Privacy Policy
Last updated:
1. Who we are
VELA COMPUTE - FZCO ("VELA", "we", "us") is a Free Zone Company registered with the International Free Zone Authority (IFZA), Dubai, United Arab Emirates (Licence No. 91144, Registration No. 84371), registered address: IFZA Business Park, Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, United Arab Emirates. We are the controller of the personal data described in this policy. Contact: info@velacompute.ai, +971 55 767 7835.
2. What this policy covers
This policy explains how we handle the personal data of visitors to this website, of people who contact us, and of the representatives of our business customers. It also explains our role in relation to the data our customers place on the machines they order.
We process personal data in accordance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL") and, where it applies to a particular customer, other data protection law such as the EU and UK General Data Protection Regulation (the "GDPR").
3. This website
This website consists of static pages. It does not use cookies, analytics, advertising or tracking technologies, does not embed third-party content and does not collect personal data by itself. Our hosting provider may keep standard server logs (IP address, requested page, time, browser type) for security and operational purposes; we do not use these logs to identify individuals.
4. Personal data we collect and why
4.1 Contact and business details. Name, business e-mail address, telephone number, job title, company name and registration details, and the content of your messages, when you contact us, request a quote or place an Order. Purpose: to respond to you, to verify the business and the person placing the Order, and to form and perform the contract. Legal basis: performance of a contract or steps taken before a contract; compliance with legal obligations, including anti-fraud, sanctions and record-keeping duties; our legitimate interest in running our business securely.
4.2 Order and payment records. Order Confirmations, invoices, the type of payment method, the last four digits of a payment card, transaction identifiers and refund records. Card numbers are entered directly with our payment service provider; we never receive or store full card numbers. Purpose: to take payment, issue invoices, process refunds, handle payment disputes and keep accounting and tax records. Legal basis: performance of the contract; legal obligations under UAE commercial and tax law.
4.3 Service access data. The e-mail address to which access details are sent, access logs of the management systems we operate (time, source IP address, action) and support correspondence. Purpose: to deliver and support the service and to investigate security incidents or breaches of our Terms of Service. Legal basis: performance of the contract; our legitimate interest in security.
4.4 Verification data. Where required, copies of business registration documents and of the identity document of the person placing the Order. Purpose: to comply with anti-fraud, anti-money-laundering and sanctions obligations and with the requirements of our payment service provider and bank. Legal basis: legal obligation; our legitimate interest in preventing fraud.
5. Customer Content on ordered machines
Data that our customers place on, run on or transmit through a machine ("Customer Content") is controlled by the customer. In relation to Customer Content we act as a processor on the customer's instructions, as set out in the Terms of Service: we do not access it except to the extent necessary to provide requested support, to investigate a suspected breach of the Terms or a security incident, or where required by law. Customer Content is permanently deleted within 24 hours after the end of the Term unless a later time is agreed in writing. Customers are responsible for having a lawful basis for any personal data they process on a machine and for backing it up.
6. Who we share personal data with
We share personal data only where necessary:
- Infrastructure suppliers that operate the data centres and machines used for an Order. They receive only what is technically necessary to provision access — for example a public key or a delivery e-mail address — and not your business or payment records.
- Payment service providers and banks, to take payments, issue refunds and handle payment disputes. They process your payment data as independent controllers under their own privacy policies.
- Professional advisers (accountants, auditors, lawyers) bound by confidentiality.
- Public authorities, regulators and courts, where we are legally required to do so.
We do not sell personal data and do not share it for advertising.
7. International transfers
We are based in the United Arab Emirates. Infrastructure suppliers, payment service providers and other service providers may be located in other countries, so your personal data may be processed outside the UAE. Where that happens we rely on the transfer mechanisms permitted by the PDPL (Articles 22 and 23): transfer to a country with an adequate level of protection as recognised by the UAE Data Office, contractual safeguards with the recipient, your express consent, or the necessity of the transfer for the performance of our contract with you.
8. How long we keep personal data
- Enquiries that do not lead to an Order: 12 months after our last contact.
- Contract, Order, invoice and payment records: 7 years after the end of the financial year in which the Order was completed, as required by UAE corporate tax and commercial record-keeping rules.
- Verification documents: for the duration of the customer relationship and 5 years after its end.
- Service access logs: 12 months.
- Customer Content: deleted within 24 hours after the end of the Term (section 5).
9. Security
We protect personal data with technical and organisational measures appropriate to the risk: encrypted connections for all access to machines and management systems, unique credentials for every Order, access limited to the people who need it, and secure wiping of machines at the end of each Term. No system is completely secure. If we become aware of a personal data breach that is likely to cause harm to you, we notify you and the UAE Data Office as required by the PDPL.
10. Your rights
Subject to the conditions in the PDPL and other applicable law, you have the right to:
- obtain confirmation of whether we process your personal data, and receive a copy of it;
- have inaccurate or incomplete data corrected;
- have your data erased, or its processing restricted, where the law allows;
- object to processing based on our legitimate interests, and to direct marketing (we do not carry out direct marketing);
- receive the data you have provided to us in a structured, commonly used, machine-readable format;
- withdraw consent where processing is based on consent, without affecting processing carried out before withdrawal.
To exercise a right, e-mail info@velacompute.ai. We may ask you to verify your identity. We respond within 30 days. If you are not satisfied with our response you may complain to the UAE Data Office or, where the GDPR applies to you, to your local supervisory authority.
11. Children
Our services and this website are intended for businesses. We do not knowingly collect personal data of persons under 18.
12. Changes to this policy
We may update this policy from time to time. The current version, with its "Last updated" date, is always available on this website. Material changes that affect existing customers are communicated by e-mail.
13. Contact
VELA COMPUTE - FZCO
IFZA Business Park, Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, United Arab Emirates
E-mail: info@velacompute.ai
Telephone: +971 55 767 7835 (Monday to Friday, 09:00–18:00 Gulf Standard Time, UTC+4)