Privacy policy
How Velma handles personal data: what we collect, why, who helps us, and the rights you have. It also includes our data processing agreement with the companies that use Velma.
In short
- Your company's data belongs to your company. We only use it to run Velma for you.
- We never sell your data, never share it for advertising, and never use it to train AI.
- Velma stores everything in the EU.
- What Velma finds in someone's personal email stays private to that person.
- You can ask for a copy of your data, or for it to be deleted, at any time.
Who we are
Velma is a product from Highgate AS, a Norwegian company (org.nr. 930 718 424 MVA). In this policy, "we" and "us" means Highgate AS. You can reach us about anything in this policy at hello@velmaknows.com.
Your data or ours
Privacy law separates two roles, and we have both:
- Your company's content is everything your company puts into Velma or lets Velma read: conversations, what Velma learns, and documents, email and records from the tools you connect. For this, your company is the controller and we are the processor: we handle it only on your company's behalf and following its instructions. Our data processing agreement below sets out how.
- Accounts, billing and running the service: who signs in, billing details, support emails and security logs. For this, Highgate AS is the controller.
What we collect
When you use Velma
- Your account: your name and email address, and an identifier from Google when you sign in with Google. We never see your Google password.
- Your company's content: what you and your team tell Velma, what Velma learns and you accept, the history of who changed what and when, and what Velma reads from the tools your company connects. Your own conversations with Velma are saved privately to you.
- Access to connected tools: the keys that let Velma read a tool you've connected. They are stored encrypted.
- Your company's AI key: if your company adds its own AI key so routines can run when nobody's computer is on, we store it encrypted and never show it again.
- Technical logs: errors, request times and IP addresses. The change history also notes the IP address a change came from.
- Billing: your company's name, organisation number, VAT number and who receives the receipts. Card details go straight to our payment partner, Creem; we never see them.
- Support: what you write when you email us.
- The waitlist: if you join it, your email, company name, language and what kind of computer you're on, so we can let you in when it's your turn.
What we don't collect
When you use your own Claude or ChatGPT subscription with Velma, you sign in to it on your own computer. We never see, store or pass on that login.
Why, and on what basis
| What we do | Legal basis (GDPR) |
|---|---|
| Create your account, run Velma and give you support | Our contract with you or your company (art. 6(1)(b)) |
| Process your company's content | On your company's instructions, as its processor (art. 28) |
| Keep Velma secure, prevent misuse and fix errors | Our legitimate interest in a safe, working service (art. 6(1)(f)) |
| Keep the waitlist and tell you when it's your turn | Steps you ask for before an agreement (art. 6(1)(b)) |
| Take payments and keep accounting records | Legal obligation under the Norwegian Bookkeeping Act (art. 6(1)(c)) |
| Count how Velma is used, in anonymous totals | Our legitimate interest in improving Velma and planning our prices (art. 6(1)(f)) |
| Tell you about important changes to Velma | Our contract with you (art. 6(1)(b)) |
We don't send marketing emails unless you've asked for them, and you can stop them at any time.
AI and your data
- We never train AI on your data, and we only use AI providers that contractually agree not to train on it either.
- Your own AI: when someone uses their own Claude or ChatGPT subscription, or Velma runs a routine with your company's own AI key, what's needed for the job goes to that AI provider, under your agreement with them.
- The AI that comes with Velma: when you use it, we send the question and what's needed to answer it to the AI provider listed under subprocessors, only to answer it.
- Personal email: when someone connects their own email, Velma looks for what's useful for the company. Once an email has been used or skipped, its text is deleted, and emails that aren't relevant are deleted entirely. Velma doesn't keep a copy of your inbox. What it finds stays private to that person until they choose to share it.
- A person decides: what Velma learns is suggested first. Nothing becomes part of what Velma knows until someone on your team accepts it.
Where your data is stored
Velma's servers and database are in France, and backups in another EU data centre, all with Scaleway, a French company. We don't store your company's content outside the EU/EEA.
AI providers, and Google when you sign in with Google, may handle data outside the EU/EEA. When that happens, the transfer is protected by the EU Commission's adequacy decision for the United States (the EU-US Data Privacy Framework) or by the EU's standard contractual clauses.
Subprocessors
These companies help us run Velma and may handle personal data for us. Each one is bound by a data processing agreement with us.
| Company | What they do for us | Where |
|---|---|---|
| Scaleway SAS | Servers, database, backups and file storage | France (EU) |
| Anthropic (Anthropic Ireland, Limited) | The AI that comes with Velma: answers questions and runs routines when you use it | United States |
When you sign in with Google, Google confirms who you are under its own privacy policy. It isn't our subprocessor.
