PassControl legal
Privacy notice.
What personal data PassControl and Vertias process, why it is needed, where it goes and what choices you have.
1. Who is responsible
Kristiyan Ivanov is the controller for PassControl Cloud, passcontrol.vertias.eu and www.vertias.eu, operating under the Vertias name from Sofia, Bulgaria.
Kristiyan IvanovIndividual operating the Vertias project
Sofia, Bulgaria
owner@passcontrol.vertias.eu
Launch status: if the page above is marked as a pre-launch draft, its effective date is still unresolved and external beta invitations must not begin.
2. Data we process
- Account data: email address, authentication records, session data, MFA state and recovery-code hashes.
- Beta application data: email address, intended integration and provider, estimated call range, use-case description, consent time, invitation state and optional setup feedback.
- Agent configuration: agent names, identity keys, direct-key hashes and suffixes, scopes, policies, budgets, suspension state and break-glass settings.
- Call records: agent and credential identifiers, provider, model, token counts, cost, outcome, latency, time, receipt and shadow-policy verdict.
- Provider credentials: keys placed in the managed Vault. They are retrieved only after a call passes the gate.
- Security and operations data: IP-derived rate-limit keys, nonces, budget reservations, audit events and scrubbed error diagnostics.
- Problem reports: the text you write when you report a problem, and — only if you tick the box after seeing exactly what it contains — a diagnostic summary of your workspace: agent, budget and failure metadata, plus which build of PassControl you were using. Text that looks like a key, token or visa is removed before it is stored. No prompts, model responses, provider keys, credential hashes, recovery codes or session tokens are included.
- Communications: email address and message content when you contact Vertias or receive authentication, invitation, one-time setup-follow-up, feedback-request or recovery email.
3. Model traffic
PassControl must process model requests and responses in plaintext while proxying them so it can apply the gate, add the provider credential and return the result. The selected model provider also receives that content.
PassControl does not store prompts or model responses in agent_logs. It stores the call metadata listed above. Infrastructure providers may still process transient request data and operational logs under their own retention and security terms.
4. Why we process it
| Purpose | Legal basis |
|---|---|
| Provide accounts, agent control, gateway routing and receipts | Contract and steps requested before entering a contract |
| Review beta applications and send personal invitations or the one permitted activation follow-up | Steps you request before entering the beta agreement and consent to application contact |
| Protect the service, enforce limits, investigate abuse and keep reliable records | Legitimate interests in security, integrity and operating the beta |
| Respond to legal requests and exercise or defend claims | Legal obligation and legitimate interests |
| Send optional marketing in the future | Consent, if such messages are introduced; beta application and setup email is transactional, not a marketing list |
5. Who receives data
PassControl uses Vercel, Supabase, Upstash, Resend, ImprovMX and, when configured, Sentry. Their roles and links are listed on the service providers page. Your chosen model provider receives calls you route to it. Data may be processed outside the EEA using the safeguards made available by those providers.
Personal data is not sold. PassControl currently uses no advertising or behavioural-analytics service. Beta emails are text-only and contain no open-tracking pixel or click-tracking wrapper.
6. Retention
Resolved problem reports are deleted 180 days after they are resolved. A report that is still open is kept until it is answered, because deleting it would destroy the only record of a problem that has not been fixed.
Pending or unaccepted beta applications are kept for no more than 180 days. Declined or withdrawn applications are scheduled for deletion after 30 days. Expired, revoked or used invitation metadata is removed after its relevant date is more than 30 days old. Setup feedback is kept for up to 180 days. The raw invitation token is never stored.
Account, configuration, audit and call metadata are retained while your beta account is active. Permanent workspace deletion removes linked beta application and feedback records through the same account cascade, except for limited records that must be preserved for legal obligations or legal claims. Processor backups and logs expire under each provider's retention process.
Do not place data in PassControl that you cannot lawfully retain under this model.
7. Your rights
Depending on the circumstances, you may request access, correction, deletion, restriction, portability or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting earlier processing.
Authenticated operators can download a machine-readable account export or permanently delete their workspace from Dashboard → Settings → Account data. An MFA step-up is required when MFA is enrolled. You may also email owner@passcontrol.vertias.eu; identity may be verified before acting on a request.
You may complain to Bulgaria's Commission for Personal Data Protection.
8. Security, children and automated decisions
PassControl applies technical controls intended to protect credentials and tenant data, but this is an early beta and has not been independently audited. No Internet service can promise absolute security.
The beta is for adults aged 18 or over. Its automated gate controls access to model providers; it is not used to make decisions producing legal or similarly significant effects about people.
9. Changes
Material changes will be posted here and, where appropriate, sent to active invitees before taking effect.