Privacy Policy
Last Updated: August 18, 2026
1. Introduction
VELRIO LIMITED, a company incorporated in the Republic of Cyprus ("VELRIO LIMITED," "we," "us," or "our"), is committed to protecting the privacy of individuals who use the Finestro platform available at finestro.io (the "Service"). This Privacy Policy outlines how we collect, use, process, and share Personal Data in connection with the Service.
This Privacy Policy is an integral part of our Terms of Service. By accessing or using the Service, you acknowledge that you have read, understood, and agree to the practices described herein. If you do not agree with this Privacy Policy, you must cease using the Service and may request deletion of your data by contacting [email protected].
VELRIO LIMITED determines the purposes and means of Processing your Personal Data and acts as the data controller under applicable data protection law.
The following definitions apply throughout this Privacy Policy:
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, storage, adaptation, retrieval, use, disclosure, erasure, or destruction.
- "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation).
- "UK GDPR" means the GDPR as retained in United Kingdom domestic law by the European Union (Withdrawal) Act 2018 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019.
- "EEA" means the European Economic Area. For purposes of this Privacy Policy, references to the EEA include the United Kingdom with respect to data protection obligations.
- "LGPD" means Brazil's Lei Geral de Protecao de Dados (Law No. 13,709/2018).
- "PIPEDA" means Canada's Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5).
- Other capitalized terms not defined in this Privacy Policy have the meanings assigned to them in the Terms of Service.
2. Data Controller and Contact Information
The data controller responsible for the collection and Processing of your Personal Data through the Service is:
VELRIO LIMITED, a company incorporated in the Republic of Cyprus, with its registered address at Prodromou, 75, ONEWORLD PARKVIEW HOUSE, Floor 4, Nicosia, Republic of Cyprus 2063.
For privacy inquiries and data subject requests, contact: [email protected]. Please include "Privacy Inquiry" in the subject line of any privacy-related correspondence to help us direct your request promptly.
Depending on your location, payment method, or other relevant factors, your subscription or purchase may be processed by Findmy LLC, a Delaware limited liability company with its principal address at 501 E Las Olas Blvd, Suite 300, Fort Lauderdale, FL 33301, USA, acting as an authorized web distributor and merchant of record for certain transactions. In this capacity, Findmy LLC and VELRIO LIMITED act as joint controllers for the payment-related Personal Data processed in connection with those transactions. VELRIO LIMITED remains the sole controller for all other Personal Data collected through the Service.
3. Information We Collect
This section describes the categories of Personal Data we collect when you use the Service.
3.1 Information You Provide Directly
- Registration and Onboarding Data: name, email address, password (stored in hashed form only), age, gender, and responses to onboarding questions regarding your AI learning goals, experience level, and areas of interest.
- Communications: information you provide when contacting us via support emails or contact forms.
- Interactions: Finestro uses third-party AI service providers (such as OpenAI) to generate responses. When you submit a query, the content of your query is transmitted to the applicable third-party AI provider's API for processing. We transmit only the information necessary to generate a response (typically your query text) and do not transmit your name, email, or other account identifiers to the AI provider. These third-party AI providers process your queries under their API data processing terms. As of the date of this Policy, our providers' API terms provide that data submitted via the API is not used to train or improve their general-purpose models. We do not use your AI interaction data to train any proprietary machine learning model. Your AI interactions are treated as private and are not visible to other users. The AI response is for educational and informational purposes only and does not constitute professional advice of any kind.
- Payment Information: collected by our third-party payment processors (Stripe, Braintree, PayPal) and, where applicable, by Findmy LLC as merchant of record. We receive only limited transaction records: name, date and time, amount, and last four digits of the payment method.
- Sensitive Personal Data: we do not actively collect sensitive Personal Data (such as racial or ethnic origin, health data, or religious beliefs). If you voluntarily provide such data, we will handle it with special care in accordance with this Policy.
3.2 Information Collected Automatically
- Device and Technical Information: IP address, operating system, browser type, device model, language settings, and timestamps. We collect general location only (city and country level), not precise geolocation.
