Velo
Back to home

Privacy policy

Last updated: 21 July 2026

This policy explains how Velo (“we”, “us”) handles personal data. It covers people who visit our website or contact us, the organisations and users who use our product, and the individuals whose data we process when providing the product.

Velo lets an organisation build agents which connect to its tools, act on its data, and communicate with its people. In doing so, Velo builds a curated and traceable knowledge base for the organisation.

1. Our role: controller and processor

For the purposes of the EU/UK GDPR, Israel’s Privacy Protection Law, and other applicable privacy laws, our role depends on the situation:

2. How Velo is deployed

Velo is available in two forms, and the form determines who holds the data and how much access we have:

The rest of this policy applies to both forms, except where a section states otherwise.

3. Information we collect

3.1 Website visitors and people who contact us

We collect the information you give us directly, such as your name and email address when you sign up for updates or contact us.

3.2 Account and user data

To use the product, individual users within a customer organisation, as well as the organisation’s administrators, may need to set up a Velo account. To do so they provide account details such as name, business email, job title, and authentication credentials.

Where their role requires it, users or administrators also provide credentials or access tokens for the tools Velo will act on (see section 4). We also keep records of the configuration a customer sets up, such as which tools are connected and which actions are permitted.

3.3 Data processed through connected tools (our role as processor)

Velo connects to the tools a customer uses (for example, GitHub, Slack, Notion, or Jira) and, on the customer’s instruction, reads, writes, updates, and acts on the data within them. That data may contain personal data, such as names, email addresses, message content, and any other personal data the customer stores in those tools.

We process this data only to provide the product and only within the scope the customer configures. We do not use it for our own purposes. The customer determines what data Velo may access, what actions it may take, and the legal basis for that processing.

3.4 Communications with users

Velo does not only act on tools; it also communicates with users. For example, it may send messages, updates, requests for approval, and responses to instructions, through channels such as chat, email, the connected tools themselves, or any other internal means of communication. In doing so we process the content of those communications and the identifiers needed to deliver them. Where this happens inside a customer’s environment as part of the service, we act as a processor on the customer’s behalf.

3.5 Agents you build and the knowledge base

Customers build their own agents that use their connected tools, data, and communications to perform tasks. The customer decides what each agent does and what data it uses. Some agents a customer builds may process sensitive personal data, for example a whistleblowing agent. In every case, where an agent processes personal data on the customer’s behalf, we act as a processor on the customer’s documented instructions.

In providing the product, Velo also builds a curated and traceable knowledge base from the organisation’s data and activity, sometimes described as a “company brain”. This may contain personal data. We maintain it on the customer’s behalf as a processor, and each entry and action remains traceable to its source.

4. Setup, access, and credentials

During setup, the organisation grants Velo access to the tools and data it will operate on. The organisation decides the scope of that access: which data Velo may read or change, and which actions it may take. Customers then build agents that use this access to perform tasks and communicate with users.

To make those connections, we store the credentials or access tokens that the organisation or its users authorise. These are stored securely and are used only to perform the connections and actions that have been approved.

Velo performs actions in connected tools (reading, writing, updating, and communicating) as configured by the customer. Where the customer requires it, actions can be subject to human approval before execution.

5. AI model processing

To carry out its functions, Velo sends relevant data to AI model providers. Velo uses the AI providers that the customer configures, under the customer’s own accounts and agreements with those providers. The customer chooses which provider is used and the terms that apply, including whether data may be used to train models. We send only the data needed to perform the task the customer has requested.

6. How we use data and our lawful bases

For data where we are the controller:

For data where we are a processor, the customer determines the lawful basis. We act only on their documented instructions.

7. Sharing with third parties

We do not sell personal data. We share it only with:

8. International data transfers

For hosted (SaaS) deployments, we and our sub-processors may process personal data outside your country, including in the EU, the USA, and Israel. Where data is transferred out of the EEA or UK, we rely on an appropriate safeguard, such as an adequacy decision or the relevant Standard Contractual Clauses.

For on-premises deployments, data stays within the customer’s own infrastructure and is not transferred by us, except to the extent the customer enables support or telemetry.

9. Data retention

We keep personal data only for as long as needed for the purpose it was collected, to meet our legal obligations, and to resolve disputes and enforce agreements. In general, we keep it for the duration of the applicable contract and, afterwards, for the legal limitation periods that apply to potential claims (generally up to five years). For data we process on a customer’s behalf, including the knowledge base, we retain and delete it in line with the DPA and the customer’s instructions. For on-premises deployments, retention of the data within the customer’s infrastructure is controlled by the customer.

10. Security

We take reasonable technical and organisational measures to protect personal data against unauthorised access, loss, or misuse, and we limit access to staff who need it. No method of storage or transmission is fully secure, however, so we cannot guarantee absolute security. We will notify the relevant authorities and affected individuals of a data breach where the law requires it.

11. Your rights

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict its processing, and to withdraw consent where we rely on it. You also have the right to complain to a supervisory authority (in Israel, the Privacy Protection Authority; in the EU or UK, your local data protection authority).

To exercise these rights for data where we are the controller, contact us at support@velowork.io. Where we process your data on a customer’s behalf (see section 1), please contact that customer, as they control the data.

12. Cookies

We do not use cookies on our website.

13. Changes

We may update this policy as the product develops. The “last updated” date above reflects the most recent change.

14. Contact

Questions about this policy:support@velowork.io, Velo, BeALL, 111 Arlozorov St., Tel Aviv, Israel.