Skip to main content

Privacy Policy

What this website processes, why, and what it deliberately does not do.

Who is responsible for this website

VMD Software Technology is the name of this website and of the engineering work presented on it. It is not a registered company. The website is operated by the individual named below, who is also the controller for the processing described in this policy.

Operator and controller
Vladimir Korać
Address
Puškinova 11, 21102 Novi Sad, Serbia
Email
office@vmdsoftwaretechnology.io

Write to that address, or to that email address, for anything in this policy — including to exercise the rights described at the end of it.

What this policy covers

This policy covers https://vmdsoftwaretechnology.io and nothing else. Where this site links to a service run by someone else, that service is governed by its own policy.

The site has no accounts, no login, no shop, no newsletter and no contact form. There is no profiling and no automated decision-making that produces legal effects.

Hosting and server logs

Serving a web page requires a connection between your device and a server. In the course of that connection the hosting provider processes technical data, which typically includes your IP address, the time of the request, the address requested, the referring page and your browser identification. This is unavoidable if the site is to be delivered at all, and it is used to deliver it and to keep it secure.

Hosting provider
Vercel Inc.
Processing region
Frankfurt (fra1), Germany
Legal basis
Article 6(1)(f) GDPR. The legitimate interest is operating a website that is reachable, stable and secure.

ASK VMD, the assistant on this site

ASK VMD answers questions about what VMD does. It only runs when you open it and send a message; it reads nothing about you otherwise.

When you send a message, the following is transmitted to the AI provider named below in order to generate a reply:

  • the messages you have typed in this conversation
  • the path of the page you opened the assistant from — for example /technology — so the answer can be relevant to it
  • a short structured summary of what the conversation has established so far, which your browser sends back with each turn
AI provider
OpenAI
Contracting entity
OpenAI OpCo, LLC
Processing region
No specific data residency region configured.
Legal basis
Article 6(1)(f) GDPR. The legitimate interest is answering questions about our work without requiring the visitor to write an email first.

We do not keep your conversation. It exists in the browser tab you are using and is gone when you close or reload the page; no copy is written on our side, and there is nothing to retrieve later. Our server records only that a request happened: the outcome, how long it took, token counts, which entries from our own knowledge base were consulted, and the detected language. It does not record what you wrote or what the assistant replied.

The request is sent with storage in the provider’s application state switched off, so the conversation is not kept in our provider account and cannot be read back from it. That is not the same thing as the provider retaining nothing.

Two things follow from the provider’s own terms rather than from our settings. Data sent through the API is not used to train the provider’s models by default; that would require us to opt in, and we have not. Separately, the provider keeps abuse-monitoring logs which may contain the content of a request, for up to 30 days, unless a different approved retention arrangement applies to the account. We do not control that retention and do not claim otherwise.

Two practical consequences. Please do not type confidential information, personal data about other people, credentials or anything you would not send in an ordinary email — the assistant does not need it, and it leaves your browser. And treat the answers as a starting point rather than advice: a language model can be confidently wrong, and anything that matters should be confirmed with a person.

Abuse prevention and rate limiting

The assistant is a public endpoint that costs money to run, so requests are counted and capped at 12 per minute per visitor.

To count them without keeping addresses, your IP address is combined with a secret value held on the server and hashed; a truncated form of that hash is used as the counter key. The address itself is never written to the counter store. The key exists only for the counting window and expires automatically within 120 seconds — every 60-second window uses a new key and the old one is discarded.

We describe this as pseudonymous rather than anonymous, deliberately: a value derived from an IP address remains personal data even when it cannot be read directly, and calling it anonymous would overstate what the hashing achieves.

Counter store
Upstash, Inc.
Processing region
Frankfurt (fra1), Germany
Retention
At most 120 seconds, after which the key expires by itself.
Legal basis
Article 6(1)(f) GDPR. The legitimate interest is protecting a public endpoint from abuse and uncontrolled cost.

Contacting us by email

Every contact option on this site — including “Book a demo” — is an ordinary email link. Clicking it opens your own email program with the address, and a subject line, already filled in. Nothing is submitted to this website at that moment: there is no form, and we receive nothing until you decide to send the message yourself.

Once you do send it, we process what you wrote, your email address and anything else you chose to include, in order to answer you and, where it leads to that, to discuss possible work together.

Email provider
Hostinger (HOSTINGER, UAB)
Legal basis
Article 6(1)(b) GDPR where your message concerns a possible engagement, and Article 6(1)(f) GDPR otherwise, the legitimate interest being to answer enquiries addressed to us.

Cookies and browser storage

This website sets no cookies. It stores nothing in localStorage or sessionStorage. It runs no analytics, no tracking pixels, no advertising technology, no A/B testing and no embedded social media widgets, and it does not fingerprint your device.

This is a measured statement rather than an intention: the pages were loaded in a clean browser and inspected, and no cookie, no stored value and no request to any third-party server was observed on any of them, before or after using the assistant.

That is also why you are not asked for cookie consent. There is nothing on this site to consent to, and a banner that asks anyway would be theatre. If that ever changes, this section changes with it — and consent will be requested before anything non-essential is set, not after.

Fonts, images and other assets

Every asset the site loads — fonts, images, styles, scripts — is served from this domain. Fonts in particular are self-hosted rather than requested from a font provider, so your IP address is not disclosed to one when a page opens. The site loads no resource from any external server.

How long data is kept

  • Rate-limit counter keys: at most 120 seconds, expiring automatically.
  • Assistant conversations: not stored by us at all.
  • Server-side request logs: outcome and timing information only, with no message content; retained by the hosting provider under its own log retention.
  • Email correspondence: for as long as needed to deal with the matter it concerns, and longer only where a statutory retention obligation applies.

Transfers outside the EU/EEA

Using the assistant means your message is sent to the AI provider named above. Where that involves processing outside the EU/EEA, the transfer is covered by the mechanism stated here.

Transfer mechanism
Where international transfers of personal data require appropriate safeguards under applicable data protection law, OpenAI relies on the transfer mechanisms described in its Data Processing Addendum, including Standard Contractual Clauses where applicable.
Data processing agreement
In place with the provider.

If you would rather not have a message processed this way, do not use the assistant — write to us by email instead. Nothing on this site requires the assistant.

Your rights

Under the GDPR you have the right to:

  • ask whether we process data about you, and receive a copy of it (Article 15)
  • have inaccurate data corrected (Article 16)
  • have data erased (Article 17)
  • have processing restricted (Article 18)
  • receive data you provided in a portable form (Article 20)
  • object to processing based on legitimate interests (Article 21)

Write to the address or the email address at the top of this policy. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the country where you live or work.

One honest limitation: because assistant conversations are not stored and rate-limit keys are hashed and expire within minutes, there is usually nothing left for us to retrieve, correct or delete in relation to your visit. That is a consequence of collecting almost nothing, not a refusal to help.

Changes to this policy

This policy describes the site as it is built today. If the site starts doing something new — analytics, a contact form, an account system — this policy is updated before that goes live, not afterwards.