Trust documents
Privacy Policy
Effective date: 2026-10-09
Operator and controller: CrossTenant Ltd, a company registered in England & Wales (company no. 17349672), registered office Unit 82a James Carter Road, Mildenhall, Bury St. Edmunds IP28 7DE. Contact: privacy@vaze.ai. ICO registration reference: ZC261682. Registered 2026-09-29; registration expires 2027-09-28. The register lists both CrossTenant and Vaze as trading names.
This policy explains what information Vaze ("we", "us") reads, what it stores, who processes it and the rights you have. It covers this website (vaze.ai) and the Vaze console (app.vaze.ai): a management console that shows an organisation its accounts, seats, API keys, plans, spend, usage and governance across the AI vendors it connects. Vaze is operated from the United Kingdom.
In short. Vaze's connectors read administrative metadata from AI vendor accounts that you own, using credentials you supply. They do not request prompts, conversation content, documents or source code. Vaze stores the estate history and accountable action record needed to provide the service. Our separate business-contact activities are described below.
1. Whose data is involved
The people whose information is described here include:
- Console operators — the people at a customer organisation who sign in to Vaze with a Google identity or a Microsoft work or school identity. Personal Microsoft accounts are not supported.
- The customer's own staff — the people whose seats, keys and usage the customer's AI vendors report. They do not use Vaze directly.
- Digest and report recipients — addresses a customer configures to receive scheduled summaries, if that feature is enabled.
- Public website visitors — people whose request metadata and optional consented website analytics are described in section 9.
- Professional business contacts — people whose limited professional information we obtain from public business sources for the separate contact purpose below.
Vaze is an independent controller for operator accounts and the audit trail, for its own security, integrity and accountability purposes, and for public-website statistics and the professional business-contact activities described below. Vaze is a processor, acting on the Customer’s documented instructions, for the members, seats, key records and per-person usage it reads from a Connected Vendor, for the history it keeps of those reads, and for the digest and report recipients the Customer selects. The Customer is the controller (or a processor acting for the organisation whose estate it administers) of that estate data, and a separate controller of audit entries it views or exports. The engineering description of each data path is in section 4 and on the sub-processor page. Where the personal data of a customer’s staff reaches Vaze from a Connected Vendor rather than from them, the customer, as controller, is responsible for telling its staff; this policy is provided to help it do so.
2. What Vaze reads from your AI vendors
When a customer connects a vendor, Vaze reads that vendor's administrative API with the credential the customer supplied, limited to what the credential can reach. Depending on the vendor this includes:
| Category | Examples | Used for |
|---|---|---|
| Members and seats | Member lists, roles, seat assignments, pending invitations | Seat inventory, idle-seat and leaver checks |
| API key records | Key names, owners, creation dates, last-used dates, project and workspace membership. Never the key secret itself. | Key inventory and rotation posture |
| Plans, spend and limits | Plan tier, billing usage, cost lines, rate limits | Spend history and the readiness score |
| Usage, including per person | Requests, tokens and activity counts as the vendor reports them, some of it attributed to a named member | Adoption and per-person usage views; see section 4 for how a person's identity is handled at rest |
| Licence and sign-in records (Google and Microsoft) | Licence assignments and, where authorised, which third-party AI apps hold a work identity | Bundled-AI seat counts and identity-plane discovery |
Not read by connectors: prompts, conversation content, generated output, documents, e-mail, source code or any file content. These are outside the evidence boundary by design, and no connector has a code path that requests them.
Vaze's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. Purposes and lawful bases
- To show authorised operators their organisation's AI estate and its governance posture.
- To keep an accountable record of who read and changed what through the console.
- To deliver scheduled digests and reports that a customer has configured.
- We do not use operator accounts, customer estate data, audit data or customer-selected report-recipient data for advertising, sell it, or use it to train machine-learning or AI models. Professional business-contact information has the separate purpose and lawful basis described below; customer estate permissions are not outreach permissions.
The lawful basis for each purpose is as follows: operator accounts — our legitimate interests (Art 6(1)(f)) in operating a secure console for the organisation the operator works for (performance of a contract, Art 6(1)(b), only where the operator is themself the contracting customer); the audit trail — our legitimate interests (Art 6(1)(f)) in keeping an accountable record of administrative actions; customer-selected digest and report recipients, members, seats, key records and per-person usage read from a Connected Vendor — processed on the Customer’s documented instructions, under a lawful basis the Customer holds as controller.
