Skip to content
Design a Pilot
Legal

Privacy Policy

This policy explains what personal information Veilancy collects through this website, why we collect it, who it is shared with, how long we keep it, and the rights you can exercise over it.

Last updated — August 2026

Who is responsible for your data

Veilancy is a managed remote operations company based in Amman, Jordan. For information you submit through this website, Veilancy is the controller — meaning we decide why and how it is used. You can reach us about anything in this policy at contact@veilancy.com. We aim to acknowledge privacy requests within five business days and to resolve them within 30 days.

Scope of this policy

This policy covers veilancy.com and the forms, email addresses, and private admin tools connected to it. It does not cover third-party websites we link to, such as social profiles, or the internal systems of our clients, which are governed by their own policies.

Where local law gives you stronger rights than this policy describes — for example under the EU or UK GDPR, Jordanian personal data protection law, or U.S. state privacy laws — those rights apply and we will honour them.

Information we collect

We collect only what you give us, plus a minimal amount of technical information needed to operate and secure the site. We do not buy personal data, and we do not build advertising profiles.

  • Client enquiries. Name, work email, company, website, company size, the operation you want to improve, timeline, and anything else you type into the pilot or contact form.
  • Candidate applications. Name, email, phone, city and country, language level, role and availability preferences, written answers, work history you choose to share, and your CV file if you upload one.
  • Product and usage events. A random visitor identifier, page path, referring site, and which buttons or forms were used. These records are not linked to a name or account.
  • Technical and security data. Server and infrastructure logs generated automatically when a page or form is requested, including IP address, timestamp, and user agent, used to keep the site available and to detect abuse.
  • Correspondence. Emails and messages you send us, and our replies.
  • Admin accounts. For the private area used by our own staff: email address, authentication records, and role assignments.

Please do not send us special-category information — such as health, religion, political opinions, or government identity numbers — through this website. We do not ask for it and do not need it to evaluate an enquiry or an application.

Why we use it, and on what basis

Where the GDPR or a comparable law applies, these are our purposes and the legal bases we rely on:

  • Responding to enquiries and scoping a pilot — steps taken at your request before entering a contract, and our legitimate interest in running a business.
  • Assessing candidate applications — steps taken at your request before a possible employment relationship, and our legitimate interest in hiring well.
  • Keeping your details on file for future roles — your consent, which you can withdraw at any time.
  • Improving the site using aggregate usage data — our legitimate interest in understanding which content is useful, balanced against a design that avoids identifying individuals.
  • Security, fraud prevention, and abuse detection — our legitimate interest in protecting the site and the people who use it.
  • Legal, tax, and record-keeping obligations — compliance with law.

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it for any purpose that is incompatible with the one it was collected for.

Who we share it with

  • Veilancy personnel who need the information to do their job, under role-based access.
  • Service providers that host, store, or deliver messages on our behalf, under contract and only on our instructions.
  • A client, only where you are a candidate who has explicitly agreed to be presented to that client, or where you are the client contact yourself.
  • Professional advisers such as accountants or lawyers, where necessary and confidential.
  • Authorities, where we are legally required to disclose, or where disclosure is necessary to establish or defend legal claims.
  • A successor, if the business or part of it is reorganised or acquired; the information stays subject to protections at least as strong as this policy.

Service providers we rely on

We keep our vendor footprint deliberately small. The categories we use are: cloud application hosting, managed database and file storage, authentication, and transactional email delivery. Each is engaged under a written agreement that limits them to processing data on our instructions and requires appropriate security measures.

If you would like the current named list of providers, email us and we will send it.

International transfers

Veilancy operates from Jordan and serves clients internationally, so information may be processed on servers located outside your country — including in the European Union and the United States. Where personal data is transferred out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses, the UK Addendum where applicable, or another lawful transfer mechanism, and we assess whether additional safeguards are needed.

How long we keep it

  • Client enquiries: up to 24 months from the last contact.
  • Candidate applications and CVs: up to 12 months from your last interaction, so we can contact you about later openings. Ask and we will delete them sooner.
  • Usage events: up to 14 months, then deleted or aggregated.
  • Security and infrastructure logs: typically up to 90 days, unless retained longer for an active investigation.
  • Contracts, invoices, and other records we must keep by law: for the statutory period that applies.

When a retention period ends, we delete the information or irreversibly anonymise it. Backups are cycled out on their own schedule shortly afterwards.

Your rights and how to use them

Depending on where you live, you may have the right to:

  • Access a copy of the personal information we hold about you.
  • Correct information that is inaccurate or incomplete.
  • Delete information we no longer have a valid reason to keep.
  • Restrict or object to certain processing, including profiling.
  • Receive your data in a portable, machine-readable format.
  • Withdraw consent at any time, without affecting past processing.
  • Opt out of marketing contact.
  • Be free from discrimination for exercising any of these rights.

