Privacy Policy — VORA Lead Engine
Version: 1.1
Effective date: 16 July 2026
Last updated: 31 August 2026
1. Controller
VORA s. r. o.
Company ID: 47 352 302
Registered office: Čižmárska 540/9, 940 02 Nové Zámky, Slovak Republic
Registration: Commercial Register of the District Court in Nitra, Section: Sro, Insert No. 34858/N
Contact: info@vora.sk
VORA s. r. o. (hereinafter "VORA" or "Controller") is the Controller of personal data processed in connection with the operation of the VORA Lead Engine service (hereinafter "Service").
Data protection contact: Adam Halász (managing director), reachable at info@vora.sk. Based on the scope of processing, VORA is not required to appoint a separate Data Protection Officer under GDPR Art. 37; data protection communication is conducted directly with the managing director.
2. What personal data we process
2.1. Data of registered Service users
- Identification data: first name, last name, email, phone (optional)
- Login data: hashed password, second-factor tokens (2FA)
- Organization data: company name, Company ID, Tax ID, registered office (for company accounts)
- Billing data: invoice recipient, billing address, Tax ID (managed via Stripe)
- Service usage data: IP address, browser, logins, actions in the Service (audit log)
2.2. Data on contacts (leads) generated by the Service
Based on Client instruction, VORA processes data on third-party company contacts found by Radar or imported by the Client:
- Company data: company name, address, website, business type (Company ID not always available)
- Contact data: email, phone, contact person name (if publicly available)
- Email communication: content of sent and received emails, time of send/receive, statistics (open rate, reply rate)
In relation to contact data (leads), the Client (i.e. the entity registered in the Service) is Controller of this data and VORA s. r. o. is Processor under GDPR Art. 28 — VORA processes this data exclusively based on documented instructions from the Client. The terms of this relationship are governed by a separate Data Processing Agreement (DPA) available at https://lead-engine.vora.sk/dpa.
2.3. Cookies and technical data
A detailed list of cookies used is in a separate Cookie Policy available at https://lead-engine.vora.sk/cookies.
2.4. Access to your Google Account (Gmail)
If you connect your Google account in the Service, VORA is granted a single permission — gmail.send, the right to send e-mail on your behalf.
How we access the data: exclusively through Google's Gmail API, based on your explicit consent given in Google's standard consent screen. You can withdraw that consent at any time at https://myaccount.google.com/permissions or by disconnecting the account in the Service's Settings.
What we use it for: solely to send the outreach e-mails and follow-up messages you have configured in the Service. Nothing else.
What we do NOT do: we do not read the contents of your mailbox, do not browse incoming messages, and do not modify or delete any e-mails, labels or settings. We request no permission that would allow it — so it is not technically possible.
What we store: the text of the e-mails the Service has sent and the time they were sent, which is needed to track the campaign and to make sure the same company is not contacted twice. Access and refresh tokens are stored encrypted in Supabase Vault.
Sharing: data obtained through the Gmail API is not shared with third parties, not used for advertising, not sold, and not used to train artificial intelligence models.
