Roccavera LLC, a Wyoming limited liability company, doing business as Vayaflow
Effective Date: July 8, 2026
This Privacy Policy explains how Roccavera LLC, a Wyoming limited liability company doing business as Vayaflow (“VayaFlow,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information in connection with our website at vayaflow.com, our web application, application programming interfaces, AI voice and SMS services, AI assistant chat, e-signature and contract storage, lead-distribution and intake software, embedded chatbots and widgets, integrations, support channels, Customer-configured workflows, and related products or features (collectively, the “Platform” or “Services”).
Please read this Policy carefully. By accessing or using the Services, you acknowledge that you have read and understood this Policy. If you do not agree, do not access or use the Services.
IMPORTANT: The Platform is intended for use within the United States. By using the Services, you consent to the transfer, storage, and processing of your personal information in the United States, which may have data protection laws different from those of your country of residence.
1. Scope and Roles
This Policy applies to information we collect from or about three categories of individuals: (a) Customers and Authorized Users — the businesses and the people at those businesses who register for, configure, and use the Services; (b) Consumers — the individuals whose information our Customers submit to the Services or whom our Customers contact through the Services, including leads, prospects, applicants, patients, clients, and end users of a Customer’s workflows; and (c) Site Visitors — people who browse our public website or interact with us before becoming a Customer.
For VayaFlow-controlled data (our website, marketing, sales engagement, and our own business records), VayaFlow generally acts as the controller or business. For Customer Content and Consumer data processed through a Customer account, workflow, integration, or other Customer-configured channel, the relevant Customer generally controls the purposes and means of processing, and VayaFlow generally acts as the Customer’s service provider, processor, or solution provider. This Policy describes our own practices; it does not replace any Customer’s own privacy notice.
If you are a Consumer, please first contact the Customer that directed us to process your personal information. You may also contact VayaFlow at privacy@vayaflow.com, and we will intake the request and, where appropriate, coordinate with the relevant Customer.
2. Key Definitions
“Customer” means a law firm, insurance agency, real-estate brokerage, solar installer, home-services contractor, healthcare practice, lender, university, or other business that purchases, subscribes to, or uses the Services.
“Authorized User” means an administrator, employee, contractor, agent, or other representative of a Customer that the Customer permits to access the Services.
“Consumer” means any individual whose personal information is collected, processed, or contacted through the Services, including leads, prospects, applicants, patients, clients, and end users of a Customer.
“Customer Content” means all data, text, voice scripts, images, audio, lead records, contact information, recordings, transcripts, electronically signed documents, SMS message threads, AI-assistant chat threads, AI agent configurations and prompts, and any other materials submitted to or generated through the Services under a Customer’s account, including personal information about Consumers and Authorized Users.
“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household, as further defined under applicable law.
“Site Visitor” means a person who interacts with our public-facing website at vayaflow.com or other VayaFlow-controlled properties.
3. Customer Data Commitments
For Customer Content and Consumer data processed on behalf of Customers:
- We do not sell Customer Content or Consumer data.
- We do not use Customer Content or Consumer data for VayaFlow-owned cross-context behavioral advertising, retargeting, audience building, or advertising attribution.
- We do not use the substantive content of Customer’s Consumer-facing voice calls, SMS threads, AI-assistant chat threads, or electronically signed documents to train, fine-tune, or improve any AI model — whether VayaFlow’s own proprietary models or any third-party foundation models — unless the Customer has expressly opted in in writing. We do not permit foundation model providers to do so either.
- We do not use Customer Content or Consumer data for any purpose outside the direct business relationship with the Customer or beyond the Business Purpose described in our Data Processing Addendum.
- Customer-directed advertising attribution, conversion measurement, optimization, and conversion posting (where Customers configure these workflows) are processed on behalf of the Customer and according to the Customer’s instructions.
- We may use de-identified, aggregated, or anonymized information to operate, secure, support, analyze, and improve the Services, in each case in compliance with 11 CCR § 7050(c) and analogous provisions of other U.S. privacy laws, and provided that such use does not identify any Customer, Authorized User, or Consumer.
