Privacy Policy

Last updated: 19 June 2026

This Privacy Policy explains how Velluva Ltd ("Velluva", "we", "us", "our") collects, uses, shares and protects personal data when you use our website and subscription software service (the "Service"). Velluva is a UK SaaS platform designed for salon and beauty businesses.

1. Who we are

Velluva Ltd is a company registered in England and Wales. We are the data controller for personal data of our account holders and website visitors. For personal data that you, as a salon, upload about your own clients (for example to send SMS reminders or review requests), you are the data controller and we act as your data processor.

If you have any questions about this policy or wish to exercise your data rights, contact us at privacy@velluva.com.

2. Personal data we collect

  • Account data: name, email address, password (hashed), business name, business type and location.
  • Billing data: subscription plan, billing history and partial card details handled by our payment processor (Stripe). We do not store full card numbers.
  • Content data: prompts, captions, ad copy, reminder templates and other content you generate or save in the Service.
  • Client data you upload: client first names and UK mobile numbers used to send reminders or review requests on your behalf.
  • Usage data: log data, device, browser, IP address, pages visited and feature usage.
  • Cookies: see our Cookie Policy (within this page, section 8) and the consent banner.

3. How we use personal data

  • To provide and operate the Service, including generating AI content and sending SMS on your instructions.
  • To take payment and manage your subscription.
  • To provide customer support and respond to enquiries.
  • To improve the Service, troubleshoot issues and keep it secure.
  • To send service-related emails (account, billing and security notices).
  • To comply with our legal obligations under UK law.

4. Lawful bases (UK GDPR)

We rely on the following lawful bases under the UK GDPR:

  • Contract: to deliver the subscription Service you have signed up for.
  • Legitimate interests: to operate, secure and improve the Service, provided your interests and rights do not override ours.
  • Legal obligation: to comply with tax, accounting and other UK laws.
  • Consent: for non-essential cookies and any optional marketing emails. You can withdraw consent at any time.

5. Sharing your data

We share personal data only with trusted subprocessors needed to run the Service:

  • Hosting and database: our cloud infrastructure providers (EU/UK regions where available).
  • Payments: Stripe Payments Europe Ltd.
  • SMS delivery: Twilio Ireland Ltd.
  • AI providers: for generating captions, ad copy and review messages from prompts you submit.
  • Email delivery: for transactional emails.

We do not sell personal data. We may disclose data where required by law or to protect our rights.

6. International transfers

Some subprocessors process data outside the UK. Where this happens we rely on UK adequacy regulations, the UK International Data Transfer Addendum or Standard Contractual Clauses to safeguard your data.

7. Retention

We keep account and billing data for the lifetime of your subscription plus up to 7 years to meet UK accounting and tax requirements. Generated content and client lists are deleted within 30 days of account closure unless you request earlier deletion. Backups are overwritten on a rolling cycle of up to 35 days.

8. Cookies

We use a small number of strictly necessary cookies to keep you signed in and the Service secure. Analytics and other non-essential cookies are only set after you accept them in the consent banner. You can change your choice at any time by clicking "Cookie settings" in the footer or clearing the velluva-cookie-consent entry in your browser storage.

9. Your rights

Under the UK GDPR you have the right to access, rectify, erase, restrict or object to processing of your personal data, and the right to data portability. To exercise any of these rights email privacy@velluva.com. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk).

10. Security

We use TLS encryption in transit, encryption at rest, role-based access controls and row-level security policies to protect your data. No system is 100% secure, but we work hard to keep yours safe.

11. Children

The Service is intended for business users aged 18 or over and is not directed at children.

12. Changes

We may update this Policy from time to time. Material changes will be notified by email or in-app at least 14 days before they take effect.