Bezpieczeństwo i lokalizacja danych
Obowiązuje od 16 listopada 2026
This page summarises where Virbe sp. z o.o. ("Virbe") stores and processes customer data, how we protect it, and how customers can export their data and switch providers. It provides the information required by Articles 26 and 28 of Regulation (EU) 2023/2854 (the "Data Act"). The binding commitments are in the Terms of Service (https://virbe.ai/terms) and the Data Processing Agreement (https://virbe.ai/dpa).
1. Company and jurisdiction
Virbe is a limited liability company established in Lublin, Poland, and is subject to the law of Poland and the European Union. Virbe has no establishment outside the European Union.
2. Where your data is stored
2.1. Virbe-Hosted. The Virbe Hub and customer data (conversations, knowledge base, configuration, analytics and backups) are hosted by OVHcloud (OVH SAS, France) in data centres located in the European Union. When additional hosting regions become available, customers choose the region at set-up; data stays in the selected region and is moved to another region only with the customer's agreement (see Section 8 of the DPA).
2.2. Customer-Hosted. Customers can deploy the platform in their own Microsoft Azure subscription through Azure Marketplace. Data then stays in the Azure region chosen by the customer, in infrastructure controlled by the customer. Virbe has no standing access and connects only at the customer's request.
2.3. AI and speech providers. Depending on the configuration, conversation content is sent to AI model and speech providers chosen by the customer, or provided by Virbe. Their locations and transfer safeguards are listed on the Sub-processors page (https://virbe.ai/legal/subprocessors). Customers who require processing in the EU can choose providers and deployments that offer EU data residency (for example Azure OpenAI in EU regions).
3. Safeguards against unlawful governmental access (Data Act, Article 28)
3.1. Virbe-Hosted services are hosted by OVH SAS, an EU company, in data centres in the European Union. Virbe itself is subject to EU and Polish law. Some sub-processors listed at https://virbe.ai/legal/subprocessors (for example providers of e-mail delivery, authentication or AI engines) are subject to the law of the United States, including laws that may compel the disclosure of data; Sections 3.2 and 3.3 below and Section 9 of the DPA apply to them, and customers can avoid AI engines subject to US law by choosing their own providers and deployments.
3.2. Virbe will not give a public authority of a third country access to, or transfer, non-personal customer data held in the European Union where such access or transfer would conflict with Union law or Polish law, unless it is based on an international agreement (such as a mutual legal assistance treaty) or the conditions of Article 32 of the Data Act are met.
3.3. If Virbe receives a request from any public authority for customer data, it reviews its legality, challenges it where there are grounds to consider it unlawful, discloses only the minimum data necessary and informs the customer before complying, unless this is prohibited by law. The same principles apply to personal data under Section 9 of the DPA.
3.4. Technical and organisational measures that protect customer data from unauthorised access, including encryption in transit and at rest, strict access control and logging, are described in Annex II of the DPA.
4. Security overview
- Information security management. We are implementing an information security management system based on ISO/IEC 27001 and will publish the certificate here once obtained.
- Testing. Independent penetration tests are performed at least annually; summaries are available to customers under a confidentiality agreement.
- Access control. Least-privilege access with multi-factor authentication for Virbe personnel; role-based access for customer users; credentials for AI providers are obfuscated in the Dashboard.
- Data minimisation. No training of AI models on customer data; optional detection and removal of personal data from conversations; configurable retention and automatic clean-up; on-device processing of kiosk camera images.
- Incidents. Personal data breaches are notified to customers within 48 hours of Virbe becoming aware of them (see Section 10 of the DPA).
- Vulnerability disclosure. Report security vulnerabilities in the Virbe platform, the Widget or the Kiosk Application to [email protected]. We acknowledge reports within 3 business days, keep reporters informed and do not take legal action against good-faith research that respects customers' data and does not disrupt the services. We handle vulnerabilities and incidents affecting our software products in accordance with Regulation (EU) 2024/2847 (Cyber Resilience Act).
5. Exporting data and switching providers (Data Act, Article 26)
5.1. What you can export. Conversation transcripts and metadata, knowledge base content, configurations of assistants (flows, prompts, instructions, settings), analytics reports, custom assets and user data, as listed in Annex B of the Terms of Service.
5.2. Formats and interfaces. Data is exported in open, machine-readable formats: JSON and CSV for structured data, Markdown or the original file formats for documents and assets. Export is available through the Dashboard and the documented APIs; the data structures and formats of exports are described in the Documentation (https://docs.virbe.ai), which serves as the online register of data structures and formats. Virbe assists with exports that these tools do not cover.
5.3. Procedure. Request switching or a full export at [email protected], with a notice period of up to 2 months. The transitional period lasts up to 30 days, during which the service continues and Virbe provides reasonable assistance; you then have at least 30 days to retrieve your data, after which it is erased. Virbe does not charge for switching or data export.
5.4. Known limitations. Assistants built with Virbe use Virbe-specific flow and configuration formats; they can be exported but cannot be run directly on another platform without adaptation. Vector embeddings and internal indices are not exported, but they can be regenerated from the exported knowledge base content. Stock avatars, voices and other Virbe content are licensed only for use within the Virbe platform. Conversation audio is exportable only where audio storage was enabled.
5.5. Customer-Hosted deployments. Customers have direct access to their data in their own Azure subscription and can export it at any time with Azure tools.
6. Contacts
Security: [email protected] · Data protection: [email protected] · Legal and authorities: [email protected] · Support: [email protected]