Legal
Data Use
Who owns the data that enters the platform, what we use it for, how it relates to AI models, and how to export it.
Last updated: 12 August 2026
1. Three categories of data
We distinguish three categories, because they follow different rules:
- Customer Data: what you enter or connect to the Service — accounting documents, invoices, bank transactions, records, source code, project files.
- Account Data: the information needed for the contractual relationship — identifiers, contacts, active plan, billing details.
- Usage Data: technical telemetry generated by use — access logs, performance metrics, error events, consumption counters.
This page describes processing in operational terms. Legal bases and data subject rights are set out in the Privacy Policy.
2. Customer Data stays yours
Vascend acquires no ownership rights over Customer Data. You retain title to what you upload and the rights attached to it.
As regards personal data contained in Customer Data, you act as data controller and Vascend as processor: we process that data solely to deliver the Service and in accordance with the controller's documented instructions.
3. Purposes of processing
We process Customer Data to: deliver the requested features, perform reconciliations, forecasts, and document processing, maintain the availability of the Service, provide support at the user's request, and comply with legal obligations.
We do not use Customer Data for commercial profiling, we do not disclose it to third parties for marketing purposes, and we do not sell it, in any form or on any basis.
4. Data and AI model training
Customer Data is not used to train artificial intelligence models, whether our own or those of third-party providers.
Where a feature requires processing by a model, the necessary data is transmitted to the model provider for the duration of that processing only, under agreements that exclude use for training and require deletion once the request completes.
If we introduce improvement programmes based on real data in future, participation will be voluntary, explicit, and revocable: never enabled by default.
5. Sub-processors and location
We rely on selected providers for hosting, model inference, communications, and payments. Each provider is bound by an agreement imposing adequate security measures and limiting processing to the purposes of the Service.
Primary infrastructure is located in the European Union. Any transfers to third countries take place only under an adequacy decision or standard contractual clauses, with the applicable supplementary safeguards.
An up-to-date list of sub-processors is available on request at privacy@vascend.it.
6. Retention and deletion
Customer Data is retained for the duration of the contractual relationship.
On termination, you have thirty days to export your data; after that period, data is deleted from production systems within a further thirty days and removed from backups according to the rotation cycle, in any case within ninety days.
Only data required for tax and accounting obligations and for the defence of legal claims is retained for the statutory periods.
7. Segregation and internal access
Each customer's data is logically segregated: no tenant can access another tenant's data.
Vascend personnel may access Customer Data only where necessary for support or maintenance, limited to the strict minimum, logged, and revoked once the work is complete. The technical measures are described on the Security page.
8. Export and portability
You can export your data at any time from your account area, in open formats readable by other systems.
On written request we provide a full extraction within thirty days. Export is not conditional on outstanding payments: the data belongs to whoever uploaded it.