- Usage Information: features used, session duration, pages visited, links clicked, navigation flow, subscription status, ad interactions, crash reports, error logs, and load times.
- Referral Information: source website, campaign ID, and referral codes collected via URL parameters, cookies, or tracking pixels.
- Cookies and Similar Technologies: We use cookies classified into four categories.
- Strictly Necessary: required for authentication, session management, security, and preferences. These cannot be disabled without affecting functionality and do not require consent.
- Functional: personalize your experience by remembering choices such as language or extended login. Disabling these may affect certain features.
- Performance and Analytics: help us understand how users interact with the Service (Google Analytics, Amplitude). We configure these tools to minimize PII collection, including IP anonymization for Google Analytics. Where required by law, we obtain consent before use.
- Targeting and Advertising: used by us and our partners (Meta/Facebook Pixel, TikTok Pixel, Google Ads) to measure ad effectiveness and display relevant ads on other platforms. For EEA and UK users, we obtain prior consent before placing these cookies.
For EEA and UK users, we obtain prior consent before placing non-essential cookies. You may manage your preferences at any time through cookie settings. Cookies may be session-based (deleted when you close your browser) or persistent (remaining until expiration or manual deletion). You may also control cookies through browser settings or opt-out tools provided by the NAI, DAA, and EDAA.
- Analytics Data: We use Google Analytics (with IP anonymization enabled; browser opt-out add-on available) and Amplitude, both configured to minimize PII collection and acting as data processors. We honor the Google Analytics opt-out browser add-on and Do Not Track signals where feasible.
3.3 Information from Third Parties
- Third-Party Login Providers: if you register or log in using a third-party service, we may receive basic profile information from that provider.
- Advertising and Marketing Partners: we may receive aggregated campaign performance data and referral partner data from our advertising and marketing partners.
4. How We Use Your Information
We use the Personal Data we collect for the following purposes:
- Provide and Maintain the Service: to operate Finestro, deliver AI education content, facilitate access to third-party AI tools, manage your subscription, and ensure the Service functions as intended.
- Manage Your Account and Provide Support: to create and administer your account, authenticate your identity, and respond to your inquiries and support requests.
- Communicate With You: to send transactional and administrative messages (e.g., account confirmations, security alerts, service updates). We may also send marketing communications where you have opted in or where permitted under applicable law (soft opt-in). You may opt out of marketing communications at any time via the unsubscribe link in each message or by contacting [email protected].
- Research, Analytics, and Service Improvement: to conduct A/B testing, analyze usage patterns using aggregated or pseudonymized data.
- Personalize Content and Advertising: to tailor educational content to your interests and to deliver interest-based advertising and retargeting through our advertising partners. You may adjust your preferences through cookie settings or opt-out mechanisms described in Section 14.
- Process Payments: to facilitate transactions through our third-party payment processors and merchant of records.
- Enforce Terms and Prevent Fraud: to enforce our Terms of Service, detect and prevent fraudulent activity, and protect the rights, property, and safety of VELRIO LIMITED, our users, and the public.
- Comply with Legal Obligations: to meet applicable legal, regulatory, tax, and accounting requirements, and to respond to lawful requests from public authorities.
5. Legal Basis for Processing (EEA, UK, Brazil, Canada)
If you are located in the European Economic Area (EEA), the United Kingdom, Brazil, or Canada, we process your Personal Data only where we have a valid legal basis. The legal bases we rely upon include the following:
- Consent: We rely on your freely given, specific, informed consent for processing activities such as sending marketing communications, placing non-essential cookies (where required by law), and processing any Sensitive Personal Data you voluntarily provide. You have the right to withdraw your consent at any time by adjusting your account settings or by contacting us at [email protected]. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.
- Contract Performance: Processing necessary for the performance of a contract to which you are a party, including creating and managing your account, delivering the Service, processing payments, and providing customer support.
- Legitimate Interests: Processing necessary for our legitimate interests or those of a third party, provided such interests are not overridden by your fundamental rights. These interests include analytics and service improvement, fraud prevention, network and information security, soft opt-in marketing to existing customers, and intra-group data sharing for administrative purposes. We conduct a balancing test for each such purpose. You have the right to object to processing based on legitimate interests by contacting [email protected].
