Varren - Privacy Policy

Alpha Innovation Technologies - F.Z.C, a free zone company registered in Ajman Free Zone, United Arab Emirates, trading as AlphaIT Engineering. Effective date: 22 September 2026 Version: 2.2 Applies to: varren.co, the Varren application, the Varren API, and every associated Varren service (together, the "Service").

Published at https://varren.co/privacy. This is the privacy policy referenced by the Google sign-in consent screen and by every other sign-in and account-connection flow in Varren.

1. Overview

This section points to the provisions that govern common questions. It is not a summary and does not vary them.


2. Who we are, and our two roles

The Service is operated by Alpha Innovation Technologies - F.Z.C, a free zone company registered in Ajman Free Zone, United Arab Emirates, trading as AlphaIT Engineering ("Varren", "we", "us", "our"). It is the contracting party and the entity responsible for this policy.

Affiliates and local billing. Where local law, payment rails or tax rules require a local invoice, an affiliate may invoice you, collect payment and issue local tax documentation, processing your billing data for that purpose. That determines who bills you and does not change the entity responsible for the Service or this policy, which remains Alpha Innovation Technologies - F.Z.C. Your invoice names the entity that issued it.

We act in two roles. We are the controller of data about you as an account holder: your identity, login and security records, billing data, support messages, and your use of the Service. We are your processor for the material you upload, connect or instruct us to work on: your documents, prompts, content library, the contents of connected accounts, and the personal data of people you communicate with. For that material you decide the purposes and means and we act on your instructions, under the Data Processing Addendum at https://varren.co/dpa, which forms part of your contract. As controller of that material you are responsible for holding a lawful basis for it, for giving the people in it the notice their law requires, and for the instructions you give us.

There is one exception to that split, set out in Section 12: for the likeness consent record and the withdrawal route only, you and Varren are joint controllers.

Where your data sits in a customer's workspace and you are not our customer, that customer is your controller and the first point of contact. On a request to [email protected] we will identify that customer, pass your request to them promptly, and assist them in answering it.

This policy does not cover the platforms you connect. Where Varren publishes to a platform on your instruction, that platform's own policy governs its subsequent processing.


3. The data we collect

Data you provide. Identity data: name, email address, organisation, role, workspace membership, and the credentials, access links or single sign-on identifiers used to authenticate you. Security data: two-factor secrets, recovery codes, trusted device records, passkey credentials. Content and instructions: prompts, briefs, messages, documents, files, images, audio, video, brand assets, content libraries, and the settings, rules, schedules and automations you configure. Billing data: your plan, your Varren Credits balance and ledger, invoices and transactions; where you pay by card, the card number and bank details remain with the payment processor and we receive only a payment token, the last four digits, the card brand, the expiry and the outcome. Support correspondence.

Account, security and billing data are a contractual requirement, without which we cannot open, secure or bill an account. Other data is optional, and withholding it limits the related feature.

Data from the accounts you connect. Varren accesses only what your enabled features require:

This may contain personal data about other people, and may contain sensitive information. You are its controller and we process it for you.

Data Varren observes while it works. Some features drive a browser inside a session you have signed in to. Varren observes the pages it navigates, the elements it touches and the results, and records what it did and the outcome. We do not capture or store passwords typed into that session, and we do not use the session outside your mandate. Every autonomous action is recorded under Section 10.

Data collected automatically. Features used, screens viewed, actions taken, timestamps; IP address, user agent, device and operating system, coarse location inferred from IP, diagnostic and error logs; sign-in events, session records, and consent records showing which version of which document you accepted and when; cookies and local storage under Section 19.

Data from other sources. Data reaches us from the platforms you connect, our payment processors, our infrastructure providers, and security and anti-abuse services. Personal data we hold about a person who is not our customer came from the customer whose workspace it sits in, or from the platform that customer connected.

Data you must not submit. You must keep payment card numbers, government identity numbers, health and medical records, and credentials for systems unrelated to Varren out of prompts, documents, libraries and connected content. No feature requires them, and we apply no controls to them beyond those in this policy. You are responsible for any consequence of the presence of such material in your workspace, including any notification duty it creates for you.


4. Why we use your data, and our lawful basis

Where the EU GDPR or UK GDPR applies we rely on the bases below. Where the UAE Personal Data Protection Law, the Nigeria Data Protection Act 2023 or the Kenya Data Protection Act 2019 applies, the equivalent bases are consent, performance of a contract, compliance with a legal obligation, and legitimate interests, for the same purposes.

