A privacy policy, terms of service, and data processing terms:
each a single page, in plain language.
[DRAFT — accurate to what veil does, written in plain English. NOT legal advice; have a solicitor review before publishing. Fill [PLACEHOLDERS] from SHARED-FACTS.txt. Items marked [LEGAL REVIEW] are genuine legal judgment calls to confirm with a solicitor.]
veil. is a threat-intelligence service for small and medium businesses. This policy explains what personal data we collect, why, how long we keep it, who we share it with, and the rights you have over it.
veil. is operated by [ENTITY NAME] ([TRADING NAME]), a company registered in [JURISDICTION] under company number [COMPANY NUMBER], with its registered office at [REGISTERED ADDRESS]. In this policy, "veil.", "we", "us" and "our" mean [ENTITY NAME].
For anything to do with your personal data — including any of the requests described in section 9 — contact us at [PRIVACY CONTACT EMAIL]. Our data-protection contact is [DPO / CONTACT].
We are the data controller for the personal data described in this policy. We are registered with the UK Information Commissioner's Office (ICO) under registration number [ICO REGISTRATION NUMBER].
We handle personal data in line with UK data-protection law: the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. Where we serve customers or users in the EU, we also handle their data in line with the EU GDPR. [LEGAL REVIEW: confirm EU-GDPR applicability and whether an EU representative under Article 27 is required based on your EU user base.]
We collect only what we need to run the service. We do not sell your personal data, and we do not use it for advertising.
(a) ACCOUNT AND PROFILE DATA
What: your name, your work email address, and your account role.
Why: to create and secure your account, identify you within your organisation, and communicate with you about the service.
Lawful basis: performance of our contract with you (to provide the service you signed up for).
(b) AUTHENTICATION DATA
What: the credentials you use to sign in — a password or passkey, and multi-factor authentication (MFA). We also generate single-use account-recovery codes for you.
Where it lives: your password, passkey and MFA are held by our authentication provider (see section 6); we do not store your password or passkey in our own database. The recovery codes we generate are stored only in a hashed (irreversible) form — never in plain text.
Why: to keep your account secure and let only you access it.
Lawful basis: performance of our contract, and our legitimate interest in keeping accounts secure.
(c) ORGANISATION AND CONFIGURATION DATA
What: information about your business that you provide during onboarding and in settings — your organisation name, sector and industries, the domains you enter, and the technology and vendors you declare that your business uses. This is largely information about your organisation rather than about you as an individual, but we treat it with the same care.
Why: this is the core of how veil. works — we use what you declare to match the world's threat intelligence to what is actually relevant to your business.
Lawful basis: performance of our contract.
(d) TEAM INVITATION DATA
What: if you invite colleagues, we store the email addresses you enter to send those invitations, and a record of who sent each invitation.
Why: to invite the people you choose and manage your team's access.
Lawful basis: our legitimate interest (and yours) in letting you build your team. If you invite someone, please make sure you are entitled to give us their work email for this purpose.
(e) NOTIFICATION PREFERENCES
What: your chosen notification settings and the delivery destination (such as a notification email address or a webhook reference).
Why: to send you the alerts and updates you ask for, in the way you choose.
Lawful basis: performance of our contract.
(f) USAGE AND ACTIVITY DATA
What: records of significant actions taken in your account (an activity log), which may include the email address of the user who took an action.
Why: for security, troubleshooting, and to give administrators an accurate record of what happened in their account.
Lawful basis: our legitimate interest in the security and integrity of the service.
(g) NOTES YOU WRITE
What: free-text notes that users (including managing providers) may write within the service. Because these are free text, they may contain whatever the author types.
Why: to let your team record context and decisions.
Lawful basis: performance of our contract; our legitimate interest in letting your team collaborate. Please do not enter special-category personal data (see section 4) into free-text notes.
(h) BILLING DATA — NOT COLLECTED YET
We do not currently collect or store any payment or billing data. When we introduce paid subscriptions, payments will be handled by a payment provider (see section 6), and we will update this policy to describe exactly what billing data is collected and why.
(i) ENQUIRY DATA
What: if you contact us through our website — for example, the managed-service-provider enquiry form — we store the details you give us: your name, your work email address, your role, your organisation's name, size and sector, and the message you send.
Why: to respond to your enquiry, understand what you need, and follow up with you about the service.
