
Privacy Policy
Last updated 30 September 2026
This policy explains what personal data Velo collects, why we collect it, and the choices you have. Velo is run by Elysium Designs(“we”, “us”). You can reach us about anything in this policy at velo@elysiumdesigns.in.
1. Two kinds of data
Your account data. This is information about you as a Velo customer. We are its controller.
Your workspace data. This is everything you put into Velo about your own business and clients: client names and contact details, invoices, proposals, messages, files, time entries and so on. You are its controller. We process it only on your instructions, to provide Velo to you. If one of your clients asks us about their data, we will refer them to you.
2. What we collect
- Account: your name, email, password (stored only as a salted hash), business details, and the settings and branding you choose.
- Security: sign-in codes (stored only as one-way digests), sessions, devices you have chosen to trust, failed sign-in attempts, and IP addresses used for rate limiting and abuse prevention.
- Billing: your plan, subscription status and billing dates. Card details go to Dodo Payments and never reach us.
- Workspace content: whatever you create or upload, including anything you type or say to Ask Velo.
- Your clients’ interactions:when your clients open a shared invoice or portal, fill in an intake form, book a call or sign a proposal, we record what they submit and when. E-signatures also record the signer’s email verification, IP address and browser, to make the signature verifiable.
We do not use advertising trackers. We do not sell personal data, and we do not share it for advertising.
3. Why we use it
- To provide Velo: storing your work, sending what you ask us to send, and running the features you turn on. This is necessary to perform our contract with you.
- To keep accounts and the service secure, and to prevent fraud and abuse. This is our legitimate interest.
- To bill paid plans and meet our tax and accounting obligations. This is a legal obligation.
- To send service emails you cannot opt out of, such as sign-in codes, security notices and billing notices. Digests and reminders can be turned off in Settings.
- To answer you when you contact support.
We do not use your workspace content to train AI models, and our AI provider processes prompts only to generate the response.
4. Who we share it with
We use the service providers below to run Velo. Each receives only what it needs for its purpose and is bound by its own data-protection terms.
- Vercel handles hosting the app, and storing uploaded files (Vercel Blob).
- Neon handles the Postgres database that holds accounts and workspaces.
- Resend handles sending email, including sign-in codes, invoices, reminders and digests.
- Groq handles running the AI models behind Ask Velo, voice input, drafted proposals and digests.
- Cartesia handles reading your morning brief aloud.
- Dodo Payments handles selling and billing Velo subscriptions as merchant of record.
- Meta (WhatsApp) handles only if you connect WhatsApp: delivering messages to and from Ask Velo.
- Intuit (QuickBooks) and Xero handles only if you connect one: syncing invoices, clients and payments.
We may also disclose data where the law requires it, or to protect the rights and safety of our users or the public. If Velo is ever sold or merged, this policy will continue to apply to your data.
5. International transfers
We are based in India, and our providers may process data in the United States, the European Union and elsewhere. Where the law requires it, we rely on appropriate safeguards such as standard contractual clauses.
6. How long we keep it
We keep your data while your account is open. Items you delete go to Trash first, so you can restore them. When you delete your account, your account and the workspaces you own are removed from our database immediately. Copies in encrypted backups and uploaded files can persist for a limited time after that. Email us if you want them removed sooner. We keep billing records for as long as tax law requires.
7. Security
Every connection is encrypted with HTTPS. Signing in needs your password plus an email code, unless you have trusted the device. Tokens for connected accounting software are encrypted at rest. Links you share with clients are long and unguessable, and you can revoke them. Anyone who has a link can open it, though, so treat a portal or invoice link like a password.
8. Cookies
We use only essential cookies. They keep you signed in, remember which workspace you have open, remember a device you have chosen to trust, and protect sign-ins to connected services. The app also stores a few display preferences in your browser. There are no advertising or cross-site tracking cookies.
9. Your rights
Depending on where you live, including under the GDPR, the UK GDPR and India’s Digital Personal Data Protection Act, you may have the right to access, correct, export or delete your data, to object to or restrict how we use it, and to withdraw consent. You can do most of this yourself in Settings: Profile, Data (export) and account deletion. For anything else, email velo@elysiumdesigns.in. We will reply within 30 days. You can also complain to your local data-protection authority.
10. Children
Velo is for businesses and is not meant for anyone under 18.
11. Changes
If we change this policy in a way that matters, we will tell you by email or in the app before the change takes effect. The date at the top shows when this policy was last updated.