Privacy Policy
We collect only what we need to operate Vetto AI, run annotator projects, and keep our platform secure. We do not sell your data and do not share it for cross-context behavioral advertising. You can email privacy@vetto.ai at any time to access or delete your data. Customer datasets are processed under contract and deleted/returned as agreed (standard retention of up to 60 months, unless a shorter term applies by contract or law).
Vetto Inc. ("Vetto", "we" or "our") provides human-in-the-loop services to help organizations evaluate and improve artificial intelligence systems. This Privacy Policy explains how we collect, use, disclose, and protect personal information when individuals interact with our sites, products, and services, including when they participate as project contributors ("annotators") or when personal information is contained in data we process for our customers.
This Policy is designed to meet the requirements of major privacy laws, including Brazil's LGPD, the EU/UK GDPR, and California's CCPA/CPRA, and applies globally, except where a local policy provides otherwise.
Who we are
- Controller / Provider
- Vetto Inc.
- Registered address
- 1911 Valparaiso Ave, Menlo Park, CA 94025, USA
- Website
- https://vetto.ai
- Privacy contact
- privacy@vetto.ai
- General contact
- contact@vetto.ai
- DPO
- Jonathan Borges Silva, CTO/DPO — privacy@vetto.ai
Scope
This Policy covers personal information we process as a controller (for example, visitors to our site, current and prospective customers, suppliers, and annotators), and personal information we process as a processor/service provider on behalf of our customers (for example, datasets provided by customers for evaluation, labeling, review, or other post-training activities).
When acting as a processor, we process personal information in accordance with our contract with the customer and their instructions; customers remain responsible for providing the necessary notices to individuals.
Information we collect
We may collect the following categories of personal information:
- Site & Communications Data — device identifiers, IP address, general location, pages viewed, referring URLs, cookies and similar technologies, and any information you send us via forms or email.
- Account & Business Contact Data — name, email, phone, job title, company, billing details, and authentication information for Vetto accounts.
- Annotator/Contributor Data — application details, background/skills information, identity verification data where legally required, work history, and work-product metadata (e.g., time spent, quality metrics).
- Operational & Security Data — logs, diagnostics, and telemetry used to provide, secure, and improve our services.
- Customer-Provided Data — any personal information contained in datasets that customers provide for annotation, evaluation, red-teaming, or related services (e.g., text, images, audio, video, or other content). We process these datasets only under our customers' instructions.
We do not intentionally collect sensitive personal information unless it is necessary for specific projects or compliance (for example, workforce eligibility checks), and then only with appropriate safeguards and minimization.
Sources of information
- Directly from you (forms, email, chat, or during hiring).
- Automatically from your device/browser when you use our sites or services.
- From customers or partners who provide datasets or business contact details.
- From service providers who support background checks or identity verification where legally required.
How we use information
We use personal information to:
- Provide and operate our services (contractual necessity / GDPR Art. 6(1)(b)).
- Secure, monitor, and improve our services, infrastructure, and quality (legitimate interests / Art. 6(1)(f)).
- Manage relationships with customers, suppliers, and annotators, including payments (contract / legitimate interests).
- Comply with legal obligations and enforce our agreements (legal obligation / Art. 6(1)(c)).
- Communicate about updates, opportunities, and security or service notices (legitimate interests / consent where required).
- Processor role — when processing customer-provided data, we act in accordance with the customer's documented instructions and for their specified purposes.
For Brazil (LGPD), we rely on bases such as performance of a contract, compliance with legal/regulatory obligations, and legitimate interest, and on consent where required.
Cookies and similar technologies
We use cookies necessary for site operation and may use analytics cookies to understand usage and improve the services. Where required, we obtain your consent for non-essential cookies. You can manage preferences through your browser settings or our cookie banner (where available).
Disclosures of personal information
We may disclose personal information to:
- Service providers / Processors that help us host, secure, monitor, test, and deliver services (e.g., cloud hosting and deployment, security scanning, code quality, dependency management). Our core stack includes AWS and Vercel for hosting and delivery; security tooling may include WAF, AWS Inspector, Beagle, SonarQube, and Dependabot.
- Professional advisors (legal, accounting) under confidentiality.
- Authorities where required by law or to protect rights and safety.
- Business transfers in connection with a merger, acquisition, or similar transaction with appropriate safeguards.
