Legal

Privacy Policy

Last updated: May 2026

1. Who We Are

VELOZ Compliance Ltd is a UK-based software company providing compliance management tools for the construction industry. Our flagship product is VELOZ Matrix, an all-in-one workforce compliance platform.

Company No. SC436388

ICO Registration No. ZC144695

Contact: info@veloz-compliance.co.uk

2. What Data We Collect

When you or your organisation uses VELOZ Matrix, we collect and process the following personal data:

User account data:

  • Name, email address, job title and role within your organisation

Worker records:

  • Worker names, job roles, departments and employee numbers
  • Email addresses (where provided)
  • Worker photographs (where uploaded)

Compliance data:

  • Certificate details, expiry dates and certificate numbers
  • Training records and booking information
  • PPE issue and inspection records
  • Induction records and checklists
  • Holiday and absence records
  • Site and project information

Uploaded documents:

  • Certificate files, holiday request forms, PPE request forms, doctor's notes and other compliance documents uploaded by your organisation

Subcontractor data:

  • Subcontractor company details and worker information submitted through the supply chain portal

Usage data:

  • Login timestamps and general platform usage for security and service improvement purposes

3. How We Use Your Data

We use the data we collect to:

  • Provide and operate the VELOZ Matrix platform
  • Send automated compliance reminder emails to your nominated users
  • Generate compliance reports, gap analyses and PDF documents on your behalf
  • Process AI-assisted certificate scanning when you use that feature
  • Respond to support requests and enquiries
  • Improve and develop our products and services

We do not sell, rent or share your personal data with any third party for marketing purposes.

4. Legal Basis for Processing

We process your personal data under the following legal bases under UK GDPR:

Contract — processing is necessary to deliver the services you have subscribed to

Legitimate interests — sending compliance reminders and improving our platform

Legal obligation — where we are required to retain records by law

5. Where Your Data is Stored

All data entered into VELOZ Matrix is stored within the United Kingdom on servers hosted by Supabase, using Amazon Web Services infrastructure in the eu-west-2 (London) region.

Your data does not leave the UK except in the specific circumstances described in Section 6.

6. Third Party Processors

We use the following third party services to operate the platform:

ProcessorPurposeLocation
SupabaseDatabase and file storageUK (London)
VercelPlatform hosting and deploymentEU/US edge network
ResendTransactional email deliveryEU
AnthropicAI-powered certificate scanningUnited States

Important note regarding Anthropic:

When you use the AI certificate scanning feature, the content of uploaded documents is temporarily processed by Anthropic's API in the United States. This processing is transient — document content is used solely to extract certificate information and is not stored or used to train AI models. Anthropic operates under appropriate data protection safeguards. If you prefer not to use AI scanning, all certificate data can be entered manually.

7. Data Retention

We retain your data for as long as your account is active. When your subscription or trial ends:

  • You may request deletion of your data at any time by emailing info@veloz-compliance.co.uk — we will action this within 30 days
  • If no deletion request is made, your data will be automatically deleted within 90 days of your account closing
  • Backups are purged on the same schedule

8. Your Rights

Under UK GDPR you have the following rights:

  • Right of access — request a copy of the data we hold about you
  • Right to rectification — ask us to correct inaccurate data
  • Right to erasure — ask us to delete your data
  • Right to restrict processing — ask us to limit how we use your data
  • Right to data portability — request your data in a portable format
  • Right to object — object to processing based on legitimate interests

To exercise any of these rights please contact us at info@veloz-compliance.co.uk. We will respond within 30 days.

9. Data Security

We take the security of your data seriously. Our platform uses:

  • Encrypted connections (HTTPS/TLS) for all data in transit
  • Row-level security policies ensuring each organisation can only access their own data
  • Supabase authentication with secure session management
  • Private storage buckets for all uploaded documents

10. Cookies

VELOZ Matrix uses only essential session cookies necessary for the platform to function. We do not use tracking, advertising or analytics cookies.

11. Children's Data

Our platform is intended for use by businesses and is not directed at individuals under the age of 18. We do not knowingly collect data from children.

12. Changes to This Policy

We may update this privacy policy from time to time. When we do we will update the "Last updated" date at the top of this page. For significant changes we will notify account holders by email.

13. Contact and Complaints

For any data protection queries please contact:

Craig Burns — Data Protection Contact
VELOZ Compliance Ltd
info@veloz-compliance.co.uk

If you are not satisfied with how we handle your data you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO): ico.org.uk | 0303 123 1113