- Legal Obligation: Processing necessary to comply with applicable laws, regulations, court orders, or other binding legal requirements.
- Brazilian Users (LGPD): For users in Brazil, we process Personal Data in accordance with the legal bases set forth in Article 7 of the Lei Geral de Protecao de Dados, including consent, contract performance, legitimate interests, and compliance with legal or regulatory obligations. You may exercise your rights under the LGPD by contacting [email protected].
- Canadian Users (PIPEDA): For users in Canada, we collect, use, and disclose Personal Data in accordance with the Personal Information Protection and Electronic Documents Act and applicable provincial legislation. We obtain meaningful consent (express or implied, as appropriate to the sensitivity of the data) before or at the time of collection, limit collection to purposes a reasonable person would consider appropriate, and retain Personal Data only as long as necessary to fulfill the identified purposes.
6. How We Share Your Information
We do not sell Personal Data for monetary consideration. We share Personal Data only as described below.
6.1 Service Providers (Processors). We engage reputable third-party service providers to perform functions on our behalf. Each provider is bound by a Data Processing Agreement (DPA) and, where applicable, Standard Contractual Clauses (SCCs). We share Personal Data with these providers only to the extent necessary for them to carry out their services. Our current sub-processors are listed below.
(a) Cloud Hosting and Infrastructure:
- Amazon Web Services (AWS): cloud hosting, databases, and servers. Privacy: https://aws.amazon.com/privacy/
(b) Data Analytics, Attribution, and Performance Monitoring:
- Google Analytics: web and app analytics (IP anonymization enabled; opt-out via browser add-on at https://tools.google.com/dlpage/gaoptout). Privacy: https://policies.google.com/privacy
- Amplitude: product analytics and feature usage tracking (certified under the EU-U.S. Data Privacy Framework). Privacy: https://amplitude.com/privacy
- HotJar: behavioral analytics. Privacy: https://www.hotjar.com/privacy/
- Sentry: error and crash monitoring. Privacy: https://sentry.io/privacy/
- AppsFlyer: attribution analytics and deep linking (also collects analytics data). Privacy: https://www.appsflyer.com/legal/privacy-policy/
(c) Payment Processing:
- Stripe: payment processing (PCI-DSS compliant). Privacy: https://stripe.com/privacy
- Braintree (PayPal): payment processing (PCI-DSS compliant). Privacy: https://www.braintreepayments.com/legal/braintree-privacy-policy
- SolidGate: payment processing (PCI-DSS compliant). Privacy: https://solidgate.com/privacy-policy
(d) Email and Communications:
- Reteno: email delivery and communication platform. Processes contact information (email address) and message content solely on our behalf. Privacy: https://reteno.com/privacy-policy
(e) Geolocation and IP Services:
- Geoapify: IP-based geolocation for content localization (language, currency) and fraud prevention. Receives IP address, returns approximate location (country/city). Privacy: https://www.geoapify.com/privacy-policy
- ip-api.com: IP-based geolocation. Receives IP address, returns approximate location data. Privacy: https://ip-api.com/docs/legal
(f) AI and Machine Learning Services:
- OpenAI (ChatGPT): AI API for generating responses. We transmit only query text; we do not transmit your name, email, payment details, or other direct identifiers. All transmissions are encrypted in transit. OpenAI processes API-submitted data under its data processing terms and is contractually prohibited from using it to train or improve its general-purpose models. The technical infrastructure by which OpenAI processes, temporarily retains (including for limited abuse-monitoring periods), and deletes such data is determined solely by OpenAI. Privacy: https://openai.com/policies/privacy-policy; API data usage: https://openai.com/policies/api-data-usage-policies
- Google (Gemini): AI API for generating responses. Same data-handling principles as described above apply. Privacy: https://policies.google.com/privacy; Gemini API terms: https://ai.google.dev/gemini-api/terms
(g) Tag Management:
- Google Tag Manager: manages deployment of analytics and marketing tags on our website and app. Does not independently collect or store Personal Data beyond what is necessary for tag deployment. Privacy: https://policies.google.com/privacy
If we engage a new sub-processor, we will update this Privacy Policy at least fourteen (14) days before the new sub-processor begins processing your Personal Data. If you have a reasonable objection to a new sub-processor, you may contact us at [email protected] within fourteen (14) days of the update.
