Privacy

Privacy Policy

Last updated: September 11, 2026

This policy explains how Vindex handles data across AI narratives, portfolio maps, compliance operations, institutional/commercial workflows, and billing. Vindex is a business platform; account owners are generally responsible for lawful collection and use of data they upload or connect.

Identity & account data

  • Name, email, role, organization/account membership, and auth/session metadata.
  • Plan, seat, billing identifiers, and entitlement state.

Portfolio & operations data

  • Properties, units/beds, work orders, violations, cases, bids, and activity/audit records.
  • Files and attachments (photos, PDFs, statements, compliance evidence).

Intelligence & external context

  • Geocoding + geography context, market trend snapshots, and normalized external signal summaries.
  • Imported feeds you enable (for example: regulatory, market, tax/lien, and mortgage datasets).

Technical telemetry

  • Request metadata, pageview events, error diagnostics, and security controls (rate limits, abuse checks).
  • Device/browser metadata and IP-derived security context.
  • Property Insights measurements record the guide identifier, event type and broad search/direct channel, without names, emails, property addresses or full referrers. These measurements honor Do Not Track and Global Privacy Control. Consultation-link clicks are not evidence of completed bookings.

How we use data

  • Operate account-scoped workflows for compliance, legal, maintenance, financing, and marketplace operations.
  • Generate analytics and AI narrative summaries from workspace data and enabled external datasets.
  • Enforce security controls, role permissions, abuse prevention, and incident response.
  • Provide support, billing, and service communications.
  • Meet legal obligations including retention, audit, and lawful process handling.

AI outputs in Vindex are decision-support tools and should be reviewed by qualified operators before final legal, credit, or compliance decisions.

Sharing and subprocessors

Vindex does not sell personal data. Data may be processed by trusted service providers needed to run the platform.

  • When you explicitly request market evidence for an authorized property, its address is sent to RentCast for an estimate and comparable listings. Vindex does not include tenant details, private finances or documents in that request. The results may be supplied to Vindex AI for explanation; this does not train the model on your conversations.
  • AI service providers process the questions and authorized records supplied to Vindex AI. Product branding does not mean that Vindex developed the underlying model. Contact support for current processor information.
  • Infrastructure vendors (hosting, storage, logging, email, and monitoring).
  • Billing providers (for example, Stripe) for subscription and payment processing.
  • Data providers you or your admin enables for market, geography, or property intelligence.

Data is also shared with users your organization authorizes (owners, staff, counsel, consultants, contractors, lenders).

Security controls

Access controls

Role- and account-scoped permissions.

Transport security

Encrypted transport for client/API communication.

Abuse protection

Rate limits, blocklists, and suspicious-activity checks.

Auditability

Operational and access events for review and forensics.

Retention and deletion

Property market-evidence cache

Results are reusable for six hours within the same authorized account and property. Expired entries are not served and may remain in storage until operational cleanup; they are never published as customer-property pages.

Account and membership records

Retained while account is active + required legal retention period.

Operational records (violations/work orders/cases/bids)

Configured by workspace policy; may be retained for compliance history.

Vindex AI quality measurements and optional feedback

Up to 30 days under the operational retention process. New quality events contain timings, usage estimates, guide references and rating categories—not raw conversation text—and are not approved for training.

Vindex AI short-term conversation context

Browser memory only: up to four turns, cleared after 15 minutes without a new answer or when the account, role or page changes. Signed topic references expire after 15 minutes and contain no private records.

Security and audit logs

Retained based on security policy and applicable legal requirements.

Billing and subscription records

Retained for accounting, tax, and dispute handling requirements.

Your privacy rights

  • Request access to or export of your account-scoped data.
  • Request correction of inaccurate account/profile records.
  • Request deletion where legally permitted and contractually supported.
  • Manage notification and communication preferences.

If you are an employee or invited user, route requests through your account owner/admin first.

Cross-border and legal process

Depending on deployment and enabled integrations, data may be processed in multiple jurisdictions. Vindex will respond to valid legal requests where required by law and will seek to protect customer data using contractual and technical safeguards.

Policy updates

We may update this policy as the platform and legal requirements evolve. Material updates will be posted with a revised “Last updated” date.