Privacy notice
Deduction Recovery audits the deductions a distributor took from a brand's payments. What we hold is almost entirely commercial: remittance and deduction reports between two companies. The personal data is small — the name and work e-mail of the people who use an account. This notice describes what the software does today.
Who is responsible
Data controller for this service: Armen Sarkisian, Komitas 57, 0032 Yerevan, Armenia. Questions about your data: privacy@vitersoft.com.
What is stored
- The brand's name, website, revenue range and distributors, as typed on the form.
- The name and work e-mail address of each person on the account.
- The files you upload, in private storage, and the deduction lines read from them.
- Our notes and decisions on each line, the text of each dispute, and what the distributor answered.
- The name and title of the person who accepted the engagement, and when.
We do not store IP addresses, and we do not ask for a distributor portal password on this site.
How long
For as long as the account exists. The owner can delete the account from the settings page: that removes the files, every line, the audit, the authorisation and the people at once, and we count each of our tables afterwards to confirm nothing is left. An account that was requested but never signed in to is removed automatically after 30 days. Sign-in links are stored only as a hash and removed within a day of expiring.
Who else sees it
- Cloudflare, Inc. (USA and EU) — runs the application.
- Supabase (EU, Frankfurt) — the database and the private file storage. Only our server can read them; the public keys hold no rights at all.
- Sendinblue SAS, 9-17 rue Salneuve, 75017 Paris, France (trading as Brevo) — sends sign-in links and the message that an audit is ready. No message carries a figure from your books. Brevo puts an invisible image in every letter it sends, so it registers when a letter is opened; we do not ask for that and cannot switch it off per message. The sign-in link itself is not rewritten and does not go through Brevo.
- PostHog (EU, Germany) — counts how the tool is used: numbers and categories, no names, no invoice numbers, no amounts.
- OpenRouter, Inc. (USA) — only when you upload a PDF rather than a spreadsheet: the text of each page is sent to a language model to find the deduction lines on it. Requests are routed only to model providers that retain nothing (zero data retention), and nothing else about your account is sent. Spreadsheets and CSV files are read in your browser and never go to a model.
- The distributor you name — once you authorise us, the disputes we file for you and the documents attached to them.
Where a recipient processes data outside the EEA, the transfer is covered by Standard Contractual Clauses.
Cookies
One: the sign-in cookie, which holds the account and the person and nothing else. The analytics are configured without cookies and without local storage, so there is no banner to click.
Your rights
You can ask for a copy of what we hold about you, have it corrected, or have it deleted — the last of these you can do yourself in settings. Residents of California and other US states with privacy laws have the rights those laws give; we do not sell or share personal information. Write to privacy@vitersoft.com and a person answers.