Privacy Policy

    VA.Team LLC

    1

    Introduction

    VA.Team LLC ("VA.Team," "we," "us," "our," or the "Company") respects your privacy and is committed to protecting the personal information you share with us. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website (www.va.team), use our platform and services, or communicate with us via SMS/MMS, email, or other methods.

    This Privacy Policy applies to all users of the VA.Team platform, including clients and visitors. By creating an account, clicking "I Agree" (or similar acceptance mechanism), using VA.Team services, or submitting your information through our website, you agree to the terms of this Privacy Policy.

    For processing based on your consent (such as marketing communications), you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal. If you do not agree with these practices, please do not use our services.

    2

    Information We Collect

    2.1 Information You Provide

    We collect information that you voluntarily provide when using our services. For each category below, we specify the legal basis under GDPR where applicable:

    Personal Information

    Name, email address, phone number, company name, business address, and billing information.

    Company Profile

    Company logo, industry type, team size, and business description.

    VA Request Information

    Job descriptions, required skills, preferred working hours, and project details.

    Communication Data

    Messages exchanged between you and VA.Team, including SMS/MMS content related to service coordination, emails, feedback, support inquiries, and correspondence with our team and VAs.

    User-Generated Content

    Files, documents, and other materials you upload to the platform or share with Nabu AI.

    2.2 Automatically Collected Information

    When you access our platform or website, we automatically collect certain information:

    • Usage Information: IP address, browser type and version, operating system, referring URLs, pages viewed, features used, time spent on platform, click patterns, and the dates/times of visits.
    • Device Information: Device type, operating system, device identifiers, and hardware model if accessing our services from a mobile device.
    • Cookies and Similar Technologies: Session cookies, authentication tokens, and preference settings (see Section 9 for details).
    • Geolocation Data: Approximate location based on IP address for timezone settings, regional customization, and fraud prevention.
    • Address Autofill Lookups: During signup, when you type a postal code we send only the postal code and country you entered to zippopotam.us, a public postal-code directory, to pre-fill the city and region fields. No IP address, account identifier, or other personal data is included in these lookups.

    2.3 Payment Information

    Payment card information is processed by our PCI DSS-compliant third-party payment processors. VA.Team does not store complete payment card numbers on our servers. We receive only limited payment data necessary for billing and record-keeping purposes, such as the last four digits of your card, card type, and billing address.

    2.4 Information We Do Not Collect (Regulated Data)

    VA.Team's platform is not designed to collect, process, or store Regulated Data, including: Protected Health Information (PHI) subject to HIPAA, payment card data subject to PCI-DSS (other than through our Stripe integration), data subject to FINRA, SEC, or financial services regulations, educational records subject to FERPA, children's data subject to COPPA, and export-controlled data subject to ITAR or EAR. Users are prohibited from uploading such data to the platform. See our Terms and Conditions for the complete Regulated Data Exclusion policy.
    3

    How We Use Your Information

    We use the information we collect to:

    • Provide and manage our virtual assistant services and match you with suitable VAs
    • Communicate with clients about tasks, scheduling, project updates, and service-related matters
    • Create and manage your account, process payments, and provide customer support
    • Send service-related notifications via email or SMS
    • Respond to inquiries and provide customer support
    • Improve and personalize your experience on our platform and website
    • Analyze usage patterns, fix technical issues, conduct research, and develop new features
    • Detect, prevent, and address fraud, security issues, abuse, and violations of our Terms and Conditions
    • Comply with legal obligations, enforce our terms of service, and respond to governmental requests
    • With your consent, send promotional materials and special offers (you may opt out at any time)
    4

    SMS/MMS Messaging and Consent

    4.1 Service-Related Messages

    If you provide your mobile phone number, you may receive service-related SMS/MMS messages from VA.Team. These messages may include:

    • Task status updates and project notifications
    • Meeting confirmations, changes, or reminders
    • VA assignment and availability notifications
    • Billing and payment confirmations
    • General service communications and support responses

    4.2 Opt-Out and Help

    Opt-Out Instructions

    You may opt out of SMS messages at any time by replying STOP to any message. To receive assistance or information about our SMS program, reply HELP to any message or contact us at hello@va.team.

