Privacy Policy
Last updated 1 March 2026
Who we are
Veydria (referred to as Veydria, we, or us) runs a platform that helps teams govern, test, and document their AI systems. This policy explains what personal data we handle, why we handle it, and the choices you have. For personal data our customers send us about their own users, the customer is the controller and we act as a processor under their instructions. That data is governed by our Data Processing Addendum.
Data we collect
- Account data: your name, work email, organization, role, and the sign in identifiers our auth provider returns when you register or accept an invite.
- Billing data: company details and the payment references our billing provider gives us. We do not store full card numbers.
- Usage data: pages viewed, features used, device and browser details, and log data such as IP address and timestamps, used to run and improve the service.
- Agent event data: the inputs, outputs, and metadata you choose to send about your AI systems. This can contain personal data if you include it, so you decide what to send.
- Support data: the content of messages you send us when you ask for help.
How we use data
We use personal data to provide and maintain the service, to authenticate you and secure your account, to process payments, to answer support requests, to send you service messages about your account, to debug and improve the product, and to meet our legal obligations.
Legal bases
Where the GDPR applies, we rely on the following bases: performance of our contract with you to run the service, our legitimate interests in securing and improving the product balanced against your rights, and legal obligation for records we must keep such as tax and accounting data.
Sharing and subprocessors
We do not sell personal data. We share it with the vendors that help us run the service, including our hosting, authentication, billing, and error monitoring providers, and each is bound by a contract that limits use to our instructions. The current list is on the sub processors page. We may also disclose data if the law requires it, to protect our rights and our users, or to a buyer in a merger or acquisition, with notice where we can give it.
International transfers
We are based in the United States, and some of our vendors process data in other countries. Where we move personal data out of the EEA, the UK, or Switzerland, we rely on the Standard Contractual Clauses and add further safeguards where they are needed.
How long we keep data
We keep account data while your account is active and for a limited period afterward, then delete or anonymize it, unless we must keep records for legal reasons. Agent event data is retained according to your plan and settings, and is deleted on request or when your account closes, as set out in the Data Processing Addendum.
Security
We protect data with encryption in transit, access controls, and the append only audit log described on our security page. No system is perfect, but we work to reduce risk and to respond quickly when something goes wrong.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or port your personal data, to object to or restrict some processing, and to withdraw consent. Under the GDPR you can also complain to a supervisory authority. Under the CCPA, California residents can request access and deletion and can opt out of any sale, though we do not sell personal data. To make a request, email privacy@veydria.com. For data we process on behalf of a customer, we will pass your request to that customer.
Children
The service is built for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16.
Changes to this policy
We will update this policy as the product and the law change. If a change is significant, we will give notice in the app or by email. The date at the top shows the current version.
Contact
Questions about privacy? Email privacy@veydria.com.