Legal
Privacy policy
How Vellaci processes personal data for the public website and the application.
Controller. Vellaci (see the imprint for provider identification) is the controller for website visitor data and account data. For customer workspace content (products, SBOMs, vulnerabilities, incidents, evidence), Vellaci acts as processor on behalf of the customer organisation under a data processing agreement.
Data we process. Account data (name, email, authentication factors), organisation profile, workspace content entered by users, usage events (allow-listed, without vulnerability descriptions or evidence content), transactional email delivery records, billing data held by Stripe, and support requests.
Legal bases. Contract performance (providing the service), legitimate interests (security, fraud prevention, product improvement with privacy-conscious analytics), legal obligations (billing records) and consent where required.
Retention. Workspace content is retained according to the organisation's retention setting (default 10 years, reflecting CRA documentation expectations). Audit events are append-only. Accounts and organisations can be deleted through the application; deletion follows a 30-day grace period with a final export.
Subprocessors. Supabase (database, authentication, storage; EU (Frankfurt)); Vercel (application hosting and cdn; EU (Frankfurt) functions; global edge network for static assets); Stripe (subscription billing; EU/US (PCI DSS Level 1)); Resend (transactional email; EU/US); PostHog (product analytics; EU (Frankfurt)); Anthropic (ai assistant (only when enabled by the organisation); US/EU API endpoints; minimised data); Atlassian / Linear / Slack / Microsoft / PagerDuty / GitHub / GitLab (customer-configured integrations; As configured by the customer). The same register is published in the Trust Center and forms part of customer agreements; changes are announced to organisation owners in advance.
Cookies and analytics. The application uses strictly necessary session cookies. The public website sets a first-party, HTTP-only attribution cookie (vellaci_attr, 90 days) recording the campaign or referrer of your first visit so we can attribute sign-ups; it contains no identifier that tracks you across sites. Website analytics run on PostHog (EU, Frankfurt) in cookieless mode: no analytics cookie or local-storage identifier is set, IP addresses are not stored, and visits are aggregated with a daily-rotating, salted hash. No marketing trackers or third-party advertising pixels are used.
Your rights. Access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with a supervisory authority (in Switzerland the FDPIC; in the EU your national authority). Requests: privacy@vellaci.ch. Organisation administrators can export all workspace data at any time from Settings → Data.
Transfers. Primary processing takes place in the EU. Where a subprocessor processes data outside the EU or Switzerland (for example Stripe for billing), transfers rest on the EU Standard Contractual Clauses or an adequacy decision. The current subprocessor register is published in the Trust Center.
Security and disclosure. The controls protecting personal and workspace data are described on the Security page; vulnerabilities in Vellaci itself can be reported through the responsible disclosure programme or security.txt.
Last updated 13 September 2026.