Legal

Privacy Policy

This policy explains how Vasthelm handles personal and business information when you visit vasthelm.com, use the client portal, or engage us for managed IT services. Last updated August 12, 2026.

This page is informational and is not a substitute for advice from your own counsel. Engagement-specific data processing may also be covered in your statement of work or data processing addendum.

1. Who we are

Vasthelm operates vasthelm.com and related managed IT services. Privacy questions: hello@vasthelm.com.

2. Information we collect

Website and contact. Name, email, company, and message content you send us (for example via hello@vasthelm.com), plus standard server and analytics logs such as IP address, browser type, and pages visited.

Client portal accounts. Account identifiers, authentication data, and profile details needed to sign in and manage your engagement. Authentication may be handled by Clerk or a successor provider.

Billing. Billing contact, payment method metadata, and invoice history. Card and bank details are processed by Stripe (or another processor we name); we do not store full card numbers on our servers.

Service delivery. Technical and operational data needed to deliver managed IT — for example inventory of systems in scope, credentials you entrust to us, ticket or request history, monitoring alerts, and configuration notes for systems we operate on your behalf (password vault, documentation, monitoring, and related service components).

3. How we use information

  • Respond to inquiries and scope engagements
  • Provide, secure, and improve the portal and services
  • Process payments and maintain billing records
  • Operate and support client environments under your agreement
  • Send service-related notices (security, outages, invoices)
  • Comply with law and enforce our terms

We do not sell personal information. We do not use client operational data for advertising.

4. Processors and subprocessors

We use trusted providers to run parts of the product, including:

  • Clerk — authentication and session management for the client portal
  • Stripe — payment processing and billing
  • PostHog — product analytics (pageviews and related usage events) for the website and portal
  • TechOnSite — field-service / on-site technician dispatch when we arrange physical site visits for you
  • Hosting, email, and infrastructure providers needed to run the site and deliver services

Tools we operate for you (for example password vault, documentation, or monitoring platforms) process data according to your engagement and the configuration we agree with you. Those systems may hold credentials, documents, or telemetry that belong to your organization.

5. Sharing

We share information with processors who act on our instructions, with your authorized contacts, when required by law or to protect rights and safety, or in connection with a business transfer. We do not share client environment data with unrelated third parties for their own marketing.

6. Retention

We keep information as long as needed for the purposes above — typically for the life of the engagement plus a reasonable period for invoices, security logs, and legal obligations. On request at the end of an engagement, we will discuss deletion or return of client-controlled data as scoped in your agreement, subject to backup and legal retention needs.

7. Security

We use administrative, technical, and physical safeguards appropriate to a managed IT practice, including access controls, encryption in transit where supported, and least-privilege handling of client credentials. No method of transmission or storage is perfectly secure; please report suspected incidents to hello@vasthelm.com.

8. Cookies and similar

The site and portal may use cookies or local storage for sessions, authentication (including via Clerk), and basic analytics or preference settings. You can control cookies through your browser; disabling some cookies may affect portal sign-in.

9. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, or export personal information, or to object to certain processing. Contact us to make a request. We will verify your identity and respond as required by applicable law. Portal account holders can often update profile details through their account provider (for example Clerk).

If you signed in with Facebook Login, see Facebook data deletion for how to remove associated account data, including when you remove the Vasthelm app from Facebook.

10. Children

Our services are directed to businesses and adults. We do not knowingly collect personal information from children under 16.

11. International transfers

We and our processors may process data in the United States or other countries where we or they operate. If you are located elsewhere, you understand that your information may be transferred to those locations subject to appropriate safeguards where required.

12. Changes

We may update this policy by posting a revised version with a new “last updated” date. Material changes affecting client engagements will be communicated as appropriate under your agreement.

13. Contact

Privacy requests: hello@vasthelm.com. Related: Terms of Service.