PurposeExamplesLawful basis
Run the Serviceauthenticate you, hold your workspace, generate contentContract, Article 6(1)(b). For connected material we act as your processor.
Act on connected accountspost, publish, send, reply, schedule, research, drive a browserContract, Article 6(1)(b), and your authorisation per connection
Read a mailbox you connectedbuild your unified inbox, rank items, draft replies you requestContract, Article 6(1)(b). We act as your processor and you are the controller of the mailbox.
Bill youapply credits, issue invoices, calculate tax, prevent payment fraudContract, Article 6(1)(b), and legal obligation, Article 6(1)(c)
Keep the audit trailrecord every proposed and executed action and every approvalLegitimate interests, Article 6(1)(f), and legal obligation where records are required
Support youanswer questions, send service and security noticesContract, Article 6(1)(b), and legitimate interests, Article 6(1)(f)
Security and anti-abusedetect fraud, abuse and incidents, enforce our termsLegitimate interests, Article 6(1)(f), and legal obligation, Article 6(1)(c)
Improve the Servicediagnose failures, measure reliability, improve Varren using aggregated and de-identified signals within Section 8Legitimate interests, Article 6(1)(f)
Generate a real person's likenessvideo or audio from a reference you uploadYou are the controller and must hold the depicted person's explicit consent under Article 9(2)(a). We are your processor for the generation, and a joint controller with you for the consent record and the withdrawal route in Section 12.
Defend legal claimsrespond to a complaint, regulatory inquiry, dispute or claim, and preserve what a legal hold requiresLegitimate interests, Article 6(1)(f), and for special category data Article 9(2)(f)
Comply with lawlawful requests, tax, accounting and regulatory dutiesLegal obligation, Article 6(1)(c)

Where we rely on legitimate interests we have weighed our interest against your rights. The assessment is available on request to [email protected], and you may object under Section 18.


5. How Varren uses AI, and what leaves our systems

Varren generates text, images, video, audio and documents by sending your prompts and the material they reference to third-party AI model providers, and uses those providers to plan and carry out the actions in Section 10. Routing is automatic and you do not select the provider; Varren selects a model per task, and the provider set changes.

The following commitments apply to every provider we route to:

  1. No training on your content. We route customer data only through paid commercial or enterprise tiers, never a free or consumer tier; we disable every optional data-sharing setting; and we require of every provider that the terms of the tier we use prohibit training a general-purpose or foundation model on your content. Where a provider's terms cease to meet this requirement, we stop routing customer data to it. The current provider set is published at https://varren.co/subprocessors.
  2. Retention at the provider. Each provider retains inputs and outputs only for the period necessary for abuse monitoring and service operation, and we contract for the shortest retention period each provider offers.
  3. No human review at a provider except where that provider's terms permit it for a security investigation, a legal obligation or an abuse review.
  4. Minimisation. We send only what the task requires, and never your whole workspace.
  5. Transfers. Every provider in the routing set is covered by the transfer assessment in Section 7. Two providers process in the People's Republic of China. Routing is a single service-wide configuration and not a per-workspace setting; where a provider is not acceptable to you, you may object under Section 6, and the remedy is removal of that provider from the routing configuration for all customers.

Once content leaves us, the provider handles it under its own terms and security. AI output can be inaccurate, and it is not professional advice.


6. Sub-processors, and how you find out when they change

We use other companies to run the Service. Under the GDPR these are our sub-processors. The sub-processor page groups them as infrastructure (hosting, network and edge security, and email delivery); AI model providers; and optional and feature-triggered (connector and browser infrastructure, web search, and payments). We use no third-party error, analytics or performance monitoring service.

The current list is published and versioned at https://varren.co/subprocessors, naming for each the company, its role, the categories of data it handles, the countries it processes in, and the transfer mechanism relied on. If that page is unreachable for you, or you require a prior version, ask at [email protected] and we will send you the current list and any prior version.

Change process. You may subscribe to change notices on that page. Before adding or replacing a sub-processor we publish the change and notify every subscriber and every customer holding a Data Processing Addendum at least thirty days before it takes effect. Within those thirty days you may object in writing to [email protected] on reasonable data protection grounds, and we will seek an alternative. Because routing is a single service-wide configuration, the alternative for an AI model provider is removal of that provider from the routing configuration for all customers rather than exclusion for your workspace alone. If no alternative exists you may terminate the affected part of the Service and receive a refund of the unused portion of what you paid for it. We add a sub-processor on shorter notice only where urgently required to keep the Service secure or operational, and notify you as soon as we do.

