Privacy Policy

How Velox collects, uses, and protects your data — in plain language

Last Updated: August 2026  ·  Applies to EU/EEA residents under GDPR

1. Who We Are

Velox ("we", "our", "the Company") operates the website at this domain and distributes the Velox software product. For the purpose of GDPR, Velox acts as the data controller of the personal data collected through this website and its associated services.

For any privacy-related inquiry, contact us directly through our Discord support server. We aim to respond within 72 hours.

2. What Data We Collect

We collect only what is strictly necessary to provide and secure the service. Specifically:

  • Email address — used to create and manage your account and deliver license-related communications.
  • Purchase records — transaction identifiers and plan type, processed and held by our payment provider. We do not store card details.
  • Hardware Identifier (HWID) — a non-reversible hash derived from your device hardware, used solely for license authentication and abuse prevention. It cannot identify you personally.
  • IP address at login — logged temporarily for fraud and unauthorized-access detection. Not retained beyond 30 days.
  • Software version checks — an anonymous ping confirming your client version is current. No usage content is transmitted.

We do not collect: real name, phone number, location data, browsing history, or any in-game data.

3. Legal Basis for Processing (GDPR Art. 6)

Every piece of data we process has a documented legal basis:

  • Contract performance (Art. 6(1)(b)) — account data, license keys, and HWID are processed to fulfill the software license agreement you entered when purchasing.
  • Legitimate interests (Art. 6(1)(f)) — temporary IP logging and version checks serve our legitimate interest in preventing fraud, unauthorized sharing, and license abuse. These interests are proportionate and do not override your rights.
  • Legal obligation (Art. 6(1)(c)) — we may retain transaction records to comply with applicable financial or tax regulations.

We do not rely on consent as a basis for any core service processing. You are not asked to tick a box to receive the service you paid for.

4. Third Parties & Data Sharing

We do not sell, rent, or broker your personal data. Limited sharing occurs only in the following contexts:

  • Payment processor — handles transaction data under their own PCI-DSS compliant privacy policy. We receive only a transaction ID and plan confirmation.
  • Infrastructure providers — server and CDN providers that host the license validation API. These providers are contractually bound by data processing agreements (DPAs) and may not use your data for any other purpose.
  • Law enforcement — only if compelled by a valid legal order from a competent authority. We will disclose only the minimum required and will notify you where legally permitted.

No advertising networks, analytics platforms, or data brokers receive any information about you.

5. Data Retention

We keep your data only as long as necessary:

  • Active account data — retained for the duration of your license and up to 90 days after expiry or account deletion, to handle any support or dispute.
  • HWID records — retained while your license is active. Deleted within 30 days of account deletion.
  • Login IP logs — automatically purged after 30 days.
  • Transaction records — retained for up to 7 years where required by tax or accounting obligations.

After the applicable retention period, data is permanently deleted from our systems and any backups are overwritten within the next scheduled backup cycle.

6. Your Rights Under GDPR

If you are located in the EU or EEA, you have the following rights regarding your personal data. You can exercise any of these by contacting us on Discord:

  • Right of access (Art. 15) — request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16) — request correction of inaccurate data.
  • Right to erasure (Art. 17) — request deletion of your data. Note: active license enforcement requires HWID data. Deletion of HWID will invalidate your license.
  • Right to restriction (Art. 18) — request that we limit how we use your data while a dispute is being resolved.
  • Right to data portability (Art. 20) — receive your account data in a structured, machine-readable format.
  • Right to object (Art. 21) — object to processing based on legitimate interests. We will cease unless we can demonstrate compelling grounds.
  • Right to lodge a complaint — you may file a complaint with your national supervisory authority (e.g., CNIL in France, BfDI in Germany, ICO in the UK post-Brexit).

We will respond to all verified requests within 30 days, as required by GDPR. Complex requests may be extended by up to 60 additional days with notice.

7. Security

We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, or disclosure. These include:

  • Encrypted data transmission (TLS 1.2+) across all endpoints
  • Hashed and salted credential storage — plaintext passwords are never retained
  • Access controls limiting data visibility to authorised personnel only
  • HWID data stored as a one-way hash — not reversible to device information

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify affected users without undue delay, and report to the relevant supervisory authority within 72 hours as required by GDPR Art. 33.

8. Cookies

This website uses no third-party tracking cookies and no advertising or analytics scripts. A single session cookie may be set to maintain your authenticated state on the dashboard. It is strictly necessary and expires when you close your browser.

No consent banner is shown because no non-essential cookies are placed. You can verify this by inspecting your browser's storage at any time.

9. International Transfers

If your data is processed on servers located outside the European Economic Area, we ensure appropriate safeguards are in place — including Standard Contractual Clauses (SCCs) approved by the European Commission — so that your data receives the same level of protection as within the EU.

We do not transfer data to countries without an adequate level of protection unless one of the approved mechanisms above applies.

10. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or applicable law. The "Last Updated" date at the top will always reflect the most recent revision. Where changes are material, we will notify active users via Discord or email.

Continued use of the service after a policy update constitutes acceptance of the revised terms.