Legal
Data Processing Notice
Last updated 31 July 2026.
This notice summarises how Visora processes customer data when delivering audits, monitoring and improvement services. It supports, and should be read with, our Privacy Policy.
1. Roles
Visora is the controller of account and billing data. Where we process business and analysis data on your instructions to deliver the service, we act as a processor and you remain the controller. Business customers who require a signed data processing agreement can request one from privacy@visora.app.
2. Subject matter and duration
Processing covers the generation of customer questions, AI visibility testing, signal analysis, score calculation, reporting and monitoring, for the duration of your account plus the retention periods set out in the Privacy Policy.
3. Categories of data subjects
- Your account users: owners, administrators, analysts and viewers.
- Individuals named in business contact details you enter.
- Individuals whose names appear incidentally in publicly available sources or AI responses recorded during testing.
4. Categories of data
We do not ask for, and you should not upload, special category data, payment card numbers or customer databases.
- Identity and contact data for account users.
- Business profile data: names, websites, services, locations, sectors and competitors.
- Analysis data: tested questions, recorded AI responses, observed signals, scores and recommendations.
- Technical and log data required to run and secure the platform.
5. Subprocessors
Each subprocessor is engaged under written terms requiring confidentiality, security measures and processing only on documented instructions. We maintain a current list and notify customers of material changes.
- Cloud hosting, database and file storage.
- AI model providers used for question generation and visibility testing.
- Payment processing.
- Transactional email delivery.
- Error monitoring and application logging.
6. International transfers
Some subprocessors operate outside the UK and EEA. Where that is the case, transfers rely on approved safeguards such as UK adequacy regulations, the UK International Data Transfer Addendum or Standard Contractual Clauses.
7. Security measures
These are the controls we operate today. They are described factually and are not an independent certification or audit outcome.
- Authenticated accounts with organisation membership and role-based access.
- Row-level database policies so records are only readable by the organisation that owns them.
- Encryption in transit and at rest provided by our infrastructure providers.
- Least-privilege access to production systems and audit logging of privileged operations.
8. Assistance and incidents
We assist customers with data subject requests, and will notify affected customers without undue delay after becoming aware of a personal data breach involving their data. Report a suspected issue to security@visora.app.
9. Return, export and deletion
You can export your account and report data at any time, and request deletion of your account, business records and analysis history. Live systems are cleared immediately and backups within 30 days, other than records we must keep for legal or accounting reasons.
Visora provides a proprietary AI Visibility benchmark based on observed testing and published methodology. It is not an official ranking or score issued by OpenAI, Google, Microsoft, Anthropic, Perplexity or any other AI provider.
Visora is an independent platform and is not affiliated with, endorsed by or sponsored by OpenAI, Google, Microsoft, Anthropic, Perplexity or any other AI platform unless explicitly stated.