This is the sub-processor authorisation required by Article 28(2) of the GDPR: a general written authorisation with a right to object, set out in full in the Data Processing Addendum. By agreeing to this policy you authorise us to use sub-processors on the condition that we notify you before each change and you may object.


7. Where your data is processed, and how we make transfers lawful

Varren is operated from the United Arab Emirates. Our infrastructure and most of our sub-processors are located in the United States, the European Union and the United Kingdom, and the sub-processor page names the regions for each.

Two of our AI model providers, DeepSeek and Moonshot AI, process in the People's Republic of China, for which the European Commission has issued no adequacy decision. Both are in the routing set, so a prompt can reach them. Transfers to them rely on the Standard Contractual Clauses and the supplementary measures below, and you may require any provider to be removed from the routing configuration for all customers by writing to [email protected].

Two recipients in the routing set are gateways rather than a single model host. OpenRouter and Azure AI Foundry each front more than one underlying model, so the processing location for a call routed through one of them depends on the model the routing layer selects and, for Azure, on the region of the configured endpoint. A gateway remains in the routing configuration only while it meets the training and retention requirement in Section 5, and you may require its removal for all customers by writing to [email protected].

The United Arab Emirates has no adequacy decision from the European Commission. The DIFC and ADGM financial free zones have their own data protection laws that the Commission assesses separately; we are registered in Ajman Free Zone, which has no data protection law of its own, so UAE federal law applies to us.

For personal data transferred from the European Economic Area, the United Kingdom or Switzerland to us or to a sub-processor outside those areas, we rely on:

Other jurisdictions. For Nigerian data we rely on section 41 of the Nigeria Data Protection Act 2023, using contractual clauses affording an adequate level of protection, and on the section 43 conditions where they apply. For Kenyan data we rely on section 48 of the Data Protection Act 2019, holding proof of appropriate safeguards, and obtain consent for sensitive personal data as section 49 requires. For UAE data we rely on Article 23 of Federal Decree-Law No. 45 of 2021, using contracts imposing enforceable data protection requirements.


8. Cross-tenant learning: where the line is

Varren improves for all customers by learning from what it processes. The boundary is as follows.

What may generalise across customers: patterns and structures, such as what a strong opening line looks like and how a campaign is best sequenced; quality signals, such as whether an output was accepted, edited or rejected; operational signals, such as which models handle which task well; and aggregated measures computed across many customers, from which no individual customer, person or record can be identified or reconstructed.

What never leaves your tenant: your content, meaning documents, prompts, messages, drafts, brand assets, media and library items; the identity of anyone in your data, meaning names, email addresses, handles, company names and contact records; your numbers, meaning revenue, budgets, pricing, performance figures, audience sizes and credit balances; your connected accounts, credentials and anything read from them; and your workspace configuration, strategy and instructions to Varren.

Enforcement. Every store of customer data is registered as tenant-scoped at the database layer. A cross-tenant learning path is built only after a leakage review and is covered by automated tests that fail the build if tenant data crosses the boundary. Retrieval feeding a model prompt is scoped to the requesting tenant. No customer's content appears in another customer's output, suggestion, retrieved snippet, example or model prompt.

Google user data is excluded from this layer entirely; see Section 11.

You may opt out of the pattern layer by writing to [email protected], and we will exclude your workspace at no change to the Service or its price.


9. Connected accounts, credentials and revocation

What we store when you connect an account: the identity of the account on that platform, the scopes you granted, the connection status, and the timestamps of connection and revocation.

Where the tokens are held. Where a connection is brokered by our connector infrastructure, that layer holds the access and refresh tokens and injects them into each call, and they do not reach our database. Where we hold a credential ourselves, such as a mailbox app password or a saved browser session, it is encrypted at rest with an authenticated cipher, scoped to your tenant, never displayed in the interface, never written to logs, and never sent to an AI model provider. Varren requests only the scopes the enabled features require.

Permissions requested, by platform. Varren publishes content you created and approved to your connected account, reads basic profile information to show which account is connected, and reads engagement or messages only to report them to you and let you respond. Varren does not post, send, reply or message on a connected account without your explicit approval.

Where we request a new permission from any platform, you authorise it on that platform's consent screen and this policy is updated before that occurs. When you disconnect a platform inside Varren, or revoke Varren's access from within the platform, we cease acting on it and delete or instruct the deletion of the stored credential.

