Privacy policy
Last updated 31 July 2026 · draft placeholder, not final
1. About this policy
This is a draft privacy policy prepared for legal review — it is not yet a final, lawyer-approved instrument, and it should not be relied on as one until that review is complete. It is written to describe what the Veela platform actually does today, not what a generic template says a company in this position should do. Where a fact needs the reviewing lawyer or Veela’s owner to confirm before this page is finalised, it is marked [REVIEWER: confirm].
This policy describes how Veela AI Pty Ltd (Veela) handles personal information collected through the Veela platform, including officer and member details drawn from your company register; trustee, member, beneficiary and adviser details in a Trust workspace; account information for your users; uploaded documents; and content you send to Ask Veela or the drafting agents. We handle personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
2. What we collect
- Account details: name, email address, password (stored as a hash, never in plain text), role, and the companies or trusts you act for.
- Company and register data:ACN/ABN, registered office, principal place of business, and officer, member and holding information (name, address, entity type, security class, units held, vesting) mirrored from or entered against your company’s share and option registers.
- Officer and member personal information, which can include date of birth and residential address — most commonly captured when you upload an ASIC company statement for onboarding or register import (see section 5, AI processing, on how that document is handled).
- Trust and SMSF records: trust name, type, ABN, deed details, trustees, corporate-trustee directors, SMSF members, beneficiaries, professional advisers, assets, valuation evidence, decisions, signatures and compliance tasks. Veela does not ask for or provide a structured field for tax file numbers or director identification numbers.
- Uploaded documents, such as constitutions, shareholders’ agreements, ASIC statements, trust deeds, financial statements, ownership evidence and valuer reports, and the text extracted from permitted documents for search, drafting context and Ask Veela.
- Usage data: drafts requested, questions asked of Ask Veela, and the resulting agent runs and approvals, kept as part of the immutable minute-book and audit-log record.
- Billing informationprocessed by Stripe, our payment provider — card details go directly to Stripe and never touch Veela’s servers; we hold subscription status and invoice history.
- Optional Open Banking information:if a Trust owner enables Basiq, we store the provider user, connection and account identifiers needed to operate the connection, together with institution/account labels, currency, observed balances and observation times. Consent is completed in Basiq’s hosted interface. Veela never receives or stores bank login credentials.
- Optional market and property information: instrument symbols and requested valuation dates sent to the enabled market-data provider, and property addresses, provider property/valuation identifiers and licensed valuation facts used by an enabled property workflow.
- Document and report download records: when someone downloads a document or professional handover pack, Veela records who they were, which workspace and record were involved, the seat they held, and when. Owners and admins can use this limited record to answer who has taken a copy. Invitations disclose this logging before acceptance.
- Session data: a session cookie that keeps you signed in, and a workspace-selection cookie that remembers which company or trust you last worked on. See section 10 (Cookies).
3. Why we collect it, and our legal basis
We collect and use this information to provide the company secretarial, trust record-keeping, drafting and reporting services you sign up for, to route permitted drafting and Ask Veela requests to the underlying AI model provider, to maintain your minute book, valuation record and compliance calendar, to bill you, and to communicate with you about your account. We process workspace records on the instructions of the organisation and authorised people responsible for that workspace, and for account and billing information, that it is necessary to perform the contract between you (or your company) and Veela.
4. Disclosure to subprocessors
We share personal information with the third-party service providers who help us run the platform. The full list — what each one is used for, what it can see, and where it runs — is set out on our subprocessors page. In summary: Anthropic (AI model calls), Vercel (hosting and document storage), Neon (our database), Stripe (billing), Resend (transactional email, including your signing links), Sentry (error telemetry, when enabled), Basiq (optional Open Banking), Twelve Data (optional market closes), PropTrack (optional licensed property data), and the named licensed property index or cap-rate suppliers disclosed there. We do not sell personal information. We also share information with the registered agent or company secretary you engage through Veela, with e-signature and register providers you connect (such as Tokeniser, or a bring-your-own e-signature provider), and with partner legal/accounting firms only where you have consented to a referral.
5. AI processing
Veela is built around AI agents that draft resolutions, check drafts, extract register data from documents, and answer questions in Ask Veela. Every one of these calls is sent to Anthropic, our AI model provider. What is sent varies by feature, and we want to be specific about it rather than describe AI processing in the abstract:
- Resolution drafting and the independent Checker send officer and member name, role and email, together with relevant register and constitution extracts — not full addresses or dates of birth.
- ASIC statement import (used during onboarding and register import) sends the entire uploaded ASIC company statement PDF to the model, so it can extract officeholder and member details automatically. ASIC company statements routinely contain officer dates of birth and residential addresses, and this full document — not a redacted or partial extract — is what the model receives.
