Legal
Privacy policy
Effective 23 August 2026
Who controls your data
VyrexCode is the controller for enquiries, sales and account administration. For client website analytics and campaign data, VyrexCode acts as a processor on the client's documented instructions.
Operational and product analytics
Where enabled, Better Stack receives privacy-scrubbed application errors and service health signals. PostHog measures selected product actions inside authenticated workspaces using pseudonymous account identifiers; browser persistence, automatic page capture and session recording are disabled. PageSpeed Insights receives only the public page URL required to run a Lighthouse audit.
What we collect
We process contact and account details, support and sales correspondence, transaction references, campaign performance data, website SEO elements, service logs, security records, client-supplied brand assets and reports voluntarily attached to website audit requests. For phone-farm and cloud-device services, this may include order, approval, device inventory, access-window, session-status, connection, reset and security-event metadata. The Vyrex Tag is designed not to collect visitor names, email addresses, form values, cookies or persistent identifiers.
Device sessions and customer content
Operational device logs are designed to exclude screens, keystrokes and customer content. Customer test accounts, apps or files may still be present on an assigned device during an approved session. Customers are responsible for using suitable test accounts, limiting the personal data they enter, signing out and removing customer-controlled data when the session ends. Devices may be reset or sanitised as described in the accepted quote, order and Terms of Service.
Why we process it
We use data to provide contracted services, secure accounts, process payments, respond to enquiries, measure service performance, meet legal obligations and pursue legitimate interests in operating and improving the platform. Marketing messages are sent only where permitted and can be declined.
Sharing and international transfers
We use vetted service providers listed in our subprocessor register. Where data leaves the UK, we rely on an applicable adequacy decision or contractual safeguards.
Retention
Enquiries and files voluntarily attached to them are retained for up to 24 months; account, campaign and routine device-session records for the contract plus 90 days unless the accepted quote or order specifies a shorter period; security logs for 12 months; and financial records for the legally required period. Customer data left on a device is removed through the agreed session close or device sanitisation process rather than retained as an archive. Backups expire on their normal rotation. A security investigation, dispute or legal hold may extend relevant periods.
Your rights
You can request access, correction, deletion, restriction, portability or object to processing. You may complain to the UK Information Commissioner's Office. Send requests to privacyvyrexcode.com; identity verification may be required.
Security and deletion
We use access controls, encryption, audit logs, least-privilege database credentials and protected backups. Client offboarding disables access and integrations immediately, schedules deletion according to the contract and retention schedule, and includes device reset or sanitisation where device services were supplied.