Legal
The documents, and where each one stands.
None of these are published yet. Each page says what the document has to cover, so you can see what you would be getting rather than a broken link. Our sub-processors, which is a matter of fact rather than a legal document, are listed in full.
| Sub-processors | Who receives your data, and what reaches them. | published |
| Privacy policy | Everyone, and UK and EU GDPR require it from the moment personal data is processed. | not published |
| Cookie notice | PECR and the EU cookie rules. Required as soon as anything non-essential is set. | not published |
| Terms of service | Everyone. The contract, unless a negotiated agreement replaces it for Enterprise. | not published |
| Data processing agreement | The enterprise gate. No serious buyer proceeds without one they can sign. | not published |
| Acceptable use policy | Everyone, and it is what allows an abusive account to be terminated without argument. | not published |
| Service level agreement | Anyone paying a monthly fee. Team is a real price with nothing promised in writing. | not published |
| Export control and sanctions | Load-bearing here specifically: routing to US models while serving Iranian customers is a re-export question. | not published |
| EU AI Act transparency | EU buyers. Vatan sells compliance advice, so the platform should meet it first. | not published |
| US state privacy | CCPA, CPRA and the state laws that followed them. | not published |
| Accessibility statement | Public sector and regulated buyers put WCAG and EN 301 549 in procurement. | not published |
If your review needs one of these before you can proceed, say which on the quote form and we will tell you honestly when it will exist.