01Who this applies to
This notice is for people using viralz.dev, including account holders, website visitors, and people whose information may appear in content an account holder submits or connects to Viralz.
The intended controller identity for this draft is Jasper Ruijs, Bavelselaan 82, 4835 GN Breda, Noord-Brabant, The Netherlands. Its use in final legal terms remains subject to counsel approval. Where a business customer uses Viralz for its own purposes, the parties' controller/processor roles and any required data-processing agreement remain UNKNOWN pending counsel review.
02Data we may process
- Account and access data, including account identifiers, name, email, authentication/session information, profile/onboarding data, and authorization or billing-admin status.
- Business and content data, including briefs, brand context, ideas, drafts, feedback, generated posts/creatives, uploaded assets, and associated metadata.
- Connected-service data, including authorized integration data and, when a user explicitly initiates import with their own account, Spott meeting metadata, transcript text, participant/speaker text, and API-key-related connection data.
- Image and OCR data, including source images, extracted visible text and coordinates, edit instructions, and generated versions.
- Usage, device, and diagnostic data. Where PostHog is enabled, this may include session recordings; do not enter sensitive material in fields that may be recorded.
03Purposes and proposed legal bases
- Providing accounts, requested workspace features, content generation/save/export, and subscriptions: proposed contract performance basis.
- Protecting accounts, preventing abuse, maintaining reliability, enforcing access controls, and diagnosing faults: proposed legitimate interests and, where needed, legal obligation.
- Product improvement and feature-use analysis: proposed legitimate interests, or consent where required for cookies or recording.
- User-selected content, image/OCR, public-post, integration, or explicitly initiated Spott imports: proposed contract performance and/or user instructions.
- Counsel must confirm the applicable legal bases, including the basis for third-party information in customer content or connected accounts.
04Meeting Intelligence remains off
Meeting Intelligence is OFF without current, explicit, provider-scoped user consent. Without consent, Viralz must not fetch, store, model-process, materialize, play back, or backfill Meeting Intelligence data for that user.
Consent alone is not a launch authorization. Retention, purge, tenant isolation, exclusion, and model-handling work remain unresolved. A separately initiated Spott/Fireflies BYOK creative import does not enable Meeting Intelligence.
05Providers, retention, and transfers
Product review identified services including Clerk, Supabase, Railway, Vercel, OpenRouter and selected model vendors, PostHog, Stripe, and optional integrations. Their roles, regions, subprocessors, transfer mechanisms, retention, and DPA status must be confirmed in a final vendor register.
Retention periods and comprehensive deletion or backup-purge workflows are not verified across all features. We cannot currently make a universal retention promise. International-transfer safeguards are also UNKNOWN pending provider- and region-specific confirmation.
Viralz does not claim SOC 2 certification.
06Rights and contact
Depending on location, people may have rights to request access, correction, deletion, restriction, objection, portability/export, and consent withdrawal. Product controls and complete deletion/export workflows are not verified for every data category, so requests may require a manual process.
Privacy contact: privacy@viralz.dev (interim contact pending counsel approval of final privacy terms and operating procedures).