Privacy Policy
Last updated: 3 September 2026 · v2.5 · GDPR Regulation (EU) 2016/679
1. Data Controller
The data controller is VELOVA SINGLE MEMBER P.C. (GEMI 194620801000, AFM 803325569), registered seat Zervou I 17A, 14121 Irakleio Attikis, Greece. For all privacy-related inquiries, contact privacy@velova.io.
Velova has not formally designated a Data Protection Officer because the criteria for mandatory designation under GDPR Article 37(1) are not met (no large-scale processing of special-category data, no large-scale systematic monitoring of data subjects). Privacy inquiries are handled by Velova's management team.
Once a booking is confirmed, the assigned Mover becomes an independent data controller for the personal data necessary to perform the move (Customer name, contact details, origin/destination addresses). Velova and the Mover are not joint controllers under GDPR Art. 26; each is responsible for its own processing.
2. Data We Collect
We collect the following categories of personal data:
- Account data: name, email address, phone number, role (customer or mover)
- Survey data: move details, room inventory, item lists, access conditions, preferred dates
- Media: photos and videos uploaded as part of the AirSurvey room walkthrough (personal data of a particularly private nature; not Article 9 special-category data unless content reveals e.g. religious symbols, health items, or political affiliations)
- Payment data: processed by Stripe; Velova does not store card numbers
- Mover compliance data: AFM (tax ID), GEMI number, IBAN (DAC7 requirement)
- Push-notification subscription (movers, optional): your device's push endpoint and encryption keys, stored only if you enable notifications in the mover portal (see section 4)
- Usage data: anonymised analytics via PostHog, cookies (see section 10)
When you register a customer account, we record your confirmation that you are 18 years of age or older (legal capacity to enter a contract), together with the timestamp and version of that confirmation.
3. Legal Basis for Processing
We process your data under the following legal bases as defined by GDPR Article 6:
- Contract performance (Art. 6(1)(b)): processing necessary to provide our marketplace services
- Legitimate interest (Art. 6(1)(f)): fraud prevention, platform security, service improvement
- Consent (Art. 6(1)(a)): photo/video upload, mover push notifications (section 4) and marketing communications. Marketing is split into two separate purposes you opt into independently — product tips & guides and promotional offers — each manageable at any time from the Consent preferences section of your account profile
- Legal obligation (Art. 6(1)(c)): DAC7 tax reporting, accounting records retention
4. How We Use Your Data
We use collected data to: facilitate survey submissions and quote matching, process payments via Stripe Connect, generate structured briefs for movers (see section 5), resolve disputes, comply with tax reporting obligations, and improve our platform through anonymised analytics.
Push notifications (movers). If you enable notifications on your phone or browser, we store your device's subscription identifier (push endpoint and encryption keys) to notify you of new jobs matching your settings. Notifications are delivered through the push service of your browser or device vendor (Google, Apple, Mozilla). Legal basis: your consent, which you can withdraw at any time from your profile (Notifications → Disable) or your device settings; the subscription is deleted immediately.
5. Data Sharing
Payment service provider: Stripe Inc. processes all payments. Stripe's privacy policy applies to payment data.
Movers: Movers receive a structured brief prepared by the Velova team. This brief includes move details, CBM estimates, access conditions, and special item flags. Movers never receive the raw room photos or videos — these are reviewed only by the Velova team to prepare the brief. (Exception: vehicle photos and special-item photos — e.g. piano, artwork, safe — are shared with movers with your separate consent, so they can bring the right equipment and quote accurately. PBO box photos stay with the Velova team only.) The customer's full pickup and delivery addresses are shared with verified movers at the quoting stage so they can assess vehicle access, parking, and carry distance — every first view is recorded in our audit log. Non-verified accounts see only the street zone (no house number). Contact details are shared with the assigned mover only after a booking is confirmed.
Push notification delivery: if a mover enables notifications, the device's push endpoint and an end-to-end encrypted notification payload are transmitted to the push service of the mover's browser or device vendor — Google LLC (Firebase Cloud Messaging, FCM; United States / global, EU-US Data Privacy Framework), Apple Inc. (Apple Push Notification service, APNs; United States / global, EU-US Data Privacy Framework) or Mozilla Corporation (Mozilla autopush; United States, EU-US Data Privacy Framework or Standard Contractual Clauses) — solely for push notification delivery. The provider depends on the browser or device, not on Velova; the push service cannot read the encrypted payload.
We do not sell personal data to third parties.
6. AirSurvey Media
Photos and videos uploaded during the room walkthrough survey are personal data of a particularly private nature. They are processed under heightened safeguards:
- Stored on Cloudinary servers within the European Union (Frankfurt region)
- Reviewed by the Velova team to prepare the structured mover brief
- Never shared with movers in raw form (only the structured brief is shared)
- Automatically deleted 30 days after job completion, or earlier on request
- Encrypted in transit (TLS) and at rest
Explicit, granular consent is obtained at the time of upload (media-consent@2.0). An optional, separate opt-in (ai-training-consent@1.0) lets customers voluntarily extend retention to up to 24 months for AI model training — see Section 14. You can withdraw either consent at any time, self-service, from the Consent preferences section of your account profile, or by emailing privacy@velova.io; withdrawal may affect the accuracy of the resulting quotes.