Payments are handled by Creem (Armitage Labs OÜ, Estonia), which sells Velma subscriptions as our merchant of record. Creem handles the payment details you give it under its own privacy policy, as a separate controller, and tells us what we need to give you access: your plan, whether you've paid, and who the receipts go to.
The tools your company connects to Velma, like Google Drive, Gmail or your accounting system, are not our subprocessors. Your company uses them under its own agreements with them, and Velma reads from them on your company's behalf.
How long we keep it
- Your company's content: as long as your company has Velma. When a subscription ends, we delete it within 30 days. After a free trial that doesn't become a subscription, we keep it for 30 days in case you change your mind, then delete it. Copies in backups disappear within a further 30 days.
- Personal email: an email's text is deleted once Velma has used or skipped it. Its title and link are kept, so a new reply can be picked up, until the person disconnects their email or leaves the company.
- Your account: until you're removed from your company's Velma, or the company stops using Velma.
- Technical logs: up to 90 days.
- Usage figures: we keep totals, like how many questions are asked in a month, with no way to tell which person or company they came from. They help us improve Velma and plan our prices.
- Receipts, invoices and accounting records: 5 years after the end of the financial year, as the Norwegian Bookkeeping Act requires.
- Support emails: up to 2 years after we last heard from you.
- The waitlist: until you start using Velma or ask to be taken off, and no longer than 12 months after Velma opens.
How we protect it
- Each company's data is walled off from every other company's in the database itself, not just in our code.
- Data is encrypted on its way to and from Velma. The database and its backups are encrypted, and keys to your connected tools and AI are encrypted again on their own.
- Every change is logged with who made it and when.
- Only a small number of people at Highgate AS can reach production systems, and only when needed to run Velma or help you.
Your rights
You have the right to see the personal data we hold about you, have it corrected or deleted, limit or object to how we use it, and get a copy in a format you can take elsewhere. Email hello@velmaknows.com and we'll answer within 30 days.
If your request is about your company's content, where we are the processor, we'll pass it to your company and help it answer.
If you think we handle your data wrongly, you can complain to the Norwegian Data Protection Authority, Datatilsynet, or the data protection authority where you live. We'd appreciate the chance to fix it first.
This website
This website uses no cookies, no analytics and no tracking. If you switch between light and dark mode, your choice is saved in your own browser, and is never sent to us. Everything on this site, fonts included, is served from our own hosting in the EU.
Data processing agreement
This section is the data processing agreement between Highgate AS (the processor) and each company that uses Velma (the controller), as required by article 28 of the GDPR. It applies automatically as part of our terms of service. Companies that need a signed copy can ask for one.
1. What we process
The personal data in your company's content (see What we collect), such as names, contact details, roles, what people have written, and details of customers and deals. It concerns your employees, customers, suppliers and other contacts. We process it to provide Velma, for as long as your company uses Velma. Velma isn't made for sensitive data, such as health information, so please don't add it unless you need to.
2. Only on your instructions
We process your company's content only to provide Velma as described in our terms, and following your documented instructions, including how you set up and use Velma. If we believe an instruction breaks data protection law, we'll tell you.
3. Confidentiality
Everyone at Highgate AS who can access your company's content is bound by confidentiality.
4. Security
We keep appropriate technical and organisational security measures in place, including those described in How we protect it, and review them regularly.
5. Subprocessors
You authorise us to use the subprocessors listed above. We'll tell you at least 30 days before adding or replacing one, by updating this page and emailing your company's account owner. If you object on reasonable data protection grounds and we can't resolve it, you can end your subscription and get a refund for the time you've paid for but not used. We hold every subprocessor to the same obligations as this agreement, and are responsible for their work.
6. Helping you
We help you answer requests from people who use their privacy rights, and help with security, impact assessments and consultations with authorities, where it concerns Velma.
7. Breaches
If a security breach affects your company's content, we'll tell you without undue delay, and no later than 48 hours after we become aware of it, with what we know and what we're doing about it.
8. When you leave
When your company stops using Velma, we can give you a copy of your content on request, and then delete it as described in How long we keep it, unless the law requires us to keep it.
9. Checks
We'll give you the information you need to show that we keep this agreement, and allow reasonable audits, with reasonable notice, at your cost, and no more than once a year unless there's been a breach or an authority requires it.
Changes and contact
If we change this policy, we'll update the date at the top. If a change matters to you, we'll also email your company's account owner before it takes effect.
Questions? Write to hello@velmaknows.com.