VayaFlow processes Customer Content through enterprise-grade AI infrastructure providers (currently Google Vertex AI and Amazon Bedrock) that contractually commit not to use Customer Content to train their foundation models, not to permit upstream model providers to do so, and to maintain zero-retention, inference-only processing configurations by default. We maintain Business Associate Agreements with these providers to support HIPAA-compliant processing for our healthcare-adjacent Customers. We may substitute or add backend AI infrastructure providers from time to time, in each case subject to substantially the same contractual restrictions and protective configurations.
4. Personal Information We Collect
4.1 Information You Provide Directly
We collect information you give us when you register, request a demo, communicate with us, configure the Platform, or submit content through it. This may include:
- Contact information such as name, business name, business address, business email, business phone number, and job title.
- Account information such as username, password (stored in hashed form), profile photo, time zone, and notification preferences.
- Billing information such as billing contact, billing address, and tax identification number. Payment card data is collected and processed by our third-party payment processor; we do not store full payment card numbers.
- Configuration data such as AI agent scripts, qualification criteria, workflow rules, brand voice settings, phone numbers, suppression lists, consent templates, and integration credentials for third-party systems you connect.
- Communications you send us such as emails, support tickets, demo recordings, and survey responses.
4.2 Information Customers Submit About Consumers
Customers submit, or instruct the Services to ingest, information about Consumers in the course of using the Services. Depending on the Customer’s configuration, this may include:
- Identifiers such as name, postal address, email address, phone number, IP address, and online identifiers.
- Lead, intake, matter, case, claim, incident, family, immigration, insurance, financial, education, or other workflow data, including vertical-specific qualification criteria provided by the Consumer or by the Customer’s marketing source.
- Consent and tracking records such as TCPA consent timestamps, consent language presented to the Consumer, IP address at time of consent, original landing-page URL, UTM parameters, and consent revocation events.
- Communications content such as the audio of voice calls placed or received through the Services, transcripts of those calls, SMS and MMS message threads, AI-assistant chat threads, e-signature audit trails, and the contents of electronically signed documents.
- Metadata such as call duration, call disposition, AI qualification scores, message delivery status, sender and recipient phone numbers and email addresses, and timestamps.
Customers are responsible for deciding whether their use of the Services for sensitive or regulated data is appropriate and lawful, for providing required notices to Consumers, for obtaining required consents, and for complying with professional, advertising, call-recording, privacy, data-protection, and other applicable obligations.
4.3 Information Collected Automatically
When you use the Site or Services, we and our service providers may automatically collect:
- Device and connection information such as IP address, browser type and version, device type, operating system, language settings, and referring URL.
- Usage information such as pages viewed, features used, buttons clicked, time spent in the Services, search terms, and error reports.
- Cookies and similar technologies such as browser cookies, web beacons, pixel tags, local storage, and embedded scripts (see Section 10).
- Approximate location derived from IP address. We do not collect precise GPS location.
4.4 Information From Third Parties
We may receive information about you from:
- Lead-generation partners, marketing networks, advertising platforms, data appendage providers, and other Customers who route Consumer leads through the Services.
- Telecommunications providers, including carrier metadata, line type, do-not-call status, and carrier-supplied identity information.
- Analytics, attribution, anti-fraud, and identity-verification service providers.
- Business contact databases when we engage in sales and marketing.
- Publicly available sources such as business registries, professional directories, and social media profiles you have made public.
4.5 Sensitive Information
Do not submit Social Security numbers, driver’s license numbers, financial account numbers with security credentials, payment card data, precise geolocation, biometric identifiers, genetic data, or detailed health, sex life, sexual orientation, racial or ethnic origin, religious belief, or union membership information through general Services features unless we have specifically authorized you in writing to do so (for example, under a signed Business Associate Agreement for Protected Health Information). If you submit Sensitive Information without authorization, you do so at your own risk.
5. Call Recording, AI Voice, SMS, and Voice Biometrics
5.1 Call Recording. The Services record voice calls placed or received on behalf of our Customers. Our Customers are responsible for ensuring that each Consumer is provided with the disclosure required by applicable two-party-consent and call-recording laws and for obtaining any required consent before recording. We retain call audio and transcripts as part of Customer Content (see Section 12 for retention).
5.2 AI Voice Disclosure. Voice calls placed through the Services may use AI-generated voice. The Services support configurable disclosures for use at the start of a call, on hold messaging, and after-call summaries. Customers are responsible for selecting and enabling the appropriate disclosure for each campaign and jurisdiction, including any disclosures required by FCC rules on AI-generated calls and state laws (such as those in California and Texas) regulating disclosed use of AI agents.
