← Back to legal

API privacy policy

Updated July 17, 2026

Introduction

This privacy policy explains how Vzla.io handles data when you access our product programmatically through the Vzla.io API. It is written for a developer and technical audience: people who create an API token and integrate our service into their own applications, scripts, or systems.

Vzla.io is operated by a company registered in the United States (Wyoming). Although we are not established in the European Union, we have chosen to comply with the EU General Data Protection Regulation (GDPR) for all users of our API. Where this policy refers to “personal data”, “controller”, “processor”, “lawful basis”, and “data subject”, those terms carry their GDPR meaning.

In this policy, “Vzla.io”, “we”, “us”, or “the API” refer to our platform and the team behind it. “You”, “the developer”, or “the API user” refer to the person or organization that holds an API token and calls the API.

By accessing or using our API, you accept the terms of this privacy policy.

Who is responsible for the data

Understanding who controls which data matters, because the API is a channel through which two different kinds of data flow.

  • Data about your use of the API. For the account data, the API token, and the technical logs generated when you call the API (described below), Vzla.io is the data controller. This policy governs that data.
  • Data you send through the API. If the requests you make to the API contain personal data about your own users or third parties (for example, records you create, query, or update through our endpoints), you are the controller of that data and Vzla.io acts as a processor that handles it on your instructions. Your responsibilities for that data are described under “Your responsibilities as a developer”.

Data we collect

Data collected automatically

Every request to the API is logged so that we can operate, secure, and support the service. For each request we may record:

  • The IP address the request originates from.
  • Request metadata: the timestamp, HTTP method, the endpoint (path) called, the response status code, response time, and the approximate size of the request and response.
  • The client user agent or library identifier sent with the request.
  • The API token identifier used to authenticate the request. We log a token identifier, not the secret value of the token (see “The API token as an identifier”).
  • Usage and rate-limit counters: the number of requests made, the endpoints used, and counters we maintain to enforce rate limits and detect abuse.

These records are technical logs. Because an IP address and a token identifier can be associated with a person, we treat these logs as personal data and protect them accordingly.

Data you provide

When you register for API access or manage your integration, you may provide:

  • Contact details associated with your account (such as your name and email address).
  • The configuration of your access, including token names, scopes, and permissions.

Data that passes through the API

The content of the requests and responses you exchange with the API is determined by you. If that content includes personal data, we process it only to deliver the API response and to operate the service, on your instructions, as described under “Your responsibilities as a developer”.

The API token as an identifier

Your API token authenticates your requests and identifies your integration. We store a secure representation of the token (for example a hash) and a token identifier that lets us attribute requests to your account for authentication, rate limiting, billing, abuse prevention, and support. Because the token identifier can be linked to your account, it is personal data.

You are responsible for keeping your token secret. Anyone who holds your token can act as you against the API. If a token is exposed, you should revoke it and issue a new one immediately, and notify us so we can help investigate.

How we use data and our lawful bases

We use the data described above only to run the API, and each use rests on a GDPR lawful basis:

  • To provide the API you requested — authenticate requests, route them, return responses, and manage your account and tokens. Lawful basis: performance of a contract.
  • To secure the API and prevent abuse — detect and mitigate unauthorized access, fraud, denial-of-service, and other misuse; enforce rate limits and usage quotas. Lawful basis: our legitimate interest in keeping the service secure and available.
  • To maintain and improve reliability — monitor performance, diagnose errors, and optimize response times. Lawful basis: our legitimate interest in operating a reliable service.
  • To provide technical support — investigate and resolve issues you report about access or usage. Lawful basis: performance of a contract and our legitimate interest in supporting users.
  • To comply with the law — meet legal, accounting, and regulatory obligations, and respond to lawful requests from authorities. Lawful basis: compliance with a legal obligation.

We do not use API data for advertising, we do not sell it, and we do not use it for any purpose unrelated to operating the API.

Analytics

For our public website we use Umami, a cookieless, privacy-focused analytics tool that does not collect personal data and sets no advertising cookies. Programmatic calls to the API are not part of that website analytics; API usage is measured only through the operational logs and counters described above.

