Privacy Policy
Last updated: 2 October 2026
This policy is for people who use VEEZCO outside Italy. Italian version: Privacy Policy (italiano).
1. Who we are
The controller of your personal data is VEEZCO ("we"), based in Italy. You can reach us at privacy@veezco.com.
2. Two kinds of data
We process two different kinds of personal data, and this policy covers both:
- data about you, our user — your account and how you use the Service (sections 3–4);
- business contact data shown in the Service — the businesses you find, which can include the names of the people who run them (section 5).
3. Data we collect about you
- Account data: your email address and password (stored only as a cryptographic hash), and the name and company you add to your profile.
- Usage data: the searches you run, the leads you view and save, the credits you use, the contacts you log and their outcomes.
- Technical data: IP address, browser and device type, pages visited — see the Cookie Policy.
- Payment data: handled entirely by Stripe. We never see or store your card details.
- Connected inbox: if you connect a Gmail or Outlook inbox, we keep its address and the access tokens, encrypted. With Gmail we can only send; with Outlook we can also read incoming mail, only to notice when a business you wrote to has replied, so that the next emails of a sequence stop.
4. Why we use it, and on what legal basis
- To provide the Service you signed up for (contract, Art. 6(1)(b) GDPR): searches, audits, lead profiles, your account and your credits, service emails.
- To keep the Service secure and improve it (legitimate interest, Art. 6(1)(f)): fraud and abuse prevention, rate limits, aggregated statistics.
- With your consent (Art. 6(1)(a)): non-essential cookies and marketing emails, if we use them. You can withdraw consent at any time.
- To meet legal obligations (Art. 6(1)(c)): tax and accounting records.
5. Business contact data in the Service
VEEZCO helps businesses find other businesses to work with. The information shown about a business comes from public sources: online business listings and maps, the business's own website, public company registers (such as Companies House in the United Kingdom and the Annuaire des Entreprises in France) and public procurement records (such as USAspending.gov in the United States). It can include a business name, address, phone number, email address, website, technical information about the website and, where a public register lists them, the names of the people who run the company.
We process this data on the basis of legitimate interest (Art. 6(1)(f) GDPR): business-to-business prospecting that uses information the business itself, or a public register, has made public. We do not sell personal data. Data from public registers is shown together with its source and the date it was read.
If your business or your name appears in VEEZCO and you want it corrected or removed, or you object to this processing, write to privacy@veezco.com. We reply within 30 days.
6. Who we share data with
We use these providers to run the Service:
- Vercel — hosting of the web application;
- Our database and authentication — Supabase software running on our own servers in the European Union (Hetzner, Germany);
- Our search workers — servers in the European Union (Scaleway, Italy);
- Stripe — payment processing;
- Resend — delivery of service emails;
- Anthropic and OpenAI — AI processing: understanding the searches you type, and writing or analyzing texts when you ask. They receive only the information that task needs.
We do not sell, rent or give personal data to third parties for their own marketing.
7. International transfers
Some of these providers are based in the United States. Where personal data leaves the European Economic Area, the transfer relies on the safeguards those providers offer, such as the EU-US Data Privacy Framework or the European Commission's Standard Contractual Clauses.
8. How long we keep data
- Account data: for as long as you have an account, plus 10 years for tax obligations on billing records.
- Usage data: 24 months from collection.
- Security logs: 12 months.
9. Your rights
Under the GDPR and the UK GDPR you have the right to:
- access your personal data;
- have inaccurate data corrected;
- have your data erased;
- restrict processing;
- data portability;
- object to processing, including processing based on legitimate interest;
- withdraw your consent at any time.
To use any of these rights, write to privacy@veezco.com. We reply within 30 days. You can also delete your account yourself from your Profile page.
You have the right to complain to a supervisory authority: in the EU, the authority of the country where you live or the Italian Garante per la Protezione dei Dati Personali (garanteprivacy.it); in the United Kingdom, the Information Commissioner's Office (ico.org.uk).
If you are in the United States: we do not sell personal information and do not share it for cross-context behavioral advertising. You can ask us to access or delete your personal information at the address above.
10. Security
We use appropriate technical and organizational measures to protect personal data, including TLS encryption, password hashing, role-based access, encryption of connected-inbox tokens and regular backups.
11. Changes to this policy
We may update this policy. Changes are published on this page with a new date.
12. Contact
For any question about privacy, write to privacy@veezco.com.