Purpose first
We describe why data is needed and avoid using it for unrelated purposes.
Global privacy notice
Your work is connected and your privacy stays clear. This policy explains what personal data Veopad handles, why we handle it, who can receive it, and the choices available to people around the world.
We describe why data is needed and avoid using it for unrelated purposes.
Organizations control the workspace content their people place in Veopad.
Anyone can contact us about their data, wherever they live.
01
This policy applies when you visit a Veopad website, create or use a Veopad account, join a workspace, contact us, or otherwise interact with services that link to this policy. “Veopad,” “we,” “us,” and “our” refer to the operator of the Veopad services.
A customer organization generally decides why and how workspace content is handled. For that content, the customer is the controller or business and Veopad acts as its processor or service provider. Veopad independently determines how it handles public website, account administration, billing, security, support, and service-improvement data. Ask your organization first when your request concerns its workspace content.
A customer may provide a separate notice describing its own practices. That notice, and the customer's agreement with Veopad, governs the customer's collection and use of workspace content.
02
The data involved depends on the services, settings, and integrations you use.
Name, email address, profile details, authentication credentials, organization, role, preferences, and account status.
Meetings, tasks, decisions, customer and CRM records, forms, files, messages, support requests, people-operations records, and other content submitted by users.
Plan, subscription, invoice, billing-contact, tax, transaction, and payment-status information. Payment providers handle payment-card details under their own notices.
IP address, device and browser details, timestamps, pages and features used, diagnostic events, cookie identifiers, and security and audit logs.
Messages, feedback, contact requests, survey responses, support history, and communication preferences.
Data authorized from connected services and outputs such as summaries, suggestions, classifications, analytics, and workflow results.
We receive data directly from you; from the organization that manages your workspace; from other workspace users; from connected services you or your organization enable; from service, identity, payment, and security providers; and automatically when you use the services. Customers decide what they submit and must provide any notices or permissions their use requires.
Workspace content may include sensitive or specially protected data if a customer chooses to enter it. Do not submit sensitive data unless your organization has approved that use and configured appropriate access and retention controls.
03
| Purpose | Typical legal basis where required |
|---|---|
| Provide accounts, workspaces, collaboration features, integrations, support, and requested services. | Perform a contract; take requested pre-contract steps; follow a customer's documented instructions. |
| Authenticate users, prevent abuse, protect users and systems, investigate incidents, and maintain audit records. | Legitimate interests in secure and reliable services; contract; legal obligation. |
| Manage subscriptions, billing, tax, account administration, and service communications. | Contract; legal obligation; legitimate business interests. |
| Operate, troubleshoot, analyze, and improve performance, accessibility, reliability, and product experience. | Legitimate interests; consent where the law requires it. |
| Send requested information and permitted product news or offers. | Consent or legitimate interests, depending on the message and location. |
| Comply with law, enforce agreements, establish or defend claims, and respond to valid legal process. | Legal obligation; legitimate interests; protection of legal rights. |
Where we rely on legitimate interests, we consider the purpose, necessity, and impact on people. Where we rely on consent, you may withdraw it at any time without affecting processing that already occurred. We will explain another basis if a specific activity requires one.
04
Workspace administrators choose users, permissions, enabled modules, integrations, content, workflows, and retention settings. They may access, export, correct, restrict, or delete workspace content according to their policies and agreement with Veopad.
If your organization provided your account or your request concerns workspace content, submit the request to that organization. We support customers in responding to verified requests as required by our agreement and applicable law. We may redirect your request to the relevant customer and tell you that we have done so.
06
Veopad and the providers supporting the service may process data in countries other than the country where it was collected. Privacy protections and government-access rules may differ in those locations.
Where applicable law requires a transfer mechanism, we use measures appropriate to the transfer, such as an adequacy decision, approved contractual clauses, or another lawful safeguard. Customers should contact us for information relevant to their service configuration and contractual transfer terms.
07
We retain personal data for the period needed to provide the services and fulfill the purposes described here, including customer-configured retention periods. We also consider contractual commitments, account status, security needs, dispute and claim periods, legal holds, tax and accounting duties, and other legal requirements.
Retention therefore varies by record. When data is no longer required, we delete, de-identify, or isolate it from ordinary use. Residual copies may remain in protected backups until they are overwritten under the applicable backup cycle.
08
We use administrative, technical, and organizational measures designed to protect data, including access controls, authentication safeguards, encryption in transit, logging, monitoring, and recovery practices appropriate to the service. No system can guarantee absolute security. Protect your credentials, use available account-security features, and contact us promptly if you believe an account or workspace has been compromised.
09
Depending on your location, relationship with Veopad, and applicable exceptions, you may have rights to:
To make a request, use our contact page and identify the account, organization, and right involved. We may need information to verify your identity and authority while avoiding collection of unnecessary identification. An authorized agent may submit a request where local law permits. We will not discriminate against you for exercising a privacy right.
You can unsubscribe from marketing email using the message link. Essential account, security, billing, and service notices are not marketing and may continue while you use the service.
10
The sections above describe typical purposes and legal bases. You may contact your local supervisory authority and may have rights to object where processing relies on legitimate interests or concerns direct marketing. Required controller, representative, and transfer details depend on the Veopad entity and service arrangement applicable to you.
State law may provide rights to know, access, correct, delete, or obtain a copy of personal data and to opt out of defined sales, sharing, targeted advertising, or profiling. It may also allow an appeal. We process requests according to the law that applies and the role in which we hold the data.
Under the LGPD, eligible individuals may request confirmation, access, correction, anonymization, restriction, portability, deletion, information about sharing, or a review of certain automated decisions, and may contact the national authority.
You may request access to or correction of personal data and challenge our handling of it. Where processing relies on consent, you may withdraw consent subject to legal and contractual limits.
Eligible data subjects may have rights to be informed, object, access, correct, erase or block, obtain portability, complain, and seek damages under the Data Privacy Act and applicable guidance from the National Privacy Commission.
You may request access to and correction of personal information and complain to us or the relevant privacy regulator. Cross-border disclosures are handled according to the safeguards required by applicable law.
Local law may provide additional rights, different definitions, or exceptions. Nothing in this policy limits a right that cannot lawfully be limited.
12
Veopad is a business service and is not directed to children. Do not create an account or submit a child's personal data unless an authorized organization has determined that the processing is appropriate and has supplied all notices, permissions, and safeguards required by law. Contact us if you believe data was submitted inappropriately.
13
Some features may organize information, create summaries, identify patterns, recommend next steps, or automate customer-configured workflows. Outputs can be incomplete or inaccurate and should be reviewed by an authorized person when they affect people or important decisions. A customer controls whether these features are enabled and how their outputs are used within its workspace. Additional notices or choices may apply to a particular feature.
14
We may update this policy as services, practices, or laws change. We will publish the revised version with a new effective date and provide additional notice when a change is material and the law requires it.
Questions or privacy requests
Use the contact form and select the topic closest to your request. Do not send passwords, authentication codes, payment-card numbers, or unnecessary identity documents.
Contact VeopadIf you are not satisfied with our response, you may have the right to contact the privacy regulator where you live or work or where the issue occurred.