Privacy Policy
Virexya ("we," "us") processes photographs on behalf of the organizations that engage us. This policy explains what we collect, why, how long we keep it, and the commitments that make Virexya safe for enterprise, education, and government use. For most processing we act as a data processor on the instructions of the customer, who is the data controller.
What we collect
- Uploaded photographs submitted by individuals through a single-use link.
- A display name, if provided, to label the delivered portrait.
- Administrator account details and billing contact for the purchasing organization.
- Basic technical logs (timestamps, request metadata) needed to operate and secure the service.
How we use it
Uploaded photographs are used solely to generate the requested portrait for your organization and are then deleted. We do not sell personal data, we do not use images for advertising, and we do not use any uploaded image to train, fine-tune, or improve any AI model. The base models we use remain static.
Retention and deletion
- Source photographs: hard-deleted within seven (7) days of upload.
- Final portraits: hard-deleted within thirty (30) days of delivery.
- Deletion is executed by an automated job and each deletion is logged as a receipt.
- We keep no application-level backups or copies of images beyond these windows.
Security
Data is encrypted in transit (TLS 1.3) and at rest (AES-256). Processing runs in an isolated environment with no public egress. Access to intake is limited to single-use links issued by the customer's administrator; individuals do not create accounts. A SOC 2 Type II readiness program is underway.
Subprocessors
We use a small set of vetted infrastructure providers to run the service: cloud hosting and database (Supabase), object storage (Vercel), and AI generation (Replicate, under API terms that prohibit training on submitted content). Primary data storage is in the United States. A current subprocessor list is available on request at security@virexya.com.
Data residency and processing agreements
Data is processed and stored in the United States. A Data Processing Agreement (DPA) is available for customers who require one, and dedicated or sovereign deployment options are offered for regulated engagements. Request either at security@virexya.com.
Individual rights
Because we process images on behalf of your organization, requests to access or delete a photograph should be directed to your organization's administrator, who instructs us. We support those requests promptly, and in any case source and final images are deleted on the schedule above.
Contact
Privacy and security questions: security@virexya.com. General: info@virexya.com.