Effective 26 September 2026.
This policy explains what personal data Vivotics collects, why, and what your rights are. Vivotics is operated by Cubitrek (Pvt) Ltd, Karachi, Pakistan ("we", "us"). For anything in this policy, write to support@vivotics.com.
For data about you as a visitor or account holder, such as your name, email and billing history, we are the controller. For the content a customer's team puts into its workspace, such as projects, client records, HR records, invoices and meeting transcripts, the customer is the controller and we process it on their instructions to provide the Service. If you are an employee or client of a company that uses Vivotics and you want your data corrected or removed, the workspace owner is the right first contact; we support them in answering you.
Account data: name, email address, company name, password (stored hashed) and, if you choose to add it, a phone number.
Workspace content: whatever your team enters or connects, including files, tasks, client and HR records, invoices, messages, and, if you use the Notetaker, meeting recordings and transcripts.
Billing data: your plan, invoices and payment status. Card numbers go directly to Stripe and never reach our servers.
Technical data: server logs with IP addresses for security and troubleshooting, and, on the marketing site, analytics events if you consent to them.
To run the Service you signed up for, to bill you, to answer support requests, to keep the platform secure, to send service messages such as invoices, reminders and alerts, and, with consent, to understand how the public website is used. We do not sell personal data, and we do not use your content to train shared or third party AI models.
When your workspace uses AI features, the relevant content, for example a meeting transcript being summarised or a question being answered, is processed by the AI model configured for the platform. That currently runs on our own servers; if a hosted provider is ever configured instead, it is used under terms that bar it from training on your content, and the active provider and its processing region are always visible to workspace admins under Settings, AI. The Notetaker bot joins a meeting only when invited or admitted, appears in the participant list under its own name, and its recordings and transcripts are stored in your workspace under your control.
We use a small set of service providers, each only for what is listed here:
If your team connects optional integrations, for example Google sign-in or Calendar, Dropbox, OneDrive or SharePoint, or meeting platforms through the Notetaker, data flows to those services only once you connect them, under their own terms.
The Service uses essential cookies to sign you in and protect forms (session and CSRF cookies) and Cloudflare sets security cookies to filter abusive traffic. The marketing site sets analytics cookies (Google Analytics) only after you accept them in the cookie banner; declining leaves everything working.
Production data is hosted in France. Backups are stored with the same host. Because our team and some providers operate internationally, limited data can be accessed from outside the European Union; where that happens for EEA or UK personal data we rely on the providers' standard contractual protections. Self-hosted deployments keep all workspace data on the customer's own infrastructure.
We keep account and workspace data while the account is active. You can delete your account in the app or by writing to support@vivotics.com; deletion removes workspace content from live systems, and backup copies expire on a rolling basis within about 16 days. Invoices and records we must keep for tax or accounting law are kept for the legally required period.
Traffic is encrypted with TLS, passwords are hashed, access to production systems is restricted and logged, workspaces are isolated per customer, and data is backed up daily. No system is perfectly secure; if a breach affects your data, we will inform you without undue delay.
You can ask for a copy of your personal data, have it corrected or deleted, object to or restrict processing, and take your data elsewhere. If you are in the EEA or the UK, these are your GDPR rights and you can also complain to your local supervisory authority. Write to support@vivotics.com and we will answer within one month.
The Service is a business tool and is not directed at children under 16. We do not knowingly collect their data.
When this policy changes materially we will say so in the app or by email before the change takes effect. The current version always lives at this address, with its effective date at the top.
Our experts will show you how our app can streamline your team’s work.
Plans from $2,000/year. Starts with a 30 day trial.