6.2 Findmy LLC (Joint Controller for Payment Data). Findmy LLC, a Delaware limited liability company (501 E Las Olas Blvd, Suite 300, Fort Lauderdale, FL 33301, USA), acts as authorized web distributor and merchant of record for certain transactions. For payment-related Personal Data processed in connection with those transactions, Findmy LLC and VELRIO LIMITED act as joint controllers. VELRIO LIMITED remains the sole controller for all other Personal Data.
6.3 Advertising and Marketing Partners (Independent or Joint Controllers). Certain advertising and marketing platforms process Personal Data they receive from us as independent controllers or, where applicable, as joint controllers. When we share data with these platforms (for example, through pixels, conversion APIs, SDKs, or hashed identifiers for audience matching), these platforms process the data in accordance with their own privacy policies and terms. Our current advertising and marketing partners include:
- Meta/Facebook (Meta Pixel, Custom Audiences, conversion tracking). Privacy: https://www.facebook.com/privacy/policy/
- Google Ads (conversion tracking, audience targeting). Privacy: https://policies.google.com/privacy
- TikTok Ads (TikTok Pixel, conversion tracking). Privacy: https://www.tiktok.com/legal/page/row/privacy-policy/en
- AppLovin / Axon (user acquisition, ad delivery). Privacy: https://www.applovin.com/privacy/
Where we act as a joint controller with an advertising platform (for example, under Meta's Controller Addendum for Custom Audiences), we have entered into a joint controller arrangement that sets out each party's respective responsibilities. You may contact us at [email protected] to obtain a summary of any such arrangement.
Data shared with advertising platforms is limited to hashed identifiers and conversion data. We do not share names, email addresses in plaintext, or financial details for their independent use.
6.4 Sub-Processor Change Notification. The sub-processors and advertising partners listed in Sections 6.1 and 6.3 are current as of the "Last Updated" date of this Privacy Policy. If we engage a new sub-processor or advertising partner, we will update this Privacy Policy and provide at least fourteen (14) days' notice before the new provider begins processing your Personal Data. If you have a reasonable objection, you may contact us at [email protected] within fourteen (14) days of the update, and we will work with you to address your concerns.
6.5 Other Disclosures. We may share Personal Data: (a) to comply with applicable law, regulation, legal process, or enforceable governmental request; (b) in connection with a merger, acquisition, reorganization, or sale of assets, with notice to affected users; (c) with affiliated companies under common ownership with VELRIO LIMITED, subject to this Policy; or (d) with your consent.
7. Your Privacy Rights
Depending on your jurisdiction, you may exercise the following rights with respect to your Personal Data:
- Right of Access: request confirmation of whether we process your Personal Data and obtain a copy.
- Right to Rectification: request correction of inaccurate or incomplete Personal Data.
- Right to Erasure: request deletion of your Personal Data, subject to applicable legal retention obligations.
- Right to Restriction: request that we restrict Processing in certain circumstances.
- Right to Object: object to Processing based on legitimate interests, including direct marketing.
- Right to Data Portability: receive your Personal Data in a structured, commonly used, machine-readable format.
- Right to Withdraw Consent: where Processing is based on consent, you may withdraw consent at any time by adjusting your account settings or by contacting [email protected]. Withdrawal does not affect the lawfulness of Processing carried out prior to withdrawal.
- Right to Lodge a Complaint: file a complaint with your local data protection supervisory authority.
To exercise any of these rights, contact us at [email protected] with the subject line "Privacy Inquiry." We may verify your identity before fulfilling a request. We will respond within 30 days; if an extension is necessary due to complexity or volume, we will notify you within the initial 30-day period. No fee applies unless a request is manifestly unfounded or excessive.
