deliver your gift and answer your emails.
To meet legal requirements.
We don't sell data, use it for advertising or send newsletters. If we ever want to email you about the service, we'll ask separately.
Legal bases and consent
In Kazakhstan the basis is your consent (Articles 7 and 8 of the Law “On Personal Data and Its Protection”). You give it when you create a dashboard or sign in with VITON ID on this site.
What the consent covers. Operator: —, BIN —. Data: as listed in “What we collect”. Transfer to third parties: yes, only to the recipients in “Who receives your data”. Cross-border transfer: yes. Publication in public sources: no. We don't publish your data; posts go out only in your channels and only when you decide.
The consent lasts while you have a VIT TEAM dashboard, or until you withdraw it. You can withdraw it, including only the consent to cross-border transfer, by writing to —. The team can't work without processing data and sending it to AI providers, so withdrawing closes the dashboard. Consent can't be withdrawn where that would break the law or while an obligation is still unfulfilled (Article 8(2)).
If the GDPR (EU) applies to you, the bases are (GDPR Art. 6(1)): contract, for the account, the dashboard and the team's work; legitimate interests, for security, abuse prevention and public business contacts in research; legal obligation, for accounting records once payments start; consent, for anything we ask you about separately.
Who receives your data
The VIT TEAM team runs on AI models made by other companies. To do a task, we send them the part of your data it needs: the business profile, messages, task materials, the team's memory and search queries. Your email and password are not sent to the models.
Firebase Authentication (Google): VITON ID sign-in.
CometAPI: a gateway to the Claude (Anthropic), Gemini, Veo and Nano Banana (Google) models, and to Google Search for research.
Anthropic: Claude models directly, when that route is switched on.
Higgsfield: photos and videos.
Telegram: the posts you publish to your channel.
These companies' servers are outside Kazakhstan, including in the USA. This is a cross-border transfer: in Kazakhstan it needs your consent (Article 7(6) and Article 16 of the Personal Data Law), and it is part of the consent in “Legal bases and consent”. Where the GDPR applies, transfers outside the EEA rely on adequacy decisions or standard contractual clauses (GDPR Arts. 44–46) offered by these providers.
We don't hand your data over to train models: providers receive it to carry out the request and process it under their API terms. The team's memory lives inside your dashboard and never moves to other clients' dashboards.
People from the VITON13 studio see the dashboard owner's email and gift notes so they can make the gift. Our staff open a dashboard's content only when a gift, your request or a fix needs it. We disclose data to public authorities only when the law requires it.
Where and how long we keep it
Dashboard data is stored in a database on our server. Hosting country: the Netherlands.
While a dashboard exists, its data is kept, including after the trial or the rental ends, so the team can pick up where it stopped.
If the rental ended more than 12 months ago and hasn't been renewed, we may delete the dashboard, with an email warning 14 days in advance.
On request we delete the whole dashboard: the profile, chat, content, memory, connections and team list. Your VITON ID stays: it is shared across the VITON13 ecosystem and can be deleted with a separate request.
Payment records, once there are any, are kept as long as tax and accounting law requires. Cookie lifetimes are listed in “Cookies and browser storage”.
Other people's data
Sometimes you give us other people's data: customer reviews in the profile, colleagues' emails, contacts from research. We process it on your behalf and only for your team's work. Make sure you have a basis for it, such as those people's consent.
Research opens only the pages the task needs, respects robots.txt and keeps a link to the source. We don't build databases by mass extraction from public sources: Kazakhstan prohibits it (Article 7(11) of the Personal Data Law).
If you contact people found in research, follow their country's rules on marketing messages. In the EU, for example, you must tell a person where you got their data within a month, or at the first contact (GDPR Art. 14).
Your rights
You can find out what data we hold about you, where it came from, why and for how long it is processed; correct it; block or delete it; withdraw consent, including to cross-border transfer; and claim compensation for harm (Article 24 of Kazakhstan's Personal Data Law).
Some of this you can do yourself: Plan → Download all data exports the business profile, the posts and the dashboard activity log, and you can remove teammates and disconnect Telegram in the dashboard.
For the rest, write to — from the address your VITON ID uses. We reply within 3 working days; correct, block or delete data within one working day once there are grounds to; and stop processing within 15 working days of a consent withdrawal unless the law requires us to keep the data. These are the deadlines of Kazakhstan's law.
If the GDPR applies to you, you have the same rights, plus the right to receive your data in a machine-readable form, to object to processing and to complain to a data protection supervisory authority. We reply without undue delay and within one month (GDPR Art. 12(3)). Requests are free.
AI and automated decisions
In the dashboard you work with AI, not with people. People step in only when the VITON13 studio makes your gift or answers an email.
The team writes drafts, finds information and suggests options. It makes no decisions that create, change or end anyone's rights (Article 19-1 of Kazakhstan's Personal Data Law): a person decides what to publish and what to do.
Children
VIT TEAM is a service for businesses and is not meant for anyone under 18. If we learn that a child has given us data, we'll delete it.
Security
The sign-in cookie is signed and not readable by scripts on the page. Firebase checks passwords; we don't store them. Connection tokens are left out of data exports. Only people who need server access for their work have it.
If a breach happens, we'll notify the authority within the legal deadline (in Kazakhstan, within one working day under Article 25 of the Personal Data Law; under the GDPR, within 72 hours under Art. 33) and tell you if it affects your data.
Don't put passwords, card details or unnecessary personal data of your customers in the chat: the team doesn't need them.
Changes to this policy
When the policy changes, the date at the top of this page changes too. We'll warn you about important changes in the dashboard or by email in advance, and ask for new consent where a change needs it.