Data Processing Agreement

Velora processes your shop’s data on your instructions, and only for that.

This agreement covers Article 28 GDPR: what Velora may do with the personal data flowing through your shop, who else touches it, where it is stored, and how long it is kept. It applies automatically to every connected shop — there is nothing to sign for the standard terms.

Draft, not reviewed by counsel. It describes what the product actually does today and is complete enough to send to your own lawyer, but it has not been through ours. The English version governs.
  1. 01Roles and subject matter

    You (the shop) are the controller. Vertexly s. r. o. (“Velora”) is the processor. Velora processes personal data on your documented instructions for one purpose: providing the analytics service described at https://veloraapp.io — attributing orders to advertising channels, measuring the funnel and reporting the results back to you. This agreement forms part of the Terms of Use and applies for as long as Velora processes data on your behalf.

    Data subjectsCategories of personal data
    Visitors to the customer’s shopPseudonymous visitor identifier, page URLs, referrer, UTM and click-id parameters, truncated IP, country, device type, timestamps
    Customers of the customer’s shopOrder identifier, order value and currency, order timestamp, and — only where the customer enables it — a hashed e-mail address used to link repeat orders
    The customer’s own staffName, e-mail address, role, last sign-in time
  2. 02Your instructions

    Your instructions are given by configuring the service (which goal pages count, which attribution window applies, whether contact details are stored at all) and by using its interfaces. Velora will not process the data for any other purpose. If Velora believes an instruction breaches the GDPR or other Union or Member State law, it will inform you without undue delay and may suspend that processing.

  3. 03Confidentiality

    Velora ensures that every person authorised to process the data is bound by confidentiality, whether by contract or statute, and has access only to what their role requires.

  4. 04Security measures

    Data is encrypted in transit (TLS 1.2 or above) and at rest. Access to production data is limited to named personnel, requires individual accounts, and is logged. Site tokens and MCP tokens are stored as salted hashes, never in plaintext, and are shown to you exactly once at issue. Ad-platform OAuth credentials are encrypted with AES-GCM. Backups are encrypted and held for 30 days. Velora reviews these measures at least annually and may change them, provided the level of protection is not reduced.

  5. 05Sub-processors

    You give general authorisation for the sub-processors listed below. Velora will notify you at least 30 days before adding or replacing one, and you may object on reasonable data-protection grounds; if the objection cannot be resolved, you may terminate the affected part of the service and receive a refund of the unused prepaid period. Each sub-processor is bound by data-protection obligations no less protective than these.

    Sub-processorWhat it doesWhere
    Hetzner Online GmbHServer hosting (application, Postgres, ClickHouse)Germany / Finland (EU)
    Google Ireland Ltd.Google Ads API — reads campaign cost for connected accountsEU / USA (SCCs)
    Meta Platforms Ireland Ltd.Meta Marketing API — reads campaign cost for connected accountsEU / USA (SCCs)
  6. 06International transfers

    Velora stores and processes personal data on servers in the European Union. Where a sub-processor transfers data outside the EEA, that transfer relies on an adequacy decision or on the European Commission’s Standard Contractual Clauses together with a transfer impact assessment.

  7. 07Assisting you

    Taking into account the nature of the processing, Velora will assist you in responding to requests from data subjects, and in meeting your obligations on security, breach notification, data protection impact assessments and prior consultation. Deletion and export of a shop’s data are available to you directly from Settings, without needing to ask us.

  8. 08Personal data breach

    Velora will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting your data, and will provide the information you need to notify your supervisory authority.

  9. 09Retention and deletion

    Raw visit data is retained for 3 years (36 months) from collection, then deleted. You may erase all data for a shop at any time from Settings; erasure removes the rows from both the relational database and the raw event store, not merely from the interface. On termination, your data remains available for export for 30 days and is then deleted, unless Union or Member State law requires Velora to keep it.

  10. 10Audit

    Velora will make available the information necessary to demonstrate compliance with Article 28 GDPR and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits take place during business hours, on 30 days’ notice, no more than once a year unless a breach or a supervisory authority requires otherwise, and are subject to confidentiality.

  11. 11Requests from public authorities

    If a public authority — police, a court, a tax or regulatory body, or an intelligence service — asks Velora for personal data processed on your behalf, Velora follows a fixed procedure rather than deciding case by case. Every request is reviewed for legal validity: whether the authority has jurisdiction over Vertexly s. r. o., whether the request is in the form the law requires, and whether it is specific rather than open-ended. A request that fails that review is challenged or refused, and Velora will use available legal remedies to contest a request it considers unlawful, overbroad, or in conflict with EU law. Where a request is valid, Velora discloses the minimum data that satisfies it and nothing further — it does not hand over a database because a single record was asked for. Every request, the reasoning applied, the people involved and what was ultimately disclosed are recorded in writing and kept. Unless legally prohibited from doing so, Velora informs you before disclosing data you control, and where prohibited, informs you as soon as the prohibition lapses. Velora has received no such request to date.

Who you are contracting with

Registered office
Vertexly s. r. o.
Karpatské námestie 10A, 831 06 Bratislava - Rača, Slovak Republic