Veslo
Terms of Service Contact Sales
Legal / Privacy

Privacy Policy

How Veslo handles data on its website and in the iPhone and iPad app, including company accounts, AI agents, meeting recordings, recipients and deletion choices.

Effective date Effective date: July 2, 2026
Last updated: October 7, 2026
Controller Neatech s.r.o.
IČO 02481103
Neklanova 150/38, Vyšehrad, 12800 Praha 2, Czech Republic
Privacy contact sales@neatech.cz
Sections Scope and responsibilities Data we process Mobile permissions Purposes and legal bases Recipients and AI Website analytics Retention and deletion Your rights Security and changes

1. Scope and responsibilities

This policy covers the public Veslo website, business communications and the Veslo iPhone and iPad app, including the company web interface loaded by the app. The mobile app is a client for an existing company account and connects to your organisation's server at <company>.app.veslo.work. Downloading the app does not create a company account.

Neatech s.r.o. acts as controller for its own website, business communications and its own operational purposes. Your organisation determines the purposes and authorised users for company conversations, documents and meetings as controller. Neatech's role in operating a particular company server and the processing terms depend on the customer arrangement. Your administrator can explain your organisation's rules.

2. Data we process

  • Account and sign-in: name or display name, work email, account identifier, company membership, roles, permissions and sign-in sessions. When you choose Google sign-in, the company server receives information needed to authenticate the account, such as name, email and provider identifier. Password sign-in uses a verification hash stored on the server rather than a plain-text password.
  • Conversations and files: messages and instructions to agents, responses, thread titles, photos, videos, documents and other attachments you send or that are produced while carrying out a task.
  • Meetings: audio recordings, title, recording time and duration, upload and processing status, transcript, summary and subsequent instructions or meeting notes. Content may include participants' personal data.
  • Operation and security: sign-in and activity times, task-processing records including status and run duration, technical errors and security events. Network connections involve IP addresses and technical request information. Server logging varies by company deployment.
  • Public website and contact: work email, optional name, company, role, message, form, language, referrer, source and UTM values; with analytics enabled, information about visits and website interactions.

Mobile version 0.2.0 (12) does not read your address book or device location and does not use the advertising identifier. Information you put in a message, document or recording yourself may contain such details.

3. Device storage, permissions and sending

The selected company and functional settings are saved on your device. Sign-in cookies and sessions maintain access to the company server. The app may temporarily store attachments and downloaded files needed for viewing or sharing.

The microphone records a meeting when you start recording and can provide optional message dictation where the company interface enables it. Recording may continue in the background or with the device locked. Audio and its recording record are first saved in the app's storage so interrupted recording or sending can be recovered. Audio is sent to the company server when you choose to send, or according to the enabled automatic-upload setting. You can change that setting in meeting settings.

The camera reads your company's QR connection code and takes a photo for a conversation; you select photos and files to attach. The QR code selects the company. The app does not upload the whole photo library or file storage.

You can change microphone, camera and photo permissions in iOS/iPadOS settings. Refusing permission limits the corresponding feature. Inform participants before recording and follow your organisation's rules and applicable law.

For message dictation, a short audio recording is sent through the company server to OpenAI to convert it to text. This is separate from longer meeting transcription by the WhisperX service. You can edit the resulting text before sending it to the conversation.

4. Purposes and legal bases

App data is used for account authentication, access control, agent conversations, working with files, recording and processing meetings, preserving history and outputs, and security, support and troubleshooting. Neatech does not embed advertising networks or targeted-advertising tracking in the app.

For its own activities, Neatech relies on performance of a contract or steps before a contract under Article 6(1)(b) GDPR; legitimate interests in secure operation, support and protecting rights under Article 6(1)(f); legal obligations under Article 6(1)(c); and consent under Article 6(1)(a) for optional website analytics. Where work content is processed on your organisation's instructions, that organisation provides the legal basis and information to affected individuals.

Sign-in details are required to access the company account. Sending a message, attachment or recording follows use of the corresponding feature. An operating-system microphone or camera permission does not by itself provide a legal basis for processing other people's data.

5. Recipients, AI and integrations

Content is processed on the selected company server and is accessible to users, agents and administrators according to their permissions. Shared projects or tasks may make content available to other members of your organisation.

