V1CE Logo
Cart
Cart

Privacy Policy

Last Updated: 24th August 2026

V1CE Limited ("V1CE," "we," "us," or "our") is committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, share, and safeguard your information when you use our website, v1ce.co, and our Client Capture OS.

1. Who we are and contact details

V1CE Limited is the data controller responsible for deciding how and why your personal information is used. Our company number is 12681711. Our registered and correspondence address is First Floor Office, 38A-42A Ormskirk Road, Preston, PR1 2QP, England and Wales. For any privacy-related questions or concerns, you may contact us at [email protected].

2. Information we collect

We collect personal information that you voluntarily provide when interacting with our website, such as when placing orders, creating an account, or contacting us. This includes your name, address, phone number, email address, title, company name, social media handles, date of birth, username, and login details.

Lead Enrichment Data: When you use our Client Capture OS to manage or engage with leads, we may enrich the data you provide (such as a name or company) with publicly available professional information. This information is sourced from third-party sales intelligence and web-scraping providers, specifically Apollo.io and Bright Data. This enriched data may include professional email addresses, job titles, employment history, and LinkedIn profile URLs.

Connected Mailbox Data: When you choose to connect your email account (Google or Microsoft), we store the messages in that mailbox so that the Client Capture OS can surface insights about your client relationships. Specifically, we store: the full message body (both formatted and plain-text versions); message metadata including sender, recipients, CC addresses, subject line, a short preview, date and time, and conversation thread identifier; and AI-generated outputs derived from those messages, such as short answers, deal scores, and evidence excerpts linked back to the source message. Where a single email involves more than one of your contacts, a copy is stored per contact. Any deletion request must therefore cover every copy, and we will process it accordingly.

Meeting Recordings and Transcripts: When you enable the AI Note Taker, an automated bot may join your scheduled meetings to record audio and produce a transcript. We obtain and log the consent of each participant before recording begins. We store the resulting recording and transcript, and we generate structured notes and a summary from them.

We collect contribution and service-related information such as feedback provided via phone, email, or social media and details about services we provide to you. We also collect technical and usage data indirectly, such as information about your browsing activity, which is collected through cookies and similar tracking technologies. Our services are not intended for children, and we do not knowingly collect information about minors.

3. Legal basis for processing your information

We process your personal information using one or more of the following legal bases:

  • Consent: When you agree to receive marketing communications, when you connect your mailbox, or when you or your meeting guests agree to be recorded.
  • Contract: When it is necessary to fulfil a contract with you, such as delivering orders or providing access to the Client Capture OS.
  • Legal Obligation: To comply with tax or reporting requirements.
  • Legitimate Interests: For improving our services, preventing fraud, and providing data enrichment services to help our users identify and engage with professional B2B leads, provided these interests are not overridden by your data protection rights.

4. AI and automated analysis

When you enable AI features in the Client Capture OS, we use artificial intelligence to analyse data you have connected or provided. Specifically:

  • What the AI reads: Synced email messages, call recordings, and meeting transcripts.
  • What the AI produces: Short answers about individual messages or calls, deal scores, gap-analysis findings, and structured meeting notes. These outputs are derived from your data only - nothing is pooled between customers. Where outputs assign a score or characterisation to a person, this constitutes profiling under UK GDPR. You have the right to object to profiling; see Section 9.
  • AI controls you hold: You can turn all AI processing off with a single master switch in Settings. Separate switches let you control each data type (email, calls, meetings) independently. Every field the AI writes to your CRM is logged so you can review it. Consent for recording is asked per meeting and stored in a log you can access.
  • Sub-processors for AI: Analysis is carried out by Anthropic (Claude); meeting bot and transcript services are provided by Gregnote; voice note transcription is provided by OpenAI. These providers are listed in our sub-processor register. Whether any of these providers use your data for model training is governed by the terms of our accounts with them; legal has verified and will maintain that statement with a date on record.

We do not make claims about data use that our systems cannot enforce. Connected mailboxes are re-synced periodically; messages may therefore be read more than once as part of normal operation.

5. How we share your information

We only share your personal information when necessary.

  • Fulfillment: We share your name and delivery address with delivery partners to fulfil orders.
  • Enrichment Services: To provide lead enrichment features, we share limited identifiers with our sub-processors, Apollo.io and Bright Data, who provide structured professional data.
  • AI and Meeting Services: To provide AI analysis and the AI Note Taker, we share relevant data with Anthropic, Gregnote, and OpenAI as described in Section 4.
  • Business Transfers: In connection with mergers, acquisitions, or the sale of company assets.
  • Advertising: With providers such as Adroll, Meta, and Google to deliver relevant advertisements.
  • Legal Requirements: To comply with law enforcement or legal obligations.

6. Google and Microsoft connected accounts

You may connect a Google or Microsoft account to enable mailbox sync and calendar features. When you do, we access and store the data described in Section 2 (Connected Mailbox Data) under the scope of permissions you grant at the time of connection.

Google: Our use of data received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. We access Gmail under the Gmail read-access scope, which is subject to Google's yearly security review (CASA). Full message bodies are stored at rest in a dedicated table. Google data is not retained beyond what is necessary for providing the service, and we will process deletion requests within 30 days. You can disconnect your Google account at any time from your Settings page, which stops new syncing immediately.

Microsoft: We access Outlook mail and calendar data under the permissions you grant. The same storage, access controls, and disconnection rights described above apply to Microsoft account data. You can disconnect your Microsoft account at any time from your Settings page.

