Skip to main content
VORYNAI
LegalFactual notice — pending formal legal review

Privacy

This notice describes what the VORYN AI website actually does with information you send us. It is written from the system as implemented, not from intention. Where a policy has not yet been set, this notice says so rather than implying one exists.

Last reviewed against the running system on 16 August 2026.

What the contact form collects

The contact form at /contact is the only place on this website where you can submit information to us. Nothing else on the site collects data about you.

Name
Required. So we know who we are replying to.
Email address
Required. The address we reply to.
Message
Required. What you want to discuss, up to 4000 characters.
Consent acknowledgement
Required. You must tick the consent box before the form will submit. The form cannot be submitted without it.
Company
Optional. Helps us prepare a relevant response.
Role or title
Optional. Same purpose.
Industry
Optional. Same purpose.
Business challenge
Optional. A single choice from a fixed list, so we can route your enquiry to the right area.
Preferred contact method
Optional. A single choice from a fixed list — email, phone, video call, or no preference.

What we do not collect

  • No analytics, tracking pixels, advertising tags, or session-recording tools are loaded anywhere on this website.
  • No third-party scripts run on the public pages. Web fonts are served from this site's own domain, not from an external font provider.
  • No cookies are set on the public pages. Cookies are used only on the /admin sign-in area, and only to hold an administrator's authenticated session.
  • Your IP address is not stored against your message. It is used only in transient, hashed form as described below.
  • The form contains a hidden anti-spam field. If it is filled in, the submission is rejected and nothing is stored.

How a submission is processed

When you submit the form, the information is validated on our server, not only in your browser. If validation fails, nothing is stored and the form returns to you with the fields to correct.

A valid submission is written to a PostgreSQL database hosted by Supabase, which acts as our data-hosting provider. The write happens from our server. Your browser never talks to the database directly.

Abuse protection and hashed request identity

To limit automated abuse of the form, our server derives a short one-way fingerprint from your IP address and browser user-agent string. It is a SHA-256 hash, truncated to 16 characters. The underlying IP address and user-agent are not written to storage.

This fingerprint is used to count recent submissions from the same connection and is recorded on our internal operational events so that a blocked or failed submission can be investigated. It is not attached to your message record, is not used to profile you, and is not shared.

This rate limiting is deliberately lightweight and best-effort. It runs within a single server instance and does not persist across restarts, so it should be understood as basic hygiene rather than strong protection.

Operational and audit events

VORYN keeps a minimal internal event log so that the handling of enquiries and administrator sign-ins remains traceable. Events record what happened and when — for example that a message was received, that a submission was rate-limited, or that an administrator sign-in was requested, succeeded, or failed.

These events carry the hashed fingerprint described above, never your name, email address, or message text. For an administrator sign-in, the event records the administrator's internal account identifier only.

Who can see your message

Access to submitted messages is restricted at the database level, not only in the application. By default the database denies all access. A separate, explicit rule grants read-only access to signed-in accounts that carry an administrator role, which is assigned manually by VORYN and cannot be self-assigned from the website.

The administrative review screen is read-only. There is no interface for editing, replying to, exporting, or deleting messages from within the website, and no automated or AI processing is applied to your message. Enquiries are read by a person.

The administrative area is not indexed by search engines and is not reachable without a valid single-use sign-in link sent to an authorised address.

Why we hold it

We use what you submit to understand your enquiry and respond to it. We do not sell it, rent it, trade it, or share it with third parties for their own purposes.

Our data-hosting provider (Supabase) necessarily processes the data on our behalf in order to store it. We do not send your submission to any other external service.

Your choices

You can ask us what we hold about you, ask us to correct it, or ask us to delete it. Write to hello@vorynaia.com and we will act on the request.

You are never required to use the form. If you would rather not submit anything through this website, email us directly at the same address.

Not yet established

VORYN would rather state this plainly than imply a policy that does not exist. The following are not yet set, and this notice will be updated when the Founder and a qualified legal reviewer have settled them:

  • A defined retention period. Submissions are currently kept until a deletion request is acted on or the record is removed manually. No automatic deletion schedule is in force.
  • A formal determination of which data-protection regimes apply to VORYN AI, including the Protection of Personal Information Act (POPIA) in South Africa, and the identity of the responsible party for the purposes of any such regime.
  • A concluded lawful basis assessment. The consent you give on the form is recorded, but no formal lawful-basis analysis has been published.
  • A published data-processing agreement with our hosting provider, and a recorded position on the hosting region and any cross-border transfer of the data.
  • A named privacy contact or information officer, and a formal complaints route.

Changes to this notice

This notice was reconciled against the running system on 16 August 2026 as part of the Web Presence v2.2 trust-perimeter review. If the way we handle information changes, this page is updated in the same change as the code that changes it.

Privacy questions

Questions about this notice, or a request about your information, can go to hello@vorynaia.com.