Privacy
Last updated · 2026-08-02
Vorel runs customer operations infrastructure on behalf of regulated businesses. We process personal data both as a data controller (for our marketing site and prospect interactions) and as a data processor (when handling the calls, messages, and CRM records of our customers' end users). This page covers the controller side. The processor side is governed by our DPA.
What we collect on this site
- Contact details you provide on demo or contact forms (name, work email, company).
- Standard server logs (IP, user agent, requested URL) for operational and security purposes.
- Aggregated page analytics via Plausible. No cookies, no individual identifiers, no third-party advertising trackers.
- If you accept the cookie prompt, we also enable Google Analytics (configured for analytics only, with Google advertising and cross-site signals turned off) and HubSpot, which ties your visits to your demo request so we can answer your call with context. You can decline at the prompt or clear the consent in your browser settings.
What we never do
- Sell or rent personal information.
- Share contact lists with third-party advertisers.
- Use customer call transcripts or CRM data for model training without an explicit, signed addendum.
Your rights
You can request access, correction, deletion, or export of personal data we hold about you by emailing [email protected]. We respond inside 30 days. Where applicable, we honour GDPR, CCPA, and equivalent rights regardless of where you live.
Data deletion
Anyone can ask us to delete the personal data we hold about them, whether they filled in a form here, spoke to an agent Vorel operates for one of our customers, or messaged one of those businesses on WhatsApp.
- End users — email [email protected] from the address you used, or include the phone number you called or messaged from, and name the business you contacted. That is all we need to locate the records. You can also ask that business directly; they can trigger the same deletion from their Vorel console.
- Customers — deleting a conversation, contact, or your whole workspace from the console removes the underlying records, including call recordings, transcripts, and message content.
We verify the request, action it within 30 days, and confirm by email. Deletion covers transcripts, recordings, message content, and derived records such as summaries and lead rows. We may retain the minimum required for legal, tax, or fraud-prevention obligations, and de-identified aggregates that cannot be traced back to a person; anything retained on that basis is named in our reply.
Subprocessors
A current list of subprocessors (cloud hosting, telephony, model providers, CRM connectors) is available on request and is maintained as part of the DPA. We notify customers under contract before adding a new subprocessor that handles regulated data.
This policy applies to vorel.ai and to the Vorel platform. Questions, data-subject requests, and deletion requests go to [email protected]. Processing carried out on behalf of a customer is additionally governed by the signed DPA.