Revocation is immediate and runs both ways. Disconnect inside Varren and we revoke the connection wherever the platform supports revocation and delete or instruct deletion of the stored credential, so no scheduled or pending action on that account can execute afterwards. Revoke Varren's access from within the platform, for example at https://myaccount.google.com/permissions, and our access ends at that moment; we detect the revocation and mark the connection dead. Revocation stops future processing. It does not delete content Varren already produced or the audit record of what it did; for those, see Section 15.


10. Autonomous action, your mandate, and automated decision-making

Varren posts, publishes, sends, replies, schedules and researches on the accounts you connect, and drives a browser inside sessions you are signed in to.

Your mandate. Varren acts only within a mandate you configure: which accounts are connected, which action types are enabled, and what limits apply. An action with an effect outside your workspace executes only against a recorded approval, matched at the moment of execution to the exact action it covers, so an approval cannot be replayed or extended to cover something else. Every action is recorded before and after it runs, showing what was proposed, which approval covered it, whether it executed, and the reason where it was refused or expired. That record is append-only, has no update or delete path, and the gate that writes it cannot be disabled. The workspace activity history, which carries published and scheduled actions, is additionally hash-linked so that an alteration or deletion is detectable. You may narrow or revoke the mandate at any time by changing your approvals or disconnecting the account.

Automated decision-making, GDPR Article 22. Varren makes operational decisions about how to carry out your instructions: what to draft, when to post, which model to route to, what to prioritise. We do not use Varren to make decisions about a person that produce legal or similarly significant effects, and our terms prohibit you from using it that way.

If you configure Varren so that a decision about a person is made without meaningful human involvement and carries such an effect, you are the controller of that decision and Article 22 falls on you. You must hold a valid basis for it, and you must give the person affected the right to obtain human intervention, to state their view, and to contest the outcome. We provide the approval layer and the audit trail that make meaningful human involvement possible; approving whatever Varren proposes without review is not meaningful involvement. There is no single control that halts all activity at once, so the involvement must be the approvals you keep in place before an action runs.

When an action goes wrong, withdraw the approval covering that work and disconnect the account it runs on, then write to [email protected], where a person can halt work for your workspace. We preserve the audit record and assist you in establishing what happened.


11. Google user data, connected mailboxes, and the Limited Use requirements

This section applies when you sign in with Google, connect a Google account, or connect any mailbox for Varren to read. There are two paths, and they give Varren different access.

11.1 Direct Google sign-in and publishing

What we request. Your OpenID identifier, email address and basic profile (openid, email, profile); permission to send email on your behalf (gmail.send); permission to upload video to YouTube on your behalf (youtube.upload); and permission to create and manage calendar events on your behalf (calendar.events). These scopes do not permit us to read your mail. The send scope sends and does not open your inbox; the calendar scope adds and updates events and does not read your calendar history for any other purpose.

How we use it. Your profile and email address identify your account and show which Google account is connected. The send scope is used only for the message you or your mandate direct us to send. The upload scope is used only for the video you direct us to publish. The calendar scope is used only to schedule or update the meetings and events you or your mandate direct. We keep the record of each message sent, each video uploaded and each event created as part of the audit trail.

Where we add a scope, you will be asked to authorise it explicitly, and this section is updated before that occurs.

11.2 Connected mailboxes, including Gmail read access

Separately from sign-in, you may connect a mailbox so that Varren can read it and run your unified inbox, for a Gmail account connected through our connector infrastructure or any mailbox connected by IMAP. Where you do so, Varren reads that mailbox:

Disconnect the mailbox inside Varren, or revoke access from within Google at https://myaccount.google.com/permissions, and the reading stops at that moment.

11.3 How we share Google user data

We do not share Google user data with third parties except: with the infrastructure sub-processors needed to run the Service, listed on our sub-processor page; where you direct us to; for security purposes; to comply with applicable law; or as part of a merger, acquisition or sale of assets, in which case we will give you notice.

11.4 Human access to Google user data

No human at Varren reads Google user data except where you have given specific affirmative agreement to look at a specific item, where it is necessary to investigate a security issue or abuse, where it is necessary to comply with the law, or where the data has been aggregated and anonymised for internal operations. This is stricter than the general internal-access position in Section 14, and overrides it for Google user data.

11.5 Limited Use

Varren's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

11.6 Artificial intelligence and machine learning

We do not use Google user data to develop, improve or train any artificial intelligence or machine learning model. We do not retain, use or transfer it to develop, improve or train non-personalised or generalised AI or ML models, and it is excluded from the cross-customer pattern learning in Section 8.

