Privacy Policy
This Privacy Policy explains how personal data is handled when you visit Veyra Labs, request a demo, create an account, purchase services, submit advertising materials or communicate with us. It is designed for a Poland-based, unregistered business operated personally by its owner and for customers in the EEA, United Kingdom, United States and other markets.
Who is the controller?
The controller responsible for the Website and customer-account data is [FULL LEGAL NAME REQUIRED], an individual operating under the commercial name “Veyra Labs” as an unregistered activity (działalność nierejestrowana) in Poland. This activity is not incorporated and is not entered in CEIDG.
- Controller
- [FULL LEGAL NAME REQUIRED]
- Postal address
- [POSTAL ADDRESS REQUIRED]
- Privacy contact
- privacy@cortexinsider.pl
- Website
- cortexinsider.pl
No data protection officer has been appointed because the current processing does not require one. Privacy requests are handled directly by the controller.
Scope and our data-protection roles
For account, sales, billing, security and relationship-management data, Veyra Labs acts as controller. For personal data contained in advertising videos, customer lists, subtitles, scripts or other files supplied by a business customer, Veyra Labs normally acts as that customer's processor and uses the material only on documented instructions. A separate data processing agreement may be concluded where required.
Customers must have a lawful basis for all people, voices, likenesses, testimonials, contact details and other personal data included in submitted materials. Please do not upload special-category data, children's data or confidential personal records unless this has been expressly agreed in writing.
Personal data we process
| Category | Examples | Source |
|---|---|---|
| Identity and contact | Name, work email, account ID, country | You, your employer or agency |
| Business profile | Company, website, team size, role, ad spend, target markets | You |
| Account and authentication | Login events, confirmation state, role, password-reset records | You and authentication provider; passwords are not visible to us |
| Project and creative content | Videos, audio, images, scripts, subtitles, brand assets, performance notes and localization instructions | You or authorized workspace users |
| Communications | Demo requests, support messages, feedback and revision requests | You |
| Transaction data | Plan, amount, currency, payment status, Stripe customer and transaction identifiers | You and Stripe; we do not store full card details |
| Technical and usage | IP address, browser/device data, timestamps, security logs, pages and consent choices | Your device and service infrastructure |
| Inferences and production notes | Likely market fit, creative requirements, quality-review notes | Our team based on project materials |
We do not intentionally collect government identifiers, precise geolocation, biometric templates, health data or other sensitive personal information through the standard service. We do not purchase personal data from data brokers.
Purposes and legal bases
| Purpose | EEA/UK legal basis |
|---|---|
| Create and secure accounts; provide projects, files, messages and support | Performance of a contract or steps requested before a contract |
| Process orders, subscriptions, invoices, accounting and tax records | Contract and compliance with legal obligations |
| Respond to demo, sales and contact requests | Pre-contract steps and legitimate interest in B2B sales |
| Localize, edit, review and deliver customer creative | Contract; for customer-content data, documented processor instructions |
| Prevent fraud, abuse and unauthorized access; defend legal claims | Legitimate interests in security and legal protection |
| Service analytics and non-essential cookies | Consent where required |
| Direct marketing | Consent where required or legitimate interest for permitted B2B communications; you may object at any time |
Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing. Where data is necessary to create an account, contract or invoice, refusing it may prevent us from providing the relevant service.
AI-assisted production
The current service is human-operated and may use third-party AI tools for tasks such as transcription, translation, voice generation, lip synchronization or video editing only when needed for the ordered project. We aim to disclose material production providers and apply appropriate contractual safeguards before sending customer content to them.
Customer files are not used by Veyra Labs to train general-purpose AI models or for unrelated advertising. Do not assume a vendor offers “no training” or EU-only processing unless this is confirmed in the applicable project terms or data processing agreement. The service does not make solely automated decisions producing legal or similarly significant effects about individuals.
When data is shared
Data may be disclosed only as reasonably necessary to:
- Supabase for database, authentication and private project storage;
- the Veyra Labs deployment and content-delivery infrastructure for secure website hosting;
- Stripe for checkout, subscriptions and payment records when payments are enabled;
- Resend or another configured provider for transactional email;
- ElevenLabs and other disclosed localization, voice, video or AI production providers used for an ordered project;
- professional advisers, insurers and public authorities where lawfully required;
- a successor in a merger, financing, reorganization or sale, subject to appropriate confidentiality and notice.
Service providers may process data only for contracted purposes and under appropriate confidentiality and security duties. We do not sell personal data for money. We do not disclose customer creative to other customers. A current subprocessor list may be requested at the privacy email above.
