Legal
Privacy policy.
Written to be read. The short version: we collect what is needed to run the service and bill you, and in BYOC or air-gapped deployments we cannot see your workload data at all.
Last updated 18 September 2026
01Who we are
Velone Systems, Inc., a Delaware corporation, is the controller for personal data described in this policy. Where you use Velone to process personal data inside agent sessions, you are the controller and we are your processor — those terms are in the Data Processing Addendum rather than here.
02What we collect
Account data you give us: name, work email, company, and role. Billing data handled by our payment processor; we store the last four digits and the billing address, never the full card number.
Service metadata generated by using the platform:
- Session identifiers, timestamps, duration, region, and ring
- Tool names, decisions, and the policy rule that matched
- Approver identity for escalated actions
- Aggregate usage counts for billing
Website data: page views and referrers via privacy-preserving analytics that set no cookies and do not fingerprint. We do not run advertising trackers.
03What we do not collect
In BYOC and air-gapped deployments we do not receive tool arguments, file contents, command output, prompts, model responses, or the contents of your evidence entries. Only scheduling decisions, policy versions, and chain heads cross the boundary.
In the managed service, tool arguments may be processed to enforce argument-level policy. What is retained is governed by your redaction rules; by default argument values are hashed rather than stored.
We never use customer data to train models. We have no model to train.
04Why we process it
To provide the service, which includes scheduling sessions, evaluating policy, routing approvals, and writing evidence. To bill you accurately. To keep the platform secure, including investigating abuse. To support you when you ask.
Our legal bases are performance of a contract for service delivery and billing, legitimate interests for security and product improvement, and consent where required for marketing email.
05Where it lives
Account and billing data is stored in the European Union. Service metadata is stored in the region you select for a session; a session pinned to eu-central does not schedule, snapshot, or log outside the EU.
Transfers outside the EEA or UK, where they happen, rely on Standard Contractual Clauses and the UK Addendum.
06How long we keep it
- Account data: for the life of the account, then 30 days
- Billing records: seven years, because tax law requires it
- Service metadata: 12 months by default, configurable on Enterprise
- Evidence entries: your retention setting, with legal hold available
- Support conversations: two years
- Website analytics: 14 months, aggregated
When you close an account we delete or irreversibly anonymise personal data within 30 days, except records we must keep for tax or legal reasons.
07Who we share it with
Subprocessors listed on our subprocessors page, each under a data processing agreement. We give 30 days' notice before adding one, and you may object.
We do not sell personal data. We have never received a government request for customer data; if we receive one we will notify you unless legally prohibited, and we publish a transparency count annually.
08Your rights
Depending on where you live you may have rights to access, correct, delete, port, restrict, or object to processing of your personal data, and to withdraw consent.
Write to privacy@velone.in and we will respond within 30 days. We will not make you use a form or charge you a fee. If you are unhappy with our response you may complain to your supervisory authority.
09Security
TLS 1.3 in transit and AES-256 at rest. No standing production access for staff; break-glass access requires a second approver and is recorded in the same evidence chain customers can read. Full detail is on our security page.
10Children
The service is for business use and not directed at anyone under 16. We do not knowingly collect data from children.
11Changes
If we make a material change we will email account administrators at least 30 days before it takes effect, and keep the previous version available. Typo fixes do not get an email.
Questions about this document: privacy@velone.in