Privacy Policy
Last updated: March 2026
1. Introduction
VAERION Systems ("VAERION," "we," "us," or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you visit our website at vaerion.ai, use our platform, or interact with our services (collectively, the "Service").
2. Information We Collect
Information You Provide
- Contact information: first name, last name, email address, phone number
- Business information: business name, organization details
- Form submissions: access requests, support inquiries, and any other information you provide through our forms
- Consent preferences: your opt-in or opt-out choices for transactional SMS, promotional SMS, and marketing emails
Information Collected Automatically
- Device and browser information: IP address, browser type, user agent
- Consent records: timestamp, source URL, IP address, and user agent at the time consent was given or modified, retained for compliance purposes
Information We Do Not Collect
This website does not use cookies, tracking pixels, or third-party analytics services. We do not collect browsing behavior, page view history, or advertising identifiers.
3. How We Use Your Information
We use the information we collect for the following purposes:
- To process and respond to your access requests
- To communicate with you about your account, onboarding, and platform access
- To send transactional SMS messages (access notifications, onboarding updates, appointment reminders, account/service alerts) based on your consent
- To send promotional SMS messages (product updates, feature announcements, tips, special offers) only if you have separately opted in
- To send promotional emails only if you have separately opted in
- To provide customer support
- To comply with legal obligations and enforce our Terms of Service
- To maintain consent records for regulatory compliance
4. SMS and Messaging Disclosure
When you provide your phone number and consent to receive SMS text messages from VAERION, we collect and store your phone number and consent status. We use this information to send you text messages as described in our SMS Program Terms.
Consent records: When you submit our Request Access form, we record your consent choices along with a timestamp, the page URL, your IP address, and browser user agent. These records are retained for compliance and audit purposes.
Opt-out: You can stop receiving SMS messages at any time by replying STOP to any message from VAERION. You will receive a one-time confirmation and no further messages will be sent unless you re-subscribe.
Costs: Message and data rates may apply depending on your mobile carrier and plan. VAERION does not charge for SMS messages, but your carrier may.
No sharing for marketing: We do not sell, rent, or share your phone number or messaging consent data with third parties for their marketing purposes.
5. How We Share Your Information
We do not sell your personal information. We may share your information only in the following circumstances:
- Service providers: We use third-party service providers to deliver SMS messages (third-party messaging providers) and send emails (third-party email delivery providers). These providers receive only the information necessary to deliver messages on our behalf and are contractually obligated to protect your data.
- Legal requirements: We may disclose your information if required to do so by law, court order, or governmental regulation, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction.
6. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce our agreements. Consent records are retained for the duration required by applicable telecommunications regulations.
7. Data Security
We implement reasonable administrative, technical, and physical safeguards to protect your personal information. The VAERION platform enforces tenant isolation at the architectural level, uses role-based access control on all endpoints, and maintains a full audit trail of data access operations. However, no method of transmission over the Internet or electronic storage is completely secure, and we cannot guarantee absolute security.
8. AI and Automated Processing
The VAERION platform uses artificial intelligence and machine learning to provide its services. This includes:
- Behavioral intelligence: Analyzing engagement patterns to generate customer insights and risk assessments within your tenant boundary
- Autonomous decision-making: Generating and executing communication decisions based on governance rules you configure — including autonomy mode, budget limits, and consent requirements
- Document generation: Creating personalized communications and documents using AI language models
- Multi-model orchestration: Routing tasks to the optimal AI provider based on task requirements. Multiple providers are used; no single provider receives all data.
All AI processing is performed within your tenant's data boundary. Your data is never used to train third-party AI models. Every AI-driven decision is recorded in a tamper-evident audit ledger with full explainability — including what data was used, what decision was made, and why.
9. Multi-Tenant Data Isolation
VAERION is a multi-tenant platform. Your data is strictly isolated from other tenants at every layer of the system — database queries, API access, asynchronous processing, and file storage are all scoped to your tenant identifier. Cross-tenant data access is architecturally prevented and enforced by automated checks in our development pipeline. VAERION's edge computing platform is SOC 2 Type II certified.
10. HIPAA and Regulated Data
For healthcare customers and other organizations handling Protected Health Information (PHI), VAERION supports execution of a Business Associate Agreement (BAA).
PHI access control: PHI processing is gated by active BAA status. No PHI is processed or stored without an executed, counter-signed BAA in place.
Audit trail: All access to PHI is logged to a dedicated audit trail. Every action is traceable to a specific user, timestamp, and authorization.
For BAA inquiries, contact chris@vaerionsystems.com.
11. Data Retention Schedule
In addition to the general retention policy above, the following specific retention periods apply to platform data:
- Audit and governance records: 7 years (HIPAA and SOC 2 compliance)
- Communication logs: 3 years
- Customer profile data: Duration of subscription plus 90-day grace period
- Voice recordings: 1 year (configurable per tenant)
- Session data: 24 hours after expiry
After the applicable retention period, data is securely deleted or anonymized. Tenants may request shorter retention periods for certain data categories, subject to regulatory minimums.
12. International Data Transfers
VAERION processes data on its global edge computing platform. Data may be processed in data centers outside your country of residence. VAERION's infrastructure maintains appropriate safeguards for international data transfers, including Standard Contractual Clauses where applicable under GDPR.
13. Your Rights
Depending on your jurisdiction (including GDPR, CCPA, and other applicable laws), you may have the following rights:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate personal information
- Deletion: Request deletion of your personal information (right to erasure), subject to legal retention requirements
- Portability: Request your data in a machine-readable format
- Restriction: Request we restrict processing of your personal data
- Objection: Object to processing of your personal data
- Opt-out: Opt out of promotional communications at any time (SMS: reply STOP; email: use the unsubscribe link)
To exercise any of these rights, contact us at contact@vaerionsystems.com. We will respond within a reasonable timeframe.
14. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information promptly.
15. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date at the top of this page. We encourage you to review this Privacy Policy periodically. Your continued use of the Service after any changes constitutes your acceptance of the updated Privacy Policy.
16. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:
See also: Terms of Service