Privacy policy
Last updated: 21 July 2026
This policy explains how Velo (“we”, “us”) handles personal data. It covers people who visit our website or contact us, the organisations and users who use our product, and the individuals whose data we process when providing the product.
Velo lets an organisation build agents which connect to its tools, act on its data, and communicate with its people. In doing so, Velo builds a curated and traceable knowledge base for the organisation.
1. Our role: controller and processor
For the purposes of the EU/UK GDPR, Israel’s Privacy Protection Law, and other applicable privacy laws, our role depends on the situation:
- We are a controller for personal data relating to our website visitors, people who contact us, and the users and representatives who set up and manage a Velo account. In these cases we decide why and how the data is processed.
- We are a processor for the personal data we access, communicate, or act on inside a customer’s environment and connected tools when we provide the product. That data belongs to the customer, who is the controller. We process it on the customer’s instructions under a data processing agreement (DPA). If your data is processed by us in this way, please contact the relevant customer to exercise your rights or to understand how your data is handled.
2. How Velo is deployed
Velo is available in two forms, and the form determines who holds the data and how much access we have:
- Hosted (SaaS): we operate the environment and process data on the customer’s behalf using our cloud infrastructure and sub-processors. The sections below on sharing (section 7) and international transfers (section 8) apply.
- On-premises: the software runs inside the customer’s own infrastructure. The data stays under the customer’s control, and depending on the configuration we may have little or no access to it. The sections on storage, sharing, and international transfers apply only to the extent that we actually process data, for example support or telemetry that the customer chooses to enable.
The rest of this policy applies to both forms, except where a section states otherwise.
3. Information we collect
3.1 Website visitors and people who contact us
We collect the information you give us directly, such as your name and email address when you sign up for updates or contact us.
3.2 Account and user data
To use the product, individual users within a customer organisation, as well as the organisation’s administrators, may need to set up a Velo account. To do so they provide account details such as name, business email, job title, and authentication credentials.
Where their role requires it, users or administrators also provide credentials or access tokens for the tools Velo will act on (see section 4). We also keep records of the configuration a customer sets up, such as which tools are connected and which actions are permitted.
3.3 Data processed through connected tools (our role as processor)
Velo connects to the tools a customer uses (for example, GitHub, Slack, Notion, or Jira) and, on the customer’s instruction, reads, writes, updates, and acts on the data within them. That data may contain personal data, such as names, email addresses, message content, and any other personal data the customer stores in those tools.
We process this data only to provide the product and only within the scope the customer configures. We do not use it for our own purposes. The customer determines what data Velo may access, what actions it may take, and the legal basis for that processing.
3.4 Communications with users
Velo does not only act on tools; it also communicates with users. For example, it may send messages, updates, requests for approval, and responses to instructions, through channels such as chat, email, the connected tools themselves, or any other internal means of communication. In doing so we process the content of those communications and the identifiers needed to deliver them. Where this happens inside a customer’s environment as part of the service, we act as a processor on the customer’s behalf.
3.5 Agents you build and the knowledge base
Customers build their own agents that use their connected tools, data, and communications to perform tasks. The customer decides what each agent does and what data it uses. Some agents a customer builds may process sensitive personal data, for example a whistleblowing agent. In every case, where an agent processes personal data on the customer’s behalf, we act as a processor on the customer’s documented instructions.
In providing the product, Velo also builds a curated and traceable knowledge base from the organisation’s data and activity, sometimes described as a “company brain”. This may contain personal data. We maintain it on the customer’s behalf as a processor, and each entry and action remains traceable to its source.
4. Setup, access, and credentials
During setup, the organisation grants Velo access to the tools and data it will operate on. The organisation decides the scope of that access: which data Velo may read or change, and which actions it may take. Customers then build agents that use this access to perform tasks and communicate with users.
To make those connections, we store the credentials or access tokens that the organisation or its users authorise. These are stored securely and are used only to perform the connections and actions that have been approved.
Velo performs actions in connected tools (reading, writing, updating, and communicating) as configured by the customer. Where the customer requires it, actions can be subject to human approval before execution.
5. AI model processing
To carry out its functions, Velo sends relevant data to AI model providers. Velo uses the AI providers that the customer configures, under the customer’s own accounts and agreements with those providers. The customer chooses which provider is used and the terms that apply, including whether data may be used to train models. We send only the data needed to perform the task the customer has requested.
6. How we use data and our lawful bases
For data where we are the controller:
- To provide, maintain, and improve the product, and to manage our relationship with customers and users. Lawful basis: performance of a contract and our legitimate interests.
- To send updates and respond to enquiries. Lawful basis: consent or legitimate interests.
- To meet legal and reporting obligations. Lawful basis: legal obligation.
For data where we are a processor, the customer determines the lawful basis. We act only on their documented instructions.
7. Sharing with third parties
We do not sell personal data. We share it only with:
- Sub-processors and service providersalready described in this policy, such as our cloud hosting provider and the tools and AI providers the customer connects. They act under contract, on our or the customer’s instructions. For on-premises deployments, this sharing applies only to the extent we process data at all.
- Authorities or advisers where we are required to by law, or to establish, exercise, or defend legal claims.
- A successor in the event of a merger, acquisition, or sale of assets, in which case personal data may be among the transferred assets.
8. International data transfers
For hosted (SaaS) deployments, we and our sub-processors may process personal data outside your country, including in the EU, the USA, and Israel. Where data is transferred out of the EEA or UK, we rely on an appropriate safeguard, such as an adequacy decision or the relevant Standard Contractual Clauses.
For on-premises deployments, data stays within the customer’s own infrastructure and is not transferred by us, except to the extent the customer enables support or telemetry.
9. Data retention
We keep personal data only for as long as needed for the purpose it was collected, to meet our legal obligations, and to resolve disputes and enforce agreements. In general, we keep it for the duration of the applicable contract and, afterwards, for the legal limitation periods that apply to potential claims (generally up to five years). For data we process on a customer’s behalf, including the knowledge base, we retain and delete it in line with the DPA and the customer’s instructions. For on-premises deployments, retention of the data within the customer’s infrastructure is controlled by the customer.
10. Security
We take reasonable technical and organisational measures to protect personal data against unauthorised access, loss, or misuse, and we limit access to staff who need it. No method of storage or transmission is fully secure, however, so we cannot guarantee absolute security. We will notify the relevant authorities and affected individuals of a data breach where the law requires it.
11. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict its processing, and to withdraw consent where we rely on it. You also have the right to complain to a supervisory authority (in Israel, the Privacy Protection Authority; in the EU or UK, your local data protection authority).
To exercise these rights for data where we are the controller, contact us at support@velowork.io. Where we process your data on a customer’s behalf (see section 1), please contact that customer, as they control the data.
12. Cookies
We do not use cookies on our website.
13. Changes
We may update this policy as the product develops. The “last updated” date above reflects the most recent change.
14. Contact
Questions about this policy:support@velowork.io, Velo, BeALL, 111 Arlozorov St., Tel Aviv, Israel.
