← Back to Velu

Privacy Policy

Last updated: 14 May 2026 · Operated by Velu · Espoo, Finland · Contact: privacy@velu.fi

Velu is designed with privacy by default. We do not store your inputs, we do not build user profiles, and we do not use your data for advertising. This policy explains exactly how your data is handled when you use Velu's tools.

1. Who we are

Velu is an AI-powered business operations service operated by Henrique Moreira, based in Espoo, Finland. Velu provides five AI-powered tools for B2B sales and customer service teams: email triage, pipeline health reporting, process gap mapping, competitive intelligence and task tracking.

For privacy matters, contact us at: privacy@velu.fi

2. What data we process and why

2.1 Data you input into Velu tools

When you use Modules 1 through 4 (Email triage, Pipeline report, Process mapper, Competitive intelligence), any text you type or paste is transmitted to the Anthropic API to generate a response. This may include business data, operational information or other content you choose to submit.

Legal basis: Legitimate interests (Article 6(1)(f) GDPR) — processing is necessary to provide the service you requested.

Retention: Velu does not store your inputs. Anthropic retains API inputs for up to 30 days for trust and safety purposes, after which they are deleted. Anthropic does not use API inputs to train its models.

2.2 Task data (Module 5)

Tasks you create in the Task & action tracker are stored exclusively in your browser's localStorage. This data never leaves your device and is never transmitted to Velu or any third party. Clearing your browser data will permanently delete all tasks.

Legal basis: Not applicable — no personal data is processed by Velu for this module.

2.3 Technical data

Velu's pages are hosted on Netlify. Netlify may collect basic server logs including IP addresses and page requests for security and performance purposes. This is standard web hosting infrastructure and is covered by Netlify's own privacy policy.

3. Our sub-processors

Velu uses the following third-party services to provide its functionality:

We do not use any advertising networks, marketing trackers or analytics platforms that collect personal data.

4. International data transfers

Velu is operated from Finland (EU). When you use Modules 1–4, your input is transmitted to Anthropic's servers in the United States. This transfer is covered by EU Standard Contractual Clauses (SCCs) as provided in Anthropic's Data Processing Addendum, which constitutes a valid transfer mechanism under GDPR Article 46.

Netlify also operates servers in the United States. This transfer is similarly covered by EU SCCs under Netlify's Data Processing Agreement.

5. Cookies

Velu does not use tracking cookies, advertising cookies or analytics cookies. Netlify may set technical cookies necessary for security and content delivery. These are essential cookies and do not require consent under the ePrivacy Directive.

Module 5 uses your browser's localStorage to store task data locally. This is not a cookie and does not transmit data to any server.

6. Your rights under GDPR

As a person in the EU, you have the following rights regarding your personal data:

Since Velu does not store personal data on its own systems, most requests relate to data held by Anthropic or Netlify. We will assist you in exercising your rights and forward requests to the relevant sub-processor where applicable.

To exercise any of these rights, contact us at: privacy@velu.fi

You also have the right to lodge a complaint with your national supervisory authority. In Finland, this is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto).

7. Data security

All data transmitted between your browser and Velu's tools is encrypted using TLS (HTTPS). Data transmitted to the Anthropic API is encrypted in transit using TLS 1.2 or higher and at rest using AES-256 encryption, as specified in Anthropic's security documentation.

Velu does not maintain databases of user data. The attack surface for a data breach affecting your inputs is therefore minimal.

8. Important warnings

Do not paste sensitive personal data into Velu's tools. This includes names, email addresses, national identity numbers, health information, financial account details or any other special category data under GDPR Article 9. Velu's tools are designed for business operational data, not personal data about individuals.

For business use, you are responsible for ensuring that any data you submit to Velu complies with your organisation's data protection policies and applicable law, including GDPR.

9. Children

Velu is a professional B2B service and is not directed at or intended for use by children under the age of 16. We do not knowingly process data relating to children.

10. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the date at the top of this page. For significant changes, we will add a notice to the Velu landing page. Continued use of Velu after changes constitutes acceptance of the updated policy.

11. Contact

For any privacy-related questions, requests or concerns: