How Veld handles personal data collected through this website and the portal. Short version: we collect very little, we cannot read your workspace, and we never sell anything.
Last updated: August 2026 — revised when workspace syncing was introduced.
Veld ("we") is a UK data protection practice operating at veldprivacy.co.uk. For personal data collected through this website, Veld is the controller. You can reach us at hello@veldprivacy.co.uk.
This site is a static site hosted on Netlify. We do not run advertising trackers or analytics cookies. Form submissions are processed by Netlify Forms on our behalf; Netlify acts as our processor and its infrastructure may process data outside the UK under appropriate safeguards.
The portal runs three ways, and our role differs between them. In all three, the workspace is encrypted in your browser with a key derived from your passcode or password, and that key is never transmitted to us.
On a synced account we also hold your email address, sign-in timestamps, and the size and revision count of the encrypted workspace. Envelope size is a rough indication of how much work the account holds; we mention it because it is the one thing our records reveal about your activity. Lawful basis: performance of a contract (UK GDPR Art 6(1)(b)).
We never see your card. Card details are entered on a form served by our payment provider and go directly to them; there is no code path in Veld that could receive a card number, which is a property of how the checkout is built rather than a promise about how we behave.
We do ask for a billing address, and a VAT number if your business has one. This is the one piece of information our design cannot avoid collecting: VAT on a digital service is charged according to where the customer belongs, so there is no way to work out the right amount without knowing that. It is a trading address for an invoice. It is held by our payment provider rather than by us, it never enters your workspace, and it has nothing to do with your client records. Our own records keep a customer reference, your plan, and its status — not the address.
Lawful basis: performance of a contract (Art 6(1)(b)) for taking the payment, and legal obligation (Art 6(1)(c)) for keeping the tax records HMRC requires.
This section describes processing that has not started. The assistant is built, no model provider is engaged, and it is not available to anyone. It is described here in advance so you can assess it before it ships. Where a contractual term is stated below, it is a requirement we will meet before switching the assistant on, not one already in force — and when a provider is engaged we will name it here and tell you before that happens.
Your records are not sent to the model. The assistant is given a set of read-only tools it may ask for by name, and those tools run in your browser against your open workspace. Only the result of a tool leaves your device, and each tool is limited in code to a fixed set of fields.
In practice that means the model receives your question, and structured data of this kind: a record type, an internal reference, a due date, a number of days, and an internal reference for the client. It does not receive names of data subjects or client organisations, notes, correspondence, document contents, or any free text you have written. References are your workspace's own random identifiers and carry no meaning outside your browser; the names you read in an answer are substituted back on your own device.
We will not retain any of it. No question, answer or tool result is written to storage, to a log, to a trace or to an error report — that half is built and you will be able to check it. Our contract with the model provider will be required to impose zero retention, no use of your content for training, and processing in a UK/EU region; the assistant will not be switched on under terms weaker than those. What we do keep is a count: how many tokens a request used, when, and which model answered — held to bill you and to reconstruct which version of the system produced an answer you may have relied on. Lawful basis: performance of a contract (Art 6(1)(b)).
The assistant cannot change your records. Every tool it can reach is read-only, so anything it suggests is a suggestion you act on yourself. It can also be wrong; answers cite the records they used so you can check them, and you should.
If you would rather no third party processed anything about your work, leave the assistant off. Every other feature works without it.
Supabase provides the database and authentication for the synced service in a UK/EU region. Supabase receives the same ciphertext we do and likewise cannot read it.
Stripe processes subscription payments and issues invoices. They receive your email address, billing address, VAT number if you give one, and your card details — which reach them directly and never pass through us. Stripe acts as a processor for the payment and as a controller in its own right for its fraud-prevention and regulatory obligations, which is the ordinary position for a payment institution. Nothing about your clients or your workspace is shared with them.
When the AI assistant becomes available, one model provider will additionally process assistant requests. No model provider is engaged at the date of this notice, and none will be added without being named here first. Because changing a sub-processor is a contractual matter rather than an engineering one, we will notify you in advance of any addition or change and you may object.
You can export your workspace at any time from the portal's settings, in an open format. Deleting a synced account deletes the stored envelope with it; a workspace held only on your device is removed by clearing it there.
Enquiries are kept for up to 12 months from last contact, then deleted unless you become a client.
For a synced account, the encrypted workspace and your account details are kept until you delete the account, at which point both go and there is no backup of yours for us to restore from. Assistant usage counts are kept for 24 months for billing and dispute purposes and are deleted with the account. Assistant content is never retained at all, so there is nothing to put a period against.
Billing records — invoices, the address they were issued to, and the payments against them — are kept for six years after the end of the accounting period they fall in, because HMRC requires it. This is the one thing that survives deleting your account, and it is a legal obligation rather than a choice: a request to erase it is one we are not able to grant while the retention period runs.
Because they outlive the account, you can still reach them after it is gone. Sign in at our payment provider's billing portal with the email address the invoices were issued to, and they will send you a link. We deliberately keep no record that would let us identify you there once your account is deleted, so this is the route rather than asking us. Deleting your account also cancels the subscription first: if it cannot be cancelled, nothing is deleted and we tell you, because we will not leave a card being charged for an account that no longer exists.
You have the usual UK GDPR rights — access, rectification, erasure, restriction, objection and portability. Email us and we will respond within one calendar month. If you are unhappy with our handling of your data you can complain to the ICO at ico.org.uk.