Privacy Policy
Version 2026-07-12
1. Who we are
VFXBoi provides pipeline and production-management software (the App Suite) to studios and individual artists. This policy describes how we handle personal data when you use our hosted or self-hosted services.
2. Data we collect
- Account data: name, email, studio name, role, authentication identifiers.
- Studio configuration: show/shot structure, user assignments, license and entitlement metadata.
- Usage telemetry: feature usage, seat and machine counts, storage consumption, project counts, last-seen timestamps, instance health and software version, sent to our vendor portal about every fifteen minutes to operate licensing, billing, fleet health, and support.
- Diagnostics data: automated self-tests and health probes we run against the service produce scenario results, error traces and stacks, performance timings, anomaly signals, and anonymized fingerprints, so we can detect and fix bugs, gaps, and vulnerabilities before they affect you. By default this data is anonymized and never includes your production media, project files, or client personal data. See section 3b.
- Content-security (forensic) data: when you enable protected review or delivery links, we record viewer IP address, device or machine identifiers, timestamps, and view, download, and share counts for those links, so you can trace leaks of your own media. See section 3c.
- Provenance metadata: to keep your pipeline traceable, produced outputs may embed which user produced a file, on which machine, and when.
- Purchase and subscription records: your email, payment identifier from our payment provider, plan, and subscription history, held in our vendor records to run billing, prevent duplicate or fraudulent signups, and support you.
- Security logs: IP addresses, login and session events, and audit entries for media access, role changes, deletions, configuration, and administrative actions.
- Support communications: tickets, chat, and email correspondence you send us.
3. How we use data
We use personal data to provide and secure the App Suite, authenticate users, enforce license limits, bill licensed seats, deliver support, improve reliability, and meet legal obligations. We do not sell personal data.
3a. Our data promise (purpose limitation and data minimization)
We use your data ONLY to run the service you are paying for. Specifically:
- We do not sell, rent, or share your personal data or production data with advertisers or data brokers.
- We use your data only for the purposes in section 3. We do not repurpose it for anything unrelated.
- We collect only what the service needs (data minimization).
- We do not use your production files, media, project data, or messages to train AI models, and we do not feed them to third-party AI except a feature you explicitly turn on (for example the optional AI assistant), and then only to answer your request.
- We do not send you marketing email without your consent; service and account emails are separate and necessary to operate your account. You can opt out of non-essential email at any time.
- Optional AI features, when enabled by you, send only the specific text needed to fulfil your request to the AI provider named in our subprocessor list, and the result is returned to you.
3b. Diagnostics and product improvement
We run automated self-tests, health probes, and passive watchers across the service to detect and fix bugs, gaps, and vulnerabilities and to keep the service reliable and secure. Diagnostics come in two clearly separated levels:
- Operational diagnostics (always on, anonymized): scenario pass or fail results, error traces and stacks, performance timings, anomaly signals, and fingerprints that group similar issues. These are anonymized, contain no production media or client personal data, and let us find and fix a problem across our systems without identifying anyone. Like error monitoring and security scanning, they are a necessary part of operating and securing the service, so they are not optional. This is the level our automated bug and vulnerability detection uses.
- Deep diagnostics (opt-in, and you can switch it off): only if you explicitly turn it on, for example so we can investigate a specific support case for you, may a diagnostic include limited identifiers that tie it to a particular user or record. You can withdraw this at any time with a per-account switch.
We never send your production files, media, or personal data as diagnostics, and we do not use your content to train AI models.
3c. Security and forensic monitoring
When you enable protected review or delivery links, we provide content-security monitoring on your behalf: we log viewer IP address, device or machine identifiers, timestamps, and view, download, and share counts for those links, so you can detect and trace unauthorised sharing of your own media. This is a security feature we operate for you, the customer, on the media you choose to protect. External reviewers who open a protected link see a short notice that access is logged for content security, so the tracked person is informed. We also keep audit and session logs of security-relevant actions (logins, role changes, deletions, configuration, and administrative actions) for accountability and incident response.
3d. Our roles: when we are controller and when we are processor
Being clear about which role we play matters. We act as the data controller (we decide the purpose and means) for our own account and billing data, usage telemetry, diagnostics, and our vendor subscription records. We act as the data processor (we act on your instructions under the Data Processing Agreement) for the production, HR, finance, and media content you put into the App Suite, which remains yours. Forensic monitoring is a security feature we provide to you as processor on the media you protect.
4. Where data is stored
Data is stored on infrastructure you configure (self-hosted) or that VFXBoi operates on your behalf (cloud). Backups and logs follow the same deployment. Cross-border transfers, if any, use appropriate safeguards described in our Data Processing Agreement.
5. Retention
We keep data only as long as needed for the purpose we collected it, then delete or anonymize it. By category:
- Account and studio configuration: for the life of your subscription, then deleted or anonymized after a short wind-down window unless you ask sooner.
- Usage telemetry: recent history is kept rolling (the most recent readings) for fleet health; older detail is aggregated into counts.
- Diagnostics: findings are anonymized at source, per-user identifiers are hashed and short-lived, and aggregate counts are retained to track quality trends.
- Content-security (forensic) logs: retained for the window you choose for each protected link, so you keep the audit trail for as long as you need it.
- Security, audit, billing, and tax records: retained as required by law and for legitimate accountability, which may be longer than your subscription.
You may request earlier deletion, subject to records we are legally required to keep.
6. Your rights
Depending on your jurisdiction you may request access, correction, export, restriction, or deletion of personal data. Contact privacy@vfxboi.in. We respond within applicable legal timeframes.
7. Subprocessors
We use infrastructure and email providers to operate the service. A current list is available on request or in the DPA annex. We require subprocessors to protect data consistent with this policy.
8. Contact
privacy@vfxboi.in