Privacy Policy

Last updated: June 2026

Who we are

The Viso service is provided by VISO ("Viso", "we", "our"). VISO is the data controller for the personal data described in this notice. You can reach us at contact@getviso.io.

What data we collect

We collect and process the following categories of personal data:

  • Account data — your email address and authentication identifiers used to sign in.
  • Financial data you enter — income, expenses, assets, investments, budgets and any other figures or notes you add or upload.
  • Support communications — messages you send us when you contact support.
  • Technical data — limited logs (IP address, browser type, timestamps) used for security and to keep the service running.
  • Cookies — a session cookie that keeps you logged in. We do not use tracking or advertising cookies.

Payment card details are not collected or stored by us — they are handled directly by our payment provider, Paddle (see "Who we share data with").

Purposes and legal basis

  • Providing the service (creating your account, storing your data, showing your dashboards) — performance of a contract with you.
  • Billing and subscription managementperformance of a contract and legal obligation.
  • Security, fraud prevention and keeping the service stable — our legitimate interest in operating a safe service.
  • Customer supportperformance of a contract and our legitimate interest in helping you.
  • Product improvement (aggregate, non-identifying usage data) — our legitimate interest.
  • Optional marketing emails (e.g. newsletter) — only with your consent, which you can withdraw at any time.

Who we share data with

We share personal data only with the following categories of recipients:

  • Paddle — our Merchant of Record and payment processor. When you buy a subscription, Paddle receives your name, email, billing address and payment details, and handles payments, invoicing, tax compliance and refunds. See Paddle's Privacy Policy.
  • Supabase — our cloud database and authentication provider, hosting your data on infrastructure in the EU.
  • Resend — our transactional email provider, used to deliver account, billing and support emails.
  • Professional advisers and authorities — where required by law (e.g. responding to a legal request) or to defend our rights.

We do not sell your personal data and we do not use it for third-party advertising.

International transfers

Your data is stored on Supabase infrastructure in the EU. Some of our service providers (such as Paddle and Resend) may process limited data outside the EU/EEA. Where that happens, we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.

How long we keep data

  • Account and financial data — kept for as long as your account is active. If you close your account, we delete or anonymise it within 90 days, except where we must keep it longer to comply with legal obligations.
  • Billing records — kept for the period required by applicable tax and accounting law (typically up to 10 years).
  • Support messages — kept for up to 24 months after the issue is closed.
  • Security logs — kept for up to 12 months.

Your rights

Under GDPR you have the right to access, rectify, erase, restrict and port your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time. You also have the right to lodge a complaint with your local data protection authority. To exercise any of these rights, email us at contact@getviso.io. We will respond within one month.

Security

We use appropriate technical and organisational measures to protect your data, including encryption in transit, row-level security in the database so only you can access your data, restricted administrative access, and regular monitoring.

Cookies

We use a single essential session cookie to keep you logged in. We do not use tracking or advertising cookies. A small cookie notice asks for your acknowledgement on first visit.

Changes to this notice

We may update this privacy notice from time to time. If we make material changes we will notify you by email or with an in-app notice.