Privacy Policy
Version 1.0.0 · Effective from 20 September 2026
Velyora Privacy Policy — data held about you as an account holder or helper
Who is responsible for your data
The controller of your own account, billing, security and correspondence data is Aario Shahbany, Calle Santiago 5, 3º Izq., 38002 Santa Cruz de Tenerife, Tenerife, Spain, tax identifier Z4371744R. Write to privacy@velyora.app about anything in this policy. For the data of members and attendees the Provider is only a processor: your Organisation is the controller of that data, and this policy does not govern it — the Data Processing Agreement (published in Spanish as the Contrato de encargado del tratamiento) does, at https://velyora.app/data-processing.
What your data is used for, and on what basis
Your data is processed for these purposes on these bases. Providing and administering your account: performance of the contract. Taking payment and issuing and keeping invoices: performance of the contract, and the legal obligation to retain accounting records under Spanish tax and commercial law. Sign-in and abuse records and the security measures around them: legitimate interests, those interests being keeping other organisations’ accounts secure and keeping the service available. Answering your support correspondence: performance of the contract and legitimate interests. Product email and published reviews: your consent alone. Withdrawing consent stops only product email and review publication; it does not stop the contract, legal-obligation or legitimate-interest processing. Those interests have been weighed against your own rights and freedoms, and you may object to that processing at any time by writing to privacy@velyora.app. Where you object to the sign-in and security processing, the Provider will consider the objection and answer it with reasons, but may continue that processing where it can demonstrate compelling legitimate grounds that override your interests — keeping other organisations’ accounts secure is capable of being such a ground, because switching the records off for one account creates a gap that affects everyone else. You may complain to the supervisory authority if you disagree with that answer. No decision is taken about you solely by automated means that produces legal effects concerning you or similarly significantly affects you, and your data is not used for profiling.
What you have to provide
To open and keep an account the Provider needs an email address it can reach you at and a name for your organisation. Both are required to perform the contract: without them the account cannot be created or administered. Nothing else about you is required. Everything your organisation records about its members and attendees is its own data, is encrypted on the member’s device, and is not readable by the Provider at any point.
Who receives your data
Your data is disclosed to the hosting supplier, to the payment service provider if your account is paid, to the mail service that delivers email to you, and to a public authority where a legally binding request compels disclosure. The current list is published on the sub-processor list. The Provider does not sell your data, share it with advertisers, or use it to train any model, and will not do so under this policy.
OVH Hispano SL hosts the service in France, and Sendinblue SAS (Brevo), established in France, delivers the email we send you from servers in the European Union. The hosting provider’s remote technical support may be carried out from within the European Union and from Canada and the United Kingdom, both of which the European Commission has decided offer an adequate level of protection; no support access can read member or attendee details, which are encrypted under keys held only on your own devices. Stripe Payments Europe, Limited, established in Ireland, processes payments and hosts data in the United States and certain regulated data in India. The payment service provider acts as an independent controller in respect of payment data, not as a processor on the Provider’s behalf. The only processing outside the European Union that requires a transfer safeguard concerns your billing data: no member or attendee record leaves the European Union, and none reaches the payment service provider. That transfer is made under the payment service provider’s standard contractual clauses and, for the United States, its certification under the EU–U.S. Data Privacy Framework. A copy of those safeguards is available on request to privacy@velyora.app.
How long your data is kept, and how it is destroyed
Your account and profile data is kept while the account exists and is deleted with it. Invoices and the underlying billing records are kept for the period Spanish tax and commercial law requires — at present four years under the Ley General Tributaria and six under the Código de Comercio — and survive deletion of your account. Erasure does not reach them: retention is required by law, and Article 17(3)(b) GDPR permits the Provider to refuse erasure on that ground. Those records contain your billing name, address and tax identifier, and contain no member or attendee data. They are deleted when the statutory period expires. Sign-in and security records are kept for 365 days. Support correspondence is kept for 12 months after the matter closes. Consent records are kept while the consent stands, to evidence it, and for 36 months after you withdraw it. That period is the outer limit in both cases: it is the window in which a dispute about whether consent was given could still be raised.
Deletion removes the records from the live service immediately and irreversibly. Encrypted backups of the service are kept on a rolling 30-day cycle and are then destroyed in their entirety. A deletion is not chased into backups that already exist: a backup taken before your deletion still contains your encrypted records until that backup ages out, which is at most 30 days later. Nobody can read the member and attendee details in those backups, in the live service or anywhere else, because the keys are held only on your own devices.
If nobody signs in to your account for 12 months, and it is neither on an active paid subscription nor within a window earned by past payment, it is deleted in full and irreversibly: your profile, your settings, your events and every attendee record. Signing in is what stops the deletion, by you or by any helper; reading the warning does not. Warning email is sent beforehand, but delivery cannot be verified and a warning may never reach you, so do not rely on it: sign in within the period, or keep your own copy of anything you need.
Email you receive
Commercial email is identifiable as such, identifies the sender and carries a free opt-out route usable at any time. Service messages — notices of changes to these agreements, deletion warnings, invoices and security notices — are not commercial communications and continue whatever your marketing choice.
This optional consent covers occasional email to your own address about the product itself — new features, material changes explained plainly, and new plans becoming available. It does not cover email to any member, attendee or helper, does not cover third-party marketing, and involves no profiling and no sharing of your address. Withdraw it by writing to privacy@velyora.app. We give effect to a withdrawal without undue delay, and in every case no later than 30 days after we receive it. Withdrawal stops future product email and nothing else: invoices, security notices, deletion warnings and notices of changes continue on the basis of performance of the contract, and email sent before withdrawal remains lawful.
Reviews
This optional consent covers publishing a review you write, with your name, your role and your Organisation’s name, on the Provider’s website and marketing pages. It covers no member or attendee data and is not a condition of any plan or feature. Withdraw it at any time by writing to privacy@velyora.app, and the review will be removed from the Provider’s own pages. Removal reaches those pages only: search engine caches, third-party web archives, screenshots, quotations and offline material are beyond recall. Separately, your review text and the role label attached to it are stored readably from the moment you write them — the only free personal text in the system that is not encrypted — so a review you compose but never publish would still be disclosed by a breach.
Your rights
In respect of your own data you have the rights of access, rectification, erasure, restriction of processing, portability and objection. Exercise them by writing to privacy@velyora.app.
These rights concern your own account data. A request from one of your members or attendees about their own details is answered by your organisation, not by the Provider: your organisation is the controller of that data and holds the only keys that can read it. The service provides your organisation with the means to export a single person’s record or the whole of its data. If the Provider receives such a request it forwards it to your organisation without undue delay and does not answer it itself. You will receive an answer within one month, extendable by up to two further months for a complex request, in which case you will be told within the first month.
You may withdraw any consent at any time, as easily as you gave it, without giving reasons and free of charge. Withdrawal takes effect for the future only and does not affect the lawfulness of processing carried out before it. You may complain to the Agencia Española de Protección de Datos (C/ Jorge Juan 6, 28001 Madrid; www.aepd.es), or to the supervisory authority where you habitually live or work.