Where you ask Varren to act on a message, such as to draft a reply, the extract described in 11.2 is sent to a model provider solely to produce that output for you, under the requirements in Section 5: a paid commercial or enterprise tier, every optional data-sharing setting off, and terms of that tier that prohibit training a general-purpose model on the content sent, with the shortest retention period the provider offers. Routing is a single service-wide configuration, so an extract from your mailbox may reach any provider in the routing set. Where that is not acceptable to you, write to [email protected] and we will remove the provider you name from the routing configuration for all customers and confirm the date we did so.

11.7 What we do not do

We do not transfer or sell Google user data to advertising platforms, data brokers or information resellers. We do not use it to serve advertising of any kind, including retargeted, personalised or interest-based advertising. We do not use it to determine creditworthiness or for lending purposes.

11.8 Revoking

Withdraw Varren's access at any time at https://myaccount.google.com/permissions, or by disconnecting inside Varren.


12. Likeness, faces and voices

This section governs generation of video and audio carrying a real person's likeness or voice, from a reference photo, clip or recording you upload. It binds you from the moment the feature becomes available in your workspace.

Consent is required before you upload, and we may require you to evidence it. You may upload a reference of a person's face or voice only where that person is you, or has given you clear, specific, informed and documented permission to create synthetic media of them for the purpose you intend. The feature is available in Varren Motion, where you attach a reference photo of the person a clip must depict. You must keep a record of who the person is, the basis on which you hold their permission, and the date it was obtained, and produce it to us on request. Uploading without that permission breaches your contract with us and we may terminate the account.

We treat every reference face and voice as special category data. A facial image is biometric data under Article 9 of the GDPR when processed by technical means to uniquely identify a person. We rely on explicit consent under Article 9(2)(a) and require it from the person depicted. It must be freely given, specific, informed and unambiguous, and it may be withdrawn at any time.

Responsibility. You are the controller of the reference material and of the decision to generate. We are your processor for the generation. For the consent record and the withdrawal route only, you and Varren are joint controllers under Article 26 of the GDPR: we operate the contact route so the depicted person has a route to us, handle contact from them and inform you, and you remain responsible for having obtained the consent. The essence of that arrangement is set out in this section and in the Data Processing Addendum, and either of us may be approached by the depicted person.

Storage and retention. A reference you attach in Varren Motion is sent with the generation request to the model provider named on the sub-processor page and is not retained by Varren after the request completes; we keep no copy of it and no representation derived from it. The generated output is stored in your workspace and follows Section 15. Where we hold a reference, a derived representation or a consent record, the reference and any derived representation are deleted twelve (12) months after your last generation using them, or immediately on deletion or withdrawal of consent, whichever is first; a consent record is kept for as long as we hold the reference plus six (6) years, as evidence that the processing was lawful.

Withdrawal. The depicted person may withdraw consent by writing to [email protected], whether or not they are a Varren customer. We then cease all further generation using that likeness, delete the generated output and any reference or derived representation we hold, and inform the customer who uploaded it. We cannot recall content already published, and the customer who published it must remove it.

Legal hold. Where we are on notice of a dispute, claim, regulatory inquiry or criminal investigation concerning particular likeness material, we retain that material and the associated consent record for as long as necessary to establish, exercise or defend the legal claim, relying on Article 9(2)(f), and no longer, and delete it when the matter closes.

Prohibited. You may not use Varren to create a likeness of a person who has not consented; a likeness of a child; sexual or intimate imagery of any real person; a depiction of a person saying or doing something they did not, intended to deceive; an impersonation used to obtain money, credentials or a benefit; or synthetic media of a candidate for public office in connection with an election. We will terminate an account for any of these.

Local law. Illinois, Texas and Washington regulate the capture and use of biometric identifiers, and in Illinois this carries a private right of action with statutory damages per violation. Tennessee, California and other states regulate digital replicas of a person's voice or likeness, and several countries criminalise non-consensual synthetic intimate imagery and election deepfakes. Where the depicted person is in one of those places, their law governs you, and consent that satisfies this policy may not satisfy their statute.

Labelling. Where the model that produced your output embeds a machine-readable marker or watermark, we preserve it, and we preserve embedded provenance metadata where the file format supports it. Article 50(2) of the EU Artificial Intelligence Act requires providers of generative AI systems to mark AI-generated output in a machine-readable form. Where you publish the content you are the deployer under Article 50(4) and must disclose that it is artificially generated or manipulated no later than the first time a person sees it, and the same applies to AI-generated text you publish to inform the public on matters of public interest. Platforms add their own labelling rules and you must meet those. Both duties apply at once. We record in the audit trail that an output was AI-generated.


