Privacy Policy

Velen Ltd · effective 2026-05-20

This Privacy Policy explains how Velen Ltd(“Velen”, “we”, “us”) processes personal data when you sign up for and use Speed To Lead(the “Service”) and the connected channels that receive messages on your behalf. We're committed to processing your data and your customers' data lawfully, transparently, and with the minimum scope necessary to deliver the Service.

1. Who is the controller

Velen Ltd (registered in England and Wales, registration number [Company number — fill in], registered address [Registered address — fill in], United Kingdom) is the controller of personal data we collect from you, our customer. You — the business using Speed To Lead— are the controller of personal data we process about your end customers' messages, while we act as your processor. A separate Data Processing Agreement (DPA) is available on request from legal@velen.ai.

2. What we collect

From you (account owner)

  • Account data: name, email, password hash (via Clerk), workspace name, business industry.
  • Business profile: services, prices, hours, FAQs, policies, escalation contacts — anything you enter into the onboarding wizard.
  • Knowledge base content: documents, website content, and answers you upload or generate during onboarding interviews.
  • Channel credentials: encrypted OAuth tokens and phone-number identifiers you grant when connecting Gmail, Meta (WhatsApp / Messenger / Instagram), Postmark, or other channels.
  • Billing data: handled by Stripe — we store only a Stripe customer ID and subscription ID, never card numbers.
  • Usage telemetry: per-message logs (agent_runs) including model + token counts + grounding sources, so you can audit every reply the Service sent on your behalf.

From your end customers

  • Message content: the text of messages they send to your channels.
  • Sender identifiers: email address, phone number, WhatsApp ID, Messenger PSID, or Instagram IGSID — whichever the channel surfaces.
  • Conversation metadata: timestamps, channel, conversation thread state.

3. Why we process it (lawful bases)

  • Performance of contract (GDPR Art. 6(1)(b)) — to deliver the Service you signed up for.
  • Legitimate interests (Art. 6(1)(f)) — to keep the Service secure, prevent fraud, and improve features (always balanced against your rights; full Legitimate Interest Assessment available on request).
  • Legal obligation (Art. 6(1)(c)) — tax records, anti-money-laundering checks where applicable.
  • Consent (Art. 6(1)(a)) — for any non-essential cookies or marketing emails, only when you opt in.

4. Subprocessors we share data with

To deliver the Service we share specific, scoped data with the following subprocessors. A full subprocessor register with locations and links to their DPAs is at /subprocessors.

  • Anthropic (US) — language model that generates and verifies replies. Anthropic does not train on API data.
  • OpenAI (US) — embedding generation for the knowledge-base RAG layer. Does not train on API data.
  • Neon (EU, London region) — Postgres database hosting all customer data.
  • Vercel (EU, London region) — application hosting.
  • Clerk (US) — authentication and session management.
  • Postmark (EU servers) — transactional email delivery.
  • Stripe (US/EU) — billing.
  • Meta (US/EU) — for the WhatsApp / Messenger / Instagram channels you connect.

Transfers outside the EU/UK are protected by Standard Contractual Clauses where required.

5. How long we keep your data

  • Account + business profile: kept while your account is active and for 30 days after deletion, then permanently removed.
  • Messages + conversations: kept for 12 months by default; configurable per workspace.
  • Billing records: 7 years (legal requirement).
  • Agent run logs (audit trail): 12 months.

6. Your rights

Under UK GDPR / EU GDPR you have the right to access, rectify, erase, restrict, or port your data, and to object to processing based on legitimate interests. To exercise any of these, email legal@velen.ai. We respond within 30 days.

You can request deletion at any time — instructions are at /data-deletion.

You also have the right to complain to your supervisory authority (the UK Information Commissioner's Office for UK users; your national DPA for EU users).

7. Security

  • TLS in transit, AES-256 at rest (provided by Neon).
  • Strict per-workspace data isolation (every database row carries a workspace ID; queries are auth-scoped).
  • Encrypted credential storage for channel OAuth tokens.
  • Full audit trail of every AI reply sent, visible in your dashboard.

A full security overview is at /security.

8. AI processing

Customer messages are sent to Anthropic for generation and to OpenAI for embedding. Neither provider trains on data sent via their commercial APIs. Anthropic's API Data Usage Policy and OpenAI's Enterprise/API privacy commitments apply.

Every AI-generated reply is grounded by a verifier model that blocks unsupported claims from being sent. Outputs are logged so you can audit them.

9. Cookies

We use strictly necessary cookies for authentication (Clerk session cookies) and for our Meta OAuth nonce. No analytics or marketing cookies are set by default.

10. Children

The Service is for businesses and not directed at children under 16. We don't knowingly collect data from anyone under 16. If you believe we have, email legal@velen.aiand we'll delete it.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified by email or an in-app banner at least 14 days in advance.

12. Contact

For any privacy-related question, including DPA requests, data subject access requests, or to flag a potential breach, email legal@velen.ai.