Privacy Policy
Effective August 7, 2026
Vambris LLC (“Vambris,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect information when you visit vambris.com (the “Website”) or communicate with us through the Website.
This Privacy Policy applies to the Vambris public website and related communications. It does not govern the processing of data within customer-controlled environments through Vambris products such as EIDGuard.
1. Who We Are
Vambris LLC is a New York limited liability company based in the United States. Vambris develops software and services focused on cloud resilience, backup, recovery, and related technologies.
For privacy-related questions or requests, contact:
Vambris LLC
New York, United States
privacy@vambris.com
2. Information We Collect
We seek to collect only the information reasonably necessary to operate our Website, respond to inquiries, understand Website usage, and protect our services.
Information You Provide
If you submit a contact form or otherwise communicate with us, we may collect information such as:
- Your name
- Business email address
- Company or organization
- Information contained in your message
- Other information you voluntarily provide
Please do not submit passwords, authentication credentials, sensitive personal information, production data, or other confidential information through the Website contact form.
Website Usage Information
We use Cloudflare Web Analytics to understand general Website usage and performance. This may provide aggregated or limited technical information about visits to the Website, such as page views, referral information, device or browser characteristics, and approximate geographic information.
We configure our Website analytics with the goal of avoiding advertising profiles and unnecessary tracking.
Security and Network Information
Our infrastructure providers may automatically process limited technical information necessary to deliver and secure the Website. This can include IP addresses, request information, security signals, and similar network data used for functions such as traffic delivery, abuse prevention, bot detection, and security monitoring.
3. Contact Form Processing
When you submit a contact form on our Website, the submission is transmitted through a server-side function and delivered to Vambris through Microsoft 365 using Microsoft Graph.
The Website has no database and does not store contact form submissions. The resulting email in our Microsoft 365 environment is the only retained copy of the communication.
The Website does not expose Microsoft Graph credentials or other mail-delivery credentials to the visitor’s browser.
4. How We Use Information
We may use information collected through the Website to:
- Respond to questions, requests, and business inquiries
- Communicate with prospective or existing customers
- Evaluate requests for product demonstrations or information
- Operate, maintain, secure, and improve the Website
- Understand Website performance and general usage
- Detect or prevent spam, abuse, fraud, or security threats
- Comply with applicable legal obligations
- Establish, exercise, or defend legal claims
We do not sell personal information.
We do not use Website visitor information to build advertising profiles or serve targeted advertising.
5. Legal Bases for Processing
Where the General Data Protection Regulation (“GDPR”), UK GDPR, or similar laws apply, Vambris processes personal information only where we have an appropriate legal basis.
Depending on the circumstances, those bases may include:
Steps at your request before entering into a contract. We may process information when you contact us about Vambris products or services and request information, a demonstration, or other action relating to a potential business relationship.
Legitimate interests. We may process information where reasonably necessary for our legitimate business interests, including responding to business communications, maintaining relationships with prospective or existing customers, operating and securing our Website, preventing abuse, and improving our services, provided those interests are not overridden by your rights and interests.
Legal obligations. We may process information where necessary to comply with applicable law, regulation, legal process, or governmental request.
Consent. Where required by law, we may rely on your consent. Where processing is based on consent, you may withdraw it as permitted by applicable law.
6. Cookies and Similar Technologies
The Vambris Website does not set cookies.
Vambris does not use advertising cookies or third-party advertising trackers on the Website.
We use Cloudflare Turnstile to protect Website forms against automated abuse and spam. Turnstile may process limited technical and security information necessary to distinguish legitimate users from abusive or automated traffic.
We also use Cloudflare Web Analytics to obtain privacy-focused Website usage information.
These services may use technical mechanisms necessary to provide security, traffic measurement, and Website functionality. We do not use them for behavioral advertising.
7. Service Providers
We use a limited number of third-party service providers to operate the Website.
Cloudflare
Cloudflare provides Website hosting and delivery infrastructure, content delivery, DNS-related services, security functionality, Cloudflare Turnstile, and Cloudflare Web Analytics.