    4.3 Message Frequency and Rates

    Message frequency may vary depending on your service activity and communication preferences. Message and data rates may apply depending on your mobile carrier. Please contact your carrier for details about your messaging plan.

    4.4 No SMS Marketing; No Sharing

    We do not use SMS messages for marketing purposes. Your mobile phone number will never be sold, rented, or shared with third parties for marketing purposes.
    6

    Nabu AI and Data Usage

    6.1 Nabu AI Processing

    When you use Nabu AI, your inputs, queries, and uploaded files are processed to provide AI-powered assistance. This data is used solely to deliver services to you and is not used to train or improve AI models.

    6.2 Third-Party AI Service Providers

    Nabu AI may utilize third-party AI service providers acting as subprocessors to deliver AI functionality. These providers:

    • Process content solely to provide the service to VA.Team under contract
    • Are bound by confidentiality and data protection obligations
    • Do not use your data for training their models
    • Are listed on our Subprocessor List (available upon request at hello@va.team)

    6.3 Data Confidentiality

    All content processed by Nabu AI remains confidential and is subject to the same privacy protections as other data on our platform. We do not share Nabu AI interactions with third parties except:

    • With AI subprocessors as described above
    • As required by law
    • As otherwise described in this Privacy Policy

    6.4 Automated Decision-Making Technology (ADMT) Disclosure

    Nabu AI is a technology system designed to assist with task automation and content generation. VA.Team uses Nabu AI as a supplementary tool to enhance service delivery. Nabu AI may process your data to provide recommendations, insights, and automated assistance with assigned tasks.

    Nabu AI should not be considered an automated decision-making technology (ADMT) that produces solely automatic decisions with legal or similarly significant effects as defined under CCPA and other privacy regulations. VA.Team maintains human oversight and control over all significant business decisions affecting clients. Any automated assistance from Nabu AI is reviewed and approved by VA.Team representatives before implementation.

    California residents and other applicable state residents have the right to request information about whether Nabu AI produces automated decisions affecting them and to request human review of such decisions. Contact hello@va.team to exercise these rights.

    6.5 Global Privacy Control (GPC) Signal Support

    VA.Team respects Global Privacy Control (GPC) signals transmitted through your browser or device. If your browser sends a GPC signal, we will:

    • (a) Treat the signal as a request to opt out of selling or sharing of personal information, to the extent applicable under state privacy laws;
    • (b) Treat the signal as a request to limit use and disclosure of sensitive personal information;
    • (c) Treat the signal as a request to opt out of targeted advertising and profiling.

    Please note that GPC signals do not disable essential cookies or service-related functionality required to operate our platform. We will respond to valid GPC signals in compliance with applicable state privacy laws. You may also exercise these rights directly by contacting us at hello@va.team.

    6.6 Google Workspace API Data and Limited Use

    When you connect a Google account to Nabu, Nabu accesses Google Workspace data (Google Drive files and Google Calendar events) only at your direction and only to carry out the tasks you request. The OAuth scopes you grant are listed on Google's consent screen before you authorize, and you can revoke access at any time from the Nabu integration settings or from your Google Account's Third-party apps with account access page.

    The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

    Specifically, Workspace API data received by VA.Team is:

    • Used only to provide or improve user-facing features of Nabu that are prominent in the user experience.
    • Not transferred to third parties except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets (with notice to users).
    • Not used or transferred for advertising, including retargeting, personalized, or interest-based advertising.
    • Not used to train, fine-tune, or otherwise improve general-purpose AI or machine-learning models.
    • Not read by humans, except (a) with the user's affirmative agreement for specific messages, (b) as necessary for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymized for internal operations.
    7

    Data Sharing and Disclosure

    7.1 We Do Not Sell Your Data

    We Do Not Sell Your Data

    VA.Team does not sell, rent, or trade your personal information to third parties for their own marketing purposes or for monetary consideration. We do not disclose your personal data to third parties for their independent use. We do not engage in the "sale" or "sharing" of personal information as those terms are defined under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). We do not use your data for targeted advertising or cross-context behavioral advertising.

