Legal

Privacy Policy

Effective from 18 August 2026 · operator Nydrok LLC

What data Vorda.studio processes, why, and what you can do about it. Written to be read, not to be survived.

This English text is a translation provided for convenience. The binding version is the Slovak one, available at vorda.studio/ochrana-osobnych-udajov. In the event of any discrepancy, the Slovak wording prevails.

1. Who the controller is

The controller is Nydrok LLC, 1209 Mountain Road Pl NE, Ste R, 87110 Albuquerque, New Mexico, Spojené štáty americké, EIN 36-5152970. For data protection matters write to info@vorda.studio.

This document describes how we handle personal data when running the vorda.studio website and the application behind the login.

2. Two different roles, two different regimes

For data about your account (email, company name, billing, what you did in the application) we are the controller. We decide why and how it is processed and we are responsible for that.

For data from your advertising and analytics accounts, including data about clients you manage in the tool, we are a processor. We process it on your instruction and you decide what happens to it. If you need to conclude a data processing agreement, get in touch.

3. What data we process

Account and billing data

  • Email address and login credentials. The email lives in the authentication service; we do not duplicate it into our own database.
  • Company and brand names, the name of the third level, roles and memberships.
  • Billing details and payment history. Your card number never reaches us; Stripe processes it.

Data from connected accounts

  • Campaign performance data from Google Ads and Meta, traffic from Google Analytics 4, queries from Search Console, the product feed from Merchant Center.
  • Store orders, if you enable that option.
  • Access tokens for those accounts. We store them encrypted (AES-256-GCM), never in readable form.

Content created in the tool

  • Conversations with VIA, campaign proposals, copy and generated creative.
  • A record of changes made in your advertising accounts.

Technical data

  • Operational and error logs needed to run and secure the service.

4. Why we process it and on what basis

  • To make the service work (performance of a contract): account, connections, overviews, monitoring, campaigns, creative, support.
  • To be able to invoice (performance of a contract and legal obligation): payments, invoices, accounting.
  • To keep the service secure and improve it (legitimate interest): operational logs, detecting misuse, fixing errors.
  • To be able to inform you (performance of a contract for operational messages, consent for commercial messages, which you can withdraw at any time).

5. What happens to data when VIA answers

VIA is a language model. To answer a question about your numbers, the part of your data the question concerns is sent to the model. The model is operated by Anthropic.

We do not use your data to train models and we do not let model providers store it beyond processing the request. Vorda keeps the conversation history in its own database so that it does not sit in two places at once.

6. Where the data sits and how it is protected

Both the database and the file storage are in the European Union, Frankfurt region.

  • Access tokens for advertising accounts are encrypted (AES-256-GCM).
  • Access to database rows is restricted at the database level, not only in the application.
  • Transfers take place over an encrypted connection.
  • We do not see passwords; the authentication service handles them.

7. Who we share data with

We do not sell data. We share it only with suppliers without which the service would not work, and only to the extent they need for their task:

SupplierFor whatProcessed in
SupabaseDatabase, login and file storageEU (Frankfurt)
VercelRunning the application and websiteEU and USA
AnthropicThe language model that powers VIAUSA
fal.aiGenerating image creativeUSA
DatoviaCreative generation, when enabledEU
UpstashCache for speedEU
InngestRunning long background jobsEU and USA
StripePayment processingEU and USA
WebsupportSending email (SMTP)EU

We may also disclose data to public authorities where the law requires it.

8. Transfers outside the European Economic Area

The operator is established in the United States and some of the suppliers listed above process data in the USA. Such transfers are covered by the European Commission’s standard contractual clauses and by supplementary measures including encryption. We will provide a copy of the transfer documentation on request.

9. How long we keep it

  • Account data: for as long as the account exists.
  • After the account is closed: deleted within 30 days, except what we must retain by law.
  • Billing documents: for the period required by tax rules.
  • Access tokens: deleted immediately once an account is disconnected.
  • Operational logs: as a rule within 90 days.

10. Your rights

If the GDPR applies to you, you have the right to:

  • know what data we process about you and obtain access to it,
  • have incorrect data corrected,
  • request erasure,
  • request restriction of processing,
  • receive your data in a machine-readable form and transfer it elsewhere,
  • object to processing based on legitimate interest,
  • withdraw consent at any time where we asked for it.

Write to info@vorda.studio and we will reply within one month at the latest. If you are not satisfied with how we handled it, you can turn to the supervisory authority in your country. In Slovakia this is the Office for Personal Data Protection of the Slovak Republic.

11. Cookies

We use strictly necessary cookies only, without which logging in and staying logged in would not work. They maintain the session, provide security, remember the selected context (which brand and client you have open) and remember the language you pick on the website. The language is stored only once you choose it yourself, not on arrival.

We do not use advertising or third-party tracking cookies and we do not link your behaviour on our website to advertising profiles. That is why we do not ask you for cookie consent; it is not required for strictly necessary cookies.

You can delete cookies in your browser settings. Once deleted, the service will log you out.

12. Changes to this document

We will update this document when what it describes changes, for example when a supplier is added. We will notify you of a material change by email or in the application. The version with the effective date shown above is always the one that applies.