Data retention

We keep data only as long as it serves the purpose it was collected for:

  • Technical and rate-limit logs are retained for a limited period sufficient for security monitoring, abuse investigation, and troubleshooting, and are then deleted or aggregated into non-identifying statistics.
  • Account and token data are kept for as long as your API access is active, and for a limited period afterward where we need to meet legal, accounting, or security obligations.
  • Data passing through the API is retained according to the product’s data model and your instructions as controller; when you delete records or close your integration, we delete or return that data as agreed, subject to any legal retention requirement.

Data sharing

We do not sell the data we collect, and we do not share it with third parties for their own purposes. We disclose data only in these cases:

  • Service providers (sub-processors). We use a small number of infrastructure and hosting providers to run the API. They process data solely on our behalf, under contractual confidentiality and data-protection obligations, and only to the extent needed to provide their service.
  • Legal compliance. Where required by law or in response to a valid request from a competent authority.
  • Security and abuse prevention. To investigate and mitigate fraud, unauthorized access, or misuse of the API.

Security

We apply technical and organizational measures appropriate to the risk, including:

  • Encryption in transit. All communication with the API is protected with HTTPS/TLS.
  • Restricted access. Only authorized Vzla.io personnel can access API logs and account data, on a need-to-know basis.
  • Token protection. Token secrets are stored using a secure, non-reversible representation, and tokens can be revoked at any time.

No system is perfectly secure, and we cannot guarantee absolute security, but we work to protect your data and to detect and respond to incidents.

Your responsibilities as a developer

When you send personal data about your own users or third parties through the API, you are the controller of that data and Vzla.io is your processor. In that role you must:

  • Have a valid lawful basis under the GDPR for the data you send through the API, and provide the required privacy information to the people whose data it is.
  • Only send data that is necessary for your integration; do not transmit special-category data through the API unless it is genuinely required and lawful.
  • Protect your API credentials, keep your token secret, and never share it with unauthorized parties.
  • Implement appropriate security measures in your own systems and integration to prevent unauthorized access.
  • Comply with the usage limits and terms set out in the API terms and conditions.
  • Notify us promptly of any security incident or suspected misuse involving the API or your credentials.

As your processor, we act only on your documented instructions (the API calls you make and your account configuration), assist you with data-subject requests and security obligations where the data is under our control, and do not use the data you send for our own purposes. Vzla.io is not responsible for how third parties use the API, nor for security failures in the applications that integrate it.

International data transfers

Vzla.io is operated from the United States, so data processed through the API — including logs and account data — may be transferred to and stored in the United States. Where we transfer personal data from the European Union, we rely on appropriate safeguards recognized under the GDPR, such as the European Commission’s Standard Contractual Clauses, together with additional technical measures like encryption in transit. By choosing to comply with the GDPR, we apply its protections to your data regardless of where it is processed.

Your data protection rights

Subject to the GDPR, you have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to its processing, and to request that it be transferred to another organization (data portability). Where our processing relies on consent, you may withdraw it at any time.

To exercise any of these rights over data for which Vzla.io is the controller, contact us at privacy@vzla.io. We respond to requests within the time limits set by the GDPR (normally within one month). If your request concerns personal data that another developer sends through the API, that developer is the controller and you should direct your request to them; we will assist them as their processor.

Complaint to a supervisory authority

If you believe we have not handled your personal data or your request properly, you have the right to lodge a complaint with a data protection supervisory authority in the European Union member state where you live, work, or where the issue arose. We would appreciate the chance to address your concern first, so we encourage you to contact us at privacy@vzla.io before doing so.

Changes to this privacy policy

We may update this privacy policy from time to time. Changes take effect once published on our website, and the “updated” date above reflects the latest revision. We recommend reviewing this page periodically to stay informed.

Contact

If you have questions about this privacy policy or about how we handle data in the API, contact us at privacy@vzla.io. For general support with your integration, you can reach us at support@vzla.io.

By using our API, you confirm that you have read and accepted this privacy policy.