Cloudflare may process limited technical information necessary to deliver, protect, and measure use of the Website.
Microsoft
Microsoft provides Microsoft 365 and Microsoft Graph services used to receive and manage communications submitted through our Website.
Information submitted through our contact form may therefore be processed and stored within Vambris’s Microsoft 365 environment.
We may also disclose information to professional advisers, regulators, courts, law enforcement, or other parties where reasonably necessary to comply with law, protect legal rights, or address security or fraud.
8. EIDGuard and Customer-Controlled Data
EIDGuard is designed to operate within infrastructure controlled by the customer.
As part of EIDGuard’s normal operation, Microsoft Entra External ID tenant configuration data, backups, recovery points, recovery data, and related customer content are processed and stored within the customer’s own Azure environment.
Vambris does not receive, host, or store that customer tenant data as part of the normal operation of EIDGuard.
The customer controls its Azure environment, storage accounts, identities, access controls, retention configuration, and other infrastructure used by EIDGuard.
This Privacy Policy governs the Vambris Website and Vambris’s own handling of personal information. Product-specific terms, customer agreements, or other contractual documentation may separately govern the use of EIDGuard.
9. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including applicable legal, accounting, security, and business requirements.
Communications submitted through the Website, including contact form inquiries, are generally retained for up to 24 months following the most recent substantive communication, unless:
- A business relationship continues;
- The information becomes part of an active customer or contractual record;
- A longer period is required by law;
- Retention is reasonably necessary to establish, exercise, or defend legal claims; or
- The information is deleted earlier because it is no longer needed.
Security and infrastructure providers may maintain technical logs according to their own applicable retention schedules.
10. International Data Transfers
Vambris is located in the United States, and our service providers may process information in the United States and other countries.
If you access the Website from the European Economic Area, United Kingdom, Switzerland, or another jurisdiction with data-transfer restrictions, your information may be transferred to countries whose data-protection laws differ from those in your jurisdiction.
Where required, Vambris and its service providers rely on legally recognized mechanisms for international transfers, which may include adequacy decisions, approved contractual safeguards, or other mechanisms permitted under applicable law.
11. Your Privacy Rights
Depending on where you live, you may have rights regarding your personal information, including the right to:
- Request access to personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your personal information
- Request restriction of certain processing
- Object to certain processing
- Request portability of information where applicable
- Withdraw consent where processing is based on consent
- Lodge a complaint with an applicable data-protection authority
These rights are subject to applicable law and may not apply in every circumstance.
To exercise a privacy right, contact privacy@vambris.com.
We may need to verify your identity before completing certain requests.
12. U.S. State Privacy Rights
Residents of certain U.S. states may have additional privacy rights under applicable state law.
Vambris does not sell personal information and does not share personal information for cross-context behavioral advertising as those terms are commonly defined under U.S. state privacy laws.
If an applicable state privacy law provides you with rights concerning information Vambris maintains about you, you may submit a request to privacy@vambris.com.
13. Data Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information under our control.
However, no Internet transmission, email system, or information-storage system can be guaranteed to be completely secure. You should not send passwords, credentials, highly sensitive personal information, or confidential production information through the Website contact form.
14. Children’s Privacy
The Website and Vambris products are intended for businesses and professional users. They are not directed to children.
We do not knowingly collect personal information from children under 13 through the Website. If we become aware that such information has been collected inappropriately, we will take reasonable steps to delete it.
15. Third-Party Websites
The Website may contain links to third-party websites or services.
Vambris does not control the privacy practices of those third parties, and this Privacy Policy does not apply to information you provide directly to them. You should review the applicable privacy policies of third-party services before providing information.
16. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes to our Website, products, business practices, service providers, or legal obligations.
When we make changes, we will update the effective date shown at the top of this Privacy Policy. Material changes may also be communicated through the Website or other appropriate means.
17. Contact Us
For questions about this Privacy Policy, our privacy practices, or requests concerning your personal information, contact:
Vambris LLC
New York, United States
privacy@vambris.com
