Skip to content

Privacy notice

What we hold about you as a subscriber, why, on what legal basis, for how long, and how to have it corrected, exported or erased.

Version 2.0Last updated 26 September 2026

01Who we are and how to contact us

This notice is issued by the operator of the Veilux platform ("Veilux", "we", "us"), for the personal data we hold as controller — see the next section for what that means and where it stops. Our registered company name, number and address will be added here (docs/LEGAL.md tracks this as an open item); until then, write to us at [email protected] and we will confirm them.

For anything about this notice or the personal data we hold about you, write to [email protected]. If you are one of a subscribing firm’s own customers rather than a subscriber yourself, see "Two different relationships" below before writing to us — the firm you deal with is usually the right person to ask first.

02Two different relationships

For the firms that subscribe to Veilux, and the people who work there, we are the controller: we decide what personal data we hold about you as a subscriber and why, and this notice is about that data.

For a subscribing firm’s own customers and contacts — the people in its records and its client portal — the firm is the controller and we are its processor. We hold that data only to run the service for the firm, strictly under the firm’s instructions and the data processing agreement. If you are one of a firm’s customers and want to know what a firm holds about you, the firm is who to ask; we help the firm answer, including by giving its customers direct export and erasure tools inside the client portal where the firm has switched them on.

03The personal data we collect, and where it comes from

Directly from you: your name, work email address, job title and phone number where you give them to us — at signup, when a colleague invites you, or when you update your own profile; your password, which we store only as a one-way hash we cannot reverse; a two-factor authentication secret, if you choose to set one up; the settings and preferences you choose; and support requests you raise with us through the account portal.

From your use of the product: a record of the changes you make, which forms part of your firm’s own audit log; sign-in times and the rough location and device a sign-in came from, kept to secure the account and investigate misuse; and, where your firm has switched on two-factor authentication or an API integration, records of that configuration.

From your firm, about your firm: its name, trading address, VAT or tax number and the plan it pays for, given to us by whoever set up or administers the account. Card details are entered directly into our payment processor’s own checkout and never reach our systems; we hold only the resulting subscription and invoice records.

From others, in limited cases: if your firm invites you, the inviter gives us your name and email address so we can send the invitation; if you accept an invitation to sign in as a support session (impersonation) on our side, that access and its stated reason is recorded in your firm’s own audit log, described on the security page.

04How we use it, and our lawful basis

The table below sets out what we use your data for and the UK GDPR / EU GDPR lawful basis we rely on for each. Where the basis is "legitimate interests", we have considered whether that interest is overridden by your own rights and freedoms, and concluded it is not; write to [email protected] if you would like to see that assessment.

Purposes, data used and lawful basis
PurposeData usedLawful basis
Creating and running your account, billing your firmName, email, role, firm and billing detailsPerformance of a contract with your firm
Keeping the service secure, investigating misuseSign-in records, audit log entries, two-factor statusLegitimate interests (ours, and every other tenant’s)
Responding to a support request you raise with usWhatever you tell us in the requestPerformance of a contract with your firm
Sending account and service messagesName, email, what the message is aboutPerformance of a contract; legal obligation for some notices
Sending marketing about Veilux itselfName, emailConsent, or legitimate interests where the law allows soft opt-in, until you opt out
Accounting, tax and financial reportingBilling and invoice recordsLegal obligation
Defending or bringing a legal claimWhatever is relevant to that claimLegitimate interests

05Marketing communications

We send account and service messages — invoices, security notices, password resets, notices about changes to these documents — to every subscriber, because they are necessary to run the account; you cannot opt out of these while your account is active.

We may separately send marketing messages about Veilux itself (product updates, tips, occasional offers) to people who have not opted out. You can turn these off at any time in your own notification preferences inside the product, or through the one-click unsubscribe link every non-mandatory email carries, without affecting the account messages above.

This is separate from messages your own firm sends to its customers through Veilux, which are the firm’s own marketing, sent on the firm’s instructions and under the firm’s own compliance with the Privacy and Electronic Communications Regulations (PECR) — we are the firm’s processor for those messages, not the sender, and our role is limited to delivering them and keeping the delivery log described below.

06Cookies and similar technologies

The cookies and browser storage the product actually uses — a short list, and no analytics or advertising anywhere on the site or in the product — are described in full on the cookie policy.

07Who we share it with

We do not sell personal data, and we do not share it with anyone for their own marketing. We share it with the companies that help us run Veilux — our sub-processors, listed with what each one does and where in the world it happens on the sub-processors page — and, where the law requires it, with a regulator, court or law enforcement body, on request and after checking the request is properly made.

If Veilux’s business is sold or reorganised, personal data may transfer to the new owner as part of that transaction, on the same terms as this notice, and we will tell affected subscribers before that happens if the transaction is one we can disclose.

08Sub-processors

The specific companies that process personal data on our behalf, what each is used for, and where each one is based, are kept up to date on the sub-processors page rather than duplicated and risked going stale here.

09International transfers

We intend to keep subscriber and Business Data hosted in the United Kingdom or the European Economic Area; the specific hosting provider and region will be named on the sub-processors page and in the data processing agreement before any customer’s data is hosted with it, rather than promised in the abstract now.

Where a sub-processor is based outside the UK and EEA — for example a messaging provider used only when a firm switches on a specific integration — the transfer is protected by the UK’s International Data Transfer Addendum to the EU Standard Contractual Clauses, or by the EU Standard Contractual Clauses themselves for EU-originating data, or by another safeguard UK GDPR and EU GDPR recognise as adequate. The sub-processors page states which applies to each vendor.

10How long we keep it

We keep your personal data for as long as your firm’s account is open and you remain associated with it, plus a limited period afterwards for the reasons below.

When a firm closes its account, it enters a 30-day grace period during which the former owner can change their mind and reopen it, or take a final export; after that period the account and the personal data in it — including staff accounts tied only to that firm — are permanently deleted from our production systems, and that deletion is itself logged, without the data it describes. Backups roll off on their own retention schedule after that, described in the data processing agreement.

Billing and invoicing records are kept for the period our own accounting and tax obligations require, ordinarily six years from the end of the financial year they relate to, even after an account closes.

Where you are a contact or lead inside a firm’s own account rather than a subscriber yourself, that firm’s own retention settings and your rights against the firm are what govern how long your data is kept there — see "Two different relationships" above.

11How we keep it secure

Passwords are hashed with bcrypt and never stored or logged in the clear; two-factor authentication is available to everyone and required for the roles that can change money, permissions or settings; every business record is scoped to its own tenant twice over — once in application code and once by a Postgres row-level security policy that refuses a mismatched row even if the application code were wrong. The full, exact list of what is in place today is on the security page.

12Your rights

Under UK GDPR and, where it applies to you, EU GDPR, you have the right to ask us to confirm what personal data we hold about you and give you a copy (access); to correct data that is inaccurate or incomplete (rectification); to have it deleted in some circumstances (erasure); to limit how we use it while a dispute about it is resolved (restriction); to receive certain data in a portable format or have it sent to another provider (portability); to object to processing based on our legitimate interests or carried out for direct marketing (objection); and to withdraw consent at any time where consent is the basis we rely on, without affecting anything done before you withdrew it.

To exercise any of these, write to [email protected]. We will ask enough to confirm who you are, and will respond within one month, extendable by a further two months for a complex request, in which case we will tell you why.

If you are not satisfied with our answer, you have the right to complain to the UK Information Commissioner’s Office (ico.org.uk), or to the supervisory authority in your own EU member state if you are based in the EU. We would rather have the chance to put things right first, so please tell us before you do.

13Automated decision-making

We do not use your personal data to make decisions about you by automated means that have a legal or similarly significant effect on you, without a human involved. If that ever changes, this notice will say so and will describe the logic involved and your right to a human review, before the change takes effect.

14Children

Veilux is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 18 as a subscriber or Authorised User. If you believe a child’s data has reached us, write to [email protected] and we will delete it.

15Changes to this notice

We may update this notice as the product or the law changes. Where a change is material, we will email subscribing account owners at least 30 days before it takes effect; the version number and "last updated" date at the top of this page always show which version is current, and the previous version is available on request.

16Contact us

For anything about this notice, to exercise a right described above, to report a security concern, or for anything else: [email protected].

Questions about this document: [email protected].

Privacy notice · Veilux