Brazilian Users (LGPD): You hold all rights under LGPD Article 18, including confirmation of Processing, access, correction, anonymization, portability, deletion, and information about third parties with whom data has been shared. Contact [email protected] or the Brazilian National Data Protection Authority (ANPD) to exercise these rights.
Canadian Users (PIPEDA): You may request access to and correction of your Personal Data. We will respond within 30 days and inform you of any denial with reasons and available recourse, including the right to file a complaint with the Office of the Privacy Commissioner of Canada.
We are committed to honoring data subject rights regardless of your location, to the extent required by applicable law.
8. Age Requirements
8.1 The Service is designed for individuals who are at least eighteen (18) years of age. VELRIO LIMITED does not knowingly collect, solicit, or process Personal Data from anyone under the age of 18. If you are under 18, you may not use the Service, create an account, or provide any Personal Data to us.
8.2 In compliance with the U.S. Children's Online Privacy Protection Act (COPPA), we do not knowingly collect Personal Data from children under the age of 13. We also do not knowingly collect Personal Data from minors between the ages of 13 and 17.
8.3 If you are a parent or guardian and believe that your child has provided Personal Data to us without your consent, please contact us immediately at [email protected] with the subject line "Underage Data Report." Upon verification, we will take prompt steps to delete such data from our systems.
8.4 If we become aware that we have collected Personal Data from an individual under 18 without appropriate legal basis, we will delete that information as soon as reasonably practicable and take steps to prevent future collection from that individual.
9. International Data Transfers
VELRIO LIMITED stores Personal Data primarily on servers located in the United States (hosted by Amazon Web Services) and may process Personal Data within the European Union. When Personal Data is transferred from the EEA, the United Kingdom, or Switzerland to a country that has not received an adequacy decision from the relevant authority, we apply the following safeguards.
- Standard Contractual Clauses: We incorporate the EU Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914 and the UK International Data Transfer Addendum into our contracts with all recipients of Personal Data in countries that have not received an adequacy decision.
- Data Privacy Framework: Where our service providers are certified under the EU-U.S. Data Privacy Framework (DPF), the UK Extension to the EU-U.S. DPF, or the Swiss-U.S. DPF, we rely on such certification as a valid transfer mechanism.
- Explicit Consent: In limited circumstances, we may transfer data based on your explicit consent, where you have been fully informed of the possible risks and have explicitly consented to the transfer.
- Transfer Impact Assessments: In accordance with the Schrems II decision (Case C-311/18) and EDPB guidance, we conduct Transfer Impact Assessments for transfers to third countries without adequacy decisions. We implement supplementary technical, organizational, and contractual measures where necessary.
The primary destination country for cross-border transfers is the United States, where AWS, Findmy LLC, our payment processors (Stripe, Braintree, SolidGate), AI service providers (OpenAI, Google), analytics providers (Amplitude, HotJar, Sentry, AppsFlyer), advertising platforms, and other service providers operate. Some providers may also process data in the European Union or other jurisdictions. VELRIO LIMITED, as data controller, remains responsible for all transferred Personal Data, and your rights under applicable data protection law continue to apply regardless of where your data is processed.
10. Data Security
VELRIO LIMITED implements appropriate technical and organizational measures designed to protect Personal Data against unauthorized access, alteration, disclosure, or destruction.
These measures include, but are not limited to, the following:
- Encryption: All data transmitted between your device and our servers is protected using TLS/SSL encryption. Personal Data stored on our systems is encrypted at rest.
- Access Controls: We enforce role-based access controls and require strong authentication for personnel who access Personal Data, limiting access to those with a legitimate business need.
- Infrastructure Security: Our infrastructure is hosted on Amazon Web Services (AWS), which provides network segmentation, firewalls, and intrusion detection systems.
- Password Security: User passwords are cryptographically hashed and are never stored in plaintext.
- Payment Security: All payment processors (Stripe, Braintree, SolidGate, PayPal) maintain PCI-DSS compliance for the handling of payment card data.
