Privacy

Privacy Policy

How Coldvio collects, uses and protects your data. Last updated: August 17, 2026.

1. Who we are

Coldvio is a LinkedIn content and outreach platform operated by Taktflow ApS, CVR no. 46667832, registered at Tinbergens Alle 123, 9260 Gistrup, Denmark. Coldvio ApS is a registered secondary name of Taktflow ApS.

We are the data controller for personal data you provide directly to us. Where you use our leads and enrichment features, you act as data controller for contact data you upload or enrich — and Coldvio acts as your data processor for that data.

2. Data we collect

  • Account dataEmail address, name, and password (hashed) when you sign up.
  • Voice profileText samples, interview answers, and writing preferences you provide to train your voice profile.
  • LinkedIn usage dataProfile and professional information, post and comment context, message content, post drafts, scheduled content, campaign configurations, and engagement metrics used by the LinkedIn features you choose.
  • Email drafting dataSubject lines and active email-thread context sent when you request a Gmail or Outlook draft. Coldvio does not collect your email-account password.
  • Usage dataFeature usage, credit consumption, session logs, and error data used to operate and improve the service.
  • Payment dataWhen billing is activated, payments are processed by Stripe. We store subscription and credit records, but Coldvio does not store full card numbers.
  • Lead dataContact data you upload or enrich via the leads feature. You are the data controller for this data; Coldvio processes it on your behalf as a data processor.

3. How we use your data and our legal basis

We process your personal data only for specific purposes and under a lawful basis under Article 6 of the GDPR.

  • Service deliveryTo provide, maintain and improve Coldvio — including authentication, billing, and feature access. Legal basis: performance of contract (Art. 6(1)(b)).
  • AI content generationTo generate content, replies, and outreach in your voice using your voice profile. Legal basis: performance of contract (Art. 6(1)(b)).
  • LinkedIn actionsTo prepare drafts and execute connection requests or messages you explicitly approve. Content publishing uses a clipboard handoff to LinkedIn; provider-based automatic publishing remains disabled in this release. Legal basis: performance of contract (Art. 6(1)(b)).
  • PaymentsTo process subscriptions and credit top-ups. Legal basis: performance of contract and legal obligation (Art. 6(1)(b) and (c)).
  • Transactional emailTo send receipts, password resets, and service updates. Legal basis: performance of contract (Art. 6(1)(b)).
  • Service improvement and securityTo analyse usage patterns, diagnose errors, and prevent abuse. Legal basis: legitimate interests (Art. 6(1)(f)) — our interest in operating a reliable and secure service.
  • Analytics cookies (active by default)PostHog product analytics and privacy-masked session replay are active by default to understand how the product is used and diagnose friction. Replay masks all page text and form inputs and excludes console logs and network bodies. You can reject analytics immediately or withdraw consent at any time via cookie settings.
  • No sellingWe do not sell your data to third parties.
  • No model trainingWe do not use your voice profile, drafts, or content to train public AI models.

4. International data transfers

Coldvio uses Supabase for account, voice, and usage data in its documented Ireland production region. Contractual and account evidence is retained.

Product usage events and privacy-masked session replays are processed in PostHog EU Cloud in Frankfurt, Germany, and are active by default unless you reject analytics. An executed account DPA and region evidence are retained.

When you use content generation or AI features, relevant request content is sent through Coldvio's Railway-hosted LiteLLM proxy to an approved model provider. Anthropic is the release provider. Google Gemini integrations remain disabled in both application runtime and release proxy configuration until paid-service processor evidence is retained.

Railway and Sentry production processing has documented EU-region evidence. Vercel uses global infrastructure. Rate limiting and short-lived cache data use Railway-hosted Redis, reachable only on the Railway private network and covered by the Railway entry below. Stripe and People Data Labs are US-based services.

Before a commercial feature transfers personal data outside the EU, Coldvio must verify and document a valid transfer mechanism for each provider. That may be an adequacy decision or executed Standard Contractual Clauses (SCCs) under Article 46(2)(c) GDPR with any required transfer assessment. A feature must remain disabled where that verification is pending.

A full list of sub-processors is provided in Section 5.

5. Service providers and other recipients

The following services may process personal data depending on the features you use. Provider-specific agreements and transfer safeguards must be verified before the corresponding commercial data processing is enabled.