Email contact@veilancy.com with the request and the email address you used. We may ask a small number of questions to confirm identity before acting, and we will respond within 30 days. An authorised agent may submit a request on your behalf with written proof of authority. Requests are free unless they are manifestly unfounded or excessive.

Candidates and CVs

CV files are stored in a private bucket that is not publicly readable, and are opened only through short-lived signed links by staff involved in hiring. We use CVs solely for recruitment. We do not send a CV to a client, and do not publish any part of it, without the candidate's explicit agreement for that specific introduction.

Assessment notes are factual and job-related. You can ask for a copy of them, ask us to correct an error of fact, or ask us to delete your application entirely.

When we act on behalf of a client

During a client engagement, our teams may handle personal data that belongs to that client's customers or employees. In that context the client is the controller and Veilancy acts as a processor: we act only on the client's documented instructions, under the data protection terms of the signed services agreement, and we do not use that data for our own purposes. Requests about such data should go to the client, and we will support them in responding.

Payments and billing

Where a pilot deposit or invoice is paid online, payment is processed by our payment provider acting as merchant of record. Card and bank details are entered directly with that provider and never reach Veilancy's systems. We receive only the confirmation record we need for accounting and delivery: payer name, billing email, billing country, amount, currency, tax treatment, a provider transaction reference, and payment status.

The provider processes this data as an independent controller under its own privacy terms, including for fraud screening and tax reporting. We keep the confirmation record for the statutory accounting and tax retention period that applies in Jordan and, where relevant, in the client's country.

Email, marketing, and preferences

Operational email — a reply to your enquiry, a payment receipt, an interview arrangement, or an account notice — is sent because it is necessary to the relationship you started, and cannot be switched off while that relationship is active.

Anything promotional is separate. We send it only where you asked for it or where a business contact relationship allows it under the law that applies to you, and every such message carries a one-click unsubscribe link and an honest sender address. Unsubscribing takes effect immediately and we retain a minimal suppression record so we do not contact you again by mistake. We do not sell or rent our contact lists.

AI-assisted features

We use AI tools inside our private workspace to draft text, summarise notes, and answer questions from our own documented playbooks. Where a request is sent to a model provider, it is sent under an enterprise or API agreement that prohibits using our inputs or outputs to train that provider's public models, and we retain no more than we need for the feature to work.

We do not feed candidate CVs or client customer data into public consumer AI tools, and no AI system decides an application, a payment, or an account outcome on its own.

Our own workforce

Veilancy staff use an internal workspace that records shifts, tasks, work logs, and — where a client engagement requires documented assurance — periodic activity check-ins and session evidence. This is disclosed to every team member in writing before it begins, is limited to working hours and work systems, is proportionate to the delivery obligations we have accepted, and is accessible only to the manager and administrators responsible for that engagement. It is never used for covert surveillance, and never extends to personal devices or personal accounts.

Cookies and similar technology

This site does not use advertising or cross-site tracking cookies, and does not run third-party ad networks. We use:

  • Strictly necessary storage — a signed-in session cookie for the private admin area used by our own team, and security tokens that protect form submissions.
  • Local and session storage — a random identifier and short-lived keys used to avoid double-counting the same click or form submission.

You can clear this storage in your browser at any time. Doing so may mean a repeated action is counted twice, but no site feature will stop working.

Do Not Track and Global Privacy Control

Because we run no advertising trackers and never sell or share personal information for behavioural advertising, there is nothing for an opt-out signal to switch off. We still honour a Global Privacy Control or Do Not Track signal as a valid opt-out request where the law treats it as one, and we do not attempt to identify you across other websites.

Automated decisions and profiling

We do not make decisions about you by automated means alone. Every enquiry and every application is reviewed by a person before any outcome is decided, and no algorithm rejects a candidate.

How we protect information

Our controls include encrypted transport, least-privilege and role-based access, row-level database policies, private file storage with signed access, individual named accounts for staff, and logging of administrative activity. Access is reviewed when roles change and revoked when someone leaves.

No system is perfectly secure. If a breach affects your personal information, we will notify you and any relevant regulator without undue delay, and describe what happened and what we are doing about it. If you believe you have found a vulnerability, please report it to contact@veilancy.com rather than testing it further.

Children

This site is intended for business use. We do not knowingly collect information from anyone under 18. If you believe a minor has sent us information, contact us and we will delete it.

Regional disclosures

We serve clients and candidates across several legal regimes. The following disclosures add to — and, where they conflict, override — the rest of this policy for people in the regions named.

