Legal

Privacy policy.

Plain-English promise: we collect only what you give us, use it only to help you, store it securely, and never sell it.

Last updated: 30 August 2026

1. About this policy

Veleria ("Veleria", "we", "us", "our") is a custom software development studio based in Melbourne, Victoria, Australia. We build websites, web applications, CRMs, mobile apps and AI automation for businesses.

We are committed to handling personal information in accordance with the Australian Privacy Principles (APPs) set out in the Privacy Act 1988 (Cth). This policy explains what personal information we collect, why we collect it, who we share it with, how we protect it, and how you can access, correct or delete it.

This policy applies to personal information we collect:

  • through the veleria.com.au website
  • by email, phone, SMS and video call
  • in the course of quoting for, delivering and supporting software development services

It does not apply to personal information held inside software we build for clients. Where we develop a system for a client, that client is the entity responsible for the personal information in it, and their own privacy policy governs how it is handled. Our role and obligations in that situation are described in section 11.

Contact for anything in this policy: contact@veleria.com.au or 0478 333 107.

2. Dealing with us anonymously

Where it is lawful and practicable, you may deal with us anonymously or under a pseudonym. You can ask general questions about our services by phone or email without telling us who you are.

For most work we do need to identify you. We cannot prepare a scope or quote, enter into an agreement, issue an invoice or provide ongoing support without knowing who we are dealing with.

3. Personal information we collect

Enquiries. When you contact us through the website enquiry form, by email, by phone or through Instagram, we collect the details you choose to give us. This typically includes your name, business name, email address, phone number and a description of the project you have in mind. The website form may also ask about project type, timeline and budget range. You control what you tell us, and if a field is not required you can leave it blank.

Clients. If you engage us, we collect the additional information reasonably necessary to deliver, invoice and support the project. This may include:

  • billing and business details, including ABN and billing address
  • content, copy, images, documents and data you supply for the project
  • access credentials, API keys and account access you authorise us to use on your systems
  • records of our communications, including emails, messages, call notes and meeting notes
  • project management, scoping and technical documentation

Website usage information. When you browse veleria.com.au we record technical information about the visit. This includes the pages viewed, the date and time, the referring source, campaign parameters in the URL, approximate location at city level, and device and browser type. We use this in aggregate to understand which pages are useful and how people find us.

We also operate our own first-party page view logging, stored in our own database, which records the page path, timestamp, referrer and a short-lived session identifier so that repeat views within a single visit are not double counted. Automated traffic and bots are filtered out. This logging is not used to build a profile of you and we do not attempt to identify individual visitors from it.

Sensitive information. We do not seek out sensitive information as defined in the Privacy Act, including health information, information about racial or ethnic origin, political opinions, religious beliefs, sexual orientation or criminal record. Some projects, for example software for healthcare or disability services providers, involve systems that will hold sensitive information belonging to the client’s own customers. Where that occurs we collect and access it only to the extent necessary to build, test and support the system, only with the client’s authorisation, and under the terms of section 11.

4. How we collect personal information

We collect personal information:

  • directly from you, through the website enquiry form, email, phone, SMS, video calls, and documents or files you send us
  • automatically, through our website hosting, our own page view logging and our analytics tooling when you visit the site
  • from your authorised representatives, for example when a colleague at your organisation provides your contact details as the project contact
  • from publicly available sources, only in limited circumstances such as confirming an ABN or a business address

We do not buy personal information from data brokers. We do not scrape personal information from third-party websites or social platforms for marketing purposes.

5. Why we collect and use personal information

We collect and use personal information for the following purposes:

  • to respond to your enquiry, arrange a scoping call and prepare a quote
  • to enter into and perform our agreement with you
  • to design, build, test, deploy, host and support the software you engage us for
  • to communicate with you about your project, including updates, questions and support requests
  • to issue invoices, take payment, and keep financial and tax records
  • to maintain the security, availability and integrity of our website and systems
  • to understand in aggregate how our website performs and improve it
  • to meet our obligations under Australian law

We will not use your personal information for a purpose unrelated to the one it was collected for unless you would reasonably expect it, you have consented, or the law requires or permits it.

