https://app.veloratech.live/legal/privacy
Velora Legal
Privacy Notice
Version 1.0Effective Current
Contents
Part IV - Privacy Notice
This Privacy Notice explains how Velora processes personal data for its own business purposes as controller. It does not replace Customer’s privacy notice to its leads, clients or other data subjects where Customer is controller and Velora acts as processor.
1. Who is responsible
Controller: Leo Forsberg, operating Velora as a Swedish sole proprietorship (enskild näringsverksamhet). Contact: privacy@veloratech.live. Postal address: Strömslundsgatan 6, 461 57 Trollhättan, Sweden.
2. Who this notice covers
Prospective and current business customers, Authorized Users, billing and business contacts, support correspondents, and visitors to Velora’s customer-facing application/legal pages where Velora determines the purpose of processing.
3. Data Velora processes as controller
- Account and profile data such as name, work email, role, workspace association and account identifiers.
- Commercial and billing data such as company name, subscription, invoice/payment references and transaction status. Payment card details are intended to be handled by Stripe rather than stored by Velora.
- Support and business communications with Velora.
- Security and technical data such as authentication/session events, IP/device/request metadata and operational logs made available by hosting/authentication providers.
- Prospect/outreach records used by Velora for its own B2B sales activity, such as business contact details, outreach history and opt-out status.
4. Purposes and legal bases
- To enter into and perform the business relationship, provision accounts and provide the Service: performance of contract and steps requested before contract; where the user is not personally the Customer, Velora’s legitimate interest in performing the contract with the user’s organization.
- To bill, account, maintain business records and comply with tax/legal obligations: contract and legal obligation.
- To secure, troubleshoot and prevent abuse of the Service: legitimate interests in network, information and service security; legal obligations where applicable.
- To provide support and communicate about the service relationship: contract and legitimate interests.
- To conduct proportionate B2B sales/outreach and maintain suppression/opt-out records: legitimate interests where permitted by applicable marketing/privacy law. Separate electronic-marketing rules may restrict the channel or require consent in some jurisdictions; Velora will apply those rules to outreach.
- To establish, exercise or defend legal claims: legitimate interests and legal obligations as applicable.
5. Recipients and service providers
Velora uses providers including Supabase, Vercel, Postmark, n8n, OpenAI and, once enabled, Stripe. Their role depends on the data and service involved. The current Subprocessor List describes providers that may process Customer Personal Data for service delivery. Some providers, especially payment providers, may also act as independent controllers for their own legal, fraud-prevention or regulated purposes.
6. International transfers
Personal data may be processed outside Sweden/EEA by service providers. Where GDPR requires a transfer safeguard, Velora relies on an adequacy decision, the EU-U.S. Data Privacy Framework where valid and applicable, EU Standard Contractual Clauses, or another lawful mechanism implemented by Velora or the relevant provider.
7. Retention
- Account and commercial records are kept for the active relationship and thereafter as needed for legal, accounting, dispute and security purposes. Swedish accounting records may need to be retained for statutory periods.
- Support and security records are kept only as long as reasonably needed for the relevant operational, security or legal purpose. Prospect/outreach data is periodically reviewed; suppression records may be retained longer so that Velora can honor an opt-out.
- Customer-controlled content inside the Service is governed by Customer instructions and the DPA rather than this controller notice.
8. Cookies and local storage
The Velora application uses authentication/session technologies necessary to sign users in and keep sessions secure. As of this version, Velora does not intentionally deploy third-party advertising trackers in the product. If non-essential analytics or advertising technologies are introduced, this Notice and any required consent mechanism will be updated before use.
9. Your rights
- Depending on applicable law, individuals may have rights to access, correct, erase, restrict or object to processing, receive portable data, and complain to a supervisory authority. In Sweden, the supervisory authority is Integritetsskyddsmyndigheten (IMY).
- Where the request concerns data that Velora processes only on behalf of a Customer, the request should normally be directed to that Customer, and Velora will assist the Customer as required by the DPA.
10. Automated decision-making
Velora uses AI-assisted processing in the product, but Velora does not use its own controller-side account/billing data to make solely automated decisions producing legal or similarly significant effects about Authorized Users. Customer is responsible for determining whether its own use of Velora output engages any automated-decision requirements applicable to its business.
11. Changes and contact
The current version and effective date of this Notice will be published with the Service. Material changes will be communicated where required. Privacy questions may be sent to privacy@veloratech.live.