Privacy Policy
Last updated 11 August 2026
This policy explains what personal data Veed collects, why we collect it, who we share it with and what rights you have. It covers the Veed web application at veedy.co.uk and the API behind it.
Veed is operated from Romania. We process personal data under the EU General Data Protection Regulation (Regulation 2016/679) and Romanian data protection law. Because we offer the service to businesses in the United Kingdom, the UK GDPR may also apply to some of our processing.
Who is responsible
A.G.S. SRL, registered in Romania under number CUI 47580613 at Bd. Dacia 66, AN38, Ap. 26, Bihor 410001, Romania, is the data controller for the account and usage data described below. For personal data inside content our customers upload, the customer is the controller and we act as their processor.
For questions, requests or complaints, contact aphpdeveloperuk@gmail.com. You may also complain to our supervisory authority, the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP, dataprotection.ro). If you are in the UK you may instead complain to the Information Commissioner's Office (ico.org.uk), and if you are elsewhere in the EU, to your local authority.
What we collect
Account and organisation. Your email address, a hashed password (we never store the password itself), your role, and the organisation you belong to including its name, plan tier and — where you provide one — an FCA firm reference number and billing email.
Session and security. When you sign in we store a hashed session token, your browser's user agent and your IP address. Password reset requests record the requesting IP. These exist to keep accounts secure and to let you see and revoke active sessions.
Content you create or upload. Brand kits, products, campaigns, uploaded images, video and audio, scripts, storyboards and rendered creative. If you upload material containing personal data — a presenter's likeness or voice, for example — we process it on your behalf as part of delivering the service.
Advertising material you import. Where you import a public advertisement by URL, we store the advertisement, the advertiser it is attributed to and when we observed it. This is reference data about businesses and their published advertising, not about you.
Usage and cost records. Which features you use, when, and what each AI call cost. We use this for billing, plan limits and understanding our own unit economics.
Complaint-risk scoring. The text and metadata you submit for scoring, and the risk score and findings returned against it.
Why we use it, and our legal basis
- To provide the service — generating creative, scoring complaint risk, rendering video and storing your work. Legal basis: performance of a contract.
- To keep accounts secure — authentication, session management, rate limiting and abuse prevention. Legal basis: legitimate interests.
- To bill you and enforce plan limits — recording usage and processing payment. Legal basis: performance of a contract.
- To send service messages — email verification, password resets, team invitations and payment notices. Legal basis: performance of a contract.
We do not use your data for advertising, we do not sell it, and we do not profile you for marketing.
AI processing
Generating creative and scoring complaint risk means sending your content to third-party AI providers. Specifically: prompts, scripts and creative briefs go to Anthropic; images and audio for vision, text extraction and voice synthesis go to Google (Gemini). Only the content needed for the task is sent — we do not send your account details, billing information or other customers' data.
These providers process the content to return a result. Their own terms govern what they do with it, and we choose providers that do not train models on submitted content by default. Complaint-risk scoring runs on our own infrastructure rather than a third party.
Sending data outside the EEA
We are established in Romania, so most processing happens inside the European Economic Area — our servers and backups are hosted in the EU. Some processing necessarily happens elsewhere:
- United States — Anthropic and Google process the content sent for creative generation, vision and voice. Stripe processes payments. These transfers rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework.
- United Kingdom — many of our customers are UK businesses, so account and content data reaches them there. The European Commission has decided the UK offers an adequate level of protection, so no additional safeguard is needed.
You can ask us for a copy of the safeguards that apply to any particular transfer using the contact address above.
How long we keep it
Account and organisation records are kept while your account is active. Content you create is kept until you delete it or close your account. Session records expire automatically — access tokens in minutes, refresh tokens after 30 days. Usage and billing records are kept for six years, which is the period UK tax law requires for financial records.
Backups are taken nightly and held offline. Data you delete may persist in a backup for a short period before that backup is rotated out.
How we protect it
Traffic is encrypted in transit with TLS. Passwords are hashed with bcrypt and are not recoverable. New passwords are checked against known breach corpora and rejected if they appear in one. Sign-in attempts are rate limited and repeated failures lock the account temporarily. Each organisation's data is isolated at the database level with row-level security, so one customer's queries cannot reach another's rows.
Your rights
Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to our using it. You can also ask for it in a portable format. To exercise any of these, email aphpdeveloperuk@gmail.com. We will respond within one month.
Changes to this policy
If we change this policy materially — adding a sub-processor, or using data for a new purpose — we will update the date at the top and tell account holders by email before the change takes effect.
See also our Terms of Service.