Lawful basis: our legitimate interest in responding to enquiries about veil. and in pursuing a possible business relationship with you.
We do not ask for, and you should not provide, special-category data (such as health, racial or ethnic origin, political opinions, religious beliefs, or biometric data) — veil. has no need for it. We do not collect payment data today (see 3(h)). We do not track you across other websites, and we do not run advertising or third-party advertising cookies. [LEGAL REVIEW: confirm your cookie/tracking position and add a short cookie statement or separate Cookie Policy if the site uses any non-essential cookies or analytics — PECR applies.]
Part of how veil. works is to build an accurate picture of your business's public-facing footprint, so that we can tell what technology you run and match threats to it. We do this by reading PUBLIC information only:
We do this at onboarding and re-check it on a regular cadence.
Two things matter here, and both are true of how veil. is built:
We do not sell your data. We share it only with the service providers we need to run veil., and only for that purpose. Our providers are bound by contract to protect your data and to use it only on our instructions.
(a) HOSTING, DATABASE AND AUTHENTICATION — Supabase.
Supabase hosts our application database and provides our authentication system (this is where your password, passkey and MFA are held). Region: [SUPABASE REGION]. Entity: [SUPABASE LEGAL ENTITY].
(b) EXTERNAL LOOKUP SERVICES — used for the observation described in section 5. When we observe
your public footprint, your public domain name is queried against: - crt.sh (Certificate Transparency), operated by Sectigo (US); - Google Public DNS (dns.google), operated by Google (US); - rdap.org (registration lookups) (US). These services receive only the public domain being looked up.
(c) AI ENRICHMENT — Anthropic (Claude API).
When you use the find feature to ask a question, we send your question text and the relevant matched-threat context (which reflects your declared stack and sector) to Anthropic's Claude API to generate the answer. Anthropic acts as our sub-processor for this feature and receives this data only to return the response to you. Anthropic is US-operated, so this involves an international transfer (see section 7). We never send your password, MFA secrets or recovery codes to any AI provider.
(d) SEMANTIC SEARCH — Voyage AI.
When you use the find feature, we send your question text to Voyage AI to turn it into a numerical representation (an "embedding") so we can match it, by meaning, against our threat intelligence — this is what lets find recognise a threat you describe in your own words. We also send our threat-intelligence records (global threat data, not your personal data) to Voyage to embed them. Voyage acts as our sub-processor for this feature and receives this data only to return the embeddings. Voyage is US-operated, so this involves an international transfer (see section 7). We never send your password, MFA secrets or recovery codes to any AI provider.
(e) PAYMENTS — [PAYMENT PROCESSOR] — only once paid subscriptions launch. Not used today.
(f) EMAIL / NOTIFICATIONS — [EMAIL PROVIDER] — when we introduce email delivery. Not used today.
We may also disclose data if the law requires it (for example, a valid legal request from an authority), or to establish, exercise or defend legal claims. [LEGAL REVIEW: confirm this lawful-disclosure wording.]
PUBLIC SOURCES WE READ (NOT RECIPIENTS OF YOUR DATA): to produce intelligence, veil. reads public threat-intelligence sources (such as government vulnerability catalogues and public threat feeds). These are public sources we consume — we do not send your data to them.
Some of our providers are located outside the UK (for example, the external lookup services in section 6 and our AI providers, Anthropic (enrichment) and Voyage AI (semantic-search embeddings), are US-operated, and our hosting provider may store data in [SUPABASE REGION]). Where personal data is transferred outside the UK, we rely on an appropriate safeguard under UK data- protection law — such as UK adequacy regulations or the International Data Transfer Agreement (IDTA) / the UK Addendum to the EU Standard Contractual Clauses. [LEGAL REVIEW: confirm the exact transfer mechanism for each provider once regions are known — this depends on where Supabase hosts your data and on the providers' own transfer terms.]
We keep personal data only as long as we need it.
DELETION IN PRACTICE. When an organisation's data is deleted, we carry out a genuine deletion of that organisation's records — the account, its configuration, its domains and declared systems, the matches and briefs we generated for it, memberships, invitations, notification settings, and, where a user belonged only to that organisation, that user's profile and credentials. This is a real deletion, not a hidden archive.