    7.2 Sharing With Virtual Assistants

    Data Controller and Data Processor Relationship:

    VA.Team LLC acts as the data controller for all client data. Virtual Assistants engaged through our platform act as data processors under VA.Team's documented instruction and control, in accordance with the terms of the VA Independent Contractor Agreement (ICA) and applicable data protection regulations.

    When you engage a VA through our platform, you authorize us to disclose relevant information to that VA to enable service delivery. VAs are independent contractors who process your information solely to perform tasks you direct.

    VAs receive access only to information necessary to perform assigned tasks, including: company name, project details, task requirements, files uploaded for specific tasks, and communication history related to their assignments.

    VAs are bound by confidentiality agreements and Data Processing Agreements (DPAs) that include GDPR Article 28 requirements. All VAs execute DPAs with VA.Team prior to processing any client data.

    VAs are prohibited from using client information for purposes other than performing assigned work as directed by VA.Team.

    Access is revoked immediately upon reassignment or termination of the VA relationship.

    7.3 Service Providers and Subprocessors

    Virtual Assistants (Processors):

    VA.Team acts as the data controller for all client data. Virtual Assistants engaged through our platform act as data processors under VA.Team's instruction and control. All VAs execute Data Processing Agreements (DPAs) with VA.Team that include all requirements of GDPR Article 28, including:

    • Processing only on documented instructions from VA.Team
    • Confidentiality obligations for all personnel with access to client data
    • Appropriate technical and organizational security measures
    • Restrictions on international data transfers
    • Assistance with data subject rights requests
    • Deletion or return of data upon contract termination

    Dynamic VA Assignments:

    Because VA assignments are dynamic and may change based on client needs, workload, and availability, VA.Team provides general notice that Virtual Assistants will have access to client data to perform assigned tasks, rather than individual notifications for each VA assignment. Clients may request information about specific VAs assigned to their accounts at any time by contacting hello@va.team.

    All VAs must comply with the terms of the VA Independent Contractor Agreement (ICA) and execute DPAs containing GDPR Article 28 requirements before processing any personal data. A current list of all active VAs and their processor status is available upon request at hello@va.team.

    Additional Service Providers and Subprocessors:

    We may share your information with service providers and contractors who perform services on our behalf, under strict confidentiality agreements. We maintain Data Processing Agreements (DPAs) with all processors who handle personal data on our behalf. Our categories of service providers include:

    • Payment Processing: Stripe (payment processing, fraud detection)
    • Cloud Infrastructure: Hosting providers (data storage, hosting, computing, IT support)
    • Communication Services: Email delivery and SMS/MMS providers (transactional notifications)
    • AI Service Providers: Third-party AI services powering Nabu AI functionality
    • Analytics: Usage analytics and product improvement tools (not used for targeted advertising)

    A current list of all subprocessors is available upon request at hello@va.team. We will provide at least thirty (30) days' notice before adding new subprocessors that process personal data. During this notice period, clients may object to new subprocessors by contacting hello@va.team.

    7.4 Legal Requirements

    We may disclose your information to government agencies, regulatory bodies, or law enforcement when required by law, or in response to valid legal processes (subpoenas, court orders, search warrants), to protect VA.Team's legal rights, property, or safety, or in emergency situations involving potential harm to persons. Where legally permitted, we will attempt to notify you before disclosure.

    7.5 With Your Consent

    We may share your information with other parties with your explicit consent.

    7.6 Business Transfers

    In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of VA.Team's assets, your personal information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on our website of any change in ownership or uses of your personal information.

    8

    Sensitive Personal Information

    8.1 Our Limited Collection

    VA.Team collects limited sensitive personal information, specifically:

    • Account login credentials (email/password) for authentication purposes only
    • Financial account information solely through Stripe for payment processing

    We do not collect precise geolocation, Social Security numbers, racial/ethnic origin, religious beliefs, health information, or biometric data.

