Volent
FunkcjeIntegracjeCennik
  • ENEnglish
  • UAУкраїнська
  • PLPolski
  • DEDeutsch
Napisz do nas
FunkcjeIntegracjeCennik
  • ENEnglish
  • UAУкраїнська
  • PLPolski
  • DEDeutsch

Polityka prywatności

Wersja 1.0 · obowiązuje od 2026-10-09

Ten dokument nie został jeszcze przetłumaczony, dlatego jest wyświetlany po angielsku.

RegulaminPolityka prywatnościUmowa powierzenia przetwarzania danychPolityka plików cookieDane wydawcy

This notice explains how personal data is handled in Volent. It is written to satisfy Articles 13 and 14 of the General Data Protection Regulation (GDPR) and the Law of Ukraine "On Personal Data Protection".

Defined terms. "Volent" or "the Service" means the hosted project management service. "Operator" means Volent, the provider of the Service. "Customer" means the organisation or person that creates a workspace. "User" means an individual using a workspace. "Workspace" means a tenant, reachable at its own subdomain. "Customer Data" means everything a Customer or its Users put into a Workspace.

1. Who is responsible

The Operator is Volent, the provider of the Service. Operator identity details are published in the Imprint.

Contact for any privacy matter, including the exercise of your rights: support@volent.net.

No Data Protection Officer has been appointed. This is lawful here because the Operator's core activities do not involve regular and systematic monitoring of data subjects on a large scale, and do not involve large-scale processing of special categories of personal data, so none of the conditions in Article 37(1) GDPR applies.

2. Two roles: controller and processor

The Operator's role depends on which data is in question, and the distinction runs through the whole of this notice.

Controller. For account data and for data arising from use of the public marketing pages, the Operator is the controller. This covers registration, sign-in, authentication records, transactional email and the technical data needed to serve requests. The Operator decides the purposes and means of that processing, and this notice is the Article 13 information for it.

Processor. For Customer Data inside a Workspace, the Operator is a processor acting on behalf of the Customer, who is the controller of that data. The Operator processes Customer Data only on the Customer's documented instructions; the use of the Service by the Customer and its Users is that instruction. The terms governing this role are set out in the Data Processing Agreement.

If you are a User of a Workspace created by your employer or another organisation, that organisation is the controller of the content you create in it. Requests about that content should be addressed to it first; the Operator will support the Customer as described in the Data Processing Agreement.

3. What data is processed

Account identity. Email address, display name, avatar image URL, interface language, timezone and a password hash. Email addresses are encrypted at field level; a keyed deterministic index is stored alongside them so that lookup by email remains possible.

Authentication records. Session and "remember me" records. A "remember me" record retains the browser user-agent string of the browser it was issued to.

Workspace security log. Each Workspace keeps a log of security-relevant actions taken in it — sign-ins and failed sign-ins, membership and role changes, invitations, API tokens, integration changes and settings changes — recording who acted, on what, and when. Entries about a sign-in also record the client IP address and browser user-agent string. The log is readable only by that Workspace's administrators, and only for that Workspace.

Customer Data. Work items, comments, chat messages and file attachments, together with whatever personal data Users choose to place in them. The Operator does not determine the content of Customer Data.

Feedback form submissions. The enquiry type, name, email address, subject and description you type into the form. The form is available without signing in, so someone who has no account can use it. This data is not stored in the Service's database — it is sent to the Operator by email and stays in the Operator's mailbox.

Feedback sent from inside the Service. A signed-in User can also write to the Operator from the help menu. You type only the feedback type and the message; your name, email address and the name and address of the Workspace you are in are taken from your session. The browser, operating system, interface language, window size, Volent version and the section of the app (without identifiers or names) are added only if you tick "Add technical details". As with the feedback form, the message is sent to the Operator by email, is not stored in the Service's database and stays in the Operator's mailbox.

Technical data needed to serve requests. The data inherent in delivering an HTTP service — request data processed to route a request to the correct Workspace, to authenticate it, to apply rate limits on authentication endpoints and to defend against abuse.