6. Direct marketing

We do not add enquiry contacts to a marketing list by default.

We will only send you marketing communications if you have asked to receive them, or if you are an existing client and the communication relates to services similar to those we have provided you. Every marketing message will identify us and include a simple way to opt out. If you opt out we will action it promptly and keep a record of your preference so we do not contact you again in error.

We never sell personal information. We never share it with advertisers, data brokers or list resellers. We do not display advertising on our website.

You can opt out at any time by emailing contact@veleria.com.au.

7. Cookies and analytics

Our website uses a small number of cookies and similar technologies. These fall into two groups.

Necessary. Used to make the site function correctly and securely, and to hold a short-lived session identifier so our first-party page view logging does not count the same visit repeatedly.

Analytics. We use Google Analytics 4 to measure aggregate site usage. Google Analytics sets first-party cookies and processes information about your visit on Google’s infrastructure. We have configured our property so that it is used only to measure our own website’s performance. We do not use it to build advertising audiences, we do not run remarketing or advertising cookies, and we do not run cross-site tracking pixels for social or ad platforms.

You can block or delete cookies through your browser settings, and you can install Google’s own browser add-on to opt out of Google Analytics. The site remains usable with cookies disabled. For more information about how Google handles this data, see Google’s privacy policy at policies.google.com/privacy.

8. Who we disclose personal information to

We disclose personal information only where it is necessary to run our business or to deliver your project. Our current service providers are:

  • Supabase, for database and backend hosting of our website enquiry records and page view logging
  • Vercel, for website hosting, deployment and edge delivery
  • Google Workspace and Gmail, for business email including enquiry notifications and our internal daily summary
  • Google Analytics, for aggregate website usage measurement
  • Stripe, for payment processing where card payment is used
  • our accountant and professional advisers, for bookkeeping, tax and legal advice where required

Each provider is engaged under its own terms and maintains its own security and privacy program. We do not authorise any of them to use your information for their own marketing purposes.

We may also disclose personal information:

  • where you have consented or would reasonably expect us to
  • where required or authorised by law, a court order, a subpoena or a regulator
  • where reasonably necessary to establish, exercise or defend a legal claim
  • where reasonably necessary to prevent a serious threat to life, health or safety
  • to a purchaser or successor if our business or its assets are sold or transferred, in which case the information would remain subject to a policy no less protective than this one

If we engage a new provider that materially changes how personal information is handled, we will update this section.

9. Overseas disclosure

Some of the providers listed in section 8 store or process data on servers located outside Australia, including in the United States and other jurisdictions.

Before disclosing personal information to an overseas recipient we take reasonable steps to satisfy ourselves that the recipient handles it in a way consistent with the Australian Privacy Principles, including by reviewing their published security and privacy commitments and their contractual terms. Where a provider offers Australian or regional data residency and it is appropriate for the project, we use it.

If you would like to know where a particular category of information is stored, email us and we will tell you.

10. Automated processing and AI

We build AI automation for clients, and we use AI tools in our own work.

We do not use automated decision making that produces a legal or similarly significant effect about you. Decisions about quoting, engaging and pricing are made by a person.

Where we use third-party AI services in the course of a project, we do so under commercial terms that exclude the use of submitted content for training the provider’s models, unless the client has specifically agreed otherwise in writing. We do not submit client data or your personal information to consumer AI tools that train on inputs.

11. Client project data

Where we build or support a system for a client, the client is generally the entity with primary responsibility for the personal information held in that system.

In that role we act on the client’s instructions. Specifically we:

  • access client systems and data only to the extent needed to build, test, fix or support the system
  • use the minimum access necessary and prefer test or de-identified data where the work allows it
  • do not use client data for any purpose of our own
  • do not disclose client data to anyone except as the client directs or the law requires
  • return or delete working copies and revoke our access at the end of an engagement, on request, or when no longer needed

Individual client agreements may include additional confidentiality, security or data handling terms. Where they do, those terms apply alongside this policy.