Important: Disconnecting a mailbox stops new messages from syncing but does not automatically delete messages already stored. To request deletion of stored messages, contact us at [email protected]. Storage is scoped to the mailbox owner; other users on a shared contact cannot access the owner's synced mail - this is enforced by how the system is built, at the database query level.

7. People who are not V1CE users

Some features of the Client Capture OS process information about people who have not signed up to V1CE directly - specifically, the contacts and meeting guests of our users. We hold information about these individuals because it appears in our users' email correspondence or meeting recordings. This may include their name, email address, the content of messages they exchanged with our user, and their words in a recorded meeting.

This data comes from our users' own communications and is held on their behalf. If you are such a person and would like to know what information we hold about you, or to request its deletion, please contact us at [email protected]. We will respond within 30 days.

Meeting guests are asked for recording consent before a session begins. Email contacts do not receive such a moment, so this policy is the primary place where their rights are stated. We ask for and log consent for recording regardless of local legal minimums, because we believe that is the right standard.

8. How long we keep your data

The table below sets out retention periods for the main categories of data created by the newer features. Legal has approved these periods.

  • Synced email messages and metadata: Retained while your mailbox is connected and for [period to be confirmed by legal] after disconnection or account closure. Deletion on request within 30 days.
  • AI answers, deal scores, and evidence excerpts: Retained for the same period as the messages they are derived from. Deleted on deletion of the source message or on request.
  • Meeting recordings: Retained for [period to be confirmed by legal] after the meeting date, or until you delete them in Settings.
  • Meeting transcripts and structured notes: Retained for the same period as the recording. Deleted when the recording is deleted.

Disconnecting a mailbox stops new syncing but does not delete data already stored. To request deletion, contact [email protected].

9. Cookies and tracking technologies

We use cookies and similar tracking technologies such as pixels and web beacons. Some cookies are essential for operating our website and maintaining security. Other cookies remember your preferences, improve site performance, or help us deliver relevant marketing content. Where applicable, you may opt out of non-essential cookies.

10. Transfers of information outside the UK and EEA

If you are a resident of the UK, EEA, or Switzerland, your information may be transferred outside those regions, including to the United States (where providers like Apollo.io, Anthropic, OpenAI, and Gregnote are based). We safeguard such data transfers using legally approved mechanisms such as the UK Addendum and the European Commission's Standard Contractual Clauses (SCCs).

11. Marketing

We may send marketing communications by post, email, telephone, or text message when we have your consent or a legitimate interest. You may unsubscribe at any time using the unsubscribe link in emails, replying STOP to texts, or contacting us directly.

Our marketing copy describes what the product actually does. We do not claim that emails are never stored, or that your data is never seen by AI, because those claims are not accurate for users who choose to enable those features. The accurate strong claims are: your findings come only from your own data, nothing is pooled between customers, we never quote what your client wrote back to a third party, every AI write to your CRM is logged, and one switch turns all AI processing off.

12. Your data protection rights

All users have the right to request access to their personal information and ask us to correct inaccuracies.

European Residents (UK, EEA, Switzerland): You have additional rights under GDPR, including the right to request erasure ("Right to be Forgotten"), data portability, the right to object to processing (including profiling and enrichment), and the right to withdraw consent. To exercise these rights, email [email protected].

When handling a deletion request, please be aware that some data categories are stored in multiple places - for example, an email involving two contacts is stored once per contact, and AI answers are stored separately from the messages they came from. We will identify and delete every copy.

US Residents (California and Nevada):
California (CCPA): You have the right to know what data we collect, access data from the past 12 months, and request deletion. V1CE does not "sell" personal information as defined by the CCPA, but we do share data for "business purposes" (like enrichment).

Nevada: You may opt out of the sale of certain information. V1CE does not sell personal information under Nevada law.

To exercise these rights, email [email protected] with the subject "Request for California Privacy Information" or "Request for Nevada Privacy Information."

9. Data protection mechanisms

We take the security of your personal information seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, accidental loss, destruction, or disclosure. These measures include:

  • Encryption: Sensitive data is encrypted in transit using TLS (Transport Layer Security) and at rest where applicable.
  • Access controls: Access to personal data is restricted to authorised personnel on a need-to-know basis, enforced through role-based access controls and authentication requirements.
  • Third-party security: We require all third-party processors and sub-processors (including Apollo.io, Bright Data, Google, and Meta) to maintain appropriate security standards consistent with applicable data protection laws.
  • Monitoring: We maintain security monitoring and review our data protection practices regularly to address evolving threats.

Where we use Google APIs, any data obtained via those APIs is handled in accordance with the Google API Services User Data Policy, including the Limited Use requirements.

10. Data retention and deletion of Google user data

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, to comply with legal obligations, or to resolve disputes.

  • Account data: Retained for the duration of your account and deleted within 90 days of account closure upon request.
  • Transaction records: Retained for up to 7 years to comply with financial and tax obligations.
  • Marketing data: Retained until you withdraw consent or opt out, after which it is deleted promptly.

Google user data specifically: Any data we access via Google APIs (including Google OAuth) is used only for the purpose for which you granted access and is not retained beyond what is necessary for that purpose. Google user data is not shared with third parties except as required to provide the service you requested. You may request deletion of your Google-connected data at any time by emailing [email protected] with the subject "Delete My Google Data." We will process such requests within 30 days.