We also use limited professional business-contact information for relevant business introductions and learning from optional replies, under the legitimate-interest purpose and individual relevance and impact assessment described below.
4. What we store, and for how long
Vaze keeps its live estate state as files on a single application server in Microsoft Azure's UK West region. Encrypted recovery snapshots are held in separate Azure storage in UK South. There is no separate application database. The categories are:
- Operator identities — e-mail, display name and identity provider for each console operator, with role bindings. Kept while the operator has access.
- Vendor credentials — the administrative credentials a customer supplies, stored server-side with owner-only file permissions. The browser receives status, never key material. Removed when the customer disconnects the vendor.
- Usage and cost history — the figures read from each vendor, kept so that history and trends can be shown in the console. The scheduled retention process removes measured history older than 24 months when the signed history record is complete. Unreadable or legacy-unverified records fail closed and are retained for operator review rather than silently discarded.
- Per-person usage rows — usage attributed to a member is stored against a keyed reference rather than the person's name or e-mail; the name is resolved live from the vendor when an operator views it. This is pseudonymisation and the row remains personal data. Identity-bearing rows are retained for 6 months after the person was last present in the vendor’s member list, after which the keyed reference is removed and the rows remain only as anonymous aggregates; sooner on the Customer’s request, independently of the aggregates they contributed to.
- The audit trail — one record per write and per sensitive read made through the console: when, which estate, which operator, the class of operation and the outcome, with structural summaries in place of raw request content. Records are hash-chained; the properties and limits of that chain are stated in full on the security page. Dated entries older than 24 months are pruned automatically when integrity verification passes. Completed retirement replaces customer and termination-operator metadata in environment, connector, registry and history custody with operation-bound keyed witnesses. The source-tested terminal-audit procedure also removes the full named estate trail and replaces its raw ownership identifier and descriptive incident/operator fields through a signed, resumable transition. The signed termination receipt retains its 24-month clock; minimal keyed anti-recreation markers remain permanently. These markers are not described as legally anonymous.
- Report and digest artifacts — the rendered summaries a customer's schedule produced, together with the bounded delivery evidence that stops an interrupted send being repeated. Retained on the analytics clock above.
- Readiness answers — the attested answers an operator gives in the readiness questionnaire, and the resulting scores over time.
Requests go to privacy@vaze.ai. We verify identity and authority, respond to data-rights requests within one calendar month, and follow the DPA's return-or-deletion process for customer estate data. Live return and deletion are completed within 30 days of termination or a verified earlier deletion request. Recovery copies are put beyond ordinary use and expire under separate schedules: encrypted off-box snapshots have a daily, current-time-based 28-day cutoff, retired local recovery payloads follow a separate 28-day procedure, and Azure has additional 35-day previous-version and 14-day soft-deletion lifecycles. These are separate layers, not a guaranteed combined all-copy deadline. We investigate failed or overdue expiry and tell the requester about applicable restricted copies. Restores cannot reopen a retired estate without the reviewed retirement controls being applied. The signed termination receipt is retained for 24 months; minimal keyed anti-recreation markers remain permanently for security and are not legally anonymous.
5. Who processes the data
The service providers in the technical path are:
- Microsoft Azure (UK West and UK South) — hosts the application and its primary live-state disk in UK West, with encrypted recovery snapshots in separate Azure storage in UK South.
- Cloudflare — DNS, TLS edge and the outbound tunnel that reaches the console. It sees requests and responses in transit and records standard request logs. Where Cloudflare Access restricts a private review surface, it also processes operator identities and sign-in events. Customer console authentication and access are controlled by Vaze as described above.
- Better Stack — polls a readiness endpoint that carries no customer data and e-mails the responder when it fails.
- Resend — sends Microsoft mailbox-verification codes and separately submitted human support requests to the company mailbox. Customer-selected digest and report delivery is separate and remains disabled on the live service.
- Google and Microsoft — as identity providers for operator sign-in (Google or Microsoft work or school accounts; personal Microsoft accounts are not supported); they receive the sign-in request and return the operator's e-mail, name and identity claims.