5.3 No Voice Biometrics. We do not currently use voice biometrics or voice cloning to identify or authenticate individuals. We generate voice using third-party AI voice models; that process does not create a biometric template of any speaker. If we add voice biometric functionality in the future, we will provide updated disclosures and obtain any required consents in accordance with applicable law (including the Illinois Biometric Information Privacy Act, where applicable).
5.4 SMS and Messaging. The Services send and receive SMS, MMS, and other messages on behalf of Customers. Standard messaging and data rates apply. Recipients can opt out of any messaging program by replying STOP. Customers are responsible for honoring opt-outs across their entire account and for complying with the TCPA, CTIA messaging guidelines, and carrier requirements (including 10DLC registration).
5.5 No Sharing of Mobile Opt-In Data. Phone numbers collected for SMS purposes and SMS opt-in consent are not shared with, sold to, or transferred to third parties or affiliates for their own marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, except with service providers acting on our behalf solely to deliver the messaging service (such as telecommunications carriers and messaging platform providers), or as required by law.
6. Integrations and API Data
Customers may connect or configure third-party services through the Services, including communication channels, calendars, email, advertising, analytics, CRM, payment, document, business profile, messaging, transcription, AI model, and workflow services. When a Customer enables an integration, VayaFlow may access, receive, store, transmit, or disclose information needed to provide that integration and related Services. Customers are responsible for the integrations they choose and for any required notices, consents, and authorizations.
If a Customer connects Google, Microsoft, or similar APIs, we use API data only to provide and support enabled features, security, troubleshooting, and compliance. We do not sell that data, use it for VayaFlow-owned advertising, or use it to train foundation models or general AI models. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, where applicable.
7. How We Use Personal Information
We use personal information to:
- Provide, operate, maintain, secure, configure, and support the Services, accounts, AI-assisted features, widgets, portals, integrations, communications, payments, workflows, and Customer-configured automations.
- Authenticate users, manage Customer accounts, administer permissions, send notifications, troubleshoot issues, prevent fraud and abuse, monitor reliability, and enforce terms and security requirements.
- Process Customer Content and Consumer data according to Customer instructions, Customer configurations, the Master Service Agreement, the Data Processing Addendum, applicable law, and our role as service provider or processor.
- Communicate with Customers, Authorized Users, prospects, business contacts, and users; provide support; respond to requests; send service, transactional, product, and administrative messages; and manage billing. Service messages cannot be opted out of so long as you maintain an account.
- Send promotional communications to Customers and prospects who have consented or with whom we have an existing business relationship. You can opt out of marketing email at any time using the unsubscribe link in each message.
- Secure the Platform, detect and prevent fraud, abuse, spam, and violations of our Acceptable Use Policy, and investigate suspected illegal activity.
- Improve the Services, including by analyzing usage patterns, running A/B tests, evaluating AI model performance, and producing aggregated and de-identified statistics, in each case subject to Section 3 (Customer Data Commitments) and Section 8 (AI-Assisted Features and Training).
- Comply with our legal, regulatory, and contractual obligations, including responding to lawful requests from public authorities.
- Establish, exercise, or defend legal claims, including by retaining call recordings, transcripts, consent records, and e-signature audit trails as evidence of agreements and consents.
8. AI-Assisted Features and Training
8.1 AI Output. The Services include AI-assisted features that may include AI voice agents, AI assistant chats, summarization, translation, transcription, classification, qualification, lead scoring, routing, suggested notes, and related automation. These features may process Customer Content and Consumer data to provide, evaluate, troubleshoot, monitor, secure, and support enabled Services and workflows. Our current backend AI infrastructure providers include Google Vertex AI and Amazon Bedrock, both of which are configured in zero-retention, inference-only modes and are covered by Business Associate Agreements with VayaFlow to support HIPAA-eligible processing for our healthcare-adjacent Customers. Customer Content and Consumer data may also be processed by other third-party AI language, voice, transcription, classification, or routing service providers acting on our behalf, all of whom are bound to contractual restrictions on retention and use, including prohibitions on training their generally-available models on Customer Content.