No personal data is bought from, or enriched by, any third party.

4. Legal bases

PurposeData involvedLegal basis
Creating an account and providing the ServiceAccount identityArt. 6(1)(b) GDPR — performance of a contract with you
Authentication, session management, "remember me"Authentication records, strictly necessary cookiesArt. 6(1)(b) GDPR — performance of a contract; Art. 6(1)(f) GDPR — legitimate interest in keeping sign-in secure
Security, abuse prevention and service integrity: CSRF protection, rate limiting on authentication endpoints, SSRF filtering of outbound webhooks, signature verification of inbound webhooks, tenant isolation, the Workspace security logAuthentication records, workspace security log, technical dataArt. 6(1)(f) GDPR — legitimate interest in protecting the Service, its Customers and its Users. The measures are minimal and expected by users of a business tool, and do not override your interests
Transactional email: verification codes and workspace invitationsEmail address, display nameArt. 6(1)(b) GDPR — performance of a contract
Notification digest emailEmail address, display nameArt. 6(1)(f) GDPR — legitimate interest in keeping team members informed of activity in their Workspace
Sign-in with Google, where you choose itAccount identityArt. 6(1)(b) GDPR — performance of a contract, at your request
Optional AI text generation, when a User presses the buttonThe text of that specific requestArt. 6(1)(a) GDPR — consent, given by the deliberate act of invoking the feature and withdrawable by not invoking it. Where the text is Customer Data, the Operator acts as processor and the basis is determined by the Customer
Repository integration with GitHub or GitLab, where a Workspace enables itCustomer Data and integration metadataProcessor role: the Customer's instruction under the Data Processing Agreement; the Customer determines the basis
Hosting Customer Data in a WorkspaceCustomer DataProcessor role: determined by the Customer as controller
Handling feedback from the public form and from inside the ServiceName, email address, subject, description; for feedback sent from inside the Service, also the Workspace name and address and, if ticked, the technical detailsArt. 6(1)(f) GDPR — legitimate interest in handling and answering enquiries about the Service. You decide how much to put in the message
Complying with a legal obligation binding on the OperatorWhatever the obligation requiresArt. 6(1)(c) GDPR

Consent is used only where it is named above. Nothing else in the Service depends on consent, and withdrawing consent to the AI feature has no effect on any other processing.

5. Cookies

The public website sets no cookies at all. The Service itself sets strictly necessary cookies only: a session cookie, a "remember me" cookie, a CSRF token, and two short-lived cookies that bind an OAuth or Git installation callback to the browser that started it. There are no analytics, advertising or profiling cookies, and no third-party cookies.

Because every cookie in use is strictly necessary to deliver a service you have requested, it is exempt from prior consent under Article 5(3) of the ePrivacy Directive. The full list, with attributes and lifetimes, is published in the Cookie Policy.

6. Recipients and subprocessors

Personal data is disclosed only to the recipients listed below. Each is engaged for a defined role, and each except hosting is optional and inactive unless the Operator or a Workspace has configured it.

RecipientRoleStatus
Google (Sign-In)Federated authenticationActive only if the Operator configures a Google client; otherwise disabled
Google (Gemini API)Optional AI text generation, invoked only when a User presses the buttonActive only if an API key is configured; otherwise the endpoints return HTTP 503 and the control is hidden in the interface
SMTP providerTransactional email: verification codes, invitations, digests, and feedback sent through the form or from inside the ServiceOff by default; enabled by configuration
GitHub / GitLabRepository integrationPer-Workspace opt-in
AnthropicAI agent sessions that a Workspace runs on its own Anthropic accountPer-Workspace opt-in, with the Workspace's own API key
Hosting providerServers and infrastructureAlways
CloudflareHosting of the public websiteAlways for the public website

Object storage for file attachments is operated by the Operator and is not a third-party recipient. If the Operator moves it to a managed provider, that provider is added to the table above before it begins processing.

