Privacy Policy

Last updated: September 20, 2026

VEDA ("we", "us") operates a dataset marketplace used by human buyers/sellers and by autonomous AI agents. This policy explains what personal data we collect, why, who we share it with, how long we keep it, and the rights you have over it under the EU/UK GDPR and similar laws. VEDA is the data controller for the data described below.

What we collect

Account data

  • Email address and password hash (bcrypt) -- or nothing at all if you sign in with a one-time email code instead of a password.
  • Optional full name and billing address(es), if you add them for invoicing.
  • Wallet balance, top-up and spending history, and any auto-top-up settings you configure.

Agent & developer data

  • Agent names and API keys you create under your account (API keys are stored in plain text by design, the same way most developer-API platforms store them, so treat them like a password and rotate them if exposed).
  • Every agent transaction: amount, resulting balance, and timestamp.
  • Single-use download tokens, invalidated immediately after first use.

Payment data

We never see or store your card number. Card payments are handled entirely by our payment processor (Stripe); we only receive confirmation that a payment succeeded and its amount.

Usage & log data

  • Every request to our API/website records the method, path, status code, timing, your IP address, and browser user-agent string, for security, abuse prevention, and debugging.
  • Dataset downloads are logged with your account, the dataset, your IP address, and a timestamp, so we can investigate unauthorized redistribution.
  • Every AI-agent tool call (search, purchase, balance checks, etc.) is logged with the agent, the action, whether it succeeded, and timing.

Cookies & analytics

Analytics cookies are active by default from your first visit, on the basis of our legitimate interest in understanding how the site is used -- we show a notice on first visit and let you opt out immediately, and you can change your choice at any time from the link in the footer.

CategoryWhat it doesActive by default?
Strictly necessaryKeeps you signed in (session_token), remembers your cart, your theme, and your cookie choice itself. Can't be disabled -- the site can't function without it.Always on
Analytics (PostHog)Page views and product-usage events, so we can see which features are actually used. Data is processed in the EU. Active by default from your first visit; click "Reject non-essential" (or Cookie Preferences in the footer, anytime) to opt out -- we then stop sending new events and clear the existing analytics identifier from your browser.Yes, until you opt out
Session recording (PostHog)Records mouse movement, clicks, page navigation, and browser console logs during your visit, so we can see and debug how the site is actually used. Password fields are masked by default; card payment fields are rendered inside our payment processor's own isolated frame, which this can't see into at all. Same default and opt-out as Analytics above -- rejecting stops both together.Yes, until you opt out

Separately, our backend also records HTTP and AI-agent API traffic (see "Usage & log data" above) and forwards summary metadata about that traffic (method, path, status, timing, and a coarse actor type) to the same analytics provider. This applies to API/agent requests, which have no browser or cookie-preference UI to opt out through, so it always relies on our legitimate interest in operating, securing, and debugging the service -- it never includes dataset contents, payment details, or password hashes.

Who we share data with

We use a small number of processors to run VEDA, each bound by a data processing agreement and only given the data they need to do their job:

  • Stripe -- card payments and payouts.
  • PostHog (EU region) -- product analytics, only for visitors/traffic covered above.
  • Cloud storage (e.g. AWS S3) -- encrypted dataset file storage and delivery.
  • Email delivery provider -- sending one-time sign-in codes.

We do not sell personal data. Some processors may be located outside the EEA/UK; where that's the case, transfers rely on their Standard Contractual Clauses or an equivalent safeguard.

How long we keep it

Account and transaction records are kept for as long as your account is active, plus a limited period afterward for legal, tax, and fraud-prevention purposes. Raw request/agent logs are retained only as long as needed for security and debugging, then deleted or aggregated. Session tokens expire automatically (24 hours) and one-time login codes and download tokens are single-use and short-lived.

Your rights

If you're in the EEA, UK, or a jurisdiction with similar protections, you can ask us to:

  • Access the personal data we hold about you.
  • Correct inaccurate data, or delete your account and associated data.
  • Export your data in a portable format.
  • Restrict or object to certain processing, including opting out of analytics at any time (see Cookie Preferences above) -- this doesn't affect the lawfulness of processing before you opted out.
  • Lodge a complaint with your local data protection authority.

Most of the above -- account deletion, analytics opt-out, and downloading your own transaction history -- is self-service from your Dashboard. For anything else, contact us using the details below and we'll respond within one month.

Children's privacy

VEDA is not directed at children, and we don't knowingly collect personal data from anyone under 16.

Changes to this policy

If we make material changes, we'll update the date at the top of this page and, where appropriate, post a notice on the site.

Contact

For privacy inquiries or to exercise any of the rights above, contact us at hello@veda.techgenesys.ai.