13. Who we share your data with

Government requests. We disclose customer data to a government authority only under a valid, binding legal order that applies to us. We check every request for validity and scope, refuse or challenge those that are overbroad or unlawful, disclose the minimum the order requires, and notify the affected customer unless legally prohibited. Where a request concerns data we hold as your processor, we direct the requester to you wherever we lawfully can.

We do not sell personal information and do not share it for cross-context behavioural advertising, and we do not use your data for advertising.


14. Security

Encryption. Traffic to and from the Service is encrypted in transit using TLS. Credentials and session material we hold ourselves, such as mailbox app passwords and saved browser sessions, are encrypted at rest with an authenticated cipher. The database sits on encrypted storage provided by our hosting platform.

Tenant scoping. Every table holding customer data is registered as tenant-scoped, and every ordinary query is rewritten to your workspace before it runs, so a query written for one workspace does not return another workspace's rows. A limited number of operator paths, used for billing and platform administration and never for customer content, run outside that rewrite; they are enumerated in the code, restricted to owner-only endpoints, and covered by automated tests that fail the build if a tenant-scoped table becomes reachable without a scope.

Access control. Role-based access control, per-role and per-user permissions, and owner-only restrictions on operator and cross-tenant surfaces. Two-factor authentication is available to all users and required for administrative roles.

Internal access to your content. A named Varren engineer may access workspace content only where you ask us to look at something specific; where it is necessary to investigate a security incident or suspected abuse; where the law requires it; or where we cannot otherwise reproduce and fix a fault you reported. Access is least-privilege and every instance is logged, and you may ask to see the log for your workspace at [email protected]. Stricter limits apply to Google user data under Section 11.4.

Other measures. A full audit trail of authentication events and of every action Varren takes. Secrets held in the platform's secret store, never in source control.

No system is perfectly secure. We limit the scope and impact of any incident and notify you promptly when one occurs.


15. How long we keep data, and how to have it deleted

DataRetention
Account and profile dataWhile your account is open, then 90 days after closure
Workspace content: prompts, documents, generated output, content libraryWhile your account is open, then 30 days after closure, unless you delete it sooner
Mailbox previews and inbox triage stateWhile the mailbox is connected, then deleted within 30 days of disconnection
Connection records and stored credentialsUntil you disconnect or revoke, then deleted immediately
Likeness reference material and derived representationsA reference is sent with the generation request and not retained. Where we hold one, 12 months after last use, or immediately on deletion or withdrawal of consent, whichever is first
Likeness consent recordsFor as long as we hold the reference, plus 6 years
Action and audit records6 years from the action
Billing records, invoices, Varren Credits ledger7 years, to meet tax and accounting obligations
Security and authentication logs12 months
Application and error logs90 days
Support correspondence3 years from the last message
Database snapshotsWe retain the most recent snapshots, currently the newest seven, deleting older ones as new ones are written

Deletion. Delete content inside the Service at any time. To delete your account and everything in it, write to [email protected]. We delete it from our live systems within 30 days and confirm in writing.

Deleting data connected from a platform (data deletion instructions). Where you connected an account from Google, TikTok, Meta (Facebook or Instagram), X or LinkedIn and want the data associated with that connection removed, either route works. First, disconnect the account inside Varren, which deletes or instructs the deletion of the stored credential and the connection record, so no further action can run on that account. Second, revoke Varren's access from within the platform's own app or security settings, for example at https://myaccount.google.com/permissions for Google, and we detect the revocation and mark the connection dead. To have everything Varren holds about you deleted, including content produced from a connected account, write to [email protected] and we complete it within 30 days and confirm in writing. This paragraph is the user data deletion instruction the platforms require us to publish, and it is published at https://varren.co/privacy. Copies inside database snapshots are not individually reachable and are deleted when the snapshot holding them is deleted, as newer snapshots replace it. Data is restored from a snapshot only to recover from a failure; if a restore reinstates data you asked us to delete, we delete it again and inform you.

What survives deletion:

  1. Records we are legally required to keep, such as billing records.
  2. The audit trail of actions already taken, for the period in the table above.
  3. Data inside a database snapshot, until that snapshot is deleted.
  4. The aggregated, de-identified patterns and quality signals in Section 8, which contain no content, identity or number of yours and from which nothing about you can be identified or reconstructed, so they are not personal data and are not deleted. To exclude your workspace from that layer, tell us before you delete.