Anthropic receives data only where a Workspace's administrator connects the Workspace's own Anthropic account and API key to run AI agents. The Workspace then has its own agreement with Anthropic, so Anthropic acts for the Customer and not as a subprocessor engaged by the Operator; the Operator sends it what the Workspace's use of the agents requires, on the Customer's instruction. Anthropic is established in the United States, and the Workspace's agreement with it governs that transfer.

There is no web analytics, no advertising or ad-tech, no error tracking, no session replay and no CRM in the Service. Personal data is never sold, and is never shared for advertising or profiling.

Data may also be disclosed where the Operator is required to do so by law, or is required to do so to establish, exercise or defend legal claims.

7. Optional AI text generation

The Service contains an optional AI writing feature. It does nothing until a User presses the button. When a User does press it, the text of that request is transmitted to Google's Gemini API, which returns generated text. Nothing is sent in the background and nothing is sent automatically.

The feature exists only if the Operator has configured an API key. Where no key is configured, the endpoints return HTTP 503 and the control is not shown in the interface.

The Operator does not use the content of these requests, or any other Customer Data, to train models.

8. International transfers

Google, in its capacity as authentication provider and as provider of the Gemini API, is a recipient established in the United States. Where personal data is transferred to Google, the transfer is made on the standard legal basis available at the time of the transfer — an adequacy decision under Article 45 GDPR where one applies to the recipient, otherwise the European Commission's Standard Contractual Clauses under Article 46(2)(c) GDPR, together with the transfer safeguards Google publishes for the relevant service.

The Operator holds no certification and makes no claim to one. If you want a copy of the transfer safeguards relied on, write to support@volent.net.

Cloudflare, which hosts the public website, is established in the United States and may process the technical data of a request there. Cloudflare states that it has certified its compliance with the EU-U.S. Data Privacy Framework and that it relies on the European Commission's Standard Contractual Clauses, with supplementary measures as necessary. The transfer therefore rests on the adequacy decision for certified recipients (Article 45 GDPR) and, where that does not apply, on those Clauses (Article 46(2)(c) GDPR).

Hosting of the Service itself is under the Operator's own control and introduces no recipient and no transfer beyond those described above.

9. Retention

The Service keeps personal data for as long as the account or the Workspace exists, subject to the following, which describe the Service's actual behaviour:

  • Work items moved to trash are purged 30 days after being trashed.
  • "Remember me" records are swept daily once they have expired or been revoked; the cookie itself has a 30-day maximum age and the underlying record is burned on sign-out.
  • Workspace invitations expire 14 days after being issued.
  • Security log entries are kept for as long as the Workspace exists, but the IP address and user-agent string attached to them are erased 180 days after the entry was made.
  • Messages from the feedback form or from inside the Service stay in the Operator's mailbox for as long as they are needed to handle the enquiry and any correspondence arising from it.

Deleting your account is self-service: Profile → Delete account, confirmed with a code emailed to your address. The deletion is not immediate: it is carried out automatically one month after you confirm the request — the same one-month deadline Article 12(3) GDPR gives us to act on the request, so the wait never pushes past it. During that month the account is blocked — you can sign in, but only to view your profile and cancel the deletion, which takes one click and needs no code. The waiting period is a safeguard: if someone else confirmed the deletion from your signed-in device or mailbox, the email announcing the scheduled date leaves you time to sign in and stop it.

Your Workspaces do not change during that month: other members still see you, work assigned to you stays assigned, and notification email keeps arriving. The request takes effect when it is carried out, not when it is made. You can silence the email in your notification settings.

If, when the month is up, you still own a Workspace other people are working in, or are its only administrator, the deletion is cancelled instead of carried out: nothing is erased, the account becomes usable again, and you are emailed which Workspace stands in the way and what to do about it. Otherwise the deletion erases your sign-in credentials, email address, name, avatar, connected Git accounts, API tokens, personal notification settings and group memberships, and anonymises your membership record in every Workspace you belonged to, including those you were removed from. It does not erase content: work items, comments, chat messages and file attachments you wrote stay with the Workspace they belong to, attributed to "Deleted user" instead of to you. That boundary is stated plainly because it is the part people expect to work differently.