8.2 No-Training Default. We do NOT use the substantive content of Customer’s Consumer-facing voice calls, SMS threads, AI-assistant chat threads, or electronically signed documents to train, fine-tune, or improve any AI model — whether our own proprietary models or any third-party models — unless the Customer has expressly opted in in writing (including by check-box on an Order Form). This is our default position: no training without opt-in. Customers may opt out (or confirm continued opt-out) at any time by emailing privacy@vayaflow.com or by updating the corresponding setting in the Platform.
8.3 Service Improvement. Where internal product improvement goes beyond providing, operating, securing, troubleshooting, or supporting a Customer account or enabled feature, we use de-identified, aggregated, or anonymized information. Such use is performed as part of the Business Purpose (as defined in the Data Processing Addendum) and in compliance with 11 CCR § 7050(c) and analogous provisions of other U.S. privacy laws.
8.4 Site and Support Interactions. When you interact with our Site, sales conversations, support chats, or community channels, we may use that content to improve our marketing, support, and product experience.
8.5 Customer Responsibility. Customers are responsible for configuring and supervising AI-assisted workflows, for selecting and enabling appropriate Consumer-facing disclosures, and for complying with laws and professional obligations that apply to their use of AI-assisted features. VayaFlow does not provide legal, medical, financial, tax, insurance, real-estate, mortgage, or other professional advice; AI Output is not a substitute for human review by a qualified professional.
8.6 State AI Law Compliance. Where required by California SB 942 (the California AI Transparency Act, effective January 2026), the Colorado AI Act, the Texas Responsible Artificial Intelligence Governance Act, the Utah AI Policy Act, or other applicable state AI laws, the Services support Customer-configured disclosures, content labeling, watermarking, AI-voice disclosure templates, and similar compliance features. Customers are responsible for selecting and enabling appropriate compliance features for each campaign and jurisdiction, for confirming that their use of AI-assisted features meets the requirements of all applicable state AI laws (including any specific consent, disclosure, recordkeeping, or impact-assessment obligations), and for monitoring the evolving state AI law landscape on an ongoing basis.
9. How We Share Personal Information
We share information only as described in this Policy or with your direction. The main categories are:
- Service providers and processors. We use vetted vendors to host the Platform, process payments, send email and SMS, originate and terminate calls, generate AI output, store recordings, run analytics, and provide security services. These vendors are bound by contracts limiting their use of personal information to providing services to us.
- Customers. If you are a Consumer, the personal information you provide to a lead form, intake call, or other interaction is shared with the Customer that owns the campaign you responded to and, where applicable, with that Customer’s downstream buyers, aggregators, or referral partners as configured in the Services. Each receiving party is responsible for its own privacy practices.
- Affiliates. We share information with our parents, subsidiaries, and other entities under common ownership, who will use the information consistent with this Policy.
- Legal and safety. We may disclose information if required by law, subpoena, court order, or governmental request, or if we believe in good faith that disclosure is necessary to enforce our agreements, protect the rights, property, or safety of any person, prevent fraud, or investigate suspected illegal activity.
- Business transfers. We may disclose information in connection with a merger, acquisition, financing, reorganization, sale of assets, or similar transaction. We will require any successor to honor the commitments in this Policy with respect to information transferred.
- Public attribution. We may identify a business as a VayaFlow Customer in marketing materials only when the relationship is already publicly available (such as via a public “Powered by VayaFlow” attribution), and only without disclosing Customer Content, Consumer data, lead or client records, communications, files, pricing, security information, or other confidential information.
- With consent. We may share information for other purposes you have authorized.
We do not sell personal information in exchange for money. Certain disclosures to lead buyers, advertising networks, or analytics partners may constitute “sharing” or “selling” under some state privacy laws. See Section 13 for opt-out rights.
10. Cookies and Tracking
We and our service providers use cookies, pixels, tags, web beacons, embedded scripts, and similar technologies on the Site for purposes including: (a) authenticating users and maintaining sessions; (b) measuring and analyzing how the Site is used; (c) understanding the effectiveness of our marketing campaigns; and (d) delivering relevant content.
You can manage cookies through your browser settings; refusing cookies may impair some Site functionality. Where required by law, we provide a cookie banner with consent controls. We honor Global Privacy Control (GPC) signals as an opt-out of “sale” or “sharing” of personal information for residents of states where GPC is required.
Because the meaning of “do not track” signals is not uniformly defined, we do not respond to browser DNT signals at this time.
11. How We Protect Personal Information
We maintain administrative, technical, and physical safeguards designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and unauthorized access. These include encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256 or comparable), role-based access controls with least-privilege provisioning, multi-factor authentication for administrative access, centralized audit logging, vendor risk assessments, and incident response procedures. No system is perfectly secure; we cannot guarantee that unauthorized access will never occur.
If you become aware of any actual or suspected security incident affecting the Services, please notify us promptly at security@vayaflow.com.
Breach Notification. In the event of a confirmed security incident affecting personal information, we will notify affected Customers without undue delay and in any event in accordance with applicable contractual obligations (and, where applicable, the Data Processing Addendum and any Business Associate Agreement). Where required by law, we will notify affected individuals within the timeframes required by applicable breach-notification laws (typically thirty (30) to sixty (60) days from confirmed discovery, depending on jurisdiction). Where VayaFlow processes Customer Content on behalf of a Customer, the Customer is generally responsible for direct notification to affected Consumers; in such cases, VayaFlow will provide reasonable cooperation and factual information about the incident to support the Customer’s notification obligations.
12. Data Retention
We retain personal information for as long as needed to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. Typical retention periods are:
- Account and billing records: for the duration of the account plus seven (7) years.
- Configuration data, workflow definitions, and AI agent scripts: for the duration of the account plus thirty (30) days after termination unless extended at Customer’s request.
- Call audio recordings and transcripts: for the period set in the Customer’s plan or Order Form (default: twenty-four (24) months from the call), then deleted or de-identified.
- SMS and MMS message threads: for the period set in the Customer’s plan or Order Form (default: twenty-four (24) months from the last message), then deleted or de-identified.
- AI-assistant chat threads: for the duration of the account plus six (6) months, unless extended at Customer’s request.
- Electronically signed documents and audit trails: for the duration of the account plus seven (7) years, to support enforceability of signed agreements.
- Consent records, do-not-call lists, opt-out lists, and revocation timestamps: for the duration of the account plus four (4) years, to support TCPA compliance and defense of claims.
- Aggregated or de-identified data: indefinitely.
Customers may configure shorter retention periods through Services settings, subject to legal-minimum requirements and our need to retain records to defend legal claims. On termination of a Customer account, we will follow the deletion and export procedures described in our Terms of Service and the applicable Customer Agreement.
Interaction with deletion requests. If a Consumer or Customer submits a deletion request during the retention period applicable to any category above, we will honor the request only as required by Applicable Law. We may decline or partially fulfill the request, or retain a minimum dataset, where retention is required to (a) defend legal claims (including TCPA, lead-quality, recording-consent, or contract-formation disputes); (b) comply with regulatory recordkeeping or audit obligations; (c) maintain consent and opt-out records as required by Applicable Law; or (d) as otherwise permitted by the U.S. privacy laws. We will inform the requester of any such decline and the basis. Once the applicable retention period expires, residual data is deleted or de-identified on a rolling basis.
13. Your Privacy Rights and Choices
13.1 Account-Level Choices
You can update or correct most account information at any time by logging into the Services. You can opt out of marketing emails using the unsubscribe link in each message. To close your account or request deletion of personal information, contact privacy@vayaflow.com.
13.2 Communication Preferences
You can opt out of receiving marketing emails by clicking the unsubscribe link in any marketing email. You can stop receiving SMS marketing from us by replying STOP to any marketing SMS. Service messages related to your account (such as billing notices and security alerts) will continue regardless.
13.3 Response Timeframes
We will respond to verified privacy rights requests within forty-five (45) days of receipt, except where applicable law permits a longer response period or where we require additional time to verify the requester’s identity or to address the complexity or volume of the request. Where additional time is necessary, we may extend the response period by an additional forty-five (45) days, with notice to the requester within the initial forty-five (45) day period. If we decline a request in whole or in part, we will explain the basis for our decision and any appeal rights available under applicable law.