12. Security

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification and disclosure. Our measures include:

  • encrypted connections (HTTPS/TLS) across the website and all administrative interfaces
  • encryption at rest on our hosted database
  • role separation on our database, with service-level keys held only in server-side environment variables and never exposed to the browser
  • two-factor authentication on core accounts including email, hosting, source control and the database
  • least privilege access, with credentials and access reviewed and revoked when no longer needed
  • keeping dependencies and frameworks patched
  • collecting only the information we actually need, and deleting it when we no longer need it

No system can be guaranteed completely secure. If you believe there is a problem with information you have provided to us, or you have found a security issue on our website, please contact us immediately at contact@veleria.com.au and we will investigate promptly.

13. Data breaches

We maintain a data breach response process. If we become aware of an actual or suspected breach we will contain it, assess what information was involved and the likely risk, and take steps to remediate.

If a breach is likely to result in serious harm to any affected individual, we will notify those individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth). Where a breach affects a client’s system, we will also notify that client without undue delay so they can meet their own obligations.

14. How long we keep personal information

We keep personal information only as long as we need it.

  • Enquiries that do not proceed: retained while the enquiry is still relevant to a possible engagement, and generally deleted or de-identified within two years.
  • Client and project records: retained for the life of the engagement and afterwards while needed for support, warranty and dispute purposes.
  • Financial and tax records: retained for at least five years as required by Australian tax and business record-keeping law.
  • Website usage logs: retained in aggregate, with detailed records de-identified or deleted once no longer useful for performance analysis.

When information is no longer needed for any permitted purpose, we take reasonable steps to destroy it or de-identify it. You can ask us to delete information earlier and we will comply unless we are required by law to retain it, in which case we will tell you which category applies.

15. Access, correction and deletion

You have the right to:

  • access the personal information we hold about you
  • correct anything that is inaccurate, out of date, incomplete, irrelevant or misleading
  • request deletion of information we no longer need to hold
  • withdraw consent to any use of your information that relies on consent

To make a request, email contact@veleria.com.au. We will verify your identity, acknowledge your request promptly, and respond within 30 days. There is no charge for making a request or for a correction.

If we refuse a request in whole or in part, we will tell you in writing why, and how you can complain about that decision.

If your request relates to information held inside a client’s system, we will direct you to the client, who is the entity able to action it, and will assist them in doing so.

16. Children

Our website and services are directed at businesses, not children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it.

17. Links to other websites

Our website contains links to other sites, including our own related product pages and third-party services. This policy does not apply to those sites. We encourage you to read the privacy policy of any site you visit through a link from ours.

18. If you are outside Australia

We are an Australian business and this policy is written to meet Australian law. We do not target our services at individuals in the European Union or the United Kingdom.

If you are located in a jurisdiction with additional data protection rights and you believe those rights apply to information we hold, contact us at contact@veleria.com.au. We will consider your request and, where those rights apply, handle it consistently with them.

19. Complaints

If you believe we have mishandled your personal information or breached the Australian Privacy Principles, please contact us first at contact@veleria.com.au. Set out what happened and what outcome you are seeking. We will acknowledge your complaint within five business days, investigate, and give you a written response within 30 days.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner:

  • Website: oaic.gov.au
  • Phone: 1300 363 992
  • Post: GPO Box 5218, Sydney NSW 2001

20. Changes to this policy

We may update this policy from time to time as our services, our providers or the law change. The current version and its last-updated date are always published on this page. Where a change materially affects how we handle personal information, we will note it here and, where appropriate, contact affected clients directly.

21. Contact us

Veleria, Melbourne, Victoria, Australia.

  • Email: contact@veleria.com.au
  • Phone: 0478 333 107
  • Web: veleria.com.au

Questions? Get in touch or email contact@veleria.com.au.