International data transfers
Veyra Labs is based in Poland, while some providers may process data in the United States or other countries. For transfers from the EEA, we rely as applicable on an adequacy decision, the EU Standard Contractual Clauses, supplementary measures or a lawful Article 49 derogation. For restricted transfers from the UK, we use UK adequacy regulations, the International Data Transfer Agreement/Addendum or another permitted safeguard.
You may request information about the relevant transfer mechanism and a copy of applicable safeguards, with confidential terms redacted where necessary.
How long data is kept
| Record | Typical retention |
|---|---|
| Unconverted demo and sales leads | Up to 24 months after the last meaningful contact |
| Account and company profile | For the account lifetime and normally up to 24 months afterward |
| Project briefs, messages and production metadata | Normally 36 months after project completion |
| Source files and final deliverables | Normally deleted 90 days after completion unless the plan or order states otherwise |
| Billing, tax and accounting records | For the period required by applicable Polish law, ordinarily five years counted under the relevant tax rules |
| Consent and opt-out evidence | For as long as needed to demonstrate compliance and resolve claims |
| Security logs | Normally 12 months unless required for an investigation |
Data may be retained longer where necessary for legal claims, fraud prevention, regulatory duties, a preservation request or an active dispute. Backup copies are removed on the provider's normal secure rotation schedule.
EEA, Polish and UK privacy rights
Depending on the law and circumstances, you may request access, correction, deletion, restriction, portability, withdrawal of consent and objection to processing. You may also ask for information about safeguards used for international transfers and object to solely automated significant decisions (which Veyra Labs does not currently make).
Send a request to privacy@cortexinsider.pl. We may ask for proportionate information to verify identity and authority. Requests are normally answered within one month under the GDPR, subject to lawful extensions. Authorized workspace administrators may also make requests on behalf of their organization.
EEA residents may complain to their local supervisory authority. In Poland, the authority is the President of the Personal Data Protection Office (Prezes UODO), uodo.gov.pl. UK residents may contact the Information Commissioner's Office.
United States state privacy notice
State privacy laws may apply only when statutory thresholds and other conditions are met. To the extent a US state privacy law applies, eligible residents may have rights to know or access, correct, delete and obtain a portable copy of personal data, and to opt out of sale, targeted advertising, certain profiling, or sharing for cross-context behavioral advertising. You may also have a right to appeal a denied request and to use an authorized agent.
California notice at collection
During the preceding 12 months, Veyra Labs may have collected the categories described in Section 3: identifiers, customer-record and commercial information, internet or network activity, professional information, audiovisual content and project-related inferences. These categories are used and disclosed for the business purposes and to the provider categories described above.
Veyra Labs does not sell personal information for monetary consideration and does not knowingly sell or share the personal information of consumers under 16. Unless advertising technology that constitutes “sharing,” “targeted advertising” or a “sale” is enabled later, Veyra Labs does not engage in those activities. If that practice changes, the Website will provide a legally required opt-out method and honor recognized browser-based opt-out signals, including Global Privacy Control, where required. We do not use or disclose sensitive personal information for purposes that require a separate limitation right.
US residents can submit requests through the privacy email. We will not discriminate against you for exercising an applicable privacy right. If we deny an appealable request, our response will explain how to appeal.
Cookies, analytics and browser signals
Essential storage is used for authentication, security, session continuity and saving your privacy choice. Optional analytics or advertising technologies are disabled unless configured and, where required, accepted through the cookie banner. You can change your browser settings or clear site storage at any time.
“Do Not Track” is not a uniform legal or technical standard, so the Website does not currently respond to DNT signals. Where legally required, we will recognize supported universal opt-out mechanisms such as Global Privacy Control for applicable sale, sharing or targeted-advertising choices.
The Website does not currently permit third parties to collect personal data across unrelated websites for behavioral advertising. If analytics or advertising pixels are enabled later, this policy and the consent controls will be updated before non-essential tracking begins.
Children
Veyra Labs is a B2B service intended for adults and is not directed to children under 18. We do not knowingly collect personal information from children under 13, or under a higher local age threshold, without required authorization. If you believe a child supplied personal data, contact us so it can be investigated and deleted.
Security and incident response
We use measures appropriate to the risk, including role-based access, private storage, row-level database controls, signed file links, encryption in transit, access logging, limited service credentials and provider due diligence. No internet service can guarantee absolute security. If a breach creates a legally reportable risk, affected people and authorities will be notified as required.
Changes to this policy
We may update this policy when the service, providers or law changes. The current version and effective date will remain available at this URL. Material changes will be communicated through the service or email where appropriate. Earlier versions may be requested from the controller.
Contact and privacy requests
Email privacy@cortexinsider.pl or write to [FULL LEGAL NAME REQUIRED], [POSTAL ADDRESS REQUIRED]. Please use the subject “Privacy Request” and identify the relevant account or project without sending passwords, payment-card details or unnecessary identity documents.