Privacy Policy
Last updated: 22 September 2026
1. Controller
Wael Delacroix, 4 rue Jean Gaspard Vence, 13002 Marseille, France, is the data controller for the personal data described here. Contact: wael.delacroix@gmail.com.
2. The two roles Vela plays — read this first
Vela handles two very different kinds of data, and your obligations differ for each.
- Your account data — we are the controller. This is the data you give us to have an account.
- The data your connectors touch — we are a processor acting on your instructions. When your connector reads a client list or books an appointment for a named person, that person’s data is yours to be lawful about, not ours. You are the controller and you must have a lawful basis, inform the people concerned, and honour their rights.
For that second category, a data processing agreement is available on request at the address above.
3. What we collect as controller
- Account: email address, name if you give one, hashed password or OAuth identifier.
- Billing: subscription state, invoices and a Stripe customer identifier. Card details go directly to Stripe and never reach our servers.
- Usage: connectors created, executions run, timestamps, error and latency data.
- Technical: IP address, browser and device information, server logs.
4. What we hold on your behalf as processor
- Credentials for the sites you connect, encrypted at rest with AES-256-GCM. They are decrypted only inside the execution sandbox, only for the connector they belong to. They are never sent to any AI model and never written to logs.
- Traffic captured during a build: the HTTP requests and responses recorded while you demonstrated the task. This is what makes the connector reproducible and repairable, and it may contain personal data present on the pages you visited.
- Execution inputs and outputs, retained for 30 days for debugging and repair.
5. Why, and on what basis
- Providing the Service — performance of our contract with you.
- Billing and accounting — contract, and legal obligation for invoice retention.
- Security, abuse prevention and debugging — our legitimate interest in a service that works and is not misused.
- Product email — legitimate interest for service messages; consent for anything promotional, withdrawable at any time.
6. AI processing — what is and is not sent
Building a connector uses AI models from OpenAI, Google and DeepSeek to interpret the page and reconstruct the protocol. Page content and captured traffic from the site you are connecting are sent to those models for that purpose. Credentials and session tokens are never sent. We do not permit these providers to train models on your data. If a connector would require sending data you cannot lawfully disclose to a subprocessor, do not build it.
7. Subprocessors
- Google Cloud EMEA Limited — hosting, databases and logs (Google Cloud region us-central1, United States).
- Stripe Payments Europe Ltd — payments (Ireland).
- OpenAI (United States), Google (Google Ireland Ltd) and DeepSeek (China) — connector generation and repair.
- Brevo — Sendinblue SAS, 17 rue Salneuve, 75017 Paris, France — transactional email.
- Google Cloud Logging and Monitoring — server logs and error monitoring.
We will give 30 days’ notice before adding a subprocessor that handles your data.
8. Transfers outside the EEA
Some subprocessors are established outside the EEA. Those transfers rely on the European Commission’s
Standard Contractual Clauses or an adequacy decision, together with the supplementary measures set
out in the providers’ data processing addenda (Google Cloud: cloud.google.com/terms/data-processing-addendum; Stripe: stripe.com/legal/dpa).
9. Retention
- Account data: for the life of the account, then 30 days.
- Credentials and sessions: until you delete them or the connector. Deletion is immediate and irreversible.
- Captured build traffic: for as long as the connector exists, because repair depends on it. Deleted with the connector.
- Execution logs: 30 days.
- Invoices: 10 years, as required by French law.
10. Your rights
Under the GDPR you may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest. Write to wael.delacroix@gmail.com; we respond within one month. You may also complain to your supervisory authority — in France, the CNIL.
Where the request concerns data your connectors processed, we will refer you to our customer, who is the controller for it.
11. Security
Credentials encrypted at rest with AES-256-GCM. Generated connector code runs in an isolated process with no filesystem access beyond its own temporary directory and no ability to reach private network addresses. Access to production is restricted and logged. No system is perfectly secure; we will notify you and the supervisory authority of a qualifying breach within 72 hours.
12. Cookies
We use strictly necessary cookies for authentication, security and your language preference. We do not use advertising or analytics cookies.
13. Changes
We will notify material changes by email at least 30 days in advance.