    8.2 Use Limitation

    We use sensitive personal information only for purposes necessary to provide our services (authentication and payment processing) and not for inferring characteristics about you or for any secondary purposes. You have the right to limit our use of sensitive personal information to these necessary purposes.
    9

    Cookies and Tracking Technologies

    9.1 What Are Cookies

    Cookies are small text files stored on your device that help us provide and improve our services. We also use similar technologies such as pixels, web beacons, and local storage.

    9.2 Types of Cookies We Use

    TypePurpose
    Strictly NecessaryRequired for login, authentication, security, and platform functionality. These cannot be disabled.
    PaymentUsed by Stripe for secure payment processing and fraud prevention.
    FunctionalRemember your settings, preferences, and customization choices.
    AnalyticsHelp us understand how users interact with our platform (not used for targeted advertising).
    SessionMaintain your logged-in state during your visit and expire when you close your browser.

    9.3 Cookies We Do Not Use

    VA.Team does not use: third-party advertising or remarketing cookies, cross-site tracking pixels, social media tracking widgets, or any cookies for targeted advertising, behavioral advertising, or selling/sharing data with advertisers.

    9.4 Cookie Consent and Management

    When you first visit our platform, you will be presented with a cookie consent banner allowing you to accept or reject non-essential cookies. Essential cookies (authentication, security, and payment processing) are set automatically as they are strictly necessary for the website to function. All other cookies will only be set after you provide consent.

    Consent is as easy to withdraw as to give. You may update your preferences at any time through our Cookie Preferences center or by adjusting your browser settings. Note: disabling essential cookies may affect platform functionality and prevent you from using certain features.

    9.5 Do Not Track

    Our platform does not currently respond to "Do Not Track" (DNT) browser signals. However, because we do not engage in cross-site tracking or targeted advertising, the practical effect is the same.

    10

    Data Security

    10.1 Security Measures

    We implement industry-standard administrative, technical, and physical safeguards to protect your data from unauthorized access, disclosure, or misuse, including:

    • Encryption in transit and at rest
    • Access controls
    • Firewalls
    • Intrusion detection
    • Security monitoring
    • Regular security assessments

    10.2 Data Breach Notification

    In the event of a data breach that compromises your personal information, VA.Team will:

    • Investigate promptly and take steps to mitigate harm
    • Notify affected users in accordance with applicable law without unreasonable delay
    • Provide notification within 72 hours where required by law (such as GDPR)
    • Include in the notification: the nature of the breach, categories of data affected, likely consequences, measures taken, and contact information

    10.3 No Guarantee

    However, no system can be guaranteed 100% secure. While we strive to protect your information, we cannot guarantee absolute security. You are responsible for maintaining the security of your account credentials.
    11

    Data Retention

    We retain your information only as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods:

    Data TypeRetention Period
    Active AccountsInformation retained while your account is active and as necessary to provide services.
    Account DeletionUpon deletion request, data is retained for 30 days (for recovery), then deleted from production systems. Data may persist in encrypted backups for up to 90 additional days.
    Financial RecordsInvoices, payment history, and tax documents retained for 7 years as required by law.
    Security LogsAccess logs and audit trails retained for up to 2 years for security monitoring, fraud detection, and investigation purposes.
    VA AccessWhen a VA relationship ends, VA access to your data is revoked immediately.
    12

    Your Privacy Choices and Rights

    12.1 General Rights

    You may:

    • Opt out of SMS messages at any time by replying STOP
    • Opt out of marketing emails using the unsubscribe link or by contacting us
    • Request access to, correction of, or deletion of your personal information
    • Request a copy of your data in a portable format
    • Withdraw consent where processing is based on consent
    • Disable cookies through your browser settings (note: some site features may not function properly)

    12.2 How to Exercise Rights

    To exercise these rights, contact us at hello@va.team or use self-service tools in your account settings. We will respond within 30 days (or shorter where required by law). We may need to verify your identity.