Legal hold. Where we are on notice of a dispute, complaint, regulatory inquiry or claim concerning particular material, we retain that material for as long as necessary to establish, exercise or defend the legal claim, and no longer. We inform you and complete the deletion when the matter closes.

Content Varren already published remains on the platform, and you must remove it there.


16. Breach notification

Where a personal data breach occurs we investigate immediately, contain it, and notify as follows.

WhoWhen
Our customers, for data we process on their behalfWithout undue delay after we become aware, with what the customer needs to make its own assessment and notification. The decision whether to notify a regulator about the customer's data is the customer's.
Supervisory authorities in the EEA and the United Kingdom, for data we control (account, security and billing data)Within 72 hours of becoming aware, where the breach is likely to result in a risk to people's rights and freedoms, under Article 33 GDPR. Having no establishment in the Union, we notify each authority concerned, and separately the UK Information Commissioner.
Affected individuals in the EEA or UK, for data we controlWithout undue delay, where the breach is likely to result in a high risk to them, under Article 34 GDPR
The Nigeria Data Protection CommissionWithin 72 hours of becoming aware, under section 40 of the Nigeria Data Protection Act 2023, and affected individuals immediately where the risk is high
The Office of the Data Protection Commissioner, KenyaWithout undue delay and within 72 hours of becoming aware, under section 43 of the Data Protection Act 2019, and affected individuals where the risk is high
The UAE Data OfficeWithout undue delay after becoming aware, under Article 9 of Federal Decree-Law No. 45 of 2021
US state attorneys general and affected residentsWithin the deadline the relevant state law sets

The notice states what happened, the data involved, the approximate number of people affected, the likely consequences, what we have done, and what you should do. A notice, and anything in it, is not an admission of fault, breach of contract or liability.


17. Children

The Service is for adults. You must be 18 or older to use it. Nigeria and Kenya treat anyone under 18 as a child requiring parental consent, and Article 8 of the GDPR sets the age of consent for online services between 13 and 16 depending on the member state.

We do not knowingly collect personal data from anyone under 18. Where we learn that we have, we delete it and close the account. Where you believe a child has given us data, write to [email protected] and we will act within 7 days. You must not use Varren to generate content depicting a child's likeness or voice, or upload a child's face or voice as reference material.


18. Your rights, and how to exercise them

Send every request to [email protected], with "Data request" in the subject line and a description of what you want. We verify your identity, usually by confirming control of the email address on the account, and respond within 30 days, extendable by up to 60 days for a genuinely complex request, in which case we tell you within the first 30 with the reason. There is no charge.

A copy of your data is produced by a person on request, within the same 30 days, as JSON or CSV for records and in the stored format for uploaded and generated files. Where you need a different structure, tell us and we will state what we can do before we start.

Everyone, in every country, may ask us to tell you what we hold about you and why, who we share it with and how long we keep it; give you a copy in a portable, machine-readable format; correct anything inaccurate or incomplete; delete it, subject to the exceptions in Section 15; restrict how we use it while a dispute about accuracy or lawfulness is resolved; stop processing based on our legitimate interests, including profiling; withdraw consent at any time, without affecting what was lawful before; and put a human into any decision that significantly affects you, which you may then contest. We do not discriminate against anyone for exercising these rights. Where we are your processor and your request concerns data another Varren customer controls, that customer is the right person to ask; write to us and we will identify them, notify them promptly, and assist them in responding.

European Economic Area, United Kingdom, Switzerland. Your rights under Articles 15 to 22 of the GDPR and the UK GDPR. Every right in this section is exercised directly with us at [email protected] on the same 30 day clock, without charge. You may complain to your national supervisory authority at any time: in the United Kingdom, the Information Commissioner's Office at https://ico.org.uk/make-a-complaint/, and in the EU, the authorities at https://edpb.europa.eu/about-edpb/about-edpb/members_en.

United Arab Emirates. Your rights under Articles 13 to 18 of Federal Decree-Law No. 45 of 2021, with complaints to the UAE Data Office. Nigeria. Your rights under Part VI of the Nigeria Data Protection Act 2023, with complaints to the Nigeria Data Protection Commission at https://ndpc.gov.ng. Kenya. Your rights under Part V of the Data Protection Act 2019, with complaints to the Office of the Data Protection Commissioner at https://www.odpc.go.ke.