The owner of a Workspace can delete it. Deletion begins 14 to 15 days after the owner confirms it (at the start of the next day in UTC after 14 full days). Until then the Workspace is locked for all its members and any administrator can restore it; the administrators are told by email when the deletion is scheduled and when it is cancelled. AI agent sessions that were running when deletion was requested are stopped, and restoring the Workspace does not restart them.

When deletion begins, all content of the Workspace — projects, work items, comments, files, chat messages, knowledge-base pages, member records, the security log and settings — is erased. The connections the Workspace holds with third-party services (payment, AI agent and code hosting providers) are closed, and the objects created there on the Workspace's behalf are deleted or, where the provider offers no deletion, permanently deactivated. Erasure of the data we hold is completed within 30 days of the confirmation, and within that time we ask each provider to delete what it holds. Where a provider fails or refuses to delete an object within 7 days after deletion begins, we stop retrying and keep only the identifier of that object at the provider, which contains no personal data; the completion email to the Workspace's administrators names the objects that remain.

The Workspace's subscription, if it has one, is cancelled when deletion begins. No refund is made automatically; a request for one is handled manually through the payment provider, which as seller of record keeps its own records of the purchase under its own terms. A copy of an API key the Workspace stored with us is erased; the key itself stays valid in your account with that provider until you revoke it there. A code-hosting authorisation that a member granted from their own account is removed from the Service but stays listed in that member's account with the provider until they revoke it there.

Your personal account is not deleted with a Workspace. After the deletion we keep only a record that the Workspace was deleted: its identifier, the dates of the deletion process and any objects left with a provider as described above. The record holds no name, address, email address or user identifier.

A Workspace whose last remaining member deletes their account is erased in the same way when that deletion is carried out at the end of the month described above, without a further waiting period. We carry out the deletion on the instruction of the customer that uses the Workspace. Erased data can remain in storage media until it is overwritten in the ordinary course of operation; it is no longer accessible through the Service.

Where an administrator removes a User from a Workspace, the User loses access to it at once: their sign-in to that Workspace, their API tokens and their roles there end. Their record in that Workspace is kept — name, email address, the avatar file and the link to the work items, comments and messages they wrote — so that the Workspace's history still names them and an administrator can add them back by inviting the same email address. The avatar is no longer shown, and other members no longer see the removed User's email address; the Workspace's administrators do. The record has no fixed retention period: it is kept until the User is added back, an administrator erases it, or the User deletes their account, and never longer than the Workspace exists.

An administrator of the Workspace can erase a removed User from it, for example when the customer that uses the Workspace receives an erasure request. The erasure deletes the User's name, email address and avatar from that Workspace's record and shows "Deleted user" in their place in the Workspace's content, notifications, invitations, settings history and security log; security log entries keep the User's identifier, without the name. A pending invitation to the User's address in that Workspace is revoked. The erasure does not reach copies kept as free text without the User's identifier: the assignee's email address in an automation rule and in the work item history entry that rule writes, the label text inside a stored @-mention, the name of a group conversation made from its members' names when it was created, and the "Forwarded from" name on forwarded chat messages where it is stored only as text (older forwards and their re-forwards). The User's account and their membership in other Workspaces are not affected.

10. Security

The following measures are in place. They are listed because they exist, and no other measure should be inferred from this list.

  • Email addresses are encrypted at rest at field level, with keys held outside the database.
  • Passwords are stored only as hashes; the Operator cannot read them.
  • Session cookies are HttpOnly, Secure and SameSite=Lax. Sessions carry a sliding 8-hour idle timeout, and the session identifier is rotated periodically during a session.
  • "Remember me" is a rotating credential series that is burned on sign-out.
  • State-changing requests are protected against cross-site request forgery.
  • Tenant isolation is enforced in the authorisation layer: a Workspace resolves from its subdomain and every access is authorised against that Workspace.
  • Outbound webhooks are filtered against server-side request forgery; inbound webhooks are signature-verified.
  • Authentication endpoints are rate limited.
  • Traffic is encrypted in transit with TLS.