VORA Lead Engine's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3. Purposes and legal bases of processing
| Purpose | Legal basis | Retention period |
|---|---|---|
| Account creation and management | Performance of contract (GDPR Art. 6(1)(b)) | For the duration of the Account + 30-day grace |
| Billing and accounting | Legal obligation (Accounting Act No. 431/2002 Coll.) | 10 years |
| Provision of the Service including Radar | Performance of contract (GDPR Art. 6(1)(b)) | For the duration of the Account |
| Security and audit logs | Legitimate interest (GDPR Art. 6(1)(f)) | 90 days (audit log), 30 days (regular logs) |
| Marketing emails about the Service | Legitimate interest or consent | Until revoked (opt-out anytime) |
| Usage analytics | Legitimate interest (aggregated) | 12 months |
4. Recipients of data — Sub-processors
For the provision of the Service, VORA uses the following sub-processors that process personal data on VORA's behalf under contractual terms guaranteeing the level of protection under GDPR:
4.1. Sub-processors with servers in the EU
| Sub-processor | Purpose | Registered office / Servers |
|---|---|---|
| Supabase, Inc. | Database (Postgres), authentication, backend functions | Servers: Ireland (EU) |
| Cloudflare, Inc. | Workers hosting, DNS, CDN, edge cache | Global with priority to EU regions |
| Stripe Payments Europe, Ltd. | Payment processing, invoices | Ireland |
| Google Cloud (Google Ireland Ltd.) | Google Places API (Radar), Gmail API — sending e-mail | EU multi-region |
| Microsoft Corporation | Outlook / Microsoft Graph API OAuth (optional) | EU multi-region |
| WebSupport, s. r. o. | Email hosting for the vora.sk domain (system emails — billing notifications, team invitations) | Bratislava, Slovak Republic (EU) |
4.2. Sub-processors outside the EU (United States of America)
Data is transferred to these countries based on Standard Contractual Clauses (SCC) under Commission Decision (EU) 2021/914 and supplementary technical measures (transmission encryption):
| Sub-processor | Purpose | Registered office |
|---|---|---|
| Anthropic, PBC | Claude AI — cold email generation, intent classification | USA |
| Email Hunter, LLC (Hunter.io) | Verification of email address existence | USA |
4.3. Optional sub-processors (only upon Client opt-in)
| Sub-processor | Purpose | Registered office |
|---|---|---|
| Pipedrive OÜ | CRM synchronization (only upon manual connection by Client) | Estonia (EU) / servers possibly USA |
VORA does not disclose personal data to third parties outside the listed sub-processors, except where necessary to comply with legal regulations (e.g. request from law enforcement authorities).
The current list of sub-processors is always available on this page, and VORA will inform registered Clients of any changes by email at least 30 days in advance.
5. International data transfers
As stated in Article 4.2, some sub-processors (Anthropic, Hunter) are based outside the European Economic Area (EEA), specifically in the USA. Transfer takes place based on:
- Standard Contractual Clauses (SCC) approved by the European Commission,
- Supplementary technical measures (end-to-end transmission encryption TLS 1.2+, minimization of transferred data).
US providers are contractually obliged to maintain a level of protection comparable to GDPR.
6. Data retention
- Account and data during Subscription: retained for the entire duration of the active Subscription.
- After Subscription cancellation: 30-day grace period to export data, then data is permanently deleted from the production system. Backups are deleted within 90 days.
- Billing data: 10 years (legal obligation under the Accounting Act).
- Audit log: 90 days.
- Email logs (sent/received via the Service): for the duration of the Account, then as above.
7. Your rights
As a Data Subject, you have the following rights under GDPR:
- Right of access (Art. 15) — receive a copy of the processed data,
- Right to rectification (Art. 16) — correct inaccurate data,
- Right to erasure (Art. 17) — request deletion of data ("right to be forgotten"),
- Right to restriction of processing (Art. 18),
- Right to data portability (Art. 20) — receive data in machine-readable format,
- Right to object (Art. 21) — object to processing based on legitimate interest,
- Right not to be subject to automated decision-making (Art. 22) — VORA does not make automated decisions with legal effect.
You can exercise these rights by sending a request to info@vora.sk. We will respond within 30 days.
You also have the right to lodge a complaint with the supervisory authority — the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava, dataprotection.gov.sk.
8. Security measures
VORA implements appropriate technical and organizational measures to protect personal data:
- Transmission encryption — TLS 1.2+ for all communication,
- Encryption at rest — Supabase databases are encrypted,
- Data isolation — Row-Level Security prevents cross-access between Clients,
- Authentication — strong passwords, two-factor authentication (2FA) available,
- Access control — principle of least privilege, audit log of admin actions,
- Backups — automated daily backups, 30-day retention,
- Security monitoring — ongoing tracking of unusual activity.
In case of a personal data breach, we will notify data subjects without undue delay, at the latest within 72 hours of discovering the breach, if it is likely that the breach will lead to a high risk to the rights of Data Subjects.
9. Cookies and tracking technologies
Details about the cookies used (necessary, functional, analytical) are in a separate Cookie Policy available at https://lead-engine.vora.sk/cookies. Cookies are set on first visit through a consent banner that allows selection of individual categories.
10. Changes to these Terms
VORA reserves the right to change these Terms. We will inform registered Clients of significant changes by email and by publishing the new version on this page at least 30 days before it takes effect.
The last update date is indicated in the header of this page.
On behalf of VORA s. r. o.:
Adam Halász
managing director
For any questions about personal data processing, please contact us at info@vora.sk.