- Ask Veelaanswers from your constitution, registers and any document you have marked “use as context”. Marked documents are summarised by the model, and that summary is used to ground Ask Veela’s answers to you.
- Trust workflowscan send selected deed or workspace extracts and the user’s question to the model when the feature explicitly says it uses AI. Deterministic valuation calculations, decision validation and signing do not become legal, tax, financial or audit advice merely because Veela records their results.
Production AI use is conditional on Veela confirming the model provider’s executed retention and training terms and making the matching public disclosure. [REVIEWER: confirm the Anthropic commercial terms currently in force and replace this launch condition with the precise approved retention/training statement]. Model calls are not region-pinned in our code (the client is instantiated without a region option), so processing location depends on the provider’s own infrastructure and routing rather than anything Veela configures. See section 6 for how this interacts with our data residency practices, and the subprocessors page for the full disclosure.
6. Data residency and security
Scope of this claim:Veela’s production architecture requires the primary database to be provisioned in Sydney, so statutory register, trust, valuation, minute-book and company data at rest in that database stays onshore. Production launch is conditional on that deployment control being verified. This residency claim covers storage — it does not cover AI processing. As described in section 5, drafting, checking, extraction and Ask Veela requests are sent to a third-party AI model provider that is not region-pinned in our infrastructure, so the content of those requests (which can include register data, and for ASIC statement import, officer dates of birth and residential addresses) leaves Australian-hosted storage for that call. If you need a stricter data residency posture than this, tell us before relying on Veela for that purpose — [REVIEWER: confirm whether Veela should offer, or currently can offer, an AI-processing opt-out or region-restricted mode, and whether any customers have contracted for one].
Beyond residency, access to your data is role-based, sign-ins and security-relevant events are recorded to an audit log, sensitive secrets you give Veela (such as your ASIC corporate key or an e-signature provider’s API key) are encrypted at rest with a dedicated encryption key separate from the keys that sign sessions, and two-factor authentication (TOTP) is available from Settings. All traffic runs over TLS in transit. See our security page for more detail on these controls.
7. Retention and deletion
Minute book and register records are retained in line with Corporations Act record-keeping obligations (including the general seven-year records posture for company records), with legal-hold support where required.
The minute book is immutable by design: once a resolution passes, its entry is sealed and cannot be edited or deleted by anyone, including Veela staff, because it is the evidentiary record of a corporate decision. This means a request to delete personal information contained in a passed minute-book entry (for example, an officer’s name in a resolution) cannot be actioned by directly editing or removing that entry — the record stays, as the statutory and evidentiary record requires. Where deletion is legally required and cannot be achieved by editing the minute book itself, we will consider what other steps are available (for example, removing personal information from account records, upload documents, or Ask Veela context that are not part of a passed minute-book entry) and explain to you what can and cannot be done. [REVIEWER: confirm this position against actual deletion requests received, and whether Veela needs a documented deletion/redaction procedure beyond what is described here].
A Trust owner or admin can use Billing or Trust Settings to permanently delete that workspace’s Basiq user, bank connections, local CDR ingestion sources and balance observations. The operation is fail-closed: Veela removes the local CDR data only after Basiq confirms provider-side deletion (or confirms that the provider user is already absent). Uploaded statements and trustee-adopted statutory or evidentiary records are separate records and are not silently deleted with the feed. Any retention of those records must follow the final legal retention policy and any applicable legal hold.
8. Access, correction and complaints
You can request access to, or correction of, personal information we hold about you by contacting us using the details in section 12. Where information forms part of a statutory company register or minute book, correction may require a passed resolution or equivalent register movement rather than a direct edit, for the same reason set out in section 7.
If you have a complaint about how we have handled your personal information, contact us first so we can try to resolve it. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.
9. Notifiable data breaches
If we experience a data breach that is likely to result in serious harm to individuals whose personal information is involved, we will comply with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth), including notifying affected individuals and the OAIC where required.
10. Cookies
Veela uses functional cookies: a session cookie that keeps you signed in, and a workspace-selection cookie that remembers which company or trust you last worked on when you belong to more than one. Both are HttpOnly and used only to operate the service. We do not currently use analytics or advertising cookies, and there is no cookie-consent banner on the site because there is nothing beyond these two functional cookies to consent to. [REVIEWER: revisit this section if an analytics or marketing cookie is ever added — it would change the consent posture described here].
11. Children
Veela is a business product for company officers, trustees, adult SMSF members and their advisers, and is not directed at or intended for use by children.
12. Changes to this policy
We may update this policy from time to time. Material changes will be notified in-product before they take effect.
13. Contact
Privacy questions or requests can be sent to support@tokeniser.com. Veela AI Pty Ltd. [REVIEWER: add ABN/ACN and registered address for the entity notice — not present in the codebase].