    12.3 Appeal Process

    If we deny your privacy request, you may appeal by contacting hello@va.team within 30 days. We will respond to appeals within 45 days. You may also have the right to lodge a complaint with a supervisory authority.

    13

    EEA, UK, and Swiss Residents (GDPR Rights)

    If you are located in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, you have additional rights under the GDPR:

    Right to Access

    Obtain confirmation of whether we process your data and access to that data.

    Right to Rectification

    Have inaccurate data corrected.

    Right to Erasure

    Request deletion in certain circumstances.

    Right to Restriction

    Request restriction of processing in certain circumstances.

    Right to Data Portability

    Receive your data in a structured, machine-readable format.

    Right to Object

    Object to processing based on legitimate interests or for direct marketing.

    Automated Decision-Making Rights

    Not be subject to solely automated decisions with legal effects.

    Right to Complain

    Lodge a complaint with a supervisory authority.

    Contact hello@va.team to exercise these rights. For complaints: EEA authorities | UK ICO

    14

    U.S. State Privacy Rights

    14.1 California Residents (CCPA/CPRA)

    California residents have rights to:

    • Know what personal data is collected/used/disclosed
    • Delete personal information
    • Correct inaccurate information
    • Opt out of sale/sharing (note: we do not sell or share)
    • Limit use of sensitive personal information
    • Non-discrimination for exercising rights

    14.2 Other U.S. States

    Residents of Virginia, Colorado, Connecticut, Utah, Oregon, Texas, Montana, Delaware, Iowa, New Hampshire, New Jersey, Nebraska, Maryland, Minnesota, Rhode Island, Indiana, Kentucky, Tennessee, and other states with comprehensive privacy laws (as effective) may have similar rights including: access, correction, deletion, portability, opt-out of targeted advertising/sale/profiling, and appeal rights.

    14.3 Categories Collected

    In the preceding 12 months, we collected:

    • Identifiers
    • Commercial information
    • Internet activity
    • Geolocation data
    • Professional information
    • Inferences

    We have not sold any of these categories.

    14.4 Authorized Agents

    You may designate an authorized agent to make requests on your behalf with written permission and identity verification.

    15

    International Data Transfers

    Your information may be transferred to and processed in the United States and other countries. When transferring data from the EEA, UK, or Switzerland, we implement appropriate safeguards including:

    • Standard Contractual Clauses (SCCs): We use the European Commission's 2021 Standard Contractual Clauses with our service providers that process data outside the EEA. Transfer Impact Assessments are conducted and documented for all international transfers. Copies of SCCs are available upon request at hello@va.team.
    • UK Addendum: UK International Data Transfer Addendum for UK transfers.
    • Supplementary Measures: Additional technical and organizational protections where necessary.
    • Adequacy Decisions: Where available for destination countries.

    Request copies of SCCs or transfer safeguard information at hello@va.team.

    17

    Children's Privacy

    Our Services are intended for business use by individuals 18 years or older. We do not knowingly collect information from individuals under 18, and specifically do not knowingly collect information from children under 13 in compliance with COPPA (US) or children under 16 where applicable under GDPR. If we become aware that we have collected information from a child under 13, we will delete it promptly.

    If you believe we have collected information from a child, please contact us immediately at hello@va.team.

    18

    Updates to This Privacy Policy

    We may update this policy from time to time. Any changes will be posted on this page with the updated effective date. For material changes, we will send an email to your registered email address at least thirty (30) days before changes take effect.

    Your continued use of VA.Team after the effective date constitutes acceptance of the updated Privacy Policy.
    19

    Contact Us

    If you have questions about this Privacy Policy or your data, please contact us:

    BY USING VA.TEAM SERVICES, CREATING AN ACCOUNT, OR CLICKING "I AGREE," YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY AND CONSENT TO THE DATA PRACTICES DESCRIBED HEREIN.

    We value your privacy

    We use cookies and similar technologies to run this site and, with your consent, to understand how it's used — including session replays of on-screen activity — so we can improve it. Essential ones keep the site working. You can accept, reject, or choose what's on. See our Privacy Policy.