Visus Collects Comprehensive Data from Users, Implementing Multiple Security Measures for Protection
In today's digital age, the way companies collect and handle user data has become increasingly complex, raising important questions about privacy and security. This analysis examines Visus, a platform that collects both personal and usage data from its users, investigating how the company manages this information and what measures it takes to protect user privacy. Through an examination of its data collection methods, security protocols, and third-party integrations, we'll explore Visus's approach to managing user information and the privacy controls available to users.
Visus Company operates as Celestial Commerce AB, located at Flintvägen 16, Örebro, 703 74, Sweden. Their primary service, the Visus Application, collects both personal and usage data from users. Personal information includes basic contact details such as email addresses, first names, and last names.
The company employs a comprehensive approach to data collection, gathering not only direct user input but also technical data about how the service is used. This usage data includes information on page visit durations and other interaction metrics. From a technical standpoint, Visus collects detailed device information including IP addresses, browser types, and unique device identifiers. When users connect through social media platforms like Google, Facebook, Twitter, or LinkedIn, additional data is collected, encompassing everything from account registration information to detailed activity logs.
Visus utilizes various tracking technologies to gather this information. The company employs different types of cookies, including both session and persistent varieties, to authenticate users and track activity. These cookies help maintain user sessions and store preferences across visits. Web beacons are also used to gather broader website statistics and track user engagement.
Users have the ability to control their cookie settings through their web browsers, though Visus notes that some functionality depends on cookie acceptance. The company employs a tiered approach to cookie usage, distinguishing between necessary cookies for core functionality and additional cookies that enhance the user experience.
The Visus platform offers robust integration capabilities, allowing seamless connectivity with multiple third-party services. These include integration with popular project management tools like Google Drive, Confluence, and Notion, as well as communication platforms such as Slack, Microsoft Teams, and Discord. Additionally, the service provides a Chrome extension for users who prefer desktop integration.
From a security perspective, Visus implements industry-standard encryption protocols to protect user data. All data in transit is secured using TLS 1.2+ with perfect forward secrecy, while server storage employs full disk AES 256 encryption. The company prioritizes data security and is actively working towards SOC 2 compliance, maintaining rigorous policies and procedures to ensure system security and reliability.
User data retention is governed by legal requirements, with usage data retained for internal analysis purposes. Visus provides users with control over their information through account settings, allowing them to manage their privacy preferences and request deletion of their data when necessary. While the company takes security measures seriously, it acknowledges that no system can guarantee 100% data protection.
From the moment users interact with the Visus Application, the company begins collecting data through multiple channels. Personal information such as email addresses, names, and contact details are gathered directly through user registration and interaction. This basic information forms the foundation of user profiles, enabling essential service functions and communication.
When users engage with the application, a wealth of usage data is simultaneously collected. This technical information includes critical elements like IP addresses, browser types, and device identifiers, all of which help maintain system integrity and enhance user experience. The company employs both session and persistent cookies to authenticate users and track their activity across sessions. These cookies play a crucial role in maintaining uninterrupted functionality while allowing users to customize their experience through saved preferences.
Social media integration presents additional data collection opportunities. When users connect their accounts through services like Google, Facebook, Twitter, or LinkedIn, the scope of collected information expands significantly. Account registration data, including names and email addresses, is supplemented by detailed activity logs and interaction histories. For users who provide additional information during the setup process, this data becomes part of their overall profile.
The company employs a multi-layered approach to data management, recognizing the sensitive nature of the information it collects. All data in transit between user devices and the Visus servers is secured using TLS 1.2+ with perfect forward secrecy, ensuring that even if data is intercepted, it cannot be decrypted. Server-side storage utilizes full-disk AES 256 encryption to protect stored information. These security measures are part of the company's broader commitment to data protection, though they acknowledge that no system can guarantee absolute security.
User control remains a priority, particularly regarding how their data is used and shared. Through account settings, users can manage their privacy preferences and request the deletion of their personal information. While the company processes data for essential service operations and user communications, they also use aggregated data for internal analysis and service improvement purposes. This data is retained only as long as required by legal obligations or dispute resolution processes, ensuring that user information is protected while allowing the company to maintain its operations effectively.
All data in transit between user devices and Visus servers is protected using TLS 1.2+ with perfect forward secrecy encryption, ensuring that even if data is intercepted, it cannot be decrypted. This robust encryption standard is widely recognized as providing strong security for internet communications.
Server-side storage employs full disk AES 256 encryption, offering maximum protection for stored information. The company enforces strict permission controls, ensuring that users only access information they have been authorized to view. Any changes to user permissions are immediately reflected across the system.
Visus is actively working towards SOC 2 compliance, implementing rigorous policies and procedures to enhance system security and reliability. While the company has established robust security measures, it acknowledges that no data transmission method can guarantee 100% security.
User data retention is governed by legal requirements, with Usage Data retained primarily for internal analysis purposes. When data is transferred to locations outside the user's jurisdiction, the company ensures that adequate security controls are in place to protect the information.
Users have the ability to delete or request deletion of their personal information through account settings or by contacting the company directly. Data may also be transferred as part of business transactions, subject to proper notice and potentially new privacy policies. In compliance with legal obligations, the company may disclose personal data to public authorities or to prevent legal liability.
Visus offers extensive integration capabilities, allowing users to connect their accounts with multiple third-party services. The platform supports integration with popular cloud storage solutions including Google Drive, Confluence, and Notion, as well as communication tools like Slack, Microsoft Teams, and Discord. Additionally, Visus provides a Chrome extension for users who prefer to access the service from their desktop computers.
The company's integration framework enables seamless data exchange between these platforms and the Visus Application. This connectivity allows users to store and access their AI training materials across multiple workspaces and devices, providing flexibility in their workflow. All integrated services maintain data security through Visus's robust encryption standards, with both data in transit and server storage protected using industry-standard protocols.
Visus provides users with several mechanisms to manage their personal data. Through account settings, users can control various aspects of their privacy, including the ability to delete their personal information. This feature allows users to remove their data from the system, though the company notes that some processing may still occur based on legal obligations or dispute resolution requirements.
Regarding data sharing, the company outlines specific circumstances under which information may be transferred. These include interactions with service providers for monitoring and analysis purposes, business transfers in connection with mergers or acquisitions, sharing with affiliates, business partners, and other users in public areas. When data is shared with third parties, Visus ensures that adequate security controls are implemented to protect the information.
The company maintains that while they implement commercially acceptable security measures, no data transmission method can guarantee 100% security. For this reason, they provide transparency about potential data visibility, noting that user interactions in public areas may be visible to all users and potentially distributed outside the immediate platform. This approach balances user transparency with the practical requirements of an interconnected digital ecosystem.