No sale or cross-context behavioral sharing
We do not sell personal information and do not share personal information for cross-context behavioral advertising, as defined by the CCPA/CPRA.
Subprocessors
We use vetted subprocessors to provide infrastructure and security capabilities. A current list is available upon request at privacy@vetto.ai. Customers may subscribe to change notifications through that page or by contacting us.
International transfers
We may transfer personal information to countries other than the one in which it was collected, including the United States. We use appropriate safeguards for international transfers, such as contractual protections (e.g., Standard Contractual Clauses) and technical measures (e.g., encryption in transit and at rest). Where required, we will appoint an EU/UK representative and publish their contact details in this Policy.
Security
We maintain administrative, technical, and physical safeguards designed to protect personal information, including (as applicable): network and application firewalls/WAF, least-privilege access controls, strong authentication and password standards, vulnerability scanning and remediation (e.g., AWS Inspector), code and dependency quality scanning (e.g., SonarQube, Dependabot), logging/monitoring, and encryption in transit and at rest. We require our service providers to implement appropriate security measures as well.
We regularly review access rights, maintain incident-response procedures, and test our backup and recovery processes as part of our Business Continuity and Disaster Recovery program.
Data retention
We retain personal information only for as long as necessary for the purposes described in this Policy or as required by law or contract. For customer datasets processed for annotation/evaluation and similar services, our standard retention period is up to 60 months, unless a shorter period is specified by contract or law. At the end of the contract or upon customer instruction, we delete or return personal information and securely dispose of any remaining copies, in accordance with our Data Retention and Destruction Policy.
Your choices and controls
- Non-essential cookies/analytics — use your browser settings or our cookie banner where available.
- Marketing — you can unsubscribe from emails using the link in the message or by writing to contact@vetto.ai.
- Access, delete, or correct your data — email privacy@vetto.ai.
- Customer datasets — contact the customer that provided the data; we will give the necessary support.
Your privacy rights
Depending on your location, you may have rights to request:
- Access to your personal information
- Correction or updating of data
- Deletion of your information
- Data portability
- Restriction of or objection to processing
- Rights related to automated decision-making (where applicable)
How to exercise your rights
Email privacy@vetto.ai and include your name, contact information, the right you wish to exercise, and enough detail to verify your identity.
For data we process for a customer: contact the customer directly. We will provide the support needed to fulfill your request as required by law and our contract.
Appeals / complaints: if you are not satisfied with our response, you may contact your local data protection authority.
Children's privacy
Our services are not directed to children, and we do not intentionally collect personal information from children. If you believe a child has provided us with personal information, contact privacy@vetto.ai so we can take appropriate action.
US state privacy disclosures
If you reside in a US state with a comprehensive privacy law (e.g., California, Colorado, Connecticut, Virginia, Utah), you may have rights to access, delete, correct, or obtain a portable copy of your personal information, and to opt out of targeted advertising and certain profiling.
California (CCPA/CPRA): for our own site and account data, we act as a "business"; for customer datasets, we act as a "service provider/contractor". We do not sell personal information and do not share it for cross-context behavioral advertising.
Brazil (LGPD) — additional notice
For individuals in Brazil, you have rights to confirm processing, access, correction, anonymization/blocking/deletion of unnecessary or excessive data, portability, information about shared use, and revocation of consent, among others.
To exercise your rights, email privacy@vetto.ai. You may also contact the ANPD or another competent authority.
How to contact us
- Privacy email
- privacy@vetto.ai
- General email
- contact@vetto.ai
- Postal address
- Vetto Inc., 1911 Valparaiso Ave, Menlo Park, CA 94025, USA
- DPO
- Jonathan Borges Silva, CTO/DPO — privacy@vetto.ai
Glossary
- Controller
- Decides why and how personal information is processed.
- Processor / Service Provider
- Processes personal information on behalf of a controller.
- Personal information
- Any information that identifies or relates to an identifiable person.
- Customer-provided data
- Datasets and content provided by customers for our services.
Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will post the updated Policy. We encourage you to review this Policy periodically.
Change log
- Version
- 1.0.0 (initial release)
- Date
- November 1, 2025
- Author
- Jonathan Borges Silva (CTO/DPO)
- Approver
- José André da Silva Reis Nunes (CEO)
- Document ID
- VETTO-PP-001
- Next review
- November 1, 2026