Privacy Policy

Effective 9 September 2026.

1. Who we are

Keelan Vella, a sole trader based in Malta, is the controller of personal data processed to operate Velafa CMS and its API.

Contact: keelan@velafa.digital. Service address: https://cms.velafa.digital.

2. Controller and processor

We are the controller for Account data — the information you give us to register, sign in, manage workspaces, and contact support.

For Customer Content that contains personal data (for example names in a blog entry, or details submitted through a form you publish), we act as a processor on your instructions. You are the controller of that data. You must have a lawful basis to collect it and to ask us to process it.

3. Personal data we collect

We process the following categories when you use the Service:

  • Account and profile: name, email address, password hash, workspace memberships, and role
  • Session cookies: atlas_token and atlas_refresh, used to keep you signed in
  • Security and operations: sign-in times, session identifiers, IP address, and request logs
  • Integration tokens: OAuth access and refresh tokens when you connect Vercel, Google, Bing, or Spotify
  • Customer Content you choose to store: pages, entries, media, form definitions, and form submissions
  • Support correspondence sent to our contact email

4. Purposes and legal bases

We process personal data for these purposes, under Article 6 of the GDPR:

  • Provide the Service, authenticate you, and honour API Credentials — contract (Art. 6(1)(b))
  • Secure the Service, prevent abuse, and keep logs — legitimate interests (Art. 6(1)(f))
  • Send transactional email such as verification, invites, and form notifications — contract or legitimate interests
  • Store optional analytics or marketing cookies — consent (Art. 6(1)(a))
  • Meet legal obligations, including tax and regulatory requests — legal obligation (Art. 6(1)(c))

5. Cookies and consent

We set strictly necessary cookies to run the Service. atlas_token and atlas_refresh keep a signed-in session. These cookies are required for the console to work and are set without a separate consent prompt.

Optional analytics and marketing cookies are off by default. We do not load analytics or advertising tags until you opt in. You can accept all, reject optional cookies, or choose categories in the cookie banner or the Cookies control in the footer. You can change your mind at any time. Your choice is stored in localStorage under the key cookie-consent on your device.

Rejecting optional cookies does not affect sign-in or core editing features.

6. Recipients and subprocessors

We use the following processors to operate the Service:

  • Amazon Web Services — DynamoDB, S3, CloudFront, and SES in eu-central-1
  • Vercel — application hosting and edge delivery

When you connect an integration, the relevant provider also receives data needed for that connection.

6.1 Optional integrations

These recipients only receive data if you connect them from the console:

  • Google — account email and tokens for Analytics and Search Console
  • Microsoft — Bing Webmaster Tools tokens and site statistics you request
  • Spotify — tokens and playback data you request
  • Vercel — project and deployment data for a linked project

7. International transfers

Primary hosting is in the European Union (eu-central-1 for AWS). Vercel and connected integrations may process data in other countries.

Where we transfer personal data outside the EEA, we rely on an adequacy decision or the European Commission’s Standard Contractual Clauses, together with the safeguards those providers publish.

8. Retention

We keep Account data for as long as the Account is open and for a limited period afterwards if we must resolve a dispute or meet a legal duty.

Sessions last until they expire or you sign out. API Credentials last until you revoke them. Customer Content stays until you delete it or close the workspace. Form submissions stay until you delete them. Backups rotate on a limited cycle.

Cookie preference records live on your device until you clear site data.

9. Security

We hash passwords with Argon2id. Stored integration credentials are encrypted at rest. Traffic uses TLS. API keys and personal access tokens are scoped and can be revoked. Access to production systems is limited to people who operate the Service.

No method of transmission or storage is completely secure. Tell us at the contact address if you believe there has been a breach involving your Account.

10. Your rights

Under the GDPR you may request access, rectification, erasure, restriction, portability, and to object to processing that relies on legitimate interests. Where processing is based on consent, you may withdraw consent without affecting earlier lawful processing.

To exercise these rights, email keelan@velafa.digital. We may need to confirm your identity. You may also lodge a complaint with the Information and Data Protection Commissioner (IDPC) in Malta, or with your local supervisory authority.

11. Automated decisions

We do not make decisions based solely on automated processing that produce legal or similarly significant effects about you.

12. Children

The Service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has given us data, contact us and we will delete it.

13. Changes to this policy

We may update this Privacy Policy. The effective date at the top of the page will change when we do. Material changes will be posted here and, where practical, sent to Account email addresses.

14. Contact

Privacy requests: Keelan Vella, Malta, keelan@velafa.digital.