LEGAL

Privacy policy.

How Viotus handles personal information across its public website and direct corporate communications.

Effective
12 August 2026
Version
1.1
Scope
Visitors, Viotus Account members, customers, correspondents and professional contacts
In this document
01

Data controller

How responsibility for personal data is assigned.

Viotus is responsible for personal data it receives directly through corporate correspondence connected with viotus.com. References to “Viotus”, “we” or “the studio” have that meaning in this policy.

Privacy enquiries and rights requests can be sent through the official Viotus contact page.

No data-protection officer has been designated because the current website activities do not appear to require one. This assessment will be revisited if the scale, nature or legal basis of processing changes. The contact route shown in this policy is the operational privacy channel for the public website.

02

Scope and website architecture

This policy covers the public Viotus website, Viotus Account registration and authentication, and messages sent to the studio using contact routes referenced by it. The public frontend is delivered through Amazon S3 and CloudFront, while account identity is handled by Amazon Cognito.

A Viotus product or third-party platform may publish an additional privacy notice where its processing, Social functions, purchases or connected-world activity differs from this core website and identity service.

This policy governs the core Viotus Account identity and sign-in service described above. Product-specific profiles, connected-world activity, Social contributions, purchases, recruitment or investor workspaces may require an additional notice that identifies their data flows, providers, purposes, retention and controls at the relevant collection point.

03

Information that may be processed

Information arises when a person creates or uses a Viotus Account, makes a purchase, contacts Viotus, follows an external link, or when essential infrastructure records a request. Authentication secrets are entered on the Amazon Cognito service and are not made available to the Viotus website.

Providing information through a general enquiry is normally voluntary. Certain contact details may nevertheless be necessary to authenticate a rights request, answer a question, investigate misuse or take requested pre-contractual steps. If necessary information is not provided, Viotus may be unable to verify the sender, process the request safely or provide a meaningful response.

  • Account identity and contact data, including email address, unique Viotus username, verification status and account identifier.
  • Private billing and tax information supplied for a purchase, including name, company or customer type, billing address, country, postal code and tax identifier where applicable.
  • Order, payment-status and fulfilment records, including purchased items, amounts, taxes, Credits issued and references supplied by the payment processor. Viotus does not store full payment-card details.
  • Authentication and security information handled by Cognito, such as sign-in events, recovery and multi-factor status, device or session metadata and abuse-prevention signals.
  • Short-lived OAuth session tokens and security state stored only in the current browser session to keep the member signed in.
  • Identity and contact details voluntarily included in correspondence, together with its content, attachments, routing information and history.
  • Technical security and delivery data necessarily processed by hosting or network providers, such as IP address, request time, requested URL, browser metadata and diagnostic records.
04

Purposes of processing

Personal data is used only where relevant to operate Viotus Account, deliver the website securely and manage the relationship or request that gave rise to it.

Data supplied for one conversation is not repurposed for unrelated behavioural advertising or sold as a contact list. If Viotus wishes to use contact information for a materially different purpose, it will first identify a compatible legal basis and provide any additional information or choice required by law.

  • Create, verify, authenticate, recover and protect a Viotus Account shared across the Viotus ecosystem.
  • Display the member identity and account-level notification totals and preferences.
  • Receive, classify and respond to enquiries and provide requested product, support or corporate information.
  • Protect the website and account service, diagnose incidents, prevent abuse and maintain technical continuity.
  • Manage potential business relationships and take steps requested before entering into a contract.
  • Establish, exercise or defend legal claims, comply with binding obligations and maintain proportionate accountability records.
06

Payment-fraud prevention

For real-money Store purchases, Viotus and its payment provider may assess account age, successful-payment history, purchase amount and frequency, authentication outcome and categorical provider risk signals. Viotus stores a pseudonymous truncated-network hash rather than the raw address in its payment-risk record and does not store full card details, CVC, raw device fingerprints or a client-visible risk score.

These controls may limit a purchase, request 3D Secure or temporarily retain newly purchased Credits and entitlements. Credits remain non-transferable for a short period based on account history. Provider fraud warnings, reviews and disputes require human resolution; an Early Fraud Warning never causes an automatic refund. A customer may contact Viotus to obtain human review of a retained delivery or rejected purchase.

07

Retention periods

Account data is normally retained while the Viotus Account remains active and for a limited period after closure where necessary for recovery, security, fraud prevention, legal obligations or claims. Payment network-velocity records expire after 30 days, technical Stripe event receipts after 180 days, and payment-risk cases and their access/action audit after 18 months. Saved billing addresses may be changed by the member; the billing and tax snapshot attached to a completed order is retained for the accounting and tax periods required by law.

Raw CloudFront delivery and security logs are automatically deleted after 365 days. First-party audience reports contain aggregate counts rather than IP addresses, full user-agent strings, cookies or URL queries. Browser session data ends on sign-out and the analytics preference expires after 12 months. Data subject to a valid deletion request will be removed or irreversibly anonymised unless continued retention is required by law, security necessity or a legal claim.

Retention criteria include whether the enquiry remains open, whether a continuing professional relationship exists, whether the record is needed to evidence a response or permission, and the limitation periods or preservation duties applicable to a potential claim. Viotus should periodically review retained correspondence and remove duplicate, obsolete or excessive material rather than keeping every message indefinitely.

08

Processors, recipients and hosting

Viotus does not sell personal data. Access is limited to people and service providers who need it for the purposes described in this policy and are subject to appropriate duties.

Amazon Web Services provides the website delivery and account infrastructure through services including S3, CloudFront and Cognito and may process technical, identity and security data for those functions. Domain registration, DNS, email, security and professional providers may receive limited information where necessary. Public authorities receive information only where a binding legal basis requires it.

