// Privacy

Privacy policy

Last updated: 8 July 2026

1. Who we are

vanadio is a product of Vanilla Steel GmbH ("we", "us"). We are the controller for the processing described in sections 3 and 4, and a processor for the processing described in section 5.

Vanilla Steel GmbH
Schönhauser Allee 36
10435 Berlin, Germany
Commercial register: Amtsgericht Charlottenburg, HRB 218619 B
Email: privacy@vanadio.ai

2. What vanadio does

vanadio is software for industrial-materials businesses. It classifies incoming business email (for example requests for quotation, orders, claims, and call-offs), extracts structured line items from inquiries, and supports the quoting workflow. It is offered to business customers, not to consumers.

3. Data processed when you visit this website

This website sets no cookies. We do not profile you as an individual, and we do not record your screen activity or what you type into forms.

When you access the site, our hosting provider Netlify processes the technical data your browser transmits (IP address, date and time of the request, requested page, browser type) in server logs. This processing is necessary to deliver the site securely and is based on our legitimate interest (Art. 6(1)(f) GDPR). Log data is retained only as long as needed for security and operations.

We use Netlify Analytics to produce aggregate statistics about site usage, such as page views, most-visited pages, and referring sources. It is derived from the server logs described above, runs entirely on the server, sets no cookies, and stores nothing on your device. The legal basis is our legitimate interest in understanding how the site is used (Art. 6(1)(f) GDPR).

We use Leadinfo, a visitor recognition service provided by Leadinfo, a company established in the Netherlands, acting as a processor on our behalf. Leadinfo compares the IP address of your request against publicly available business data in order to identify the organisation from which a visit originates, together with the pages viewed. The service is configured for cookie-less operation: it sets no cookies, carries out no device fingerprinting, and no screen recording or form tracking is enabled. It does not identify you as a natural person, and we make no attempt to link a visit to a named individual. The legal basis is our legitimate interest in learning which businesses are interested in our product (Art. 6(1)(f) GDPR). The data is processed within the EU.

You may object to the processing described in this section at any time under Art. 21 GDPR by writing to privacy@vanadio.ai. We will then exclude your organisation from further recognition.

If you switch the site between English and German, your choice is saved in your browser's local storage under the key vanadio-lang so that the site remembers it on your next visit. This is required to provide the language function you selected and is not used for tracking or analysis.

Fonts are served from our own server. No requests are made to third-party font services when you visit this site.

4. Data processed when you contact us

If you email us or submit the demo form, we process your name, company, email address, role, and the content of your message to respond and to arrange a pilot (Art. 6(1)(b) and (f) GDPR). The demo form is handled by our website host, Netlify, acting as a processor: submissions are stored in our Netlify account and forwarded to us. We keep this correspondence as long as needed to handle the matter and to meet statutory retention duties.

5. Data processed in the vanadio platform and Outlook add-in

When a customer connects vanadio to their Microsoft 365 environment, vanadio accesses mailbox data through Microsoft APIs with the consent of the customer's administrator and within the permissions granted in Microsoft Entra ID (Azure AD). Access to mailbox content is read-only, and we do not modify or delete anything in the mailbox. Messages classified as relevant (for example RFQs) are stored and processed in our EU infrastructure so we can extract and structure them; other messages are not retained.

For this processing we act as a processor on behalf of our customer (the controller) under a data processing agreement pursuant to Art. 28 GDPR. Details, including the categories of data, are defined in the DPA. In summary:

  • Purpose: classification of incoming email, extraction of structured data from business inquiries, and support of the customer's quoting workflow.
  • Categories of data: email metadata (sender, recipient, timestamps, subject) and the content of business correspondence, including file attachments, which may contain contact details of the customer's business partners.
  • Hosting: all processing takes place on servers in the European Union.
  • AI sub-processor: classification and extraction use OpenAI's large-language-model API, called with EU data residency so content is processed in the European Union. Inputs and outputs are not stored at rest (zero data retention) and are not used to train models.
  • No training for others: customer data is never used to train or improve models made available to other customers.
  • Tenant separation: standard customers are logically separated within a shared database; enterprise customers can request a dedicated database. Data from different customers is never mixed.

If you are an employee or business partner of one of our customers and have questions about this processing, please contact the customer (the controller) first; we support them in answering data-subject requests.

6. Sub-processors and recipients

We use a small number of service providers under Art. 28 GDPR contracts. Customer content is processed primarily within the European Union. Our main sub-processors are:

  • Google Cloud (hosting and compute; EU region, Frankfurt and Berlin).
  • OpenAI (AI classification and extraction; EU data residency, zero data retention, not used to train models).
  • Dropbox (secure file exchange for data you provide during set-up; files stored in the EU, with limited metadata in the US).

Where limited residual transfers to the United States occur (for example certain metadata or fallback API routing), they are covered by EU Standard Contractual Clauses. The current full list of sub-processors is available on request via privacy@vanadio.ai and is annexed to the DPA.

We do not sell personal data and do not share it for advertising purposes.

7. Retention and deletion

We keep personal data only as long as needed for the purposes above or as required by law. For platform data, retention is governed by the DPA: on termination of the agreement, customer data is returned or deleted in line with our deletion concept per GDPR.

8. Security

We apply technical and organizational measures appropriate to the risk, including encryption in transit and at rest, strict tenant separation, role-based access controls, and logging. More detail is on our security page. ISO 27001 certification is in progress.

9. Your rights

Under the GDPR you have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interests. You can reach us at privacy@vanadio.ai. You also have the right to lodge a complaint with a supervisory authority; the authority competent for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Berlin, Germany.

10. Changes to this policy

We update this policy when our processing or the legal framework changes. The date at the top shows the latest revision.