Vosky AI Back to the site
Privacy

What we collect, and what happens to it.

This notice covers vosky.ai — the marketing site, the assistant on it, the consult form, and the client portal behind sign-in. It is written to be read by a risk or vendor-management team, so it names the actual systems rather than describing them in general terms.

Last updated 2026-07-25

1. Who we are

Vosky AI is the AI division of Vosky Technologies, an IT, cloud and smart-home consultancy based in Colleyville, Texas. We are the controller of the data described below.

TODO: confirm  The registered legal entity name and state of formation, and whether the mailing address above is also the address for legal notices.

2. What this notice does not cover

Client engagements are governed by the written agreement for that engagement, not by this page. Where we build a system inside your own cloud tenant — your Microsoft 365, your Azure subscription — the data in it stays in an environment you own and audit, and your agreement and any data-processing addendum control what we may do with it. This notice describes only what vosky.ai itself stores.

3. What we collect

Consult requests

The form on the home page collects your name, work email, business name, and the message you write. The server also records the IP address the request came from and the time it arrived. The record is written to our database before we attempt to email it, so a lead is never lost to a mail outage — which means a submitted enquiry is stored even if the notification email fails.

The form carries a hidden field no person can see or tab to. If it is filled in, the submission is treated as automated and discarded. We also decline more than five submissions from one IP address in a day.

Chat with the assistant

The assistant on the home page is a live demo of the kind of system we build. The messages you type are sent to Anthropic's API to generate a reply. They leave our platform to do that. Anthropic is named as a subprocessor in section 5.

We do not store the transcript. What we do store is a spend ledger: a row keyed by ip:<your address>:<date> holding the number of calls and the amount spent in micro-dollars, which is how the daily and monthly cost caps are enforced. Your conversation is not retained beyond that accounting.

Do not put confidential, customer or non-public personal information into the chat box. It is a demo on a public page. If you need to tell us something sensitive, email or call us.

Client portal accounts

For people we give access to the portal, we store:

Readiness Audit records

During a Readiness Audit we record what we learn about your institution: name, rough size, systems and core provider, where documents live, regulatory and data-residency constraints, the opportunities we identify, and our notes and verdict. These records are business information about the organisation. They are not intended to hold consumer records or non-public personal information, and we ask clients not to place any there.

Access log

Every read, write, deletion and failed lookup on a client-data path is written to an access log with the acting user, the action, the record touched, the IP address and the time. This exists so that the organisation-scoping can be proved to behave rather than asserted. Consult-form submissions are logged here too.

Cookies and third parties on the page

4. Why we hold it

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it to train AI models.

5. Subprocessors

These are the third parties that process data on our behalf for vosky.ai itself. Per-engagement subprocessors are listed in the engagement agreement and can differ.

ProviderWhat it doesWhat reaches it
Cloudflare Hosting, edge compute (Workers), the database (D1), DNS and the TLS termination in front of the site Everything. All site traffic, and every record described in section 3
Anthropic The large language model behind the assistant on the home page, and behind audit drafting in our internal workspace The messages you type into the chat box and the conversation history within that session; and, for clients, the audit intake when a Vosky consultant asks the workspace to draft findings. Nothing from the leads table, and no account or credential data, is sent
Microsoft 365 / Graph Transactional email sent from info@vosky.ai — lead notifications, your acknowledgement, invitations and sign-in links The contents of those messages, including your name, email address and the message you submitted. Sent mail is kept in the mailbox
Google Fonts Serves the two typefaces the pages use Your IP address and user-agent, from your browser directly. No data of ours is sent to Google

To be plain about the ones that matter most in a review: chat messages leave our platform and are transmitted to Anthropic over TLS in order to be answered, and audit intake is transmitted to Anthropic when a Vosky consultant asks the workspace to draft findings during your assessment. The second happens only when a person initiates it, only for staff, and always produces a draft a human reviews before it is used. Anthropic's commercial terms state that API inputs and outputs are not used to train their models. If this is not acceptable under your vendor policy, tell us at engagement and we will run the assessment without it.

TODO: confirm  Whether a zero-data-retention agreement is in place with Anthropic. Until it is confirmed in writing, this page must not claim that Anthropic retains nothing.

6. Where it is stored

Everything vosky.ai stores lives in Cloudflare D1, a database created in the WNAM region — western North America, United States. The application itself runs on Cloudflare Workers at the edge, so requests are served from whichever Cloudflare location is nearest to you, but the durable data stays in the region above.

Transactional email lives in the info@vosky.ai mailbox in our Microsoft 365 tenant.

TODO: confirm  The Microsoft 365 tenant's data residency geography, so we can state where mailbox contents sit rather than implying it.

7. How long we keep it

RecordKept for
Consult requestsUntil you ask us to delete them. They are not aged out automatically today TODO: confirm
Chat messagesNot retained by us. Only the per-IP daily and site-wide spend counters remain
Chat spend countersOne row per IP per day and per site per day and month; not deleted on a schedule today TODO: confirm
Audit recordsFor the life of the engagement and afterwards as our record of the work, until deletion is requested
Account records and passkeysWhile the account is active, and until you ask us to remove it
SessionsExpire after 30 days (staff) or 14 days (client); one day for a recovery-code session. Revoked immediately on request
Sign-in challengesFive minutes, and deleted the moment they are used
Emailed sign-in linksFifteen minutes, single use
Access logRetained as the audit trail; no automatic purge today TODO: confirm

8. Export, correction and deletion

Email info@vosky.ai from an address we can tie to the record, or call (214) 702-9523. Ask for an export, a correction, or deletion. We will respond within 30 days.

Two honest caveats. We may keep what we need to meet a legal or accounting obligation, and to defend a claim. And we cannot delete a copy that only exists inside your own systems — where a build runs in your tenant, deletion there is a change you or we make in your environment, coordinated in writing.

If you have a client account you can also do some of this yourself: the account page lists every device signed in as you and revokes any of them, and lets you remove an enrolled passkey.

TODO: lawyer  Whether the Texas Data Privacy and Security Act applies to Vosky, or whether the small-business exemption does. If it applies, this section needs the statutory rights list and an appeals process.

9. Security

The controls behind the portal — passkey authentication, per-device revocable sessions, role and organisation scoping, and full access logging — are described in detail on the data and security overview, along with a plain list of the things we do not yet have.

10. Children

This is a business-to-business service. It is not directed at children and we do not knowingly collect information from anyone under 18.

11. Changes

When this notice changes we update the date at the top. If a change materially affects how we handle data belonging to an existing client, we will tell that client directly rather than relying on them to reread the page.

12. Contact

Questions about this notice, a due-diligence questionnaire you would like completed, or a request about your data: