Viabasis Privacy Policy
This is a pilot version. Privacy Policy revision 2026-09-14.2, in the acceptance bundle viabasis-pilot-legal-2026-09-14.2. It applies to the current hosted Viabasis founding build.
Effective date: 2026-09-14.
How Viabasis handles your data in detail is in the Data-Trust Statement (https://app.viabasis.com/data-trust).
1. Who we are
1.1 Viabasis is a brand of Manapar LLC, a Delaware limited liability company at 6614 Ave U, Unit #694, Brooklyn, NY 11234, United States ("we", "us"). It is a quote-to-profit and season-money workspace for small group tour operators and travel advisors.
1.2 Privacy contact: [email protected]. We reply within 1 business day. This policy is written in plain language. It is not legal advice.
2. What we collect
2.1 Account and sign-up data. Your work email, name and company name. Public sign-up by verified work email is enabled; anonymous sign-in is disabled. We also store the time of sign-up and, if you arrived from an advertisement link, the campaign labels in that link — never your search terms or a third-party identifier. The public access request form sends the same details to support and creates no account. We may also invite a membership manually.
2.2 Workspace content you bring. When you paste or upload a supplier quote, contract, invoice or budget sheet, we store:
- the source text;
- the facts the AI extracted and you reviewed;
- your trips, budgets, business rules, logo, obligations and calendar;
- your question log and version history;
- the names, emails and phone numbers of supplier staff that appear in quotes;
- supplier payment details that you confirm.
2.3 No traveller data. Viabasis has no passenger records. You agree not to enter traveller or client personal data during the pilot. If some slips in, we delete it on request.
2.4 Usage telemetry and optional feedback. Telemetry contains event names, counts, durations and statuses, not quote content. Optional feedback fields contain what you type; the interface asks you to omit traveller details, supplier information and prices. We use no third-party analytics, session replay or advertising cookies.
2.5 AI spend ledger. A per-company record of AI usage and cost, so we can apply your quota. It holds no content.
2.6 Support emails. When you write to us, we keep the thread.
2.7 Payment status. If you take the founding offer, Stripe processes your card and sends the app signed payment notices. We store the company reference, the Stripe identifiers, payment status, amount, currency, mode and timestamps, so we can match the payment to your business. We never store card numbers, payment emails or raw payment-processor webhook bodies. After the 14-day trial and the 7-day saving grace, saving continues only while your company workspace has a manually matched paid subscription with a current reviewed paid-through date and no suspension. So that a business that has just paid is not dropped into read-only, a signed paid event keeps an existing workspace saving for up to 72 hours from Stripe's event timestamp while we check it. Otherwise the workspace returns to view, download, export and recovery only.
2.8 Reminder email. If you opt in, Viabasis emails you a weekly reminder of the departure tasks and supplier payments due in the next 14 days. It lists titles and dates only, no amounts, with a one-click link to stop it.
2.9 Cookies. Only strictly necessary cookies, which keep you signed in. We set no tracking cookies.
3. Why we use your data, and on what legal basis
3.1 To provide the service — your account, your workspace, quote extraction, budget recomputation, sign-in links. Basis: performance of a contract (GDPR art. 6(1)(b); LGPD art. 7 V).
3.2 To run and protect the service — telemetry, error logs, quota enforcement, abuse prevention, security testing. Basis: our legitimate interest (GDPR art. 6(1)(f); LGPD art. 7 IX). We do not profile you.
3.3 To answer you — support emails. Basis: contract and legitimate interest.
3.4 To bill you — payment status and bookkeeping. Stripe handles the card transaction and its own payment emails. Basis: contract and legal obligation.
3.5 Sanitised fixtures — we may ask to reuse one quote as a synthetic test file that keeps the layout and removes every name, price and identifier. Opt-in, one quote at a time, never blanket; you can say no or withdraw later. Basis: consent (GDPR art. 6(1)(a); LGPD art. 7 I).
3.6 Cross-company learning — none without your explicit consent, and then only aggregated.
3.7 Marketing — none. We send no marketing email, and no reminder email unless you opt in.
4. AI processing
4.1 How it works. The AI extracts facts. You review them. A deterministic engine recomputes the numbers and never calls an AI model. Any inferred number is labelled as an assumption.
4.2 Who processes the text, and what stays put. Pasted quote text, text read from ordinary Office files, pasted supplier replies, and PDF and image files go through the Viabasis server to Anthropic so it can classify or read them. Excel, Word and PowerPoint bytes are opened in your browser and never leave it, and Viabasis keeps no PDF or image original after the response. When Viabasis phrases a question for a supplier, Anthropic receives only bounded snippets, confirmed facts and business rules for that departure, and you decide what to send. Some material never reaches Anthropic at all. How Viabasis handles your data in detail is in the Data-Trust Statement (https://app.viabasis.com/data-trust).
4.3 Provider retention and training. Under Anthropic's commercial terms, API inputs and outputs are not used to train its models by default, and are automatically deleted from its backend within 30 days. Anthropic publishes exceptions to this for agreed retention, longer-lived features, safety enforcement, legal obligations and anonymised data. Viabasis does not submit customer work as Anthropic feedback, does not opt it into training, and has no verified zero-data-retention arrangement. See Anthropic's retention policy and training policy.
4.4 Result cache. We keep a per-company cache of validated AI results for at most 30 days, so the same input is not read and paid for twice. It holds no file bytes, and one company's entry is never served to another.
4.5 Outputs are drafts. They need professional review. They are not pricing, legal, tax or accounting advice.
4.6 No automated decisions. Viabasis makes no decision about you that has a legal or similarly significant effect.
5. Where your data lives and international transfers
5.1 Sub-processors. A sub-processor is a company we use to run Viabasis that handles your data on our behalf.
| Provider | What it does | Where |
|---|---|---|
| Supabase | Postgres database and authentication | US East (us-east-1) |
| Vercel | hosting the app and server | United States (Northern Virginia) |
| Anthropic | AI classification, extraction and supplier-question phrasing | Per Anthropic's published policy |
| Resend | sign-in and access-request email | Primary processing in the United States; published email and log retention is 30 days, with 7-day backups |
| Cloudflare Email Routing | inbound routing for [email protected]; Cloudflare says it does not store or access routed message content, while routing, authentication and delivery metadata are processed | Not yet confirmed |
| Google Workspace (Google LLC) | final support mailbox — routed support emails and our replies | United States |
| Stripe | payments for the founding offer | Per Stripe's policy |
| GitHub | private source code; holds no customer data | — |
We tell you 30 days before we add a sub-processor, by email. You may object.
5.2 Transfers from the EU, UK and Brazil. The workspace database and the server run in the United States. Where the law requires, we rely on the European Commission's Standard Contractual Clauses and, for the United Kingdom, the UK International Data Transfer Addendum. We make no complete data-residency promise.
5.3 Isolation and access. One company cannot read, list or change another company's data. Only a small number of named administrators can reach project data, for operations and support, and they are bound by confidentiality.
6. How long we keep data
6.1 Workspace content, account data and subscription records: while your account is active. After you delete your account, or ask us in writing, they are deleted within 30 days. Stripe keeps its own payment records for its legal retention period.
6.2 AI result cache: 30 days. Telemetry: up to 12 months. AI spend records: up to 13 months, then anonymous totals only. Support emails: 24 months after the last message.
6.3 Each sub-processor keeps its own copies for its own published period. Those periods, our project backups and every other item we hold are listed in the Data-Trust Statement (https://app.viabasis.com/data-trust) and in our Retention and Deletion Policy.
7. Your rights
7.1 You can ask us to:
- access — tell you what we hold about you and give you a copy;
- correct — fix wrong or incomplete data;
- export — give you your workspace as a JSON file;
- delete — erase your account and workspace;
- restrict or object — stop a use based on legitimate interest;
- withdraw consent — for sanitised fixtures or cross-company learning, at any time; earlier use stays lawful;
- not be subject to automated decisions — we make none.
7.2 Brazil (LGPD art. 18). The same rights, plus: confirmation of processing; anonymisation or blocking of excess data; who we share with; what happens if you refuse consent.
7.3 How to ask. Email [email protected]. We answer within 1 business day and complete the request within the period your law sets: one month under GDPR and UK GDPR, 15 days under LGPD, otherwise 30 days. We may ask you to confirm your identity.
7.4 Supplier staff. If your details appear in a user's quote, write to us or to that user. The user controls that data; we forward your request and help them answer it.
8. Roles: who is responsible for what
8.1 Account data. We are the controller.
8.2 Workspace content. Your company is the controller and we are the processor. We process it only to provide the service, on your instructions, using the sub-processors in section 5. Our data-processing terms are in the Terms of Service, section 5 (https://viabasis.com/terms); a standalone copy is available at [email protected].
8.3 Your duties as controller. Make sure you may share supplier quotes, contacts and bank details with a processor. Do not enter traveller data.
9. Security summary
9.1 API keys live on our servers only; your browser never sees them. Quote text is treated as untrusted data, and we test the service against attempts to use it as instructions.
9.2 One company cannot read another company's data. Sign-in is by magic link, so we store no password. Encryption in transit and at rest is provided by our sub-processors.
9.3 Card data never touches Viabasis; Stripe handles it. The app never sends money to anyone.
9.4 Breach. If we learn of a breach affecting your data, we tell you by email without undue delay and within 72 hours of learning of it. We also tell the supervisory authority where the law requires it.
10. Children
Viabasis is for businesses. It is not for anyone under 18. We do not knowingly collect data from children.
11. Changes
We post changes here with a new date. For material changes we email you before they take effect.
12. Contact and complaints
12.1 Email: [email protected]. Post: 6614 Ave U, Unit #694, Brooklyn, NY 11234.
12.2 EU/EEA. You can complain to your local supervisory authority.
12.3 UK. Information Commissioner's Office, ico.org.uk.
12.4 Brazil. Autoridade Nacional de Proteção de Dados (ANPD). Our encarregado (data protection officer): the privacy contact above.
12.5 US. We do not sell or share personal data.
12.6 Governing law and venue: the State of Delaware, United States.