18.1 California

The CCPA as amended by the CPRA gives you the rights to know, delete, correct, opt out of sale or sharing, and limit the use of sensitive personal information. Our notice at collection, by statutory category:

CategoryCollectedExamples and purpose
IdentifiersYesName, email, account and workspace identifiers, IP address. To run and secure your account.
Customer records under Civil Code 1798.80(e)YesBilling contact and transaction records. To bill you and meet tax law.
Commercial informationYesYour plan, Varren Credits ledger, invoices. To bill you.
Internet or network activityYesFeatures used, screens viewed, error and diagnostic logs. To run, secure and improve the Service.
Geolocation dataCoarse onlyCountry or region inferred from IP. For security and tax. We do not collect precise location.
Audio, electronic, visual or similar informationYesContent you upload or generate, including images, audio and video. To provide the Service.
Professional or employment informationYesYour organisation and your role. To run team workspaces.
Sensitive personal informationYesAccount log-in and security credentials; biometric information where you use the likeness feature (a reference photo, clip or voice recording).
Education informationNoNot collected.
Inferences used to build a profileNoWe do not profile you and do not sell or share data for advertising.

We keep each category for the period in Section 15.

Sensitive personal information, and the right to limit. We collect account log-in and security credentials and, where you use the likeness feature, a reference photo, clip or voice recording. We use both only to perform the Service you requested and to secure it, a permitted purpose under section 7027 of the CCPA regulations, and we do not use either to infer anything about you. A likeness reference passes through us to the model provider that performs the generation and is not retained afterwards, as Section 12 sets out. You may ask us to limit our use of it at [email protected], and we will confirm in writing what we hold and what we do with it.

Sale, sharing and Global Privacy Control. We do not sell your personal information and do not share it for cross-context behavioural advertising, whether or not an opt-out preference signal is sent. A Global Privacy Control signal directs a business not to sell or share; since we do neither, there is nothing for it to switch off.

Disclosures and process. We do not sell your personal information and do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA as amended by the CPRA. We disclose the categories above to the recipients in Section 13 solely for the business purposes in Section 4. You may use an authorised agent. We respond within 45 days, extendable once by a further 45.

18.2 Other US states

In Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia and Washington you may access, correct, delete and port your data, and opt out of targeted advertising, sale and profiling, none of which we conduct. Where your state provides an appeal, appeal a refusal to [email protected]; we respond within 45 days and tell you how to reach your attorney general.


19. Cookies, tracking and email

We use cookies and local storage for three purposes only: keeping you signed in and holding your session; remembering your workspace and interface preferences; and security, including fraud prevention and abuse detection. These are strictly necessary or functional. We use no advertising cookies, no tracking pixels, and no third-party analytics that follow you across other websites, and therefore display no consent banner. You may block or delete cookies in your browser, but signing in will then stop working.

Global Privacy Control. A GPC signal directs a site not to sell or share personal information. We do neither, whether or not a signal is sent.

Do Not Track. There is no industry standard for a site's response to a Do Not Track signal, and we run no tracking advertising and no cross-site analytics, so we do not respond to it separately.

Email from us. Service, security and billing email is part of the Service and cannot be unsubscribed from while your account is open. Product announcements and marketing email are separate: we send them on your consent, or where the law permits it for an existing customer on our legitimate interests, and each carries a one-click unsubscribe we honour immediately.


20. Regulatory position


21. Changes to this policy

We update this policy as the Service and the law change, and change the version number and effective date at the top. Prior versions are available from the company on request to [email protected], by date or version number, within five business days.

For a material change, meaning one that expands what we collect, changes why we use it, adds a category of recipient, or reduces your rights, we notify you by email and in the Service at least 30 days before it takes effect, with a plain-language summary of what changed. Where a change requires your consent we ask for it. Adding or replacing a sub-processor runs under Section 6 and is not a change to this policy.


22. Language

This policy is written and published in English, and the English text is the governing version. Where we publish a translation and the two differ, the English text prevails, except where the law of your country requires otherwise.

Because Alpha Innovation Technologies - F.Z.C is registered in the United Arab Emirates and serves customers there, we provide an Arabic translation of this policy, and of our Terms of Service, to any UAE customer or UAE resident who requests one at [email protected], within 14 days and at no charge.


23. How to contact us

Where you are unhappy with how we have handled your data, tell us first at [email protected]. Where we do not resolve it, complain to the authority for your country listed in Section 18.


Varren is a product of Alpha Innovation Technologies - F.Z.C, trading as AlphaIT Engineering. Read this policy together with our Terms of Service at https://varren.co/terms and our Data Processing Addendum at https://varren.co/dpa.