The processing of AirSurvey imagery has been assessed under GDPR Article 35 in a screening Data Protection Impact Assessment (DPIA Lite). A Record of Processing Activities (Art. 30 ROPA) is maintained by Velova.
7. DAC7 Reporting
Under EU Directive 2021/514 (DAC7), Velova is required to collect and report the following information about movers to the Greek tax authority (AADE) annually: legal name, tax identification number (AFM), IBAN, registered address, and total annual earnings on the platform. This reporting is a legal obligation and cannot be opted out of.
8. Data Retention
- Account data (non-financial): retained while the account is active, deleted 12 months after account closure
- Survey and job records: retained for 5 years (Greek consumer law statute of limitations and audit purposes)
- Photos and videos (AirSurvey media — default): deleted 30 days after job completion or cancellation
- Photos and videos (opt-in for AI training only): retained up to 24 months from job completion or cancellation (Section 14)
- Anonymized derived features (item counts, room types, volume estimates): indefinite — not personal data under GDPR Recital 26
- Payment and invoice records: retained for 10 years (Greek Accounting Standards, Law 4308/2014)
- Communications and dispute records: 3 years
- Technical logs (IP, session): 12 months
- Push-notification subscriptions (movers): retained only while notifications are enabled; deleted immediately when you disable them, when your device revokes the subscription, or when the push service reports it as expired
- Audit logs (status changes, payment events): retained for 5 years (compliance requirement)
9. Your Rights
Under GDPR, you have the right to:
- Access: request a copy of your personal data
- Rectification: correct inaccurate data
- Erasure: request deletion of your data (subject to legal retention obligations)
- Portability: receive your data in a structured, machine-readable format
- Restriction: limit processing in certain circumstances
- Objection: object to processing based on legitimate interest
To exercise any of these rights, contact privacy@velova.io. We respond within 30 days as required by GDPR.
10. Cookies
We use essential cookies for authentication and session management. Analytics cookies (PostHog, Google Analytics with Consent Mode v2) are only activated after you provide consent via our cookie banner. You can withdraw cookie consent at any time through your browser settings or by clicking “Manage cookies” in the site footer.
11. International Transfers
All primary data processing occurs within the EU (Supabase Frankfurt region, Cloudinary EU region). Where sub-processors operate from the United States (e.g. Stripe Inc., Vercel Inc. and — for push notification delivery only — Google LLC, Apple Inc. and Mozilla Corporation), transfers are protected by the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795 of 10 July 2023). For other third-country transfers, we rely on Standard Contractual Clauses (SCCs) approved by Commission Decision 2021/914.
In the event of a personal data breach affecting your rights, we will notify the Hellenic Data Protection Authority within 72 hours and notify you directly without undue delay where the breach is likely to result in a high risk to your rights and freedoms.
12. Security Incidents and Breach Reporting
If you suspect unauthorized access to your account, observe suspicious activity, or believe your personal data may have been compromised, contact our security team immediately at security@velova.io (please mark the email as urgent).
Recommended immediate steps:
- Change your password via the Platform
- Enable two-factor authentication in your account settings
- Monitor your account and linked payment methods for unauthorized activity
- Forward any suspicious phishing emails to security@velova.io with full headers
Security researchers and ethical hackers may report vulnerabilities through the same channel under responsible disclosure principles. Our security contact is also published at /.well-known/security.txt per RFC 9116.
13. Contact and Supervisory Authority
VELOVA SINGLE MEMBER P.C.
Zervou I 17A, 14121 Irakleio Attikis, Greece
GEMI 194620801000 · AFM 803325569
Privacy contact: privacy@velova.io
You have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA):
Kifisias Avenue 1-3, 11523 Athens
Tel: +30 210 6475600
Web: www.dpa.gr
14. Optional AI Model Training
Velova develops proprietary AI models to improve volume estimation accuracy. Two data layers support this:
Layer 1 — Anonymized derived features (universal, no consent required). Within the 30-day window, Velova extracts non-identifying features (item counts, room labels, volume estimates) from your survey. Features are stripped of EXIF, disassociated from your customer ID after extraction, contain no biometric or religious/political/health categorization, and qualify as anonymized data under GDPR Recital 26. Stored in EU-region infrastructure indefinitely for model training.
Layer 2 — Opt-in raw media retention (voluntary, 24-month cap). If you tick the AI training consent (ai-training-consent@1.0) at the survey step, Velova may retain your raw video and photos for up to 24 months after move completion or cancellation, exclusively to train AI volume-estimation models. Default is NO. Withdrawable any time, self-service, from the Consent preferences section of your account profile, or at privacy@velova.io with a 7-business-day deletion SLA. EU-region storage only (Supabase EU Frankfurt, Cloudinary EU). No biometric extraction; faces and voices, if incidentally captured, are blurred and muted.
Article 22 — no automated decisions about you. Models inform internal quoting accuracy; no automated decisions about individuals are made on their basis.
Assessed under DPIA Lite v1.1 (May 2026). ROPA maintained internally.