Vesti Technology Solutions Inc.

Privacy Policy

Last updated 31 July 2026

This policy is maintained by Vesti Technology Solutions Inc. (“Vesti”, “we”, “us”) and explains what personal data we collect through wevesti.com and the Vesti application, why we collect it, who we share it with, how long we keep it, and the rights you can exercise over it.

Not legal advice. Vesti is a legal technology and global-mobility platform, not a law firm. Documents drafted with Zyra, assessments, and any guidance in the product are informational templates and do not constitute legal advice. Using Vesti does not create an attorney–client relationship, and no communication with Vesti or Zyra is protected by attorney–client privilege. Where you need advice on your specific matter, we can connect you with an independent licensed attorney; that engagement is between you and that attorney.

1. Who is responsible for your data

Vesti Technology Solutions Inc. is the data controller for the personal data described in this policy. For data protection questions, requests, or complaints, contact us at privacy@wevesti.com.

2. Data we collect

  • Account data — name, email address, phone number, password credentials (hashed by our authentication provider), country and address where you supply them.
  • Assessment data — the answers you give in the eligibility wizard, résumé or LinkedIn exports you upload, education and work history, awards, publications, and the pathway scores we derive.
  • Matter and document data — the intake answers, drafted letters, company-formation details, and files you generate or upload in the Document Studio.
  • Payment data — billing name, email, transaction amount, currency, and payment status. We do not receive or store full card numbers, CVVs, or bank credentials; card data is captured directly by our PCI DSS Level 1 payment processor.
  • Technical data — IP address, device and browser type, pages viewed, and timestamps, collected through server and security logs.

We do not knowingly collect data from children under 16, and we ask you not to upload special-category data (health, biometric, religious, or political information) unless a specific matter requires it.

3. Why we use it, and our lawful basis

  • To provide the service — creating your account, running assessments, generating documents, and processing payments. Lawful basis: performance of a contract.
  • To improve and secure the platform — debugging, fraud prevention, abuse and rate-limit enforcement, and aggregate product analytics. Lawful basis: legitimate interests.
  • To send service and marketing email — transactional notices rely on contract; marketing email relies on your consent, withdrawable at any time via the unsubscribe link.
  • To meet legal and financial obligations — tax, accounting, audit, and lawful requests. Lawful basis: legal obligation.

AI processing. Assessment and drafting features send the content you provide to our AI model providers to generate output. That content is processed under contract to serve your request. We do not sell your data, and we do not use your matter content to train third-party foundation models.

4. Who we share data with

We share personal data only with vendors that process it on our instructions under written data processing agreements: cloud hosting and database providers, our authentication provider, our email delivery provider, our AI model providers, our payment processor, and — where you ask to be introduced — the independent attorney or expert you choose. We also disclose data where required by law or to defend legal claims. We do not sell personal data and do not share it for cross-context behavioural advertising.

5. International transfers

Vesti operates across the United States, Nigeria, the United Kingdom, the EU, and Canada, so your data may be processed outside your country of residence. Where data leaves the EEA, the UK, or Nigeria, we rely on appropriate safeguards — Standard Contractual Clauses (and the UK Addendum where relevant), adequacy decisions where they apply, and the transfer conditions of the Nigeria Data Protection Act. A copy of the relevant safeguard is available on request.

6. How long we keep data

  • Account and profile data — for as long as your account is active.
  • Documents, matters, and assessments — while your account is active, then deleted within 90 days of account closure or a verified deletion request.
  • Assessment and lead records for closed accounts — deleted or irreversibly anonymised within 24 months of your last activity.
  • Payment and invoice records — retained for 7 years to meet tax, accounting, and audit obligations, even after account closure.
  • Security and access logs — retained for 12 months.

Backups are cycled out on a rolling schedule, so deleted data may persist in encrypted backups for up to 35 days.

7. Security and compliance

We encrypt data in transit (TLS 1.2+) and at rest, enforce row-level access controls so users can only reach their own records, require authentication for all account data, apply least-privilege access for staff, and rate-limit sensitive operations. Vesti maintains a SOC 1 report covering controls over its financial and transaction-processing systems, and maintains PCI DSS compliance for the payment flows in scope for Vesti; cardholder data is captured and stored by our PCI DSS Level 1 processor rather than by Vesti. Current reports and our Attestation of Compliance are available to customers on request under NDA at legal@wevesti.com.

No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the relevant supervisory authority within the timeframes required by applicable law (including within 72 hours under the GDPR and as required by the NDPA).

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or object to our processing of your data, to receive a portable copy, and to withdraw consent.

  • EU / UK (GDPR, UK GDPR) — the rights above, plus the right to lodge a complaint with your local supervisory authority or the UK Information Commissioner's Office.
  • Nigeria (NDPA / NDPR) — the rights above, plus the right to complain to the Nigeria Data Protection Commission.
  • California (CCPA/CPRA) — the right to know, delete, and correct, the right to opt out of sale or sharing (we do neither), and the right not to be discriminated against for exercising these rights.

Email privacy@wevesti.com to exercise a right. We verify requests against your account and respond within 30 days (extendable by a further 60 days for complex requests, with notice). You may also edit most profile data yourself in account settings.

9. Cookies

We use strictly necessary cookies and local storage to keep you signed in and to remember interface preferences, plus limited first-party analytics to understand aggregate product usage. We do not run third-party advertising cookies. You can clear or block cookies in your browser, but sign-in will not work without the necessary ones.

10. Changes to this policy

We will update this page when our practices change and revise the “last updated” date. For material changes affecting how we use your data, we will notify you by email or in-product notice before the change takes effect. See also our Terms of Service.