No security measure is absolute. You are responsible for keeping your credentials confidential and for the access rights you grant inside your Workspace.

11. Your rights

Subject to the conditions in the GDPR, and correspondingly under Article 8 of the Law of Ukraine "On Personal Data Protection", you have the right to:

  • obtain confirmation of whether your personal data is processed, and access to it (Art. 15);
  • have inaccurate data corrected and incomplete data completed (Art. 16);
  • have your data erased (Art. 17);
  • obtain restriction of processing (Art. 18);
  • receive your data in a structured, commonly used, machine-readable format and have it transmitted to another controller where technically feasible (Art. 20);
  • object to processing based on legitimate interests, on grounds relating to your particular situation (Art. 21);
  • withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal (Art. 7(3)).

How these are actually fulfilled. Erasure (Art. 17) is self-service: Profile → Delete account records the request at once and carries it out automatically one month later — within, not after, the deadline Article 12(3) sets. Section 9 states exactly what it erases, what it leaves with the Workspace, and how the cancellation window works. The window exists so that a deletion confirmed by someone who took over your device or mailbox can still be stopped by you; the account cannot be used while it runs, and the deletion is carried out without any further action from you. An account that has not created a Workspace deletes itself from the account menu on the onboarding screen. An email is sent to that address when the deletion is scheduled and again when it is carried out. Where you own a Workspace that other people are still in, the function asks you to hand ownership over first — it will not close a Workspace other people are working in. The owner of a Workspace can delete the Workspace itself, with its content, as section 9 describes. If the confirmation code cannot reach you, erasure may also be requested at support@volent.net and is carried out within one month. Where you have been removed from a Workspace and want to be erased from that Workspace only, the request goes to the customer that uses it: its administrators carry out the erasure section 9 describes, without your account being deleted.

There is no self-service data export. Access (Art. 15), portability (Art. 20), rectification, restriction, objection, and any erasure going beyond what the delete-account function does — are carried out manually by the Operator upon a request sent to support@volent.net, and answered within one month of receipt, as Article 12(3) GDPR requires. That period may be extended by two further months where the request is complex, in which case you will be told of the extension and the reason within the first month.

Where a request concerns Customer Data and the Operator acts as processor, the Operator will forward the request to the responsible Customer and assist that Customer under the Data Processing Agreement rather than act on the data itself.

Complaints. You may lodge a complaint with a supervisory authority, in particular in the EU or EEA Member State of your residence, place of work or the place of the alleged infringement. In Ukraine, the competent authority is the Ukrainian Parliament Commissioner for Human Rights (the Ombudsman). You may also raise the matter with the Operator first at support@volent.net; that is not a precondition to complaining.

12. Children

The Service is a business tool and is not directed to children. It may not be used by anyone under 16 years of age. The Operator does not knowingly process the personal data of a person under 16. If you believe such data has been provided, write to support@volent.net and it will be deleted.

13. Changes to this notice

This notice may be updated when the Service changes or the law changes. Every version carries a version number and an effective date. Material changes will be notified in advance by email to the address on the account, or by a notice in the Service, before they take effect. Continued use of the Service after the effective date means the updated notice applies to that use.

14. Version and effective date

Version 1.0. Effective 2026-10-09.

Related documents: the Terms of Service, the Data Processing Agreement, the Cookie Policy and the Imprint.

Volent

Tracker zadań zbudowany wokół Twojego procesu.

Produkt

FunkcjeIntegracjeCennik

Informacje prawne

RegulaminPolityka prywatnościUmowa powierzenia przetwarzania danychPolityka plików cookieDane wydawcy
© 2026 Volent