Privacy Policy
Last updated: 23 June 2026
This Privacy Policy explains how VEIS ("we", "us", "our") collects, uses, shares, and protects your personal data when you use the VEIS website and services (the "Service"). We process personal data in line with the Kenya Data Protection Act, 2019 ("DPA") and guidance issued by the Office of the Data Protection Commissioner ("ODPC"). Please read it alongside our Terms of Use and Cookie Policy.
1. Data controller
VEIS is the data controller for the personal data processed through the Service. You can reach us through the contact channels listed at the end of this policy.
2. Personal data we collect
- Account data: name, email address, password hash, role.
- User Content: the Statement of Purpose (SOP) and Curriculum Vitae (CV) you upload, and other evidence you declare within them (e.g. sponsor, finances, education history).
- Application data: the destination country, programme, intake, and other details you enter when creating an application.
- Generated data: automated assessments, scores, gap reports, and PDF reports produced by the Service from your User Content.
- Technical data: IP address, device and browser metadata, log timestamps, and security events used to operate and protect the Service.
- Cookies: as described in the Cookie Policy.
3. How we use your personal data and our legal bases
- To provide the Service you requested — performance of a contract.
- To authenticate you and keep your account secure — legitimate interest, legal obligation.
- To analyse your SOP/CV and generate reports — performance of a contract.
- To investigate misuse, fraud, or violations of our Terms — legitimate interest.
- To improve and maintain the Service in aggregated, pseudonymous form — legitimate interest.
- To send service notices and, where required, to comply with the law — legal obligation.
- For non-essential cookies and analytics — your consent (which you can withdraw at any time).
We do not sell your personal data. We do not use your User Content to train third-party AI models.
4. Sub-processors and recipients
We share personal data only with the service providers listed below, under written agreements:
| Provider | Purpose | Data shared | Region |
|---|---|---|---|
| Supabase (via Lovable Cloud) | Database, authentication, file storage | Account data, application data, generated reports | EU |
| Lovable AI Gateway | Routes prompts to the inference provider | SOP text, CV text, country, course metadata | EU / US edge |
| Google (Gemini 2.5) | Large-language-model inference for the analysis pipeline | SOP text, CV text, country, course metadata | US / EU |
| Cloudflare Workers | Application hosting and edge delivery | Request metadata, IP address at the edge | Global edge |
We do not currently use a third-party analytics, advertising, or email-marketing provider. If we add one, we will update this table before activating it.
We may also disclose personal data where required by law, court order, or to protect the rights, safety, and property of VEIS or its users.
5. International transfers
Some of our sub-processors operate outside Kenya. Where personal data is transferred outside Kenya, we rely on transfer mechanisms permitted by the DPA, including the provider's adherence to comparable data-protection standards and contractual safeguards.
6. Retention schedule
We keep each category of personal data only for as long as it is needed for the stated purpose:
| Data | Retention |
|---|---|
| Raw SOP and CV text | Purged automatically once the analysis finishes — whether it succeeds or fails. |
| Generated analysis and report PDF | Kept until you delete the report or your account. |
| Account data (name, email, role) | Kept while your account is active. |
| Audit and security logs | Up to 12 months, then purged or anonymised. |
| Account-deletion requests | 30-day grace period, then your account and all linked data are permanently deleted. |
You can review, export, or delete your reports and your account from Account → Privacy & Data once signed in.
7. Your rights under the DPA
You have the right to:
- be informed about how your personal data is processed;
- access your personal data;
- request correction of inaccurate or incomplete data;
- request deletion of your personal data ("right to be forgotten");
- object to or restrict processing;
- data portability — receive your data in a structured, commonly used format;
- withdraw consent at any time, where processing is based on consent;
- lodge a complaint with the ODPC.
You can exercise most of these rights directly from Account → Privacy & Data. For anything else, contact us using the details below.
8. Security
We use technical and organisational measures appropriate to the risk, including encryption in transit, encryption of secrets at rest, row-level security policies, principle-of-least-privilege access controls, and audit logging. No system is perfectly secure; you must also keep your credentials safe and notify us of any suspected unauthorised access.
9. Children
The Service is not directed to children. You must be at least 18 years old to create an account. If we learn we have collected personal data of a person under 18 without verified parental consent, we will delete it.
10. Cookies
See the Cookie Policy for full details on the categories of cookies we use and how to control them.
11. Changes to this Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, take reasonable steps to notify you.
12. Contact and complaints
For privacy questions, data-subject requests, or to reach our Data Protection Officer, email privacy@veis.app. You also have the right to lodge a complaint with the Office of the Data Protection Commissioner of Kenya (odpc.go.ke).