Privacy Policy
1. Data Controller
The data controller for the Veilleo platform is:
Cueff Pierre - Alain Philippe12 Rue de Brest
29600 Morlaix
France
Email: admin@veilleo.com
Phone: +33 769 990 334
Questions about how we handle your personal data should be directed to the address above.
2. What We Collect
We collect the following categories of personal data:
- Account data: Full name, email address, company name, website URL, industry. Collected when you register.
- Authentication data: Hashed password, session tokens, optional remember-me token. Never stored in plain text.
- Contact form data: Name, email, company, phone (optional), subject, message body, service interest (optional). Collected when you use the contact form.
- Competitor monitoring data: Competitor names, URLs, and industry categories you submit. This is information about third-party businesses, not personal data in most cases.
- Usage data: Server log entries (IP address, request path, timestamp, user agent) retained for security and debugging. We do not maintain persistent IP-to-user associations beyond what is inherent in server logs.
- Security data: IP addresses used temporarily for rate limiting (stored in temporary files that auto-expire). Not linked to your account.
We do not collect payment card details directly. Payment processing, when enabled, is handled by a PCI-compliant third party.
We do not collect demographic data, browsing history across third-party sites, precise geolocation, or biometric data.
3. How We Use Your Data
- To create and manage your account.
- To provide the competitor intelligence service described on this platform.
- To send transactional emails you have requested (password reset, account changes).
- To respond to contact form submissions.
- To enforce our Terms of Service and protect the security and integrity of the platform.
- To comply with legal obligations under French and EU law.
We do not use your data for behavioural advertising. We do not sell your personal data. We do not share your data with data brokers.
4. Legal Basis for Processing
Under the GDPR (Regulation (EU) 2016/679), we process your personal data on the following legal bases:
- Contract (Art. 6(1)(b) GDPR): Processing your account data, competitor data, and providing the service is necessary to perform the contract between you and us.
- Legitimate interests (Art. 6(1)(f) GDPR): Server logs and security rate limiting serve our legitimate interest in keeping the platform secure, subject to your rights.
- Legal obligation (Art. 6(1)(c) GDPR): We may process your data to comply with applicable laws, including tax and accounting obligations.
- Consent (Art. 6(1)(a) GDPR): Where we rely on consent (for example, optional marketing communications), you may withdraw consent at any time by contacting us.
5. Data Storage and Retention
Your data is stored on servers operated by EU-based hosting providers. Veilleo is operated by Cueff Pierre - Alain Philippe, a French company, and all data processing is subject to French and EU law. We use industry-standard encryption for data in transit (HTTPS/TLS) and take reasonable precautions for data at rest.
Retention periods:
- Account data: Retained while your account is active and for up to 3 years after closure, to meet our legal and audit obligations, then permanently deleted.
- Contact messages: Retained for up to 3 years for operational and legal reference, then permanently deleted.
- Server logs: Retained for up to 90 days, then automatically purged.
- Password reset tokens: Expire after 1 hour and are deleted on use.
- Rate-limit files: Expire automatically after the rolling window (typically 10 minutes).
6. Third Parties
We share your personal data with third parties only to the extent necessary to operate the service:
- Hosting provider: Our server infrastructure is provided by reputable EU-based hosting providers under data processing agreements compliant with GDPR. No data is transferred outside the European Economic Area.
- Email delivery: Transactional emails (password resets, account notifications) are sent via a reputable transactional email provider operating under a data processing agreement. Only the recipient address and email content necessary for the specific transaction are shared.
We do not share your personal data with analytics platforms, advertising networks, or social media platforms unless you separately consent to that and such functionality is added in a future update with prior notice.
8. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15): Request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): Request correction of inaccurate data. Many fields can be updated directly in your account settings.
- Right to erasure (Art. 17): Request deletion of your account and associated personal data, subject to retention obligations.
- Right to restrict processing (Art. 18): Request that we limit how we use your data in certain circumstances.
- Right to data portability (Art. 20): Request your data in a structured, machine-readable format where technically feasible.
- Right to object (Art. 21): Object to processing based on legitimate interests.
- Right to withdraw consent (Art. 7(3)): Where processing is based on consent, you may withdraw at any time.
To exercise any of these rights, contact us at admin@veilleo.com. We will respond within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the French data protection authority:
CNIL (Commission nationale de l'informatique et des libertés)3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
www.cnil.fr
9. Security
We implement technical and organizational measures to protect your personal data, including:
- HTTPS/TLS encryption for all data in transit.
- Bcrypt-hashed passwords (never stored in plain text).
- CSRF protection on all state-changing requests.
- Server-side input validation and sanitization.
- HTTP-only and Secure flags on session cookies.
- Access controls to restrict administrative functions.
- Protection of database files from direct HTTP access.
No security measure is guaranteed to be impenetrable. If you discover a security vulnerability, please report it responsibly to admin@veilleo.com.
10. Contact and Complaints
For any privacy-related question or request:
Cueff Pierre - Alain Philippe12 Rue de Brest, 29600 Morlaix, France
admin@veilleo.com
We aim to acknowledge requests within 5 business days and resolve them within 30 calendar days.