14. Supplemental U.S. State Privacy Notice
You may have rights under U.S. state privacy laws, including (depending on your state of residence and as enacted from time to time) the California Consumer Privacy Act / CPRA, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, the Texas Data Privacy and Security Act, the Oregon Consumer Privacy Act, the Delaware Personal Data Privacy Act, the Iowa Consumer Data Protection Act, the Tennessee Information Protection Act, the Indiana Consumer Data Protection Act, the Montana Consumer Data Privacy Act, the Maryland Online Data Privacy Act, the Minnesota Consumer Data Privacy Act, and similar laws in other states (collectively, the “U.S. Privacy Laws”). The rights described below apply to the extent provided by the law of the state in which you reside. The rights typically include:
- Know what categories of personal information we collect, the sources, and the purposes for which it is used and disclosed.
- Access a copy of the specific pieces of personal information we hold about you.
- Request correction of inaccurate personal information.
- Request deletion of personal information, subject to legal exceptions.
- Opt out of the “sale” of personal information or “sharing” or processing for targeted advertising.
- Opt out of certain profiling that produces legal or similarly significant effects. We disclose that the Services perform automated processing of Consumer data for lead qualification, lead scoring, routing, conversion-likelihood evaluation, and similar functions. Where Applicable Law requires disclosure of, or an opt-out from, automated profiling that produces legal or similarly significant effects (such as decisions about credit, insurance, employment, housing, or education eligibility), Customers will configure the Services to provide such opt-out mechanisms to Consumers as required by Applicable Law.
- Limit the use and disclosure of sensitive personal information.
- Appeal a denial of a request.
- Not be discriminated against for exercising your rights.
In the past 12 months, we may have collected (depending on how the Services are used) the following categories of personal information: identifiers and contact information; customer records; commercial, billing, and transaction information; internet, device, and network activity; approximate location information; audio, electronic, visual, and communications content; professional or employment-related information; education-related information (in higher-education workflows); inferences; sensitive personal information submitted through accounts, workflows, integrations, or support; and other information described in this Policy. Sources include individuals, Customers, Authorized Users, Consumers, integrations, service providers, business partners, devices, browsers, cookies, and Customer-configured workflows. Purposes and recipients are described in Sections 7 and 9.
We do not sell or share sensitive personal information for cross-context behavioral advertising, and we do not use or disclose sensitive personal information to infer characteristics except as permitted by law and needed to provide the Services. We do not knowingly sell or share personal information of individuals under 16.
To exercise these rights, email privacy@vayaflow.com with subject line “Privacy Rights Request,” your full name, the state in which you reside, the email and/or phone number used in your interactions with us, and a description of the right you wish to exercise. We will verify your identity using information already in our records before fulfilling the request. You may designate an authorized agent to submit a request on your behalf, in which case we may require proof of authorization.
If you are a Consumer whose information was submitted by a Customer (for example, your information appears in a Customer’s account because you submitted a lead form or spoke with a Customer’s AI agent), we generally process your information on behalf of that Customer. We will refer your request to the Customer and assist them in responding. To exercise rights directly against that Customer, contact the Customer using the privacy notice that was disclosed to you at the point of collection.
15. Children
The Services are intended for use by businesses and are not directed to children. We do not knowingly collect personal information directly from children under sixteen (16) years of age in our own relationship with users. If we learn that a child under sixteen (16) has provided personal information directly to VayaFlow without appropriate authorization, we will take steps to delete it. Customers may submit information about minors as Customer Content or Consumer data in connection with intake workflows (for example, in family law, immigration, education, or healthcare contexts), and Customers are responsible for obtaining required authority, notices, consents, and compliance.
16. Third-Party Sites and Services
The Site and Services may contain links to or integrations with third-party websites and services. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy notices of any third-party site or service you use.
17. International Users
The Services are hosted in the United States and are intended for users in the United States. We do not direct the Services to individuals in the European Economic Area, the United Kingdom, or Switzerland and do not offer the Services there. If you access the Services from outside the United States, you do so on your own initiative and consent to the transfer and processing of your personal information in the United States, where data-protection laws may differ from those in your country. Where required, we use appropriate safeguards for cross-border transfers.
18. Changes to This Policy
We may update this Policy from time to time. The “Last Updated” date at the top reflects the most recent revision. If we make material changes, we will provide additional notice (such as by email or a prominent notice on the Site) before the changes take effect. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.
19. Contact Us
If you have questions, concerns, or requests regarding this Policy or our privacy practices, please contact:
Roccavera LLC, d/b/a Vayaflow
Attn: Privacy Officer
1908 Thomes Ave STE 41773
Cheyenne, WY 82001
Email: privacy@vayaflow.com