// LEGAL
Privacy Policy
This policy explains what personal information Veyra Security collects, why, how long it is kept, and what rights you have over it.
1. Scope
This policy covers personal information handled by Veyra Security ("Veyra", "we", "us") through this website, the Veyra platform, and our communications with you. It does not cover the contents of customer source code and systems that Veyra analyzes under a customer agreement — that material is customer data, processed on the customer's instructions, and is described in section 7.
2. What we collect
Information you give us
- Contact and enquiry details — name, work email, company name, company website, role, and the content of your message when you submit a form or email us.
- Scoping information — the technical details you provide about your environment when requesting an assessment or applying to the Founding Program.
- Account information — for platform users: name, email, organization, and role.
- Billing information — handled by Stripe. Veyra receives confirmation and limited billing metadata; we do not receive or store full card numbers.
Information collected automatically
- Technical data — IP address, browser type, and pages requested, recorded in server logs for security and abuse prevention.
- Platform activity — for signed-in users, actions taken in the product, recorded in the audit log described in the Trust Center.
This website does not use advertising cookies, third-party analytics trackers, or cross-site tracking of any kind. Fonts are loaded from Google Fonts, which receives the request as a normal web request.
3. How we use it
| Purpose | Basis |
|---|---|
| Responding to your enquiry or assessment request | Steps taken at your request prior to a contract |
| Providing the Veyra platform to a customer | Performance of a contract |
| Securing our systems and preventing abuse | Legitimate interests |
| Sending Veyra Labs research updates | Consent — withdrawable at any time |
| Meeting legal, accounting, and tax obligations | Legal obligation |
We do not sell personal information, and we do not share it with third parties for their own marketing.
4. How long we keep it
| Data | Retention |
|---|---|
| Enquiry and form submissions | 24 months from last contact |
| Assessment scoping information | Duration of the relationship, then 24 months |
| Platform account records | Duration of the account, then 90 days |
| Findings and evidence | 90 days, 1 year, or 2 years by plan — see the Trust Center |
| Audit logs | Minimum 1 year |
| Research subscription | Until you unsubscribe |
| Billing records | As required by law, typically 7 years |
| Server logs | 30 days |
5. Who we share it with
Veyra uses a small number of subprocessors to operate the service. Each is bound by contract to protect the data and to process it only on our instructions. The current list is maintained in the Trust Center, and includes our cloud infrastructure provider, Vercel, Stripe, our email delivery provider, and GitHub.
We may also disclose information where legally required. If we receive a legal demand for customer data, we will notify the affected customer unless legally prohibited from doing so.
6. How we protect it
Encryption in transit and at rest, multi-factor authentication for all staff, least-privilege access reviewed on a schedule, isolated ephemeral analysis environments, tenant isolation enforced at the data layer, and audit logging of security-relevant actions. Full detail is published in the Trust Center.
7. Customer data and our role
Where Veyra analyzes a customer's repositories, applications, and infrastructure under a customer agreement, Veyra acts as a processor and the customer is the controller. Veyra processes that material only to provide the service, only within the scope the customer has authorized in writing, and only for as long as the customer's retention settings permit.
If you are an individual whose personal information appears within a Veyra customer's systems, your relationship is with that company. Please contact them directly; we will support them in responding.
8. Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, to have it corrected, to have it deleted, to object to or restrict processing, to receive it in a portable format, and to withdraw consent at any time.
To exercise any of these, email privacy@veyra.example. We respond within 30 days. We may need to verify your identity first, and will not use that verification information for any other purpose.
If you are in the UK or EEA and are not satisfied with our response, you may complain to your local data protection authority.
9. International transfers
Veyra's infrastructure is located in the United States. Where personal information is transferred from the UK or EEA, we rely on Standard Contractual Clauses or another approved transfer mechanism with each subprocessor.
10. Children
Veyra is a business product and is not directed at children. We do not knowingly collect personal information from anyone under 16.
11. Changes
If we make a material change, we will update the date at the top of this page and notify customers by email before the change takes effect.
12. Contact
Privacy enquiries: privacy@veyra.example
Security matters: security@veyra.example