Veloci Privacy Policy

How Veloci handles your data across the services you connect.

Last updated: 27 August 2026

Who we are and what this covers

This policy explains how Veloci handles your personal data. Veloci is operated by ArcticRex Oy ("ArcticRex", "we", "us"), a Finnish company registered under business ID 3587587-8, located at Lapinlahdenkatu 16, 00180 Helsinki, Finland.

It covers everything Veloci processes when you use it: your account, the services you connect, the content our AI agents produce for you, and the technical data that keeps the service running. Our general privacy policy covers visitors to this website. Where you use Veloci through your employer's subscription, your organization decides what Veloci is used for, and we process data on its behalf under a data processing agreement. Either way, this policy describes our practices.

For any privacy question, contact privacy@arcticrex.com.

What Veloci is

Veloci keeps you on top of what you've committed to. It captures commitments as they arise — in your meetings, your calendar, and the tools you work in — helps you prioritize them against your goals, and refits your calendar and focus to match, with AI agents doing the legwork. Every connection is made with your own account, authorized by you individually, and can be disconnected by you at any time.

The data Veloci holds, and what we do with it

Veloci stores the following about you and the people you work with — what you bring, and what it makes from it:

  • Your account: name, email address, and — where you use Veloci as part of an organization — which organization and team your account belongs to.
  • Connected services: when you connect a service, Veloci accesses it with your own credentials, scoped to what the feature needs. Which services you can connect changes as the product develops, and the current list is always the one shown in Veloci’s integration settings. What data is involved depends on what you connect: calendar events, meeting transcripts and notes from services such as Google Meet, Granola, Circleback or Fireflies.ai, tasks and issues from Todoist, Linear, Jira or GitHub, and messages in channels you give access to in Slack or Microsoft Teams. Veloci also holds the credentials for the services you connect — access tokens or API keys — stored encrypted.
  • Content Veloci produces for you: extracted action items, briefings, reviews, and plans.
  • Transcripts you ask us to keep: Veloci holds your meeting transcripts where you have asked it to. We hold them on your instruction and for your purposes, they remain yours, and they are deleted when you ask or when your account closes.
  • Records of what Veloci did: a record of each agent run, and enough of the material it worked from for you to check its work.
  • Usage telemetry: product events tied to your account — for example which feature was used, whether it succeeded, how long it took, which client app and version you used, and how you respond to Veloci's suggestions and the things it creates for you — plus operational measurements (such as performance and errors) and audit events recording security-relevant actions. Telemetry is metadata about your use of Veloci; it does not contain your meeting, calendar, message, or task content.

Full calendar responses and full AI prompts are processed transiently and are not stored. Meeting transcripts are kept only where you have asked us to keep them.

Your content is used to provide the features you see. We may also use it to create material from which no individual can be identified, and use that material to improve Veloci. Telemetry is used to operate and secure Veloci, and to measure how well it is working. We do not use your data for advertising and do not sell it.

How AI processing works

Veloci's features are powered by AI models run exclusively on Amazon Web Services (AWS) Bedrock in European Union regions. The specific models evolve with the product, but the terms they run under do not:

  • Your content — the substance of your meetings, events, messages, and tasks — is never used to train AI models. Not by us, and not by our providers. AWS Bedrock does not use customer content to train or improve any model, does not retain prompts or outputs beyond serving the request, and does not share content with the companies that make the models — no model provider ever receives your data.
  • Processing stays in the EU. All model inference runs in EU AWS regions, enforced at the infrastructure level.
  • AI output is visible and yours. Model output exists to provide the features you see — action items, briefings, calendar blocks — and is attributed to Veloci's agents wherever it appears.

Veloci does not make automated decisions about you that have legal or similarly significant effects.

Google user data

If you connect your Google account, Veloci requests these permissions and uses them only as described:

  • Basic profile (email address): to identify your account and recognize meeting participants you already work with.
  • Calendar events you own (read and write): Veloci reads events on your primary calendar to prepare briefings and reviews, and creates or edits planning blocks (for example an end-of-day review block). It only accesses events you own — never other people's calendars.
  • Google Meet records (read-only): for meetings you hosted or attended, Veloci reads conference records, participant lists, and transcripts once Google has finished generating them, to extract action items and outcomes for you. Veloci never records meetings itself.

Our commitments to the platforms you connect

Every service you connect comes with developer terms that protect you, and we operate within all of them: we use the minimum data each feature needs and never move it beyond what the feature you asked for requires.

Veloci's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, and to the Google Workspace API User Data and Developer Policy. We do not use Google user data to create, train, or improve machine learning or artificial intelligence models, and we do not sell it, use it for advertising, or transfer it to data brokers or resellers. Material we create from which no individual can be identified may draw on Google-sourced content, and we may use that material to improve Veloci.

Who we share data with

  • AWS (our infrastructure and AI processor): all platform data is processed and stored on AWS in EU regions under a GDPR data processing agreement.
  • Destinations you choose: action items you confirm are delivered to the destination you configured — for example Slack, Todoist, Linear, or your organization's own task repository. These carry the extracted item (title, owner, due date, description), not your raw calendar or meeting data, and are sent only at your direction.
  • Error monitoring and product analytics: scrubbed error context and usage events — never your content — help us keep Veloci reliable and understand how it is used. The current providers are listed on our subprocessors page.
  • No one else: we do not share your data with advertisers, data brokers, or any other third party.

No human at ArcticRex reads your content except with your explicit consent (for example, when you ask for support on a specific issue), where necessary for security or abuse investigation, or where required by law.

Where your data lives, and for how long

Veloci runs exclusively in EU AWS regions, enforced by organization-level policy — your product data is not transferred outside the EU. Each customer organization's data is isolated in its own database. Everything is encrypted in transit (TLS 1.2+) and at rest. For more on our security practices, see our Trust & Security page.

Your personal data is retained for the lifetime of your account and deleted on account closure or on request: promptly from live systems, with residual copies in encrypted backups expiring on our backup rotation schedule within 30 days. Disconnecting a service deletes its stored tokens immediately and stops all access.

Legal basis for processing

For the content Veloci reads and produces, you or your organization is the controller and we process it on your instructions, as set out in section 6 of the Terms of Service. For your own account details, we process them to perform our contract with you and on our legitimate interest in keeping the service secure and reliable. Connecting a service authorizes our access to it, and you can withdraw that at any time by disconnecting.

Your rights and choices

  • Disconnect any service: at any time, from Veloci's settings. For Google, you can also revoke access from your Google Account permissions page — Veloci treats revocation as a disconnect and deletes the stored tokens.
  • Delete your data: ask us to delete stored content (captures, excerpts, run records) or your account entirely at privacy@arcticrex.com. We respond within 30 days.
  • GDPR rights: you have the rights of access, rectification, erasure, restriction, portability, and objection, and — where processing rests on consent — the right to withdraw it at any time. If you use Veloci through your employer, some requests may be routed via your organization as the data controller; we will help either way.

If you are not satisfied with how we handle a request, you can lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi) or your local supervisory authority.

Cookies and in-app analytics

The Veloci application uses only essential cookies needed to keep you signed in — no advertising or tracking cookies. Analytics on the product itself, and on the pages through which it is served, are handled by the providers listed on our subprocessors page.

Changes to this policy

We may update this policy from time to time. Significant changes will be posted on this page with an updated "Last updated" date, and material changes affecting how we handle your connected-service data will be communicated to affected users.

Contact us

ArcticRex Oy
Lapinlahdenkatu 16
00180 Helsinki, Finland
Email: privacy@arcticrex.com