  • Infrastructure: Neatech-operated hosting uses Webglobe server infrastructure. Customer-operated deployments use infrastructure selected by the customer.
  • AI: content needed for an answer or task is sent to the provider configured for the agent. Veslo supports OpenAI and Anthropic; the administrator manages the selected provider and integrations. Cloud processing may receive the message, relevant history, attached content and results from authorised tools.
  • Meetings: Neatech's current hosted transcription service runs the WhisperX model locally. This does not mean the transcript remains in that service: a company server with the short-summary feature enabled sends the opening part of the transcript to OpenAI; assigning a task to an agent also sends the transcript to the selected AI provider. Message dictation uses OpenAI to convert short audio recordings into text.
  • Sign-in, email and integrations: Google when you choose Google sign-in or connect a Google service; Resend for account email in hosted company instances; Lettr for public-website email and enabled transcription-service notifications. Other recipients depend on integrations authorised by the organisation or user.

An external provider's processing, retention and any further use depend on the selected product, contract and settings. See information from OpenAI and Anthropic; their cloud services cannot generally be described as on-device processing or zero retention. Your company administrator can provide the recipients and contractual safeguards for the specific deployment, including any transfers outside the EU/EEA.

Neatech does not sell company message, file or recording content to data brokers. Integrations also follow the permissions and terms of the external service.

6. Public website: cookies, analytics and fonts

The public website uses a language cookie and local storage for language and analytics choice. Google Analytics and Microsoft Clarity load only after you choose “Allow measurement”. Analytics measures visits, traffic sources and interactions; Clarity may generate session reconstructions and heatmaps. These tools belong to the public marketing website, not company conversations in the mobile app.

You can withdraw consent by clearing website data for veslo.work in your browser and choosing “Keep off” on your next visit. Reload the page after clearing data. Clearing local data does not itself erase information already retained by providers; you can contact us about a related deletion request.

The site loads Google Fonts from Google servers, which receive technical request information such as IP address and browser details. See the privacy information from Google and Microsoft.

7. Retention and deletion

  • On the device: a recording stays in app storage until you delete it. Successful upload does not automatically delete it. Uninstalling removes the app's local storage, not company copies already uploaded.
  • Server audio: after successfully downloading a transcript, the company server attempts to delete the working audio file. The hosted transcription service is configured to delete uploaded audio after successful processing. Unprocessed or failed recordings may remain for retry or support.
  • History, attachments, transcripts and outputs: these remain company work records according to your organisation's rules and customer arrangement. There is no single automatic deletion period shared by all deployments. Deleting a meeting from the list is a logical removal and may not delete files, the transcription-service transcript or a copy already posted to a conversation. Request complete deletion from your administrator or our contact.
  • Operational and security records: retention depends on server configuration, log rotation and troubleshooting or incident needs. We do not promise one period for all company servers. Backups and external-provider copies have their own cycles; uninstalling the app or deleting an item in the interface does not erase them immediately.
  • Public website: business contact data is kept while discussions remain relevant, normally up to three years after the last meaningful contact; legally required documents are kept for the statutory period. Analytics retention depends on Google Analytics and Microsoft Clarity settings and policies.

To request account closure and erasure of personal data, contact your company administrator or sales@neatech.cz. Include the company and account email; never send your password. We handle requests according to the responsible controller's role, organisation rules and legal obligations, and explain any limitation on erasure, such as a statutory obligation or legal claim.

8. Your rights and choices

Under GDPR, you may have the rights of access, rectification, erasure, restriction, portability, and objection. You may withdraw consent at any time without affecting earlier lawful processing. For company content, also contact your organisation; for data controlled by Neatech, contact sales@neatech.cz. We verify the authority of a request before disclosing or deleting data.

You can disconnect an integration in settings if authorised. This prevents further use of that connection but does not erase content already retrieved. You can also revoke operating-system permissions, stop recording or stop sending content to a cloud agent.

You may lodge a complaint with the Czech supervisory authority, Úřad pro ochranu osobních údajů, uoou.gov.cz, or the competent authority in your country of habitual residence.

9. Security and changes

The mobile app connects to the company server over HTTPS. Company accounts and permissions control content access; server and vendor processing is distinct from local phone storage. This service does not promise end-to-end encryption, exclusively on-device processing or one storage location across all integrations.

Veslo is designed for business use. AI outputs may be wrong and require human review. The app itself does not make decisions with legal or similarly significant effects; the relevant organisation is responsible for using outputs and setting workflow rules.

We update this policy when processing changes. The last-updated date appears above. Ask your administrator or our privacy contact for information about a specific company deployment and its processors.

Veslo · Enterprise automation
Terms Privacy

Created by neatech.cz