Privacy · Draft for review
What the service records, and why.
This is a pre-release draft dated September 29, 2026. It is not an effective privacy notice for public use. Processing locations, retention periods, and request procedures require final approval.
These information pages
These pages contain no forms, client-side scripts, or external font requests. Their code does not set cookies. They do not connect to the document service.
When hosted, the website provider may process ordinary connection information, such as IP address, browser details, requested page, and request time. Provider practices are separate from this unfinished document-service notice.
Documents and account records
VDX Authority stores each document's current content and version, plus owner, tenant, and client identifiers associated with grants and receipts.
The service checks access scopes supplied by the identity provider in memory. It does not persist those scopes as a document record.
The document store is not a full history of prior content. Receipts retain before-and-after versions and content fingerprints. Backups, when enabled, can retain earlier document content.
Grants record the document, base version, exact replacement binding, recipient, and expiry. Receipts record the committed effect, versions, content fingerprints, and the identities needed to explain who was authorized.
Linked identifiers and content fingerprints can still be personal information. They are not treated as anonymous merely because they do not display a name.
How records are used
These records support document storage, account checks, exact owner authorization, prevention of duplicate edits, and recovery when a response is interrupted. Receipt retrieval requires an authenticated client. The public deployment's authorization checks still require verification.
The service also needs operational records to investigate failures and availability. Authentication secrets and unnecessary document content must be excluded from diagnostic records; the public deployment's error paths still require verification.
Deployment and providers
- Operator's PC
- Runs the service and stores its document database. Public storage and backup procedures are still being finalized.
- Cloudflare
- Hosts these VDX information pages. HTTPS delivery at authority.vongolaventures.com was verified on September 29, 2026. Public routing to the PC-hosted document service requires separate verification.
- Cloud-IAM / Keycloak
- Provides the existing private sign-in and token-validation service. Public account setup is being prepared.
- OpenAI / ChatGPT
- Receives information you provide to ChatGPT and the tool results returned to its connected app. Its separate terms and privacy settings also apply.
- Vercel
- Hosts the existing Vongola company website, linked separately from these pages. The planned VDX document database is stored on the operator's PC.
Provider processing locations must be confirmed before this draft becomes effective. This draft makes no promise about external model training or third-party retention.
Retention, export, and deletion
Retention periods remain undecided for documents, unused and consumed grants, receipts, operational logs, and backups. No automatic deletion interval or completed self-service deletion feature is promised by this draft.
The final notice must explain how a verified request is handled and which records remain necessary to prevent duplicate execution or preserve transaction evidence.
Questions and publication gate
Vongola Ventures LLC is the service operator for VDX Authority.
Send draft questions to vongolaventuresceo@gmail.com. Do not attach private document content or credentials.
Before public onboarding: confirm provider locations, retention and backup schedules, supported request procedures, deployed logging behavior, and an effective date.