Privacy policy
This policy explains what personal data Veillo handles, why we use it, who receives it, and the choices and rights available to you.
Effective and last updated 13 July 2026. This version describes Veillo’s current service and production requirements. Product guidance is not legal advice.
1. Controller and contact
The data controller for Veillo is Arbos Folk, a sole proprietorship registered in Denmark, which builds Veillo under the Arbos Techne name. You can reach us at hello@veillo.eu.
Privacy enquiries and rights requests can be sent to hello@veillo.eu. We have not appointed a data protection officer because the current scale and nature of our processing do not require one. We review that position as the service grows.
2. Where this policy applies
This policy covers the public website, account registration, the Veillo application, support, billing, product communications, and optional integrations. When a customer puts personal data into its Veillo workspace, that customer is normally the controller and Arbos Folk acts as processor. The Data Processing Agreement governs that processing. Arbos Folk remains controller for account administration, security, billing, and its own business records.
3. Data we handle
- Account data: name, work email, password hash, verification status, profile image where supplied, and authentication-provider identifiers.
- Session and security data: session token, IP address, browser or user-agent data, sign-in and expiry times, password-reset records, OAuth state, and staff access records.
- Organisation data: organisation name, country, sector, staff band, operating countries, role, members, and invitations.
- Workspace content: AI systems, use cases, classifications, connected-service findings, documents, reviews, notes, and audit entries entered or produced by users.
- Integration data: encrypted OAuth tokens and the Google Workspace activity data requested by an authorised administrator when that connector is enabled.
- Billing data: plan, subscription state, Stripe customer and subscription references, invoices, and tax information. Stripe handles card details.
- Lead and support data: contact details, free-inventory submissions, demo requests, emails, and the content of support messages.
- Analytics data: page URL and title, referrer, device and browser details, broad geography, visit and engagement information, and Web Vitals, after analytics consent.
4. Purposes and legal bases
| Purpose | Typical data | GDPR basis |
|---|---|---|
| Provide accounts and the contracted service | Account, organisation, workspace, and integration data | Article 6(1)(b), contract |
| Secure the service, prevent misuse, and diagnose faults | Session, IP, user-agent, audit, and error data | Article 6(1)(f), legitimate interests in operating a secure service |
| Process subscriptions and keep financial records | Billing and transaction data | Article 6(1)(b), contract, and Article 6(1)(c), legal obligations |
| Answer enquiries and provide support | Contact and message content | Article 6(1)(b) or 6(1)(f), depending on the request |
| Measure website and product use | Google Analytics data | Article 6(1)(a), consent |
| Send requested updates or marketing | Name, email, and preferences | Article 6(1)(a), consent, or applicable soft opt-in rules |
| Establish, exercise, or defend legal claims | Relevant account, contract, security, and correspondence records | Article 6(1)(f), legitimate interests |
5. Google Analytics
Google Analytics 4 is configured on this deployment. The Google tag is blocked until you allow analytics in the cookie banner. Declining sends no Analytics request to Google. If you consent, Veillo disables Google advertising storage, Google Signals, ad personalisation, and ad-user-data features. Page views and performance measurements are used to understand demand and improve the service. See the cookie policy for cookie names and controls.
6. AI-assisted features
If an authorised user asks for a suggestion about a custom AI-system description, the text is sent to a Claude model through Amazon Bedrock in the configured EU region. The result is labelled AI-assisted and requires a person to confirm or override it. High-risk and prohibited suggestions require human sign-off. Veillo does not use this feature to make decisions about people, and the fallback used in local development is a visible keyword heuristic. The scheduled article workflow also uses Bedrock, but receives editorial briefs and public sources rather than customer workspace data.
7. Recipients and sub-processors
We disclose data to vendors needed to provide the service, professional advisers under confidentiality, authorities where law requires it, and a successor in a properly managed sale or reorganisation. We do not sell personal data or share it for third-party advertising. The named vendor register, purpose, location information, and activation conditions are on the sub-processors page.
8. International transfers
Core production compute is configured for Frankfurt, and the production database standard is an EU region. Some providers operate global delivery, support, security, and control-plane services. Where personal data is transferred outside the EEA, we rely on an adequacy decision, the EU-US Data Privacy Framework where applicable, or the European Commission’s Standard Contractual Clauses, with supplementary measures where appropriate. A claim that all service metadata always stays inside the EU would be inaccurate, so we do not make it.
9. Retention
- Account and workspace data: while the account is active, then until a verified deletion request or the contractual deletion process is completed, subject to legal holds.
- Sessions: configured to expire after 30 days, with active sessions refreshed after 24 hours.
- Google Workspace OAuth state: 10 minutes. Stored connector refresh tokens remain until the connection is revoked or deleted.
- Cookie choice: 180 days, unless the policy version changes or you clear it.
- Google Analytics cookies: configured for about 13 months without extension on each visit. Google Analytics event-level retention must be set in the GA property before launch.
- Billing and legal records: for the period required by accounting, tax, limitation, and other applicable law.
- Support and sales correspondence: for as long as needed to handle the relationship, then reviewed and removed when no longer needed.
Backups and vendor logs follow the applicable provider schedules. The customer DPA records the production deletion commitments agreed for workspace data.
10. Security
Measures include TLS in transit, hashed passwords, secure and HTTP-only authentication cookies in production, role checks, organisation-scoped queries, encrypted connector tokens, restricted staff access, security headers, and audit entries for material product actions. See Security for scope and limitations. No internet service can promise absolute security.
11. Your rights
Subject to the GDPR’s conditions, you may request access, correction, erasure, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent without affecting earlier lawful processing. We may need to verify identity and clarify the scope of a request. We normally respond within one month, with the extensions allowed by law. Email hello@veillo.eu.
You may complain to the Danish Data Protection Agency (Datatilsynet) or the supervisory authority where you live, work, or believe an infringement occurred.
12. Children
Veillo is a business service and is not directed to children. We do not knowingly invite anyone under 16 to create an account.
13. Changes
We update this policy when the service, vendors, or law changes. Material changes are notified through the service or by email where appropriate. The date above identifies the current version.