Skip to content
VITI

Legal

Privacy policy

Last updated: 19 July 2026

Viti provides a chat workspace, an OpenAI-compatible API and a CLI for companies. This policy explains what we process, where it is processed, and the rights you have. It is written to be read, not skimmed past.

Who does what

For the content your organisation sends through the platform — prompts, model responses, uploaded files — Viti acts as data processor on behalf of your organisation, which is the controller. For account, contract and billing information, Viti is the controller.

What we process

We process the following categories of data:

  • Account data — your name, work email address, organisation and role, used to operate your workspace.
  • Content data — prompts, model responses, uploaded files and generated documents your organisation sends through Viti.
  • Usage data — token counts, the model alias used, the region a request was served from, and cost. Usage events record the count and type of personal-data entities detected, never the values themselves.
  • Billing data — billing contact, company name, VAT id and payment details, handled by QuickPay. Card data is captured by QuickPay directly and never traverses Viti's systems.
  • Technical logs — request metadata kept for operations and security, retained for 30 to 90 days.

Processed in the EU

All application data — accounts, conversations, files, usage records and logs — is hosted on Microsoft Azure in Sweden Central. Model inference runs exclusively through EU-processing routes: GPT via Azure OpenAI's EU Data Zone, Claude via AWS Bedrock EU, Mistral in France, Kimi and DeepSeek via Azure AI Foundry Data Zone EUR.

Viti's promise is EU infrastructure with best-in-class models — not "European models only". Some model vendors are US-owned; we disclose that openly. What we control, contractually and in code, is where the processing happens and what leaves our infrastructure.

The PII masking layer

Before any request leaves Viti's infrastructure for a model provider, it passes through an internal service that detects personal data — names, national identification numbers including Faroese and Danish CPR, IBANs, email addresses, phone numbers, postal addresses — and replaces it with reversible placeholders. The provider receives "[PERSON_1]" where the user wrote a name; the response is un-masked inside our infrastructure before it reaches the user.

The mapping from placeholder to real value exists only in memory, scoped to a single request. It is never persisted — not to disk, not to logs. Usage records store only the count and type of entities detected.

Stated honestly: masking is a strong mitigation, not a guarantee. Detection can miss personal data in unusual formats or where a person is identifiable from context. Do not treat masking as licence to submit special-category data you would otherwise withhold.

Subprocessors

We use a small number of subprocessors, each contracted for EU processing. The full list — who they are, what they process and where — is published on our subprocessors page, and we give 30 days' notice before adding or replacing one.

View the subprocessor list

Retention

Conversation history and files are kept until your organisation deletes them. Account data is kept for the life of the contract plus 30 days. Usage and metering records are kept for 7 years as financial records. Logs are kept for 30 to 90 days. Prompt and completion content is not retained by model providers for training.

Your rights

Under the GDPR you can request access to, rectification or erasure of your personal data, restriction of or objection to its processing, and a portable copy of it. Write to us at the address below; we respond within one month. You may also lodge a complaint with your supervisory authority.

Contact

Privacy enquiries: hello@viti.fo — Viti, Tórshavn, Faroe Islands.