LEGAL_DOCS:
// PRIVACY POLICY
This Privacy Policy explains how VDI Agent collects, uses and protects your personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Italian privacy law.
01 // DATA CONTROLLER
The data controller for vdiagent.ai is: Beren Software Address: Rome, Italy Email: privacy@berensofware.com Website: https://vdiagent.ai For any privacy-related request, contact us at privacy@berensofware.com.
02 // WHAT WE DO NOT COLLECT
We explicitly do NOT collect or store: ► Query content or prompt text — AI queries are forwarded directly to providers without logging. ► Screen captures — screen data is processed in real-time and not stored on our servers. ► Clipboard content — we do not access or monitor your clipboard. ► File contents — we do not read or store file data from your system. ► Browser history or personal documents — we have no access to these. Your interaction with the Software remains private and secure.
03 // DATA PROCESSING & ZERO-RETENTION PROXY
We operate a zero-retention proxy architecture: ► AI queries are forwarded directly to your chosen provider (Anthropic, OpenAI, Google, etc.). ► Queries are not logged or stored on Beren Software servers. ► Client-side PII scrubbing automatically removes: - File system paths - Email addresses - Hostnames and domain names - URLs and web addresses ► Processed requests flow: Client → Beren proxy → AI provider → Response → Client We never have access to or store your original query content.
04 // ACCOUNT DATA
We collect minimal account information: ► Email address — for account creation and communication. ► Password — hashed with bcrypt (we never store plaintext passwords). ► License key or subscription tier — linked to your account. ► Account creation timestamp and last login — for security and support. This data is retained for the duration of your account, plus 30 days after deletion. You may request deletion at any time.
05 // BILLING & PAYMENT
Payment processing is handled securely: ► Billing is processed exclusively via Stripe. ► We do NOT store credit card numbers, expiration dates, or CVV codes on our servers. ► Stripe retains payment data according to their own privacy policy. ► Payment records (transaction ID, amount, date) are retained for 10 years per Italian and EU fiscal law requirements. Your payment information is handled by a PCI-DSS compliant processor.
06 // TELEMETRY & USAGE DATA
Telemetry is opt-in and disabled by default: ► You must explicitly enable telemetry in Software settings. ► Telemetry includes: query count, model selection, error rates, session duration. ► Telemetry does NOT include query content, personal information, or sensitive data. ► You may disable telemetry at any time from settings. ► Telemetry data is retained for 90 days and then deleted.
07 // THIRD-PARTY PROCESSORS
Your data is shared with the following trusted processors: ► Anthropic — AI model inference (Claude). See https://www.anthropic.com/privacy ► OpenAI — AI model inference (GPT). See https://openai.com/privacy ► Google — AI model inference (Gemini). See https://policies.google.com/privacy ► Stripe — payment processing. See https://stripe.com/privacy ► Supabase — database hosting (EU region). See https://supabase.com/privacy ► Vercel — application hosting (CDN, edge runtime). See https://vercel.com/privacy Each provider's privacy policy applies to their processing of your data.
08 // YOUR GDPR RIGHTS
Under GDPR, you have the following rights: ► Access (Art. 15) — request a copy of your personal data we hold. ► Rectification (Art. 16) — correct inaccurate or incomplete personal data. ► Erasure (Art. 17) — "right to be forgotten" — request deletion of your account. ► Restriction (Art. 18) — ask us to limit processing in certain circumstances. ► Portability (Art. 20) — receive your data in a structured, machine-readable format. ► Objection (Art. 21) — object to processing based on legitimate interest. ► Withdraw consent — revoke analytics consent at any time. To exercise any right, email privacy@berensofware.com with subject "GDPR Request". We respond within 30 days.
09 // DATA TRANSFERS TO THE UNITED STATES
Some of our processors (Anthropic, OpenAI, Google, Stripe, Vercel) operate in the United States: ► Data transfers are covered by the EU-US Data Privacy Framework (DPF). ► Processors certified under the DPF provide adequate data protection guarantees. ► You may request a copy of adequacy determinations at privacy@berensofware.com. Your data is transferred only to processors with appropriate safeguards.
10 // DATA PROTECTION AUTHORITY COMPLAINTS
You have the right to lodge a complaint with your local Data Protection Authority: For Italy: Garante per la Protezione dei Dati Personali Website: www.garanteprivacy.it Email: protocollo@garanteprivacy.it For other EU member states, you may contact your national Data Protection Authority (https://edpb.europa.eu/about-edpb/board/members_en). Complaints to DPAs do not affect your right to legal remedies.
11 // CONTACT & POLICY UPDATES
For privacy concerns or requests, contact: Beren Software Email: privacy@berensofware.com Website: https://vdiagent.ai We may update this Privacy Policy from time to time. Material changes will be notified by email to registered users. Continued use of the Software constitutes acceptance of updates. Last updated: 9 May 2026