Two honest exceptions, which we keep for accountability and disclose plainly:
CURRENT PROCESS. Deletion today is carried out by our team on request (see section 9). We are implementing automatic, time-based deletion in line with the retention periods above; until that is fully in place, we action deletion and retention on request.
Under UK data-protection law you have the right to:
HOW TO EXERCISE THEM. Email [PRIVACY CONTACT EMAIL]. We will respond within one month, as the law requires (we may extend this for complex requests, and will tell you if so). There is normally no charge.
To delete your account or your organisation's data, contact us at [PRIVACY CONTACT EMAIL] and our team will carry out the deletion described in section 8.
COMPLAINTS. If you are unhappy with how we handle your data, please tell us first so we can put it right. You also have the right to complain to the ICO (ico.org.uk), or to your local EU supervisory authority if you are in the EU.
We take appropriate technical and organisational measures to protect your data, including: encryption of data in transit; a hosted database with access controls and tenant isolation so that one customer's data is not accessible to another; authentication handled by a specialist provider, with multi-factor authentication; and credentials such as recovery codes stored only in hashed form. No system is perfectly secure, but we work to protect your data and to keep these measures current. [LEGAL REVIEW: keep this list accurate to your live security posture as it evolves.]
veil. is a business service and is not intended for anyone under 18. We do not knowingly collect data from children.
If we make significant changes, we will update the "last updated" date and, where appropriate, tell you directly. Please check this page from time to time.
[ENTITY NAME] [REGISTERED ADDRESS] Privacy: [PRIVACY CONTACT EMAIL] Support: [SUPPORT CONTACT EMAIL]
[DRAFT — plain English, accurate to the service. NOT legal advice; have a solicitor review before publishing. The LIABILITY and "NOT A GUARANTEE OF SECURITY" sections (11 and 3) are the most important to get reviewed — they are where veil.'s legal exposure lives. Fill [PLACEHOLDERS] from SHARED-FACTS.txt.]
These Terms of Service ("Terms") are the agreement between you and [ENTITY NAME] ([TRADING NAME]), a company registered in [JURISDICTION] under company number [COMPANY NUMBER], registered office [REGISTERED ADDRESS] ("veil.", "we", "us"). They govern your use of the veil. service (the "Service").
By creating an account or using the Service, you agree to these Terms. If you are agreeing on behalf of a business, you confirm you are authorised to bind that business, and "you" means that business.
veil. is a threat-intelligence service. It reads the world's threat information and public signals about your business, has that intelligence reviewed by an analyst, and gives you a curated, continuously updated picture of the threats relevant to what your business runs — together with advice on how to respond, and the ability to ask questions about your exposure.
Please read this section carefully. It defines the limits of what veil. does.
Nothing in this section limits any liability that cannot be limited by law (see section 11).
You must provide accurate information, keep your credentials secure, and use multi-factor authentication where we require it. You are responsible for activity under your account and for your team's use of the Service. Tell us promptly at [SUPPORT CONTACT EMAIL] if you believe your account has been compromised.
If you invite colleagues, you are responsible for ensuring you are entitled to add them and to provide their work email for that purpose.
The Service is offered in tiers:
[Note: the specific features of each tier are described on our pricing page. Keep the pricing page and these Terms consistent.]
Subscriptions are billed [monthly / per the cycle you choose] in advance. Prices are in pounds sterling and [are / are not] inclusive of VAT — [confirm VAT treatment]. We may change our prices; if we do, we will give you reasonable notice and the change will take effect at your next renewal.
[LEGAL REVIEW / TO COMPLETE ONCE PAYMENTS LAUNCH: payment method, when payment is taken, what happens on failed payment, auto-renewal terms, and the cancellation/refund position below. Payments are not yet implemented; complete this section before charging customers.]
You may cancel your subscription at any time; cancellation takes effect at the end of your current billing period, and you will keep access until then. [Refund position — e.g. "We do not offer refunds for the current billing period unless required by law" OR your chosen policy.] [LEGAL REVIEW: set and confirm the refund position, and note any statutory cancellation rights that apply.]
When using veil. you must not:
The provider (MSP) tier lets you act for client businesses you are authorised to manage. You must have that authority, and you must only act within the businesses you are contracted to manage.
We may suspend or terminate access for a serious or repeated breach of this section (see section 10).
[LEGAL REVIEW: confirm the IP and licence wording, and whether you wish to permit any internal copying/retention of briefs by the customer after termination.]
