Legal
Privacy Policy
Velyon AI is committed to protecting your personal data and your right to privacy. This policy explains what information we collect, how we use it, and your rights under applicable law.
Controller
Who We Are
Velyon AI is an AI automation and bespoke software development agency incorporated and operating in Cyprus. We design, build, and deploy intelligent automation systems, AI agents, and custom software solutions for businesses across Cyprus and the European Union.
For the purposes of the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Cyprus data protection legislation, Velyon AI acts as the Data Controller for personal data collected through our website, communications, and client engagements.
Company
Velyon AI
privacy@velyon.ai
Location
Cyprus, European Union
Registration
Registered under Cyprus law
Data Collection
What Data We Collect
We collect only the personal data that is necessary to provide our services, respond to enquiries, and fulfil our legal obligations. We do not collect data we do not need.
Data you provide directly
- Full name and email address when you submit a contact form or book a call
- Company name, role, and business details when enquiring about our services
- Any information you voluntarily share in messages, emails, or calls with our team
- CV, portfolio links, or professional background when applying for a role
Data collected automatically
- IP address and approximate geographic location
- Browser type, operating system, and device information
- Pages visited, time spent on site, and referral source
- Cookie identifiers and session data (see Cookies section)
Data from third-party sources
- Professional profile information from LinkedIn if you connect or interact with us there
- Contact details lawfully provided by partners or referral sources
Data Use
How We Use Your Data
We use your personal data only for specific, clearly defined purposes. We do not sell your data to any third party, and we do not use it for purposes beyond those described in this policy.
- To respond to enquiries, contact form submissions, and booking requests
- To provide, manage, and deliver our automation and software services to clients
- To send service-related updates, proposals, and project communications
- To process job applications and evaluate candidates for open roles
- To improve our website, services, and user experience through analytics
- To comply with our legal and regulatory obligations under EU and Cyprus law
- To protect our legitimate business interests, including fraud prevention and security
- To send marketing communications, only where you have given explicit consent
GDPR Compliance
Legal Basis for Processing
Under the GDPR, we are required to have a lawful basis for processing your personal data. We rely on the following legal bases:
Contractual necessity
Processing required to deliver our services to clients and fulfil contractual obligations
Legitimate interests
Processing for business development, website analytics, security, and fraud prevention, where your interests and rights are not overridden
Legal obligation
Processing required to comply with EU and Cyprus law, including tax, accounting, and regulatory requirements
Consent
Processing for marketing communications and non-essential cookies, where you have given us clear, explicit, and freely withdrawn consent
Vital interests
Used only in exceptional circumstances where processing is necessary to protect someone's life
Third Parties
Data Sharing & Third Parties
We do not sell, rent, or trade your personal data. We may share data with carefully selected third parties only where necessary and under strict contractual obligations that require them to protect your data.
Categories of third parties we may share data with
- Cloud infrastructure and hosting providers (e.g. AWS, Vercel, or equivalent)
- Analytics and website performance tools (e.g. Google Analytics — anonymised)
- CRM and communication platforms used to manage client relationships
- Payment processors for invoicing and billing (where applicable)
- AI model providers (e.g. OpenAI) where their APIs are used to deliver your contracted service
- Legal, accounting, or compliance advisors where required by law
All third-party processors are bound by Data Processing Agreements (DPAs) and are required to handle your data in accordance with GDPR and applicable data protection law.
Data Transfers
International Data Transfers
Some of our third-party service providers operate outside the European Economic Area (EEA). Where personal data is transferred outside the EEA, we ensure that appropriate safeguards are in place in accordance with GDPR Chapter V. These safeguards include:
- European Commission adequacy decisions for countries deemed to offer equivalent protection
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Binding Corporate Rules where applicable
- Other lawful transfer mechanisms as recognised under GDPR
We do not transfer personal data to countries without an adequate level of data protection unless one of the above safeguards is in place.
Retention
How Long We Keep Your Data
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by law. Our standard retention periods are:
| Data Type | Retention Period |
|---|---|
| Contact form enquiries | 2 years from last contact |
| Client project data | Duration of contract + 5 years |
| Job applications (unsuccessful) | 6 months from application date |
| Job applications (successful) | Duration of employment + as required by law |
| Website analytics data | 14 months (anonymised) |
| Financial and billing records | 7 years (legal requirement, Cyprus tax law) |
| Marketing consent records | Until consent is withdrawn + 1 year |
Once data is no longer required, it is securely deleted or anonymised so it can no longer be linked to an individual.
Your Rights
Your Rights Under GDPR
As a data subject under the GDPR, you have the following rights in relation to your personal data. These rights apply to all individuals whose data we process within the EU and EEA.
Right of access
You have the right to request a copy of the personal data we hold about you, along with information about how it is used (Data Subject Access Request / DSAR)
Right to rectification
You have the right to request correction of any inaccurate or incomplete personal data we hold
Right to erasure
You have the right to request deletion of your personal data where it is no longer necessary, consent is withdrawn, or processing is unlawful (the "right to be forgotten")
Right to restriction
You have the right to request that we limit how we use your data in certain circumstances
Right to data portability
You have the right to receive your personal data in a structured, machine-readable format and to transfer it to another controller
Right to object
You have the right to object to processing based on legitimate interests or for direct marketing purposes
Right to withdraw consent
Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing
Right to lodge a complaint
You have the right to lodge a complaint with the Cyprus Commissioner for Personal Data Protection or the supervisory authority in your EU member state
To exercise any of these rights, please contact us at privacy@velyon.ai. We will respond within 30 days as required by GDPR Article 12.
Minors
Children's Privacy
Our website and services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child under 16, please contact us immediately at privacy@velyon.ai and we will delete the data without delay.
Updates
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable law. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email or via a notice on our website.
We encourage you to review this policy periodically. Continued use of our website or services after any changes constitutes your acknowledgement of the updated policy.
Contact Us
Contact & Data Controller
If you have any questions, concerns, or requests relating to this Privacy Policy or the way we handle your personal data, please contact our team:
privacy@velyon.ai
General enquiries
hello@velyon.ai
Website
velyon.ai
Location
Cyprus, European Union
We take all privacy enquiries seriously and will respond promptly. If you are not satisfied with our response, you have the right to escalate your complaint to the Cyprus Commissioner for Personal Data Protection:
Authority
Office of the Commissioner for Personal Data Protection
Website
dataprotection.gov.cy
Jurisdiction
Republic of Cyprus / EU
Questions about your data?
Our team is happy to answer any questions about how we handle personal data or to help you exercise your GDPR rights.
This Privacy Policy was drafted in compliance with the EU General Data Protection Regulation (GDPR) 2016/679, the Cyprus Law Providing for the Protection of Natural Persons with regard to the Processing of Personal Data (Law 125(I)/2018), and the ePrivacy Directive 2002/58/EC as amended.
Get the latest updates from Velyon.