Privacy Policy
At Veault, your privacy is our foundation. Our Service is built on a zero-knowledge principle. This means that, technically speaking, we can never view the contents of your vault.
This statement explains what data we process, why we do so, and how we protect your privacy, in accordance with the General Data Protection Regulation (GDPR).
1 Data Controller
The party responsible for the processing of your personal data is:
Leval AS
Asperholen 58A
4329 Sandnes
Norway
Org. number: 935 999 170
For any privacy-related questions or to exercise your rights, please contact us at: privacy@veault.com
2 What Personal Data Do We Process?
We process various types of data, as specified below.
A Data We CANNOT View (Zero-Knowledge)
The contents of your vault belong to you alone.
- Vault contents: All personal information, notes, concepts, and documents you choose to store in your vault.
- Files and Documents: All files you upload.
Important: All this data is encrypted on your device (client-side) using AES-256 encryption before it reaches our servers. We do not hold your encryption keys and have no technical ability whatsoever to decrypt or view your vault contents.
B Personal Data We Do Process (Account and Security Data)
To provide you with the Service, we process the following categories of data:
- Identity Data:
- Email address (for authentication and communication)
- First name and last name
- Language preference
- Market information
- Technical Data:
- Authentication tokens (to securely manage your login session)
- Subscription status and anonymized billing information (managed via Stripe)
- Server and security logs, including IP addresses (for security and fraud prevention)
- Anonymous usage analytics (no personal identification; see Section 4)
- Progress metadata: for each fixed section of your vault (for example Passwords, Documents, Messages), the completion percentage and date of last modification, so we can display a progress indicator to you. This concerns exclusively this metadata, not the content of the sections themselves.
- Lead data (free guide):
- Email address and first name of visitors requesting a free guide via our website
- Verification documents (Veault Access):
- A death certificate and proof of identity uploaded by a trusted contact designated by you to support an unlock request. We recommend crossing out the social security/national identification number on the ID beforehand. These documents are used solely to assess the request and are deleted immediately afterwards; we do not retain them (see Section 7).
- Marketing data (upon consent):
- Click IDs such as a GCLID, which we only store in your browser after your consent via our cookie banner (see Section 4.3), and use to attribute an ad to a conversion
3 Why We Process Your Data (Purposes and Legal Bases)
We process your personal data (category B above) only for specific purposes and based on a valid legal basis (in accordance with Article 6 of the GDPR).
We base our processing on the following three legal bases:
A. Based on the Performance of a Contract (GDPR Art. 6(1)(b))
- Purpose: Providing the secure vault service and managing your account.
- Data: Identity Data, Technical Data.
- Purpose: Authenticating users and securing accounts.
- Data: Identity Data (email), Technical Data.
- Purpose: Processing subscriptions and payments.
- Data: Identity Data, Technical Data (subscription status).
- Purpose: Providing customer support and service communications.
- Data: Identity Data.
- Purpose: Displaying a progress indicator for your vault.
- Data: Technical Data (progress metadata).
- Purpose: Sending the free guide to those who request it.
- Data: Identity Data (email address, first name).
- Purpose: Assessing an unlock request as part of Veault Access.
- Data: Verification documents (death certificate, proof of identity).
B. Based on Legitimate Interest (GDPR Art. 6(1)(f))
- Purpose: Securing the Service, monitoring abuse, and fraud prevention.
- Data: Technical Data (incl. IP logs).
- Purpose: Improving our website and service through anonymous, privacy-friendly analytics.
- Data: Anonymous usage analytics (Vemetric).
C. Based on Your Explicit Consent (GDPR Art. 6(1)(a))
- Purpose: Sending optional marketing communications (newsletters), including the email sequence for those who requested the free guide and gave consent for this via an unchecked box.
- Data: Identity Data (email, name).
- Purpose: Measuring ad effectiveness and conversion attribution.
- Data: Marketing Data, Technical Data.
4 Cookies, Analytics, and Tracking
We distinguish between essential, analytical, and marketing technologies.
4.1 Essential Cookies
We may use functional cookies essential for the operation of the Service (for example, to manage your login session). No consent is required for this.
4.2 Privacy-Friendly Analytics (Default)
We use Vemetric for website analytics. This service was chosen specifically because it uses no cookies and collects no personally identifiable information (PII). It is completely anonymous, GDPR-compliant, and loaded by default based on our legitimate interest.
