01Processing scope
Viralz may process account and access data; business, content, and uploaded-asset data; connected-service data; image/OCR data; and usage, device, and diagnostic data to provide requested features and operate the service.
The intended controller identity for this draft is Jasper Ruijs, Bavelselaan 82, 4835 GN Breda, Noord-Brabant, The Netherlands. Its use in final legal terms remains subject to counsel approval.
Customers remain responsible for having a lawful basis and required authority or consent before submitting third-party data, connecting accounts, or importing content.
02AI and connected services
Model requests can include a user's brief, template text, business/brand context, OCR text, or image. Platform requests may route through OpenRouter to a selected model/provider; users may also configure supported BYOK provider paths.
There is no verified product-wide redaction layer, and zero-retention or no-training commitments are not verified across every provider route. This draft does not make those promises.
03Meeting-data restriction
Meeting Intelligence is not generally available. It remains off without current, explicit, provider-scoped consent and pending the separate privacy/security launch gate.
Historical meeting processing identified plaintext storage and model-processing gaps. It is not approved for production Meeting Intelligence.
04Processing terms still require counsel
- The applicable controller/processor allocation is UNKNOWN pending counsel review.
- Vendor regions, subprocessors, DPA status, and international-transfer mechanisms are UNKNOWN pending a maintained vendor register.
- Retention, deletion, backup, and DSAR operating timelines are not consistently implemented or approved.
- A final DPA, if required, must be separately approved and executed; this page is not one.