Privacy Policy
1. Controller
The data controller for this service is [LEGAL ENTITY β TODO]. You can reach the operator at security@velora.staging.septagon.dev.
2. Data we process
Account data you provide at registration (name, email); sign-in data from identity providers you choose (for example Google, limited to the profile fields you approve); essential cookies required for authentication and security; and technical logs kept for abuse prevention and reliability.
3. Purposes and legal basis
We process data to provide the service (contract), to keep it secure (legitimate interest), and to send transactional email such as sign-in and account notices (contract). We do not sell personal data.
4. Processors
Email delivery runs through Brevo; authentication can run through Google; hosting and CDN services process traffic data on our behalf. Each processor is bound by a data processing agreement.
5. Retention
Account data is kept while your account is active and deleted or anonymized within [RETENTION PERIOD β TODO] after closure. Security logs rotate after 90 days.
6. Your rights
Depending on your jurisdiction you may have rights of access, rectification, erasure, portability, restriction and objection. Contact security@velora.staging.septagon.dev to exercise them; you may also lodge a complaint with your supervisory authority.