Privacy Policy
Last updated: 8 August 2026
Draft — not legal advice. Every [PLACEHOLDER] must be filled in and the whole document reviewed by a qualified lawyer in your jurisdiction
before you take a single payment.
1. Controller
[COMPANY_LEGAL_NAME], [COMPANY_ADDRESS], is the data controller for the personal data described here. Contact: [PRIVACY_EMAIL]. [DPO_LINE — include if you have appointed a DPO.]
2. The two roles Vela plays — read this first
Vela handles two very different kinds of data, and your obligations differ for each.
- Your account data — we are the controller. This is the data you give us to have an account.
- The data your connectors touch — we are a processor acting on your instructions. When your connector reads a client list or books an appointment for a named person, that person’s data is yours to be lawful about, not ours. You are the controller and you must have a lawful basis, inform the people concerned, and honour their rights.
For that second category, [DPA_REFERENCE — either “our Data Processing Agreement applies” or “a DPA is available on request”].
3. What we collect as controller
- Account: email address, name if you give one, hashed password or OAuth identifier.
- Billing: subscription state, invoices and a Stripe customer identifier. Card details go directly to Stripe and never reach our servers.
- Usage: connectors created, executions run, timestamps, error and latency data.
- Technical: IP address, browser and device information, server logs.
4. What we hold on your behalf as processor
- Credentials for the sites you connect, encrypted at rest with AES-256-GCM. They are decrypted only inside the execution sandbox, only for the connector they belong to. They are never sent to any AI model and never written to logs.
- Traffic captured during a build: the HTTP requests and responses recorded while you demonstrated the task. This is what makes the connector reproducible and repairable, and it may contain personal data present on the pages you visited.
- Execution inputs and outputs, retained for [EXECUTION_RETENTION_DAYS] days for debugging and repair.
5. Why, and on what basis
- Providing the Service — performance of our contract with you.
- Billing and accounting — contract, and legal obligation for invoice retention.
- Security, abuse prevention and debugging — our legitimate interest in a service that works and is not misused.
- Product email — legitimate interest for service messages; consent for anything promotional, withdrawable at any time.
6. AI processing — what is and is not sent
Building a connector uses AI models from [AI_SUBPROCESSORS] to interpret the page and reconstruct the protocol. Page content and captured traffic from the site you are connecting are sent to those models for that purpose. Credentials and session tokens are never sent. We do not permit these providers to train models on your data. If a connector would require sending data you cannot lawfully disclose to a subprocessor, do not build it.
7. Subprocessors
- [HOSTING_PROVIDER] — hosting and databases ([HOSTING_REGION]).
- Stripe Payments Europe Ltd — payments.
- [AI_SUBPROCESSORS] — connector generation and repair.
- [EMAIL_PROVIDER] — transactional email.
- [MONITORING_PROVIDER] — error monitoring.
We will give [SUBPROCESSOR_NOTICE] days’ notice before adding a subprocessor that handles your data.
8. Transfers outside the EEA
Some subprocessors are established outside the EEA. Those transfers rely on the European Commission’s Standard Contractual Clauses or an adequacy decision, together with the supplementary measures set out at [TRANSFER_DETAILS_URL].
9. Retention
- Account data: for the life of the account, then [ACCOUNT_RETENTION_DAYS] days.
- Credentials and sessions: until you delete them or the connector. Deletion is immediate and irreversible.
- Captured build traffic: for as long as the connector exists, because repair depends on it. Deleted with the connector.
- Execution logs: [EXECUTION_RETENTION_DAYS] days.
- Invoices: [INVOICE_RETENTION_YEARS] years, as required by law.
10. Your rights
Under the GDPR you may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest. Write to [PRIVACY_EMAIL]; we respond within one month. You may also complain to your supervisory authority — in France, the CNIL.
Where the request concerns data your connectors processed, we will refer you to our customer, who is the controller for it.
11. Security
Credentials encrypted at rest with AES-256-GCM. Generated connector code runs in an isolated process with no filesystem access beyond its own temporary directory and no ability to reach private network addresses. Access to production is restricted and logged. No system is perfectly secure; we will notify you and the supervisory authority of a qualifying breach within 72 hours.
12. Cookies
We use strictly necessary cookies for authentication and security. [ANALYTICS_LINE — if you add analytics, describe it here and obtain consent before it loads.]
13. Changes
We will notify material changes by email at least [PRIVACY_CHANGE_NOTICE] days in advance.