1. Who we are
This Privacy Policy describes how Ventrue Technologies S.A.S. ("Ventrue Tech", "we", "us") collects, uses, and protects your personal data when you visit ventrue.tech, contact us, or use any of our products and services — including Ventrue Social, our multi-client content automation platform that connects to third-party platforms such as TikTok, Instagram, and LinkedIn on your behalf.
We are a software engineering practice headquartered in Quito, Ecuador. The data controller responsible for the processing described in this policy is Ventrue Technologies S.A.S., represented by its founder Erick Escobar. You can reach us at hello@ventrue.com.ec for any privacy-related question.
2. Scope
This policy applies to personal data we process in three contexts:
- Marketing website — visitors to ventrue.tech, including users who submit our contact form.
- Ventrue Social SaaS — businesses, creators, and operators who connect their TikTok, Instagram, and/or LinkedIn accounts to our platform so that we can schedule and publish content on their behalf.
- Client engagements — companies that hire us for software, cloud, DevOps, or AI/automation services.
It does not cover the privacy practices of third-party platforms (e.g. TikTok, Meta, LinkedIn, Google) that you authorize us to interact with. Those platforms have their own privacy policies, and you remain subject to them.
3. Data we collect
3.1 From website visitors
- Contact form submissions: name, email, optional phone, service of interest, budget range, and the project description you write. Submitted via Formspree to our inbox.
- Analytics: standard usage data such as pages viewed, referrer, device type, approximate location (country/region), and anonymized IP address, collected via Google Analytics 4.
- Cookies: see section 11.
3.2 From Ventrue Social SaaS users
When you create a Ventrue Social account and connect a social platform, we collect and store:
- Account information: email, display name, password hash, and account preferences.
- OAuth credentials: access tokens and refresh tokens issued by TikTok, Instagram, LinkedIn, and similar platforms, scoped to the permissions you explicitly grant during the OAuth consent screen. We never see or store your platform passwords.
- Connected-account metadata: your TikTok/Instagram/LinkedIn username, user ID, display name, and (where the platform provides them) public profile fields.
- Content you create or schedule: text, images, video files, captions, hashtags, schedules, and the platforms you target. Stored in our infrastructure for as long as you keep the post scheduled or want it accessible in your history.
- Posting results and telemetry: success/failure logs, platform response codes, and metrics that the connected platform exposes (e.g. number of views, likes, comments). Used to show you analytics in your dashboard and to retry failed posts.
- AI prompts and outputs (where you use AI features): the prompts you send and the generated drafts we return, retained to provide history and improve service quality.
3.3 From client engagements
- Business and billing data: company name, tax ID where applicable, contact persons, invoicing email and address, and payment records.
- Project data: any documents, credentials, or system access you share with us during an engagement, handled under the confidentiality terms of our service agreement.
4. How we use your data
We process personal data for the following purposes, on the legal bases indicated:
- To provide the services you request — including publishing content to your connected social accounts, generating AI drafts, sending you product emails, and supporting client engagements. Legal basis: performance of a contract.
- To respond to contact-form inquiries. Legal basis: legitimate interest in answering prospective clients, and your consent when you submit the form.
- To improve and secure our products — analytics, error monitoring, fraud detection, abuse prevention. Legal basis: legitimate interest.
- To comply with legal obligations — including responding to lawful requests from competent authorities. Legal basis: legal obligation.
- To send service updates and, where you consent, marketing. Legal basis: legitimate interest for transactional emails; consent for marketing.
5. Third-party services we use
To operate our products we rely on the following processors. Each is a separate data controller for the data it independently collects, and a data processor when it handles data on our instructions:
- TikTok — receiving and posting content on accounts you connect.
- Meta (Instagram, Facebook) — same purpose, where you connect those accounts.
- LinkedIn — same purpose.
- Google Analytics 4 — anonymized website usage analytics.
- Formspree — delivery of contact-form submissions to our inbox.
- Cloud infrastructure: AWS and/or Microsoft Azure — application hosting, database, file storage.
- AI model providers: Anthropic and OpenAI — generation of draft content when you use AI features. Prompts and outputs are transmitted to these providers under their data-processing terms. We do not allow these providers to train their models on your data.
- Email and messaging: Google Workspace (for hello@ventrue.com.ec).
We sign data-processing agreements with each processor and review them for adequate security and privacy practices.
6. Data sharing and disclosure
We do not sell your personal data. We share it only:
- With the processors listed in section 5, strictly to operate our services;
- With the social platforms you have authorized — for the content and metadata you direct us to publish to those platforms;
- With our professional advisors (legal, accounting) under confidentiality;
- When required by law, court order, or to protect rights, property, or safety;
- In the event of a merger, acquisition, or asset sale, in which case we will notify affected users in advance.
7. Data retention
- Contact-form submissions: retained for up to 24 months after the last contact, then deleted, unless an active engagement requires longer retention.
- Ventrue Social account data: retained while your account is active. After you delete your account, we delete personal data within 30 days, except for records we must keep for legal, tax, or accounting purposes (typically up to 7 years under Ecuadorian law).
- OAuth tokens: retained while the connection is active and revoked immediately when you disconnect the platform or delete your account. We do not keep tokens after revocation.
- Scheduled content: retained while pending and for 90 days after posting, then archived in summary form for your analytics history.
- Logs and analytics: typically 13 months for analytics, 90 days for application logs.
8. Your rights
Under Ecuador's Ley Orgánica de Protección de Datos Personales (LOPDP) and, where applicable, the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Delete your data ("right to be forgotten");
- Restrict or object to certain processing, including profiling;
- Receive your data in a portable, machine-readable format;
- Withdraw consent at any time, without affecting the lawfulness of previous processing;
- Lodge a complaint with a supervisory authority — in Ecuador, the Superintendencia de Protección de Datos Personales.
To exercise any of these rights, email hello@ventrue.com.ec with the subject line "Privacy Request". We will respond within 15 business days.
9. How to revoke access and delete your data
You can disconnect any social platform from Ventrue Social at any time through the in-app settings. Doing so immediately revokes the OAuth token we hold and deletes the connected-account metadata.
You can also revoke our access directly from the platform: for TikTok, visit your account's Manage app permissions page; for Instagram and Facebook, visit Apps and Websites in your Meta account settings; for LinkedIn, visit Permitted Services.
To delete your Ventrue Social account entirely, email us at hello@ventrue.com.ec. We will confirm deletion within 30 days.
10. International transfers
Because our infrastructure providers and AI providers operate globally, your personal data may be transferred to and processed in countries outside Ecuador, including the United States and the European Union. We rely on Standard Contractual Clauses and equivalent safeguards where required.
12. Children
Our services are not directed at children under 16. We do not knowingly collect personal data from anyone under that age. If you believe a child has provided us data, contact us and we will delete it.
13. Security
We protect your data with technical and organizational measures appropriate to the risk: encryption in transit (TLS 1.2+) and at rest, scoped access controls, MFA on administrative accounts, audit logging, and regular security reviews. No system is perfectly secure; if a breach occurs that affects you, we will notify you and the relevant authority as required by law.
14. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top reflects the latest revision. For material changes, we will give notice at least 14 days before the change takes effect — by email, in-app banner, or both. Your continued use of our services after the effective date constitutes acceptance.
15. Contact
For any question about this policy or about our handling of your personal data:
- Email: hello@ventrue.com.ec
- Postal address: Ventrue Technologies S.A.S., Quito, Ecuador
- Data controller representative: Erick Escobar, Founder