We work to keep the Service available and reliable, but we do not guarantee it will be uninterrupted or error-free. We may carry out maintenance, and we may update or change features. [LEGAL REVIEW: state whether you offer any service-level commitment (SLA) — for the provider tier in particular, business customers may expect one; if not, say so plainly.]
You may stop using the Service and cancel at any time (section 6).
We may suspend or terminate your access if you materially breach these Terms (including the acceptable-use section), if required by law, or if necessary to protect the Service or other customers. Where practical and lawful, we will give you notice and a chance to put things right.
On termination: your right to use the Service ends, and your data will be handled and deleted as described in our Privacy Policy. You may request an export of your data before termination where the Service provides for it.
[THIS SECTION IS THE MOST IMPORTANT TO HAVE REVIEWED BY A SOLICITOR. The wording below is a careful starting point that reflects veil.'s "intelligence and advice, not a guarantee" nature, but liability clauses must be drafted and checked by a qualified lawyer to be effective and to comply with UK law — including the limits on what can lawfully be excluded.]
Nothing in these Terms limits or excludes our liability where it would be unlawful to do so — including for death or personal injury caused by our negligence, for fraud, or for anything else that cannot be limited under applicable law.
Subject to that:
We provide the Service with reasonable care and skill, but except as expressly stated we provide it "as is" and make no other warranties. [LEGAL REVIEW: reconcile with the Consumer Rights Act / statutory implied terms as applicable — most veil. customers are businesses, but confirm.]
We may update these Terms. If we make significant changes, we will give you reasonable notice (for example, by email or in the Service). Continuing to use the Service after the changes take effect means you accept them.
These Terms are governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, except where mandatory local law gives you other rights. [LEGAL REVIEW: confirm jurisdiction, especially for EU customers.]
[ENTITY NAME], [REGISTERED ADDRESS] Support: [SUPPORT CONTACT EMAIL] • Legal notices: [LEGAL CONTACT EMAIL]
[DRAFT — the controller-processor skeleton business customers expect, in plain English. NOT legal advice. THIS DOCUMENT ESPECIALLY should be reviewed by a solicitor before you offer it to business customers — their own lawyers will scrutinise it, and the Article 28 UK GDPR requirements must be met precisely. Fill [PLACEHOLDERS] from SHARED-FACTS.txt. The Annexes at the end carry the specifics.]
This Data Processing Agreement ("DPA") forms part of the agreement between you ("Customer") and [ENTITY NAME] ("veil.") for the veil. service (the "Service"), and governs veil.'s processing of personal data on the Customer's behalf.
For the personal data processed under the Service, the Customer is the data CONTROLLER and veil. is the data PROCESSOR. Each party will comply with its obligations under UK data-protection law (the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025) and, where applicable, the EU GDPR ("Data Protection Law").
[NOTE on roles: for some data — for example, veil.'s own account-administration data, or the external observation veil. performs — veil. may act as a controller in its own right, as described in veil.'s Privacy Policy. This DPA covers veil.'s processing as a PROCESSOR on the Customer's behalf. LEGAL REVIEW: confirm the controller/processor split, especially for the external- observation activity.]
veil. will process the Customer's personal data only:
unless required to do otherwise by law (in which case veil. will inform the Customer, unless the law prohibits it).
veil. will tell the Customer if, in its opinion, an instruction infringes Data Protection Law.
veil. will ensure that people authorised to process the Customer's personal data are bound by an appropriate duty of confidentiality.
veil. will implement appropriate technical and organisational measures to protect the Customer's personal data, taking account of the state of the art, the costs of implementation, and the risk. An outline of veil.'s measures is in Annex 3. veil. will keep these measures under review.
The Customer gives veil. general authorisation to engage the sub-processors listed in Annex 2 to process the Customer's personal data.
veil. will:
If veil. intends to add or replace a sub-processor, it will give the Customer reasonable prior notice [e.g. at least 30 days] and the Customer may object on reasonable data-protection grounds. [LEGAL REVIEW: confirm the notice period and objection mechanism.]
Taking account of the nature of the processing, veil. will assist the Customer, by appropriate technical and organisational measures and so far as reasonably possible, to respond to requests from data subjects exercising their rights under Data Protection Law. If veil. receives such a request directly, it will refer the data subject to the Customer (unless the request relates to data for which veil. is the controller).
