Veehax (Pvt) Ltd ("Veehax," "we," "our," or "us") operates the Veehax platform an AI-powered education and productivity platform accessible at veehax.com and its associated applications. This Privacy Policy describes how we collect, use, store, and protect your personal information when you access or use our services. By using Veehax, you agree to the practices described here. If you do not agree, please discontinue use of our platform.
Overview
Veehax is headquartered at World Trade Center, Colombo, Sri Lanka. We build AI-powered products designed to democratize access to knowledge, enhance learning outcomes, and accelerate skill development globally. This policy applies to all users of our platform, including visitors, registered users, enterprise clients, and API partners.
Our CommitmentWe do not sell your personal data to third parties. Data collected is used exclusively to operate, secure, and continuously improve the Veehax platform for you and our broader user community.
Data We Collect
Account & Identity Data
- Full name, email address, and password (hashed) when you register an account.
- Profile information you optionally provide: photo, organisation, role, and preferences.
- OAuth identity tokens if you sign in via Google, GitHub, or other providers.
Platform Usage Data
- Interactions with AI features: prompts submitted, responses generated, sessions initiated.
- Learning progress, completion rates, scores, and activity timestamps.
- Feature usage metrics and navigation patterns within the platform.
Technical & Device Data
- IP address, browser type, operating system, and device identifiers.
- Referring URLs, session duration, and page-level analytics.
- Error logs, crash reports, and performance diagnostics.
Payment Data
- Billing name, address, and subscription tier. We do not store raw card numbers payment processing is handled by PCI-DSS compliant third-party processors.
Communications Data
- Support tickets, feedback submissions, and survey responses.
- Email and in-app notification engagement signals.
How We Use Your Data
We process your data only for clearly defined, legitimate purposes. The following table summarises our processing activities and their lawful basis.
| Purpose | Data Used | Lawful Basis |
|---|---|---|
| Platform access & authentication | Account & identity data | Contract performance |
| Personalised learning recommendations | Usage & AI interaction data | Legitimate interest |
| AI model quality & safety improvements | Anonymised interaction data | Legitimate interest |
| Billing & subscription management | Payment & account data | Contract performance |
| Security, fraud prevention, abuse detection | Technical & usage data | Legal obligation / legitimate interest |
| Product communications & updates | Email, notification preferences | Consent / legitimate interest |
| Analytics & product improvement | Aggregated usage data | Legitimate interest |
| Legal compliance & dispute resolution | Any relevant data | Legal obligation |
AI & Learning Systems
The Veehax platform is built on AI systems that process your inputs to generate personalised content, recommendations, and educational outcomes. Understanding how your data interacts with these systems is important.
AI Interaction DataPrompts and responses generated through Veehax AI features may be reviewed by our engineering team in anonymised form for quality assurance, safety evaluation, and model improvement. We never use your personally identifiable data to train external AI models operated by third parties without your explicit consent.
- Personalisation engine: Your learning activity and engagement signals are used to tailor content difficulty, pacing, and topic recommendations specific to you.
- Model fine-tuning: We may use aggregated, de-identified usage patterns to refine Veehax-proprietary AI models. Raw personal data is never used directly in training pipelines.
- Safety monitoring: All AI interactions are subject to automated safety filters to detect and prevent harmful, abusive, or policy-violating content.
- No automated decisions with legal effect: We do not use AI to make automated decisions about you that produce legal or similarly significant consequences without human review.
Retention & Storage
Veehax operates cloud infrastructure distributed across data centres, including facilities in Sri Lanka and internationally (AWS / GCP regions). All data in transit is encrypted via TLS 1.2+. Data at rest is encrypted using AES-256.
| Data Category | Retention Period |
|---|---|
| Account data | Duration of account + 90 days post-deletion |
| AI interaction logs | 12 months (anonymised after 90 days) |
| Learning progress & history | Duration of account + 12 months |
| Payment records | 7 years (statutory financial requirement) |
| Security & audit logs | 24 months |
| Support communications | 3 years from last interaction |
When you delete your account, we initiate a 30-day grace period during which recovery is possible. After this period, personal data is permanently purged from production systems. Certain data may persist in encrypted backups for up to 90 days before being overwritten.
Your Rights
You have the following rights with respect to your personal data. To exercise any of these rights, contact us at hello@veehax.com. We will respond within 30 days.
- Access: Request a copy of the personal data we hold about you.
- Correction: Request that inaccurate or incomplete data be corrected.
- Deletion: Request erasure of your personal data, subject to legal retention obligations.
- Portability: Receive your data in a structured, machine-readable format.
- Restriction: Request that we limit processing of your data in certain circumstances.
- Objection: Object to processing based on legitimate interest, including for direct marketing.
- Withdraw consent: Where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
Identity VerificationTo protect your data, we may request identity verification before fulfilling data access, correction, or deletion requests. This process is handled securely and the verification data is not retained beyond the request resolution.
Children's Privacy
Veehax services are intended for users aged 16 and older. We do not knowingly collect personal data from children under 16. If we become aware that a user under 16 has registered without verifiable parental consent, we will promptly delete the account and associated data.
Educational institutions deploying Veehax for students under 16 must enter into a separate Data Processing Agreement that includes appropriate safeguards and parental consent mechanisms. Contact enterprise@veehax.com for details.
Security
We implement industry-standard technical and organisational security measures to protect your data against unauthorised access, loss, alteration, and disclosure.
- All data in transit encrypted via TLS 1.2 or higher.
- Data at rest encrypted using AES-256.
- Passwords stored using bcrypt with salted hashing never in plaintext.
- Role-based access controls limiting internal data access to authorised personnel only.
- Regular penetration testing, vulnerability assessments, and security audits.
- Incident response procedures with mandatory breach notification within 72 hours where applicable by law.
No system is perfectly impervious to attack. If you suspect your account has been compromised, contact hello@veehax.com immediately.
Policy Changes
We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Post the revised policy at veehax.com/privacy with an updated effective date.
- Send a notification email to registered users at least 14 days before material changes take effect.
- Display an in-platform banner prompting acknowledgement of significant changes.
Continued use of the platform after the effective date constitutes acceptance of the revised policy. If you disagree with any changes, you may close your account before the effective date and request deletion of your data.
Contact Us
For any questions, concerns, or requests relating to this Privacy Policy or the handling of your personal data, contact our Privacy team:
- Email: hello@veehax.com
- Security disclosures: hello@veehax.com
- Postal address: Veehax (Pvt) Ltd, World Trade Center, Colombo 01, Sri Lanka.
We aim to respond to all privacy inquiries within 30 days. Complex requests may require up to 60 days we will notify you of any extension within the initial 30-day window.