1. Overview
Veles Digital ("Veles Digital," "we," "us," or "our") respects your privacy and is committed to protecting personal information you share with us. This Privacy Policy explains what information we collect when you visit veles.digital (the "Site"), how we use and share that information, the legal bases on which we rely, and the rights you have with respect to your personal data.
This Policy applies only to the Site. It does not apply to services we deliver to clients under separate engagement agreements, which are governed by the data processing terms of those agreements.
2. About Veles Digital
Veles Digital is a custom artificial intelligence and software development agency based in Belgrade, Serbia. We design and build AI tools, automation systems, conversational interfaces, and analytics solutions for clients across Europe and worldwide.
For the purposes of the EU General Data Protection Regulation ("GDPR") and the Serbian Law on Personal Data Protection ("ZZPL," Official Gazette of the Republic of Serbia, No. 87/2018), Veles Digital is the data controller with respect to personal data processed through the Site.
Contact for privacy matters: contact@veles.digital.
3. Information We Collect
We collect personal information in the following circumstances:
3.1 Information you provide directly. When you contact us by email, WhatsApp, or schedule a meeting through our booking tool, you may provide your name, email address, telephone number, company affiliation, time zone, and any additional information you choose to include in your message or scheduling form.
3.2 Information collected automatically. When you visit the Site, certain information is collected automatically:
- Technical data — IP address, browser type, operating system, device type, referring URL, and pages viewed. This information is processed primarily by Cloudflare as part of our content delivery and security infrastructure.
- Usage data — pages viewed, time spent on pages, navigation paths, approximate geographic location (city level), and similar interaction signals. This information is collected through Google Analytics 4 only after you provide consent through our cookie banner.
- Cookies and similar technologies — see Section 6 for a complete inventory.
3.3 No special category data. We do not knowingly collect special categories of personal data (racial or ethnic origin, political opinions, religious beliefs, health data, etc.) through the Site. Please do not include such information in unsolicited communications.
4. How We Use Your Information
We use personal information for the following purposes:
- Communications — to respond to your inquiries, schedule and conduct meetings, send proposals, and follow up on potential engagements
- Site operation and security — to operate the Site reliably, prevent fraud and abuse, mitigate denial-of-service attacks, and maintain the technical integrity of our infrastructure
- Analytics and improvement — to understand how visitors use the Site, identify which content is useful, and improve the Site's structure, content, and performance
- Legal compliance — to comply with applicable laws, respond to lawful requests from public authorities, and enforce our legal rights
We do not engage in targeted advertising, behavioral profiling, or remarketing. The Site does not contain advertising trackers, conversion pixels, or third-party advertising tags.
5. Legal Bases for Processing
Under GDPR Article 6 and the corresponding provisions of the ZZPL, we process personal data on the following legal bases:
- Consent (Art. 6(1)(a)) — for analytics cookies and any other processing requiring opt-in consent. You may withdraw consent at any time (see Section 10).
- Performance of a contract (Art. 6(1)(b)) — when you book a meeting or enter into a client engagement, we process the personal data necessary to provide the requested service.
- Legitimate interests (Art. 6(1)(f)) — for Site security, fraud prevention, responding to inquiries you initiate, and other activities where our interests are not overridden by your fundamental rights. We have conducted balancing assessments where applicable.
- Legal obligation (Art. 6(1)(c)) — where processing is required by applicable law, including responding to lawful requests from competent authorities.
6. Cookies and Similar Technologies
We use cookies and similar storage technologies to operate the Site, secure it against abuse, and — with your consent — to understand how it is used.
6.1 Strictly necessary cookies. These cookies are required for the Site to function and cannot be disabled while you continue to use the Site:
- `__cf_bm` — set by Cloudflare for bot management. Duration: 30 minutes.
6.2 Analytics cookies. These cookies are set only after you provide consent through our banner:
- `_ga`, `_ga_*` — set by Google Analytics 4 to distinguish unique users for aggregated usage statistics. IP addresses are anonymized prior to storage. Duration: up to 14 months.
6.3 Preference storage. We store your consent choice locally in your browser:
- `veles-consent-v1` — stored in browser localStorage (not a cookie). Records your consent decision so we do not prompt you on every visit. Duration: until cleared by you or by clearing browser storage.
6.4 Third-party service cookies. Cookies set by integrated third-party services when you actively interact with them:
- Calendly cookies (`_calendly_session`, `__cfruid`, others) — set only when you open the Calendly scheduling modal by clicking a "Book a Call" link. Managed by Calendly under its own policy.