- Incident Response: We maintain an incident response plan that includes notification to the relevant supervisory authority within 72 hours of becoming aware of a qualifying personal data breach, as required by the GDPR, and notification to affected individuals where required by applicable law.
- Vendor Security Evaluation: We evaluate the security practices of our sub-processors and service providers before engagement and on an ongoing basis.
No method of electronic transmission or storage is completely secure. While we take reasonable precautions to protect your Personal Data, we cannot guarantee absolute security. If you have reason to believe that your interaction with the Service is no longer secure, please contact us immediately at [email protected].
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make changes, we will revise the "Last Updated" date at the top of this Privacy Policy.
If we make material changes to this Privacy Policy, we will provide you with advance notice through one or more of the following methods: (a) a prominent notice on the finestro.io website; (b) an in-Service notification; or (c) an email to the address associated with your account. We will provide such notice before the changes take effect, giving you the opportunity to review the revised Privacy Policy.
Your continued use of the Service after the effective date of any updated Privacy Policy constitutes your acceptance of the revised terms. Where applicable law requires your consent for a particular change in how we process your Personal Data, we will obtain that consent before implementing the change.
If you do not agree with any changes to this Privacy Policy, you should cease using the Service and may request deletion of your Personal Data by contacting us at [email protected].
12. United States Privacy Rights
This section provides disclosures required under United States state privacy laws. If you are a resident of a state with applicable privacy legislation, you may have the rights described below.
12.1 California (CCPA/CPRA). We collect the following categories of Personal Information as defined under the California Consumer Privacy Act, as amended by the California Privacy Rights Act: identifiers; categories of Personal Information described in Cal. Civ. Code Section 1798.80(e); protected classification characteristics; internet or other electronic network activity information; geolocation data; and inferences drawn from the above.
Sale and Sharing. We do not sell Personal Information for monetary consideration. Our use of certain advertising technologies (pixels, conversion tracking, hashed identifier matching with Meta, Google, and TikTok) may constitute "sharing" under CCPA/CPRA. Categories shared include identifiers (hashed email addresses, device IDs) and internet or network activity. You may opt out by adjusting cookie preferences or contacting [email protected]. We honor opt-out preference signals, including Global Privacy Control, where required by law.
California Rights: right to know, right to delete, right to correct, right to opt out of sale or sharing, right to limit use of sensitive Personal Information, and right to non-discrimination. To exercise any right, contact [email protected]. Authorized agents are accepted with proper written authorization. For Shine the Light requests, email [email protected] with the subject line "Request for California Shine the Light Information."
12.2 CCPA Classification Table
| Recipient Category | Role under CCPA | Purpose | Categories of PI Shared |
|---|---|---|---|
| Cloud hosting (e.g., AWS) | Service Provider | Host and store data | All categories |
| Analytics and monitoring (e.g., Google Analytics, Amplitude, HotJar, Sentry) | Service Provider | Analyze usage, monitor errors, improve Service | Identifiers, Internet/Network Activity, Geolocation |
| Attribution analytics (e.g., AppsFlyer) | Service Provider | Deep linking, attribution | Identifiers, Internet/Network Activity, Geolocation |
| Payment processors (e.g., Stripe, Braintree, SolidGate) | Service Provider | Process payments | Identifiers, Commercial information |
| Billing partner (Findmy LLC) | Service Provider | Billing, subscriptions, refunds | Identifiers, Commercial information |
| Email and communications (e.g., Reteno) | Service Provider | Transactional and marketing emails | Identifiers |
| Geolocation/IP services (e.g., Geoapify, ip-api.com) | Service Provider | Approximate location for content, currency, fraud prevention | Identifiers (IP address), Geolocation |
| AI/ML providers (e.g., OpenAI, Google Gemini) | Service Provider | Power AI features | Internet/Network Activity (query content) |
| Tag management (e.g., Google Tag Manager) | Service Provider | Deploy analytics and marketing tags | Identifiers, Internet/Network Activity |
| Ad platforms (e.g., Meta, Google Ads, TikTok, AppLovin) | Third Party (independent/joint controller) | Targeted advertising, conversion tracking, user acquisition | Identifiers (hashed), Internet/Network Activity |
12.3 Other US State Privacy Rights. Residents of Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and other states with applicable privacy statutes may exercise the following rights where provided by law: opt out of targeted advertising; opt out of the sale of Personal Data; opt out of profiling in furtherance of decisions that produce legal or similarly significant effects; and the right to appeal a denial of a request. To exercise these rights, contact [email protected]. We honor Global Privacy Control signals. To appeal a decision regarding your request, email [email protected] with the subject line "Privacy Appeal."