4.3 Optional Cookies
For the following purposes, we only store items in your browser (cookies or browser storage such as local storage) after you have given consent via our cookie banner:
- Live chat: to offer you the option to use live chat on our website, we place a cookie for this purpose.
- Ad conversion tracking: when you arrive at our website via an advertisement (for example, a Google ad), we store a click ID (such as a GCLID) in your browser. If you subsequently register for Veault, we use this click ID to measure that this registration originated from that ad, and share the click ID and anonymized/hashed data with Google. We never share the contents of your vault or other vault data.
If you refuse consent for these optional purposes, nothing will be stored in your browser for these purposes and no conversion tracking will take place. You can withdraw your consent at any time via our cookie settings or through your browser settings.
5 Sharing of Data (Recipients)
We never sell your personal data. We distinguish two types of recipients.
5.1 Sub-processors (process exclusively on our behalf)
We share your data with the following partners, who are strictly necessary to deliver the Service and process exclusively according to our instructions:
- Stripe (Ireland): For processing all payments and managing subscriptions.
- Amazon Web Services (AWS) (Ireland/Sweden): For hosting our servers and your encrypted data, and for sending support and marketing emails.
- Vercel (EU): For hosting our marketing website.
- Neon (EU region): For the database where we store the contact details of visitors requesting the free guide.
- Vemetric (EU): For collecting anonymous website statistics (does not process personal data).
5.2 Independent Data Controllers (upon your consent)
For ad tracking, only after your consent (see Section 4.3), we share a click ID and/or hashed data with the following parties. They do not receive this data as a sub-processor, but as independent data controllers who determine the purpose and means of their own further processing:
- Google (Google Ads): For measuring ad effectiveness. See Google's own privacy information for how Google processes this data.
6 Data Storage and Transfers
Your privacy and data sovereignty are crucial to us.
6.1 Primary Storage within the EEA
All data necessary for the core functionality of the Service (your account data, your encrypted vault data, the lead data of guide requesters) is stored within the European Union. Our sub-processors (Stripe, AWS, Vercel, Neon, Vemetric) also process this data within the EEA.
Google (see Section 5.2), as an independent data controller, may also process data outside the EEA. This occurs solely on the basis of transfer safeguards established by them, such as the EU-US Data Privacy Framework or Standard Contractual Clauses.
7 Retention Periods
We do not retain your data longer than strictly necessary (data minimization).
- Account and Vault Data: This data is retained as long as you have an active account. Upon a request to delete your account, all this data (including all encrypted vault contents) will be permanently erased from our production systems within 30 days.
- Security logs: Server and security logs (including IP addresses) are retained for a maximum of 90 days.
- Billing and Transaction Data: Data related to your subscription (such as invoices) will be retained, even after deletion of your account, in accordance with statutory (tax) retention requirements (typically 7–10 years).
- Verification documents (Veault Access): A death certificate and proof of identity uploaded with an unlock request are used solely to assess that request and deleted immediately following review. We do not retain these documents.
- Inactivity Policy: An account is considered 'inactive' if there is no active paid subscription period (monthly/yearly) or no 'Lifetime' access active. 30 days after an account reaches 'inactive' status (for example 30 days after the expiration of a trial period or an unrenewed subscription), the account and all associated vault data are permanently deleted.
8 Your Rights
You have full control over your data. You have the right at any time to:
- Access what account data we hold about you.
- Update your profile details (rectification).
- Download your vault data (data portability).
- Permanently delete your account and all your data (right to erasure).
- Manage your subscription via the self-service portal.
- Withdraw your consent for marketing cookies.
- Object to processing based on our legitimate interest.
- Request restriction of processing.
- Lodge a complaint with your local supervisory authority (such as the Data Protection Authority in your country) or the Norwegian supervisory authority (Datatilsynet), if you believe that we are not handling your data correctly.
You can exercise most of these rights directly through your account settings. For other requests, you can contact privacy@veault.com. We will respond as soon as possible, and at the latest within 30 days.
9 Changes to This Statement
If we make significant changes to this privacy statement (for example by adding new trackers or sub-processors), we will notify you via email or a clear notice on our website.