Legal

Privacy Policy

Effective

⚠️ Draft pending legal review.

This document is a working draft. It has not yet been reviewed by counsel. Customers signing contracts before public launch should email legal@veirox.com for the negotiated version.

1. Who we are

Veirox ("we", "us") is operated by Veirox Contributors. Our principal contact is hello@veirox.com. The Veirox service is hosted at veirox.com.

2. What we collect

Account information

Usage data

Integrations

What we don't collect

3. How we use your data

4. Who we share data with

We use a small set of subprocessors. The subprocessor list is the canonical, current source. Highlights:

We don't sell data to third parties. We don't share data with governments unless legally compelled, and we publish transparency reports of any such requests.

5. Your rights (GDPR / CCPA)

You have the right to:

File a Data Subject Request from the Console at /settings/security, or via the CLI: veirox governance dsr create --subject-email you@example.com --request-type erasure. We respond within 30 days.

6. Retention

Per-org configurable retention periods are enforced for sessions, tasks, audit logs, webhook events, and stored files. Defaults:

Configurable from /console/<org>/settings/governance. PII redaction rules can be applied at write time.

7. Security

See our Security & Compliance page for the full posture. Highlights:

Report a vulnerability: security@veirox.com or see /.well-known/security.txt.

8. Children

Veirox is not directed at children under 16. We do not knowingly collect data from children. If you believe we have, contact us and we will delete it.

9. Changes to this policy

Material changes are announced 30 days in advance via email to org owners. Non-material changes (clarifications, typo fixes) are tracked in this page's git history.

10. Contact