Legal

Privacy Policy

Last updated: July 23, 2026

Before the legal language, the honest summary: Vogata turns goals, evidence, and 1:1s into measurable growth. To make that work we process some of your data, and here we tell you exactly what, why, and what you can do about it. It's written to be understood, not to hide anything.

Three things you can consider settled from the start: what's yours is not for sale, it doesn't feed anyone else's AI models, and your private notes are read by no one else, not even your organization's administrator.

Who is responsible for your data

Vogata is a B2B product, so who answers for your data depends on which data it is.

When an organization hires Vogata to manage its teams, that organization is the controller of the work content: the goals, the evidence, the 1:1 notes, and the evaluations of its people. It decides what goes in and why. Vogata acts as a processor (encargado de tratamiento): we process that data on the organization's behalf and following its instructions, never for our own purposes.

For your account data (name, email, credentials) and the website's data, Vogata is the controller.

Vogata is operated by Cristian Andrés Olivares Vásquez E.I.R.L. (RUT 76.709.713-1), with registered address at Av. Apoquindo 5559, Las Condes, Santiago, Chile. For any privacy question, write to us at [email protected].

What data we process

Always, for using the app

  • Identification: your name, work email, and role within the organization.
  • Credentials: your password, always stored hashed, never in plain text.
  • Work content: the goals you set, the evidence you record, and the evaluations. This is the heart of the product, and we treat it as sensitive.
  • Technical data: IP address and user-agent, kept in the consent and audit records so we can prove who authorized what and when.

Only if you turn the feature on (opt-in)

Each optional feature processes data only when you turn it on. If you don't turn it on, that data isn't processed.

  • 1:1 notes and agendas: only if you write or generate them.
  • Voice and its transcription: only if you turn on the Notetaker, and only with both participants' consent (see the next section).
  • Google Calendar: only if you connect your account. We request the calendar.events permission only: with it we manage the 1:1 events Vogata creates (schedule, sync, cancel) and store your token encrypted. We cannot read the rest of your calendar.
  • Outlook calendar (Microsoft): only if you connect your account. We manage the 1:1 events Vogata creates and store your token encrypted. One connected calendar at a time: connecting one disconnects the other.

The Notetaker

The Notetaker is an optional bot that can join a 1:1 on Google Meet or Microsoft Teams to take notes for you. It's off by default and runs under strict rules:

  • Dual consent. The bot only joins if the manager and the report both say yes. Without both yeses, it doesn't join. You can withdraw your authorization up to the start of the meeting, with no consequences.
  • Evidentiary record. Each consent is kept in an append-only record with IP, user-agent, date, and the version of this policy.
  • Local transcription. The bot records audio only (never video) and processes it locally, inside the same ephemeral container. The audio never reaches an external provider.
  • The audio is discarded. When the meeting ends, the audio is deleted. It is not stored.
  • Only the text goes to the AI. Only the text transcript passes through an AI model, and only to generate the meeting summary and record the agreed commitments.
  • It doesn't evaluate. Vogata does not rate performance, attitude, emotional tone, or individual productivity. The Notetaker only summarizes agreements and commitments.
  • Saying no leaves no trace. If you don't authorize transcription, the meeting continues normally in agenda and manual commitments mode, and your decision is not shown as an individual rejection.

What we use your data for

Every processing activity has a basis that makes it lawful:

  • Performance of the contract: creating and operating your account, managing plans, goals, and evidence, providing the service.
  • Consent: the opt-in features (Notetaker, calendar connection with Google or Outlook). We ask beforehand, it's specific, and you can withdraw it whenever you want.
  • Legitimate interest: security, fraud prevention, and product improvement, always balanced against your rights.
  • Legal obligation: when the law requires us to keep or hand over certain information.

These bases are the ones recognized in articles 4 and following of Law 19.628 and article 13 of Law 21.719. We don't make automated decisions with significant legal effects about you: the AI assists, it never decides about your employment.

How long we keep it

We keep each piece of data only as long as needed, with concrete periods:

  • Notetaker transcripts and summaries: deleted automatically after 90 days by default. Your organization can adjust that window between 30 and 180 days, you can shorten it further for your own meetings, and you can always delete them earlier, whenever you want.
  • If you leave your organization: your record there (plans, evidence, 1:1s) is kept for the window your organization configures, between 6 and 36 months (24 by default), and is then permanently deleted.
  • Closed-cycle evaluations: your organization can additionally configure them to be deleted 6, 12, or 24 months after each cycle closes.
  • Account data: up to 12 months after the account is closed, then deleted or anonymized.
  • Consent and audit records: 24 months, because they are the proof of who authorized what.

Who we share your data with

No data is sold or handed over for purposes unrelated to the service. This is the full list of providers involved in processing (sub-processors): who they are, what we use them for, and where they operate:

ProviderPurposeCountry
Amazon Web Services (AWS)Infrastructure, compute, and database (region us-east-2, Ohio)USA
CloudflareCDN and site protectionUSA
Anthropic PBCAI inference (Claude)USA
Google LLCAI inference (Gemini, paid API); Google Calendar and Meet only if you connect your account; Notetaker infrastructureUSA
Microsoft CorporationMicrosoft sign-in and Outlook/Teams calendar only if you connect your account; AI inference (Azure OpenAI)USA
xAIAI inference (Grok)USA
PayPalSubscription payment processing (PayPal handles your payment data under its own policy)USA

All operate under contract with a commitment not to use your data to train their models. We never sell data to third parties. The detail of each provider's safeguards, with their data processing agreements (DPAs) one click away, lives at vogata.app/en/dpa.

International transfers

Your data is hosted and processed in the United States, where our providers operate. When a piece of data leaves Chile, we require each provider to apply contractual safeguards equivalent to what Chilean regulation demands, so that your protection travels with the data.

Your rights

Over your personal data you can exercise the rights of:

  • Access: know what data we hold about you.
  • Rectification: correct what's wrong or out of date.
  • Erasure: delete your data.
  • Objection: object to certain processing.
  • Portability: take your data in a reusable format.
  • Blocking: suspend the processing of a piece of data.
  • Withdraw consent for any opt-in feature, whenever you want.
  • Not be subject to automated decisions with significant legal effects.

You exercise several of these rights directly in the app, without asking anyone: in Settings → Privacy and data you can download your data and delete your recordings whenever you want.

For the rest, write to [email protected]. We respond within 15 days (extendable as the law allows). If your data sits inside the space of an organization that hired you, we may route your request to it and help both sides. And if you believe we're not respecting your rights, you can complain to the Personal Data Protection Agency, once it is operational under Law 21.719.

Security

We encrypt data in transit and at rest, isolate each organization's content, and store private 1:1 notes in their author's partition, where no one else sees them. We restrict internal access to strictly what's necessary. No system is perfect, but we design with this in mind; if a breach ever affects your data, we'd notify you and the relevant authorities as the law requires.

See Security and architecture

Cookies

We keep cookies to a minimum: the ones needed to keep you signed in, and Google Analytics on the marketing site (vogata.app) to understand usage in aggregate. We don't run third-party advertising trackers, and we don't follow you around the web.

Children

Vogata is a B2B workplace tool. It isn't directed at minors, and we don't knowingly collect their data.

Changes to this policy

We may update this policy as the product and the law evolve. If the change is material, we'll update the date at the top and let you know with reasonable notice, by email or in the app, before it takes effect.

Contact

Questions or requests about your data? Write to [email protected] and a real person will answer.