Skip to main content
DATA PROTECTION · DESIGNED IN ACCORDANCE WITH GDPR PRINCIPLES

Privacy Policy & Data Shield

Effective Date: September 1, 2026•Framework: GDPR (EU)•Zero Data Retention (ZDR) for sovereign profile
Zero Data Retention (ZDR) Architecture & velora-zdr Profile

The Velora Gateway operates strictly in volatile memory (RAM). Prompt tokens and tool results are processed in-memory and discarded upon completion of streaming.

End-to-End ZDR Design (velora-zdr): For customers requiring strict hardware-level Zero Data Retention and European data residency, Velora provides the velora-zdr virtual key. This restricts routing exclusively to European GPU nodes hosted by Regolo AI (Frankfurt & Milan), intended to ensure zero-disk logging and strict EU jurisdiction across the inference pipeline.

1. Data Controller Identification

The Data Controller responsible for personal data processing is Growth Marketing srl (P.IVA 09899971213), with registered office at Via Ponte di Tappia, 47, Naples, Italy. The controller operates Velora. Contact: Submit a request via contact form — privacy [at] velora.ai.

2. Categories of Data Processed

We distinguish strictly between telemetry metadata and customer context:

  • Context Payload (Source Code & Prompts): Handled ephemerally in RAM. Never written to disk, never used for training models, and never logged.
  • Operational Telemetry: Timestamp, token count pre/post compression, round-trip latency, HTTP status, and tenant identifier. Used exclusively for quota enforcement and billing.
  • Account & Billing Data: Email address and payment identifiers processed via compliant payment processors (e.g. Stripe).
  • Website Forms: Email address, name, company information collected via Beta Signup and Contact forms for pre-contractual measures and support. Data stored on Airtable and processed via Resend for email delivery.

3. Legal Basis for Processing

We process personal data only on the following legal bases under Art. 6 GDPR:

  • Contract performance & pre-contractual measures (Art. 6(1)(b)): Beta trial access, account management, contact form replies and support requests.
  • Legitimate interest (Art. 6(1)(f)): Security and anti-abuse measures, reCAPTCHA v3, honeypot checks, timing verification, security logs (max 30 days), quota enforcement and service stability.
  • Consent (Art. 6(1)(a)): Non-essential analytics such as Vercel Analytics collected only after explicit cookie consent. Consent can be withdrawn at any time via the “Cookie settings” link in our footer, without affecting prior lawful processing.
  • Legal obligation (Art. 6(1)(c)): Accounting, invoicing and payment data retention as required by applicable tax laws via Stripe.

Where we rely on legitimate interest, you have the right to object at any time. We do not carry out automated decision-making or profiling with legal effects under Art. 22 GDPR.

4. Zero Model Training Policy

Velora does not use, and will never use, your codebase, queries, diffs, or completions to train, retrain, or evaluate any public or private AI models. Furthermore, all upstream calls forwarded to commercial providers enforce enterprise zero-data-retention headers where supported.

5. Data Subject Rights (GDPR)

Under Articles 15-22 of the EU General Data Protection Regulation (GDPR), you possess the right to access, rectify, or erase your account data, restrict or object to processing, and request data portability. To exercise these rights, submit a request via contact form — privacy [at] velora.ai.

You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. In Italy, this is the Garante per la protezione dei dati personali — Piazza Venezia 11, 00187 Roma, Italy — www.garanteprivacy.it.

6. Security Standards & Data Sovereignty

All data in transit is encrypted using TLS 1.3 with modern cipher suites. Infrastructure is hosted in European Union regions (Frankfurt, Germany) using cloud providers with established security programs. Dedicated private VPC options are available for enterprise customers on request.

Core processing of AI context compression is performed in RAM with zero logging of prompts, code, or outputs. The sovereign velora-zdr profile routes exclusively to European GPU nodes hosted by Regolo AI (Frankfurt & Milan) with hardware-level zero-disk persistence. Standard plans are hosted in EU regions but use third-party subprocessors for the marketing website and transactional email.

7. Subprocessors & International Transfers

For the marketing website and transactional communications, we engage subprocessors based outside the EU. All transfers are covered by standard contractual clauses or the EU-US Data Privacy Framework where applicable:

  • Vercel Inc. — Hosting & Analytics (USA)
  • Airtable Inc. — Lead storage (USA)
  • Resend Inc. — Transactional email (USA)
  • Google LLC — reCAPTCHA v3 (USA)
  • Google Cloud — Core infrastructure (EU regions)
  • Stripe Inc. — Payments (USA / DPF)
  • Regolo AI — Sovereign ZDR nodes (Germany/Italy)

8. Data Retention

  • Beta signup emails: up to 24 months or until request for deletion.
  • Contact form messages: 12 months after resolution.
  • Security logs and IP addresses: max 30 days.
  • Context payloads from AI gateway: 0 days (RAM-only processing).

Privacy Contact

Growth Marketing srl — Privacy Office (Operates Velora)
Email: privacy [at] velora.ai — submit via contact form
Registered office: Via Ponte di Tappia, 47, Naples, Italy