Back to Homepage

Privacy Notice

Effective Date: July 20, 2026 | VioraBridge LLC

This Privacy Notice describes how VioraBridge LLC (“VioraBridge”, “we”, “us”, or “our”) processes information collected through our survey routing middleware, administrative platform, and associated services.

1. Roles & Responsibilities (Processor vs. Controller)

Under global data protection laws (including the General Data Protection Regulation / GDPR and the California Consumer Privacy Act / CCPA as amended by the CPRA):

  • Data Processor: In most circumstances, VioraBridge acts as a Data Processor on behalf of our market research and consultancy customers (“Tenants”), who act as Data Controllers. Tenants configure study routing rules, specify target survey parameters, and manage respondent traffic. We process respondent technical data solely pursuant to tenant instructions and governing data processing terms.
  • Data Controller: VioraBridge acts as a Data Controller for administrative account information, tenant billing data, security logs, platform telemetry, and customer support communications.

2. Information Processed Through the Routing Middleware

When a respondent navigates through a VioraBridge routing endpoint, our cloud infrastructure processes temporary technical telemetry necessary to match, route, and protect survey campaigns:

  • Technical Telemetry: IP address, geolocation (country/region), user-agent string, operating system type, and ISP/carrier indicators used to evaluate proxy, VPN, or cellular strictness rules.
  • Session Identifiers: Non-identifiable routing hashes and vendor tracking keys provided by sample acquisition providers.

URL Parameter Safeguards: VioraBridge employs automated detection and redaction mechanisms designed to reduce the accidental transmission of common personal identifiers (such as plain-text email addresses or telephone numbers) passed via incoming URL parameters.

3. Tenant Account & Administrative Information

For tenant account administration, we collect:

  • Contact details of authorized user seats (names, professional email addresses, job titles).
  • Account access credentials (hashed passwords and multi-factor security tokens).
  • Custom domain setup specifications and CNAME routing configurations.
  • Custom mailer configurations. Private credentials stored within tenant settings are protected using industry-standard encryption measures.
  • Billing profiles, payment histories, and catalog invoice summaries.

4. GDPR Legal Bases for Processing

For data where VioraBridge acts as a Data Controller, we process personal information under the following legal bases:

  • Performance of Contract: To provision user seats, maintain workspace security, and deliver subscription services.
  • Legitimate Interests: To maintain platform security, prevent routing fraud, analyze service health, and improve infrastructure performance.
  • Legal Compliance: To satisfy accounting, tax, regulatory, and corporate record-keeping requirements.

5. Data Retention & Pruning Schedule

Respondent routing logs and session parameters are generally retained for up to 90 days to facilitate study reconciliation and quality audits, unless a tenant configures an earlier automated pruning schedule or legal obligations require longer retention. Tenant account data is retained for the duration of the active subscription plus applicable statutory record-keeping periods.

6. International Data Transfers & Service Providers

VioraBridge utilizes reputable enterprise cloud hosting and managed database infrastructure located primarily in the United States. Where personal data originating from the European Economic Area (EEA), United Kingdom, or Switzerland is transferred internationally, VioraBridge relies on recognized transfer mechanisms, including standard contractual clauses (SCCs) or applicable adequacy decisions. A formal Data Processing Addendum (DPA) is available upon request for enterprise customers.

7. California Privacy Rights (CCPA / CPRA)

VioraBridge does not sell or share personal information for cross-context behavioral advertising or commercial monetization. California residents may request access to, correction of, deletion of, and information regarding categories of personal information collected by VioraBridge in our role as a controller.

8. Cookies & Local Storage Disclosure

VioraBridge uses strictly necessary cookies and local storage tokens for core application functionality:

  • Authentication Cookies: Essential session authentication tokens used to maintain secure user login sessions.
  • Security Tokens: Anti-CSRF protection headers used to prevent cross-site request forgery.

We do not use third-party advertising or cross-site tracking cookies.

9. Children's Privacy

Our services are strictly directed to commercial businesses and adults aged 18 and older. We do not knowingly collect personal information from individuals under 16 years of age.

10. Updates to This Notice

We may update this Privacy Notice periodically to reflect changes in our legal obligations or platform practices. The revised version will be posted on this page with an updated Effective Date.

11. Contact Us

If you have questions regarding this Privacy Notice or wish to exercise data subject rights, please contact our legal and privacy team at:

VioraBridge LLC
Email: privacy@viorabridge.com | legal@viorabridge.com