- OpenAI product Help — provides optional answers from public product guidance, receiving the submitted question, up to two recent exchanges and relevant public guidance. No estate record or connected-account permissions are automatically attached. This is separate from customer-connected OpenAI accounts and the business drafting tools below.
The AI vendors themselves (OpenAI, Anthropic, GitHub, Microsoft, Google, OpenRouter) are read using credentials for accounts the customer already holds with them. Connector requests send authentication material and the identifiers and query parameters needed for the requested administrative API operation. Scheduled collection reads vendor metadata; it does not upload Vaze's stored estate history. The supported direct write sends the target project and rate-limit identifiers and the new rate limit to OpenAI only through the explicitly approved and human-executed action path. Their classification is part of the sub-processor page. If a provider is added or replaced, we give notice as described there.
6. International transfers
Primary live estate state is stored in Microsoft Azure UK West, with encrypted recovery snapshots in UK South. This does not describe every business-contact copy: the separately used company email, research records and drafting providers below can process information outside the United Kingdom. Some providers in section 5 operate globally. For the estate service, the transfer mechanism relied on for each is set out per provider on the sub-processor page: for Microsoft, the 2021 EU Standard Contractual Clauses and the UK International Data Transfer Addendum in Microsoft’s Products and Services Data Protection Addendum; for Cloudflare, the UK Extension to the EU–US Data Privacy Framework and EU SCCs with the UK Addendum under Cloudflare’s DPA; for Better Stack and, only if e-mail delivery is enabled, Resend, EU SCCs with the UK Addendum under each provider’s DPA. The AI vendors you connect are your own providers, read with your credential against your account; this customer-connected role is separate from the business records and drafting recipients below.
For business-contact replies held in the operator's consumer Gmail account, Google LLC participates in the UK Extension to the EU–US Data Privacy Framework. Google's transfer information describes that protection and its contractual safeguards for other transfers. The current consumer Claude Pro service is provided by Anthropic Ireland, Limited; transfers from the United Kingdom to Ireland are covered by UK adequacy arrangements for the EEA. Anthropic's Privacy Policy describes its processing in the United States and other countries and the safeguards it uses for onward transfers, including standard contractual clauses and their UK equivalents. Ask privacy@vaze.ai for information about safeguards relating to your business-contact record.
7. Security
How Vaze authenticates operators, authorises access, controls writes and keeps its records is described on the security page, including what it does not claim.
8. Your rights
Under UK data-protection law you can ask for access to your personal data, ask for it to be corrected or deleted, object to or restrict certain processing, and ask for a copy in a portable form. Where Vaze is processing on a customer's instructions, raise the request with that organisation first; we assist them. Otherwise contact privacy@vaze.ai. If you are unhappy with how we have handled your personal data, you can complain to us at privacy@vaze.ai; we will acknowledge your complaint within 30 days, investigate it appropriately and tell you the outcome without undue delay. You can also complain to the Information Commissioner's Office (ico.org.uk).
9. This website
vaze.ai is served through Cloudflare. Cloudflare records standard request logs. The website does not collect questionnaire responses. Choosing to start sends you to the separate Vaze application, where sign-in and dashboard setup are covered above. It loads no Google measurement before your analytics choice and no advertising script or advertising tracking under this release.
We use existing Cloudflare request metadata to understand which channels bring requests to public pages and the signup-entry page, with daily aggregate request counts by available referring website and approved campaign categories. We do not join those counts to Vaze account or company records. These are request estimates, including machines and repeat requests, rather than counts of people or conversions. This reporting adds no browser cookie or tracking script and does not extend existing log retention. Our lawful basis is our legitimate interests in understanding and improving our public resources, assessed against visitors' rights.
On eligible public website pages, you can choose optional Google Analytics 4 measurement of page views, resource selections and use of the public Start link. Google measurement loads only after you accept analytics. Rejecting analytics does not limit the service; you can change your choice and withdraw at any time using the website analytics controls. Sign-in, OAuth, console, workspace, legal and private pages are excluded. Website measurements are not joined to your Vaze account or company.
