Privacy & Data Protection Policy
Effective Date: August 2026 · VIAS Infrastructure · vias-infrastructure.com
1. Introduction
Welcome to VIAS Infrastructure. We respect your privacy and are committed to protecting your personal data. This privacy policy informs you how we look after your personal data when you visit our website (vias-infrastructure.com) or interact with our platform infrastructure, and tells you about your privacy rights and how the law protects you.
VIAS Infrastructure operates as a B2B data infrastructure provider. Our primary data processing relates to autonomous agent execution records and cryptographic proof data.
2. Data Controller
VIAS Infrastructure is the trading name of VIAS Infrastructure Ltd, a company registered in England & Wales (Company No: 17157032). We operate as an independent proof infrastructure provider for autonomous agent governance. VIAS Infrastructure Ltd is the formal data controller for all platform operations and data processing activities.
Company: VIAS Infrastructure Ltd | Company No: 17157032
Contact Email: governance@vias-infrastructure.com
2.A. Data Roles and Responsibilities
VIAS Infrastructure operates under a bifurcated data governance model:
- As a Data Controller: We act as the data controller for all direct interactions with this website, including business inquiries, account administration, and newsletter subscriptions.
- As a Data Processor: When providing our core proof and ledger infrastructure to corporate partners, VIAS Infrastructure acts strictly as a Data Processor. All ingestion, transformation, and storage of agent execution data is governed by a separate Data Processing Agreement (DPA) executed with the client, who remains the ultimate Data Controller of their organizational data.
3. The Data We Collect About You
In our capacity as an infrastructure provider, we collect, use, store, and transfer different kinds of data, primarily in a B2B context:
- Identity Data: First name, last name, title, and organisational affiliation.
- Contact Data: Corporate email address, telephone numbers.
- Technical Data: Internet protocol (IP) address, browser type and version, time zone setting, and operating system when accessing our site.
- Verification Data: If you utilise our evaluation or demonstration tools (including agent execution ingestion), we process the agent metadata and execution context provided to demonstrate governance alignment.
- Agent Execution Data: Anonymised or pseudonymised agent execution records submitted by platform and enterprise partners under a formal Data Processing Agreement (DPA).
4. How We Use Your Personal Data
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
- Legitimate Interests: For the provision of our B2B services, secure platform administration, and responding to corporate enquiries.
- Performance of Contract: Where we are about to enter into or have entered into a Service Level Agreement (SLA) with your organisation.
- Legal Obligation: Where we need to comply with a legal or regulatory obligation.
- Consent: Where you have explicitly opted in — e.g., signing up for briefings or newsletters.
5. Who We Share Data With
We do not sell personal data. We may share data with:
- Infrastructure Subprocessors: Our core ledger and data storage infrastructure is hosted exclusively within the United Kingdom via Amazon Web Services (AWS EU-West-2, London). All physical server security, geographic redundancy, and foundational network controls are managed by AWS under their shared responsibility model.
- Platform providers: Our application platform provider, operating under a data processing agreement.
- Email service providers: Used to respond to enquiries — subject to GDPR-compliant data processing agreements.
- Regulatory bodies: Where required by law, e.g., the ICO.
All third-party processors are required to handle data in accordance with UK GDPR. Each member organisation — whether a platform provider, enterprise partner, or institutional client — retains full ownership of the data they submit. VIAS Infrastructure holds no rights over member data beyond what is necessary to deliver the service.
6. Data Security & Infrastructure
As an institutional proof infrastructure provider, data security is foundational to our operations. We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way, altered, or disclosed.
- The platform is hosted on AWS EU-West-2 (London) infrastructure. All data remains within the UK region.
- We utilise tamper-evident audit logging and role-based access controls to maintain the integrity of all processed agent execution data.
- Institutional-grade encryption at rest and in transit is applied across all data flows.
- Annual independent penetration testing is conducted. Reports are available to authorised partners on request.
See our platform page for further technical details.
6.A. Data Capture Principles
All data ingestion is subject to privacy-by-design principles. Personal data is handled strictly under explicit, timestamped consent in compliance with UK GDPR. Data processing is conducted with institutional-grade confidentiality controls.
7. Data Retention
We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements.
- Enquiry and contact data: up to 2 years from last contact.
- Account data: for the duration of the account plus 12 months after closure.
- Audit logs and agent execution data: up to 7 years for compliance and legal purposes.
- Analytics data: anonymised after 26 months.
8. Your Legal Rights
Under UK GDPR, you have rights including:
- The right to request access to your personal data.
- The right to request correction of inaccurate data.
- The right to request erasure of your data (subject to legal obligations).
- The right to restrict or object to processing.
- The right to data portability (transfer).
- The right to withdraw consent at any time where processing is consent-based.
To exercise these rights, contact governance@vias-infrastructure.com.
You also have the right to make a complaint to the Information Commissioner's Office (ICO) at ico.org.uk.
9. Cookies
We use essential cookies required for the platform to function (e.g., authentication session cookies) together with Google Analytics 4 (GA4) analytics cookies for aggregate usage reporting. We do not use advertising or retargeting cookies. See our Cookie Policy for full details.
10. Changes to This Policy
We may update this policy periodically. The date at the top of this page indicates the last revision. Continued use of the platform constitutes acceptance of the updated policy.
Contact
VIAS Infrastructure · vias-infrastructure.com
Governance: governance@vias-infrastructure.com
Data queries: data@vias-infrastructure.com
