Legal

Privacy policy

Veyra speaks in your name, so you are entitled to know exactly what it holds, where it runs and who else can see it. This is that answer, in plain terms.

Last updated 19 August 2026

Who is responsible for your data

Veyra is operated by JMSystems, based in Marco de Canaveses, Porto, Portugal. Where this policy says we, it means that entity, and it is the controller for the data described in the next section.

For anything to do with this policy, including exercising the rights described below, write to hello@veyrareach.com. That address reaches the people who run the service rather than a queue, and it is the data protection contact: we have not appointed a formal data protection officer, because at our size and for the processing we do the Article 37 conditions are not met.

What this policy covers

This policy covers veyrareach.com and the Veyra application. It explains what happens to information about you when you browse the site, ask for a demo, claim a promotional code, buy a subscription, or use Veyra to run outreach for your business. It does not cover other companies whose sites we link to, each of which has its own policy.

The two roles Veyra plays

Veyra handles personal data in two distinct roles, and they carry different obligations.

As a controller, Veyra decides what happens to data about our own visitors, prospects and customers: the people who write in for a demo, claim a code, or pay for a subscription. Everything in the next section falls under that role.

As a processor, Veyra handles data about your prospects on your instructions, inside the ideal customer profile and the rules you set. In that role you are the controller and Veyra acts for you, under the terms of the data processing agreement.

What we collect, and why

  • Demo and sales enquiries. The site has no contact form. Booking a demo opens your own mail client and writes to hello@veyrareach.com, so we receive exactly what you choose to put in that email, and nothing else.
  • Summer Sweep code requests. Your email address, so the promotional code can be sent to it. The request is checked by Cloudflare Turnstile before it is accepted, and the code email is delivered by Resend.
  • Checkout. Your email address, the plan and billing period you chose, and a Stripe customer record created from that email. Card details are entered inside Stripe and never reach our servers.
  • Product data. When you use Veyra, the account and configuration you create: your ideal customer profile, your voice examples per channel, the mailbox and number you connect, and the pipeline of prospects, replies and meetings that results.
  • Technical data. Request logs kept on our own servers, including IP address, the page requested, timestamp and user agent, for security and abuse prevention. They are held for 90 days and then deleted. There is no hosting company in between: the servers are ours.
  • Abuse prevention. The checkout and code endpoints keep a short, in-memory count of recent requests per IP address so a script cannot hammer them. That counter is discarded whenever the server restarts and is never written to a database.
  • Measurement. Only if you allow it. This site loads no analytics script and no advertising script until you accept the banner, and sets no cookie to measure you before that. Accept and Google Analytics counts your visit; decline and nothing from Google is loaded at all. The cookie notice sets out every third party that can run in your browser, and when.

How your data is used with AI models

Veyra uses language models to draft outreach in your voice, from the evidence it gathered about a company and the examples you gave it. Two commitments apply, and they are the same ones stated everywhere else on this site: your data stays yours, and it is never resold or pooled into someone else's model.

The drafting runs on Anthropic's commercial API. Inputs sent through it are not used to train models, which is the contractual term that matters here, and the transfer is covered by standard contractual clauses. Only what the task needs goes into a prompt: business contact data, the public signals the sweep found, and the voice examples you gave us. The sub-processors page carries the detail.

Who else touches your data

We share personal data only with the vendors needed to run the service, each under a written agreement that binds them to process it on our instructions alone. Every one of them is named on the sub-processors page, with what it does and what data it can see.

We do not sell personal data. We do not share it for anyone else's advertising. We disclose data to an authority only where a valid legal request requires it, and we will tell the affected customer unless we are forbidden from doing so.

Where your data is processed

Veyra is built and hosted in the EU, and the data you and your prospects generate is processed there. Some vendors, payment and email delivery in particular, may process limited data outside the EEA. Those transfers rely on the European Commission standard contractual clauses together with any additional safeguards required.

The application, the database and the market sweep run on hardware we own and operate in Portugal, so the processing itself stays in the EEA. The encrypted off-site backup sits in a European region of Google Cloud Storage, also inside the EEA.

Four vendors can involve processing outside the EEA, and each is covered by the European Commission standard contractual clauses: Stripe for payments, Cloudflare for bot protection, Resend for our own transactional mail, and Anthropic for drafting. WhatsApp messages reach recipients over Meta's platform, which processes outside the EEA under the same clauses. Alongside those clauses we rely on encryption in transit and at rest, and on sending each vendor the minimum data its task needs.

How long we keep things

As a rule we keep personal data only for as long as it is needed for the purpose it was collected for, or for as long as the law requires in the case of records such as invoices. When a subscription ends, product data is returned or deleted according to the data processing agreement.

Sales enquiries and the emails around them are kept for two years from the last exchange, then deleted. Promotional code requests are kept until the offer ends, then deleted. Billing and invoicing records are kept for ten years, because Portuguese tax law requires it. Product data is kept while the subscription runs; after it ends you have 30 days to export, then the live records are deleted and the encrypted backups holding them are overwritten within 90 days. Server logs are kept for 90 days.

How we protect it

Access to production systems is limited to the people who need it to do their work. Payment details never touch our servers: card entry happens inside Stripe. Traffic to the site and to the application is encrypted in transit. Secrets such as API keys live only server side, never in anything sent to your browser.

The full list of technical and organizational measures is an annex to the data processing agreement, and it covers physical security of our own hardware, encryption in transit and at rest, individually attributed production access that is reviewed when roles change, logging and monitoring, tested backup and restore on a 90 day rotation, reviewed changes and current dependencies, confidentiality obligations that survive the end of an engagement, and a defined incident response route.

Your rights, and how to use them

If the GDPR applies to you, you have the rights below. They are free to exercise, and we answer within one month.

  • Access. A copy of the personal data we hold about you, and an explanation of what we do with it.
  • Rectification. Correction of anything inaccurate or incomplete.
  • Erasure. Deletion, where we have no overriding reason or legal duty to keep it.
  • Restriction. A pause on processing while a dispute about accuracy or legitimate interests is resolved.
  • Portability. The data you gave us, in a structured, machine-readable format.
  • Objection. An objection to processing based on legitimate interests, including any direct marketing, which we stop on request.
  • Withdraw consent. At any time, without affecting anything done before you withdrew it.

Write to hello@veyrareach.com to use any of them. We answer within a month, and sooner where we can. If you are unhappy with how we handled a request, you can complain to our supervisory authority, the Comissao Nacional de Protecao de Dados (CNPD), at www.cnpd.pt, Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa, Portugal. You can also complain to the authority where you live or work, if that is elsewhere in the EU.

Where Veyra is acting as a processor for one of our customers, we will forward your request to that customer, who is the controller, and help them answer it.

Children

Veyra is a business tool. It is not directed at children, we do not knowingly collect data about anyone under 16, and any such data we learn about is deleted.

Changes to this policy

When this policy changes materially we update the date at the top of this page and, for changes that affect a paying customer, tell them by email before the change takes effect.

How to reach us

Write to hello@veyrareach.com. A person answers. For contract and billing questions, the terms of service set out who to contact and what to expect.

Bring the hard questions

Data handling, sub-processors, audit trails: put all of it to us before you buy.