Google receives browser and session identifiers, permitted website-event categories and ordinary network information, including IP address and browser information. This is personal data, not anonymous statistics. Measurement cookies are configured for the browser session in a separate measurement context. A necessary preference cookie remembers your choice for 180 days. Google Analytics user/event-level retention is set to two months with reset on new activity off; standard aggregated reporting has a different retention scope. Google provides analytics under its Analytics Data Processing Terms and transfer safeguards, including standard contractual clauses and the UK Addendum. Analytics relies on your consent. Google Signals, advertising personalisation, email pixels and customer-record conversion exports are not enabled by this choice.
People we contact for business
CrossTenant Ltd, trading as Vaze, uses limited professional contact information to contact relevant business AI owners at corporate organisations about Vaze and useful AI administration resources, and to learn from optional replies. We record a person's name, work role, company, public work address, source and relevant company announcement or job advert. Sources include company websites, public professional profiles and business news. The source for an individual contact is given in our first email.
Our lawful basis is our legitimate interest in relevant business introductions and learning, after checking each contact's relevance and impact. A public address does not permit unrestricted marketing. Replies and taking up an offer are optional. We do not buy contact lists, use tracking pixels or sell work-contact information. We do not make solely automated decisions with legal or similarly significant effects about you. Existing customer estate permissions are not outreach permissions.
Business records and drafting providers
We use Google Workspace to send our business emails and hold company-mailbox copies. Replies to our named business-contact address, toby@vaze.ai, are forwarded by Cloudflare Email Routing into the operator's personal Gmail account, separate from the Workspace company mailbox. Cloudflare processes those messages in transit; the reply destination is a Google consumer Gmail service. Google LLC is the controller for UK consumer Gmail under Google's consumer Privacy Policy. We use local working records and a private GitHub repository for research records, and OpenAI's Codex and Anthropic's Claude for assistance with research, analysis and drafting. For the current consumer Claude Pro drafting service used for this purpose, Anthropic Ireland, Limited is the controller under Anthropic's consumer Privacy Policy. These services can receive professional contact details and prepared correspondence. Prospect information is not attached to Vaze's product Help. These business paths are separate from customer-connected vendor accounts and from the product Help API; the estate service's providers are listed on the sub-processor page. Provider infrastructure can be outside the United Kingdom, as described in section 6. Information about the arrangements for your business-contact information can be requested from privacy@vaze.ai.
We review prospect and correspondence records when the learning test or relevant conversation ends, and remove information no longer needed. Current working files, mailboxes, repository history, stored drafting conversations and recovery copies have separate review/deletion procedures: removing a current file does not erase earlier copies. Restricted historical records are retained only where needed for a documented purpose, including legal/accountability requirements, and their necessity is reviewed. Ask us about retention of your record. Removing a working record does not immediately erase retained mailbox, repository, drafting or recovery copies; we review those separately and keep only what is needed for a documented purpose.
We keep a minimal do-not-contact record for as long as business outreach continues so an objection is respected. Object to direct marketing at any time by replying or contacting privacy@vaze.ai, and we will stop. Access, correction, deletion and other applicable rights and ICO complaint information are in section 8. Publication alone does not inform each prospect: the relevant privacy information must be actively provided within the applicable period, including at first communication or an earlier disclosure where required.
Cloudflare's published Data Processing Addendum describes the UK Extension to the EU–US Data Privacy Framework and EU Standard Contractual Clauses with the UK Addendum for its international processing. GitHub's Privacy Statement describes its UK Data Privacy Framework and standard contractual-clause safeguards. OpenAI's UK consumer privacy information and business/API Data Processing Addendum describe standard contractual clauses and the UK Addendum for UK data. These are separate from customer-connected vendor agreements; describing these safeguards does not characterise every business tool as a company processor account. Copies of safeguards relevant to your record can be requested from privacy@vaze.ai.
10. Children
Vaze is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18.
11. Changes to this policy
When this policy changes, the date at the top changes with it. For a material change, we publish the change on the relevant page and e-mail the Customer’s primary account contact (and any billing contact named in a paid Order) at least 30 days before a material change takes effect. If a change materially disadvantages you, you may terminate with effect from the date it takes effect; for an affected paid service, we refund the unused proportion of prepaid fees.
12. Contact
privacy@vaze.ai · CrossTenant Ltd (company no. 17349672)