1. Data controller
The data controller is VEYRA, service published under the responsibility of Owen Saint-Val (see the Legal notice). For any question or request regarding your data: contact@veyra.business. No data protection officer has been appointed at this stage; your requests are handled directly at this address.
2. Data collected
| Category | Examples | Source |
|---|---|---|
| Identity and account | First name, last name, email, password (hashed, never readable), profile photo and Google ID if applicable, login dates and devices, IP address | Sign up, Google Sign-In, you |
| Brand profile | Activity, products/services, target audience, objectives, tone, platforms used | Onboarding, Settings |
| Content and media | Topics entered, content, strategies, ideas, plans and visuals generated, scores, calendar, campaigns, files imported into the library, results reported | Your use of the Service |
| Conversations | Messages and images exchanged with the AI Assistant | You |
| Billing | Plan, transaction history, Stripe customer ID — never a card number | Stripe |
| Social media | Encrypted account credentials and access tokens for connected platforms, publication status | Third-party platforms, with your authorization |
| Technical | AI call logs (volume, cost, latency), error logs, security events (rate limiting, anti-abuse), sent email log | How the Service works |
3. Purposes and legal bases
- Provide the Service (personalized generation, score, scheduling, library) — performance of the contract.
- Billing and credit management — contract performance and legal obligations (accounting).
- Security, abuse prevention, and fraud prevention (multiple accounts, rate limiting, moderation, new login alert) — legitimate interest.
- Service notifications (email verification, password reset, quota, renewal, payment failure, publication reminder) — performance of the contract.
- Content Score improvement from aggregated and anonymized results — legitimate interest.
- Email marketing communications (news, tips) — only with your consent, revocable at any time via the unsubscribe link or Settings. No marketing communication is sent without this consent.
4. Subprocessors and recipients
| Subcontractor | Role | Data | Localization |
|---|---|---|---|
| OpenAI (GPT-5.6 Terra) via Emergent | Text generation, moderation | Brand profile, topics, content — transmitted for processing only, not used to train models according to OpenAI API terms | United States (standard contractual clauses) |
| Google Gemini via Emergent | Image analysis and generation | Imported or described images, generation instructions | United States (standard contractual clauses) |
| Stripe | Payments, subscriptions, invoices | Email, amount, customer ID; card data collected directly by Stripe | EU / United States |
| Google (Sign-In via Emergent Auth) | Optional authentication | Email, name, photo | EU / United States |
| Resend | Transactional email sending | Email, notification content | United States (standard contractual clauses) |
| Emergent | Application and database hosting | All Service data | Secure data centers; the exact region depends on the deployment infrastructure and is provided upon request |
| Connected social platforms | Publishing | Content you choose to publish | Depending on the platform |
No data is sold or rented. Transfers outside the European Union are governed by the European Commission’s standard contractual clauses or an equivalent recognized framework.
5. Retention periods
- Account, profile, content, media, conversations: for the duration of the account, then deletion or anonymization under 30 days after account deletion.
- Billing information: 10 years (accounting obligation).
- Technical and security logs: 12 months ; anonymized logs after account deletion: 30 days.
- Social network access tokens: until platform logout or account deletion.
- Inactive accounts: deleted after 24 months without login, after email notification.
6. Your rights
You have the rights of access, rectification, erasure, restriction, objection and data portability, as well as the right to withdraw your consent at any time. You can exercise them directly from Settings (profile editing, data export, disconnecting networks, account deletion) or by writing to contact@veyra.business. We respond within one month. You may also file a complaint with the CNIL (cnil.fr).
7. Security
Encrypted exchanges (HTTPS), hashed passwords, secure session cookies (HttpOnly, Secure), encryption of social media access tokens, user-level data isolation, AI request rate limiting, email alerts for logins from an unknown device, logging without sensitive data (keys, passwords and card numbers are never recorded) and regular database backups.
8. Cookies
VEYRA uses only a session cookie strictly necessary for authentication (7-day duration), exempt from consent. No advertising cookie or third-party audience measurement tool is used. If this were to change, a consent banner would be put in place and this policy updated.
9. Automated decisions
The content score and moderation rely on deterministic rules and AI models. They have no legal effect: blocked content can be rewritten, and you may contest a decision by writing to contact@veyra.business.
10. Changes
Any substantial change to this policy will be notified to you in the app or by email at least 15 days before it takes effect.