Providers receive only the categories reasonably needed for their function and must not be understood as acquiring ownership of correspondence. Where Viotus selects a processor, the relationship will be governed by data-protection terms addressing instructions, confidentiality, security, assistance and deletion or return. A provider acting independently remains responsible for the processing it determines.

09

International data transfers

Some infrastructure or communication providers may operate outside the European Economic Area. Where Viotus acts as controller and appoints such a provider, transfers will rely on an adequacy decision, approved contractual safeguards such as Standard Contractual Clauses, or another lawful mechanism, together with supplementary measures where required.

Visitors should review the privacy information of third-party services they choose to access.

The fact that a provider is globally accessible does not by itself identify every transfer mechanism. Viotus will assess the provider, destination and role for the relevant service and will make additional information about an applicable safeguard available where the GDPR requires it, subject to lawful limits protecting security and confidential contractual material.

10

Audience measurement

Viotus performs limited first-party measurement from its own CloudFront delivery logs to understand aggregate page traffic, product and publication interest, broad device categories, approximate delivery region, errors and performance. This processing supports the legitimate interests of operating, securing and improving viotus.com. Reports exclude IP addresses, full user-agent strings, cookies and URL queries and are not used to identify people, follow them across websites, build advertising profiles or share audience data with third parties.

Google Analytics 4 is optional and is not contacted until the visitor chooses “Accept analytics”. When enabled, Viotus sends minimised page and interaction events without names, email addresses, usernames, messages, payment details or URL query strings. Google signals and advertising personalisation are disabled. The visitor may reject analytics as easily as accepting it and may change the choice at any time through “Privacy choices” in the footer.

11

Cookies and local device storage

Viotus uses essential session storage for OAuth security state, short-lived account tokens and account-interface state. It also stores the analytics choice locally for up to 12 months so the banner does not reappear on every visit. Essential first-party CloudFront measurement does not require an analytics cookie in the browser.

Only after consent, Google Analytics may use browser storage necessary to measure visits and interactions. The Amazon Cognito sign-in domain and technical infrastructure may also use strictly necessary mechanisms for authentication, security, delivery or network integrity. Viotus does not use behavioural advertising or cross-site marketing cookies.

At present there is no consent banner because Viotus does not intentionally place optional tracking technologies. A banner would not itself improve privacy where no consent choice is needed. If the technical implementation changes, Viotus will audit storage and third-party requests and introduce prior consent, rejection and preference-management controls before any non-essential technology operates.

12

Your data-protection rights

Subject to the conditions of applicable law, individuals may request access to their personal data, correction of inaccurate data, deletion, restriction, portability and objection to processing. They may withdraw consent at any time where consent is the basis used.

A request should identify the person, the relationship or message concerned, the right being exercised and a reliable response channel. Viotus may request proportionate evidence of identity and will respond within the legally applicable period. Individuals may also lodge a complaint with the Spanish Data Protection Agency (AEPD) or the competent supervisory authority in their country.

Rights requests are normally answered without undue delay and within one month after receipt or verification, subject to the extensions and exceptions permitted by the GDPR. Requests are generally free, although manifestly unfounded or excessive requests may be handled as the law allows. Any refusal or limitation will be explained together with available complaint routes.

13

Automated decisions and minors

Automated payment controls may request authentication, apply published spending limits or temporarily retain delivery. They are designed to protect accounts and payments and do not authorise a refund or final fraud determination without human action. A customer may request human review through Viotus support.

The corporate website is not directed at children and does not knowingly request their personal data. A parent or guardian who believes a child has provided data should contact Viotus so it can be assessed and removed where appropriate.

14

Security and incident response

Viotus applies proportionate organisational and technical measures including encrypted transport, OAuth 2.0 authorisation code flow with PKCE, signed-token validation, short-lived sessions, refresh-token rotation, email verification, optional multi-factor authentication, controlled access and data minimisation. Account passwords are handled by Cognito and never returned to the Viotus frontend.

No internet service can be guaranteed immune from malicious activity or technical failure. Viotus monitors the risk profile and may add rate controls or further protections as the service grows. If a personal-data breach creates a legally relevant risk, it will be documented and notified as required by applicable law.

Measures are selected according to the volume and sensitivity of information and may include least-privilege access, account protection, provider review, recovery procedures and confidential disposal. Security measures are reviewed when systems or risks materially change. This description is intentionally general so that publishing the policy does not reveal controls in a way that weakens them.

15

External websites and embedded services

External links lead to independently operated services. Their collection and use of information is governed by their own privacy notices, not this policy. Viotus should not be understood as controlling those services merely because it links to them.

16

Policy changes and contact

This policy may be updated when Viotus changes its infrastructure, communication routes, products or legal entity, or when applicable requirements evolve. Material changes will be reflected by a new effective date or version.

Privacy questions and rights requests can be submitted through the Viotus contact page with the subject “Privacy”.

A revised policy applies from its stated effective date. Where a change materially affects information already held, Viotus will consider whether direct notice, renewed consent or another measure is required instead of relying solely on publication. Previous wording may be retained internally where needed to demonstrate what information applied at a particular time.

17

Applicable framework

Official sources used to structure this publication.

EU General Data Protection Regulation 2016/679Spanish Organic Law 3/2018 on Data ProtectionSpanish Data Protection Agency — duty to informSpanish Data Protection Agency — guide on analytics cookiesGoogle — safeguarding your data in Google Analytics
Legal and privacy enquiries

Contact the studio about this document, a rights request or a legal notice.

Contact Viotus
Back to top