  • SupabaseDatabase and authentication. The production organization, DPA evidence and Ireland region are documented. supabase.com
  • RailwayBackend application and self-hosted LiteLLM proxy. An executed DPA and EU production-region evidence are retained. railway.com
  • VercelFrontend application and global edge infrastructure. The Taktflow ApS account is on a DPA-covered Pro plan; no EU-only infrastructure claim is made. vercel.com
  • AnthropicLLM inference. Its commercial DPA and SCCs apply to the documented Taktflow ApS production organization; the current 30-day provider retention is documented. anthropic.com
  • Google Gemini APIOptional LLM inference. Disabled in application runtime and release proxy configuration; commercial EEA use would require a paid Cloud-billing-backed service covered by Google's processor terms and retained account evidence. ai.google.dev
  • ResendTransactional email. The provider DPA and Taktflow ApS account evidence are retained. resend.com
  • SentryError and performance monitoring with application-level PII scrubbing. An executed DPA and EU-region evidence are retained. sentry.io
  • NangoOAuth credential storage and proxying for customer-selected CRM integrations. Its cloud DPA applies automatically, and the account is bound to Taktflow ApS. nango.dev
  • ZernioLinkedIn publishing and analytics. Commercial processing remains disabled until DPA execution and jurisdiction evidence are retained. zernio.com
  • People Data LabsOptional contact enrichment is disabled. People Data Labs receives no production data unless its processing roles, DPA and transfer safeguards are agreed in writing before a future activation. peopledatalabs.com
  • ApifyOptional public LinkedIn and trend ingestion. Commercial processing remains disabled until a written DPA and source-specific lawful-basis review are retained. apify.com
  • RedditOptional trend source. Coldvio sends only an inferred subreddit selection, not raw voice-rule text; access remains disabled until the corporate developer account, current Developer/Data API terms, controller-role assessment and transfer safeguards are approved. reddit.com
  • Hacker News search via AlgoliaOptional trend fallback. Search phrases may be derived from expertise or identity voice rules. Access remains disabled until data minimisation, Algolia contractual coverage, role allocation and transfer safeguards are approved. hn.algolia.com
  • StripePayment processing, when billing is activated. Stripe's DPA forms part of its services agreement. stripe.com
  • Google Tag ManagerOptional analytics and marketing tags. It loads only after a recorded cookie choice and only when configured. tagmanager.google.com
  • PostHogEU Cloud (Frankfurt, Germany) product analytics and privacy-masked session replay, active by default unless you reject analytics. An executed Taktflow ApS account DPA and region evidence are retained. posthog.com

6. LinkedIn data

Coldvio uses a clipboard handoff for content drafts and the Chrome extension for the LinkedIn page and outreach actions you explicitly choose. Provider-based automatic publishing remains disabled in this release.

We access only what is needed to perform the specific actions you request. We do not store your LinkedIn password; the extension works with the LinkedIn session already signed in to your browser.

7. Chrome extension

The Coldvio Chrome extension reads the supported LinkedIn or Gmail page you are viewing when needed to provide a feature you request, including draft generation, CRM save and sync, campaign execution, and reply detection.

CRM contacts, notes and message history can be stored persistently in the extension's local IndexedDB database. Authentication state, user settings and sync state are stored in Chrome local storage. Local data remains until you delete it, clear the extension's data, or uninstall the extension.

When you are signed in, CRM contacts and message history are synchronised to Coldvio over HTTPS. Page or conversation context needed for draft generation is sent to the Coldvio API and may then be processed by the approved service providers listed in Section 5. The extension does not send data directly to an LLM provider.

The extension does not collect or store your LinkedIn, Google or Microsoft password.

8. Data retention

Account data, voice profiles, and content history are retained for as long as your account is active. When you delete your account, personal data is deleted within 30 days.

Lead, CRM and synchronised message data can be deleted from the product or through an account-deletion request. Locally stored extension data can be deleted from the extension or by clearing/uninstalling it.

Payment records are retained for the period required by applicable accounting and tax law (7 years in Denmark).

PostHog privacy-masked session replays are retained for up to 30 days.

9. Your rights under GDPR

As a data subject under GDPR, you have the following rights:

  • Access (Art. 15)Request a copy of the personal data we hold about you.
  • Rectification (Art. 16)Correct inaccurate or incomplete personal data.
  • Erasure (Art. 17)Request deletion of your personal data, subject to legal retention obligations.
  • Restriction (Art. 18)Request that we limit the processing of your data in certain circumstances.
  • Data portability (Art. 20)Receive your data in a structured, machine-readable format.
  • Objection (Art. 21)Object to processing based on legitimate interests.
  • Withdraw consentWhere processing is based on consent (e.g. analytics cookies), withdraw it at any time without affecting prior processing.

10. Right to lodge a complaint

If you believe we are processing your personal data in breach of GDPR, you have the right to lodge a complaint with the Danish Data Protection Authority:

Datatilsynet · Carl Jacobsens Vej 35 · 2500 Valby · Denmark · [email protected] · datatilsynet.dk

You may also contact the data protection authority in your country of residence.

11. Security

Data is encrypted in transit (TLS) and at rest where supported by our infrastructure providers. Access to production systems and databases is restricted to authorised personnel.

12. Changes to this policy

We may update this policy. Material changes will be communicated to account holders by email before taking effect.

13. Contact

Questions, requests, or to exercise your rights: [email protected]
Taktflow ApS (registered secondary name: Coldvio ApS)
CVR no. 46667832
Tinbergens Alle 123
9260 Gistrup, Denmark

Terms of ServiceData Processing AgreementBack to Coldvio