  • Jordan. Veilancy is established in Amman and processes personal data in line with Jordan's Personal Data Protection Law No. 24 of 2023. The dedicated Jordan annex below forms part of this policy and prevails for individuals in Jordan.
  • European Economic Area and United Kingdom. You hold the rights in Articles 15 to 22 of the EU GDPR and the equivalent UK GDPR provisions, including access, rectification, erasure, restriction, portability, and objection to processing based on legitimate interests. Transfers out of the EEA or UK rely on the Standard Contractual Clauses with the UK Addendum where applicable, supported by a transfer risk assessment. You may complain to your national supervisory authority or, in the UK, the Information Commissioner's Office. Where we are required to appoint an Article 27 representative, we will name the current representative on request.
  • Switzerland. Processing follows the revised Swiss Federal Act on Data Protection, and you may raise concerns with the Federal Data Protection and Information Commissioner.
  • United States. Under California's CCPA as amended by the CPRA, and comparable laws in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and other states, you may request to know, access, correct, delete, and obtain a portable copy of your personal information, and to limit the use of sensitive personal information. We do not sell personal information, do not share it for cross-context behavioural advertising, and do not knowingly process the personal information of anyone under 16 for those purposes. We will not discriminate against you for exercising a right, and you may appeal a refused request by replying to our decision.
  • Canada. We handle personal information consistently with PIPEDA and applicable provincial legislation, including Quebec's Law 25. You may access and correct your information and complain to the Office of the Privacy Commissioner of Canada.
  • Australia. We follow the Australian Privacy Principles under the Privacy Act 1988, including notification of eligible data breaches, and you may complain to the Office of the Australian Information Commissioner.
  • Saudi Arabia and the United Arab Emirates. For individuals in the Gulf, we align with the Saudi Personal Data Protection Law and the UAE Federal Decree-Law No. 45 of 2021, including consent, purpose limitation, and cross-border transfer requirements, and we support requests routed through a client acting as controller.
  • Brazil. Where the LGPD applies, you hold equivalent confirmation, access, correction, anonymisation, portability, and deletion rights, and may contact the ANPD.

Jordan — Personal Data Protection Law annex

This annex applies to the processing of personal data of individuals in Jordan and prevails over the rest of this policy where they conflict. It is issued under Jordan's Personal Data Protection Law No. 24 of 2023 (the “PDPL”) and its implementing regulations and instructions as they come into force.

  • Data controller. The controller of personal data collected through this website is Veilancy, a company established and operating in Amman, Hashemite Kingdom of Jordan. You can reach the controller about any data protection matter at contact@veilancy.com. We will register in the national register of controllers and processors once the register is operational, as the PDPL requires.
  • Lawful bases. We process personal data only where the PDPL permits it: with your prior consent (for example, marketing messages), to take steps you request or to perform a contract (for example, evaluating an application or preparing a pilot), to comply with a legal obligation under Jordanian law (for example, tax and accounting retention), or for a legitimate interest that does not override your rights (for example, keeping our systems secure). Where consent is the basis, you may withdraw it at any time, with effect for the future.
  • Your rights under the PDPL. You may request, free of charge: to be informed about the processing of your data; to access it and obtain a copy; to have inaccurate or incomplete data corrected or completed; to have data erased when it is no longer needed for the purpose it was collected for or when you withdraw consent; to restrict or object to processing in the cases the law provides; and to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. Send any request to contact@veilancy.com; we acknowledge within five business days and respond within the periods the PDPL and its instructions prescribe.
  • Data minimisation and purpose. We collect only the data needed for the purposes described in this policy, keep it accurate, and retain it no longer than those purposes or Jordanian law require, after which it is erased or anonymised.
  • Transfers outside Jordan. Personal data is transferred or stored outside Jordan only where the destination provides a level of protection the PDPL considers adequate, or under a safeguard or exception the law allows — such as your consent or a contractual necessity — and, where required, after the approvals the competent authority prescribes.
  • Breach notification. If a personal data breach occurs, we will notify the competent authority under the PDPL without undue delay where the law requires it, and inform affected individuals when the breach is likely to cause them harm, describing the nature of the breach and the measures taken.
  • Complaints. If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Council and the competent unit at the Ministry of Digital Economy and Entrepreneurship of the Hashemite Kingdom of Jordan.

Changes to this policy

If we change how we handle personal information, we will update this page and revise the date above. Material changes will be highlighted here for at least 30 days, and where the law requires it we will ask for consent again before applying them.

Contact and complaints

Write to contact@veilancy.com with any question, request, or complaint. We would like the chance to put things right first, but you also have the right to complain to your local data protection authority.