Taking account of the nature of processing and the information available to veil., veil. will assist the Customer in meeting its obligations relating to security, personal-data breaches, data- protection impact assessments, and prior consultation with the ICO, so far as reasonably applicable to the Service.
veil. will notify the Customer without undue delay after becoming aware of a personal-data breach affecting the Customer's personal data, and will provide the information the Customer reasonably needs to meet its own breach-notification obligations. [LEGAL REVIEW: consider committing to a specific timeframe, e.g. "without undue delay and in any event within 72 hours of becoming aware"; business customers often expect this.]
On termination of the Service, and at the Customer's choice, veil. will delete or return the Customer's personal data, and delete existing copies, unless the law requires veil. to keep it.
In practice, veil. carries out a genuine deletion of the Customer organisation's data, as described in veil.'s Privacy Policy. Two limited, non-personal exceptions are retained for accountability and are disclosed in that policy: a compliance record of the deletion (which does not contain the deleted personal data), and a non-personal anonymous identifier in veil.'s global system logs. Where the Service provides an export function, the Customer may export its data before termination.
[LEGAL REVIEW: confirm this reflects your final retention decisions and the deletion mechanism, and that the disclosed exceptions are acceptable to your business customers.]
veil. will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates — subject to reasonable notice, confidentiality, frequency limits, and not compromising the security or data of veil.'s other customers. [LEGAL REVIEW: set the practical audit terms; many providers satisfy this through documentation and third-party reports rather than on-site inspection.]
Where veil. or its sub-processors transfer the Customer's personal data outside the UK, veil. will ensure an appropriate safeguard is in place under Data Protection Law (such as UK adequacy regulations or the IDTA / UK Addendum to the EU Standard Contractual Clauses). The relevant transfers and locations are indicated in Annex 2. [LEGAL REVIEW: confirm the transfer mechanism for each sub-processor once regions are known — this depends on Supabase's hosting region and the US-operated lookup services.]
This DPA forms part of, and is subject to, the agreement between the parties (including its governing-law and liability provisions). If there is a conflict between this DPA and the agreement on data-protection matters, this DPA prevails. [LEGAL REVIEW: confirm precedence and how this DPA is executed/accepted by business customers.]
CATEGORIES OF DATA SUBJECT:
TYPES OF PERSONAL DATA:
Note: the Customer's organisation/configuration data (organisation name, sector, domains, declared technology) is largely data about the organisation rather than personal data, but is processed as part of the Service.
SPECIAL-CATEGORY DATA: none is requested or required. The Customer should not enter special- category data into the Service (including into free-text notes).
[VERIFIED shape; confirm entities/regions from SHARED-FACTS.txt before offering to customers.]
1. Supabase — hosting, application database, and authentication (holds passwords/passkeys/MFA). Location / region: [SUPABASE REGION]. Transfer safeguard (if outside UK): [confirm].
2. External public-lookup services — receive the Customer's PUBLIC domain name as a lookup query when veil. observes the Customer's external footprint:
[LEGAL REVIEW: these receive only the public domain being looked up, not personal data in the ordinary sense. Decide, with your solicitor, whether to list them as sub-processors or to describe them as public services queried in the course of the Service. They are US-operated, so note the transfer position either way.]
3. [PAYMENT PROCESSOR] — payments — NOT engaged until paid subscriptions launch. 4. [EMAIL PROVIDER] — email/notification delivery — NOT engaged until email delivery is introduced.
5. Anthropic (Claude API) — AI enrichment of intelligence and answering the Customer's questions in the find feature; receives the question text and matched-threat context. US-operated. Transfer safeguard (if outside UK): [confirm].
6. Voyage AI — semantic-search embedding for the find feature: converts the Customer's find query text (and veil.'s global threat-intelligence text, which is not the Customer's personal data) into numerical embeddings so a threat can be matched by meaning. Receives the question text and the threat-intelligence text. US-operated. Transfer safeguard (if outside UK): [confirm].
NOT SUB-PROCESSORS (public sources veil. reads, which do not process Customer personal data): public threat-intelligence sources (government vulnerability catalogues, public threat feeds).
[Outline — keep accurate to veil.'s live posture; a solicitor / your security review should confirm this is complete and current.]