Privacy notice
Effective 9 October 2026. This notice applies to https://velasocial.app and the Vela Social application at https://app.velasocial.app.
Controller
VELA SOLUTIONS LTD is the controller. Company number 17163051. Registered office: Flat 17 Verum House, 19 New Street, Basingstoke, RG21 7BT, England.
Privacy contact: developer@solutionvela.co.uk. No data protection officer has been appointed.
What the product does
Vela Social is a workspace for a creator or brand. It is used to understand performance, plan content, and manage social channels the person is allowed to connect.
Connecting YouTube or TikTok lets Vela read the account identity, profile statistics, and public video list that the person authorises. This release does not upload videos and does not publish to those platforms.
Personal data we store
Account and workspace: a user id, a password hash, the workspace, the brand, and the membership role.
Connected accounts: connection state and the tokens required to keep that connection working. Tokens stay on the server. They are not shown in the browser and they are not included in an export.
Workspace records: discovery messages, evidence, strategy, plans, approvals, and content metadata for the workspace that created them.
Usage and billing metadata: metered usage inside Vela, a non-secret billing subject, and the current entitlement projection when billing is configured. Vela does not store card numbers. Payment, when it is offered, is handled by the billing provider.
Support and security records: workspace ids and error classes. These records are not a second copy of provider tokens.
Why we use it
We use this data to run the workspace, keep the person inside that workspace, connect accounts they authorise, prepare plans, explain what the product can see, enforce quotas, protect the service, and answer an export or deletion request.
We rely on contract for the workspace the person asks us to provide, on the authorisation they give when they connect a channel, and on legitimate interests for security, abuse prevention, and keeping the service operating.
Providers
The production application and its database are hosted in London, United Kingdom.
Cloudflare provides DNS and email routing for the company domains. Google and TikTok process a connection only after the person authorises that provider. If a paid plan is offered, RevenueCat handles the subscription lifecycle. Vela does not operate the card payment gateway.
A provider processes data in its own regions. This notice does not attach a separate international-transfer assessment.
Retention
Workspace data and media stay until the account is deleted. Conversation evidence and analytics snapshots are kept for up to 24 months. Raw provider payloads, operational logs, and backups are kept for up to 30 days unless an active incident requires longer. Audit events are kept for up to seven years. A deletion tombstone is kept for up to 12 months to show that the deletion happened. Payment failure does not delete the workspace.
Security
A session is scoped to one workspace. Provider secrets stay on the server. Billing notifications are checked before they change a subscription state.
Cookies
The application uses a session cookie so a signed-in person stays signed in. It is not an advertising cookie. This public website does not set an analytics cookie.
AI-assisted features
Discovery and strategy can use a model when one is configured. Model output is assistance. It is not legal, financial, or causal proof. Publishing still requires a person to use the approval action.
Your rights
You can ask for access, correction, erasure, restriction, portability, or to object. Email the privacy contact. A signed-in person can also request an export or deletion from the application.
You can complain to the Information Commissioner's Office in the United Kingdom: ico.org.uk.
Changes
If this notice changes, the effective date on this page changes with it.