You may withdraw analytics consent at any time using the "Manage your consent" controls at the bottom of this page, or by clearing site data in your browser.
7. Sharing and Disclosure
We share personal information only as described below. We do not sell or rent personal data.
7.1 Service providers (sub-processors). We engage the following service providers to process personal data on our behalf, under contractual data protection terms:
- Cloudflare, Inc. (United States) — content delivery network, distributed denial-of-service protection, bot management
- Google LLC / Google Analytics (United States) — analytics, processed only when consent is provided
- Calendly, LLC (United States) — scheduling, processed only when you actively initiate a booking
- Contabo GmbH (Germany, EU) — origin server hosting
7.2 Legal disclosures. We may disclose personal information when required by law, court order, or other legal process, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
7.3 Business transfers. If Veles Digital is involved in a merger, acquisition, financing, or sale of all or a portion of its assets, personal data may be transferred as part of that transaction, subject to the terms of this Policy.
8. International Data Transfers
Some of our service providers process personal data in countries outside the European Economic Area, including the United States. When personal data is transferred outside the EEA, we rely on the following safeguards required by GDPR Chapter V:
- EU-US Data Privacy Framework ("DPF") — Cloudflare, Google, and Calendly are certified under the DPF, which the European Commission has determined provides an adequate level of protection for personal data transferred from the EU to participating organizations in the US.
- Standard Contractual Clauses ("SCCs") — additional safeguards under EU Commission Implementing Decision 2021/914, as further guaranteed under our data processing agreements with each provider.
Our origin server is hosted in Germany by Contabo; data we control directly is processed and stored within the European Union.
9. Data Retention
We retain personal information only for as long as necessary for the purposes described in this Policy. Specific retention periods are summarized below:
- Analytics data (Google Analytics): 14 months from collection
- Cloudflare security logs: up to 14 days
- Cookie `__cf_bm`: 30 minutes
- Inquiry correspondence and meeting notes: 24 months from last interaction, unless you become a client (in which case retention is governed by the engagement agreement)
- Consent records: stored locally in your browser until you clear them
When personal data is no longer needed, we delete it or anonymize it so it can no longer be associated with you.
10. Your Rights
Under the GDPR and the ZZPL, you have the following rights regarding your personal data:
- Right of access (Art. 15) — to obtain confirmation of whether we process personal data about you and, if so, a copy of that data
- Right to rectification (Art. 16) — to correct inaccurate or incomplete personal data
- Right to erasure (Art. 17) — to request deletion of personal data, subject to certain exceptions
- Right to restriction of processing (Art. 18) — to limit the processing of your personal data in certain circumstances
- Right to data portability (Art. 20) — to receive personal data you provided to us in a structured, commonly used, machine-readable format
- Right to object (Art. 21) — to object to processing based on legitimate interests
- Right to withdraw consent (Art. 7(3)) — to withdraw any consent you have given, at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, please contact us at contact@veles.digital. We will respond within 30 days, as required by GDPR Article 12(3). We may need to verify your identity before fulfilling certain requests.
Right to lodge a complaint. If you believe our processing of your personal data infringes applicable law, you have the right to lodge a complaint with a supervisory authority. In Serbia, the competent authority is the Commissioner for Information of Public Importance and Personal Data Protection. EU/EEA residents may contact the supervisory authority in their country of habitual residence.
11. Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption in transit (TLS 1.2+), restricted access controls, secure hosting infrastructure, regular security audits of our origin server, and limited retention periods.
No method of transmission over the internet or electronic storage is completely secure. While we strive to protect personal data, we cannot guarantee absolute security.
12. Children's Privacy
The Site is not directed to children under the age of 16. We do not knowingly collect personal information from children. If you become aware that a child has provided personal information to us, please contact us at contact@veles.digital and we will promptly delete it.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable law. When we make material changes, we will update the "Last updated" date at the top of this page. For significant changes, we will provide additional notice through the Site or by other appropriate means. We encourage you to review this Policy periodically.
14. Contact Us
If you have questions, comments, or requests regarding this Privacy Policy or our processing of your personal data, please contact us:
- Email: contact@veles.digital
- Postal: Veles Digital, Belgrade, Republic of Serbia (request full address by email if needed for postal correspondence)
We will respond to all legitimate inquiries within 30 days.