13. Data Retention
VELRIO LIMITED retains Personal Data only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. The following retention periods apply:
| Data Category | Retention Period |
|---|---|
| Account and profile data | Duration of active account, plus 30 to 60 days following account deletion to complete processing |
| Support communications | 1 to 2 years from the date of the communication |
| Analytics data | Anonymized after 14 months (Google Analytics default retention period) |
| Financial and transaction records | 7 years, as required by applicable accounting and tax laws |
| Legal compliance records | As required by applicable law or regulation |
| Dispute resolution records | Duration of any active dispute, claim, or proceeding, plus any applicable limitation period |
| Fraud prevention records | Minimal records of banned or flagged accounts retained as necessary to prevent recurring fraud |
Backup systems store encrypted copies of data. Backup media are cycled out on a regular schedule. If deleted data is restored from a backup, we will re-execute the deletion promptly upon identification.
When Personal Data is no longer required for any of the purposes set out above, we will either delete or anonymize it so that it can no longer be associated with an identifiable individual. Anonymized data may be retained indefinitely for statistical and analytical purposes.
14. Control Tracking
You have several options for controlling the use of cookies and similar tracking technologies when using the Service.
- Browser Settings: Most web browsers allow you to manage or disable cookies through their settings menus. You may block or delete cookies at any time; however, doing so may affect the functionality of the Service, particularly with respect to Strictly Necessary cookies.
- Private Browsing: You may use your browser's private or incognito mode to limit the storage of cookies and browsing history during a session.
- Browser Extensions: Various browser extensions and plug-ins are available to manage cookies, block trackers, or limit data collection by third parties.
- Google Analytics Opt-Out: You may install the Google Analytics Opt-Out Browser Add-On, available at https://tools.google.com/dlpage/gaoptout to prevent Google Analytics from collecting data about your visits.
- Ad Platform Opt-Out Tools: You may opt out of interest-based advertising through the following industry tools: (a) the Network Advertising Initiative (NAI) at https://optout.networkadvertising.org (b) the Digital Advertising Alliance (DAA) at https://optout.aboutads.info and (c) the European Digital Advertising Alliance (EDAA) at https://www.youronlinechoices.eu
- Global Privacy Control: Where required by applicable law, we honor opt-out preference signals such as Global Privacy Control (GPC). You may enable GPC through supported browsers or extensions.
Third-party services integrated into the Service may respond to Do Not Track (DNT) signals or similar mechanisms according to their own policies. VELRIO LIMITED does not make any representations regarding how third parties respond to DNT signals or other opt-out mechanisms. For information on a third party's tracking practices, please consult that party's privacy policy directly.
15. Contact Us
The data controller responsible for your Personal Data is:
VELRIO LIMITED (a company incorporated in the Republic of Cyprus)
Registered Address: Prodromou, 75, ONEWORLD PARKVIEW HOUSE, Floor 4, Nicosia, Republic of Cyprus, 2063
For all privacy inquiries, data subject requests (including requests to access, correct, delete, or port your Personal Data), and questions regarding this Privacy Policy, please contact us at: [email protected]
When contacting us, please include a clear subject line (for example, "Privacy Inquiry" or "Data Subject Request") so that we may direct your correspondence to the appropriate team promptly.
We will acknowledge receipt of your inquiry and provide a substantive response within thirty (30) days of receiving your request. If additional time is required due to the complexity or volume of requests, we will notify you of the extension and the reasons for the delay within the initial 30-day period, in accordance with applicable law.