Security & data
What happens to your operating data.
This page describes the state of things, not the intention. What is established stands here with its reason. What is still open stands below as an open point — not as a promise nobody could redeem.
Where the data comes from and where it goes
Four stations. At each one it says what happens there and what does not.
Your till
The data arises where sales happen — in the till system already at your place. Veydex changes nothing about that: if you link it over Connect, the recording duty under TSE, GoBD and Kassensicherung stays with your till system.
Veydex Connect
Connect collects it — over one of five routes: cloud API, OAuth, a local connector, direct push or the legally mandated DSFinV-K export. We do not ask for your till password; with OAuth you grant access in your provider's account and can revoke it there.
Veydex Hub
In the Hub it sits separated per workspace. A workspace is one business: own settings, own team, own modules. Anyone running several businesses has one login and still separate sets of data.
Modules and helpers
What computes on it computes only on what has been booked. A module you have not booked processes nothing, and a helper sees only the data of its remit.
Access
Who in the business may see what
At Veydex, authorisation is not a setting applied afterwards but part of every access.
Three roles
Owner, admin and staff. The role applies per workspace, not per login — whoever runs one site and helps out at another has the right role at both. Changes take effect immediately.
Checked on every access
Authorisation is checked on every access, not only at sign-in. A withdrawn role therefore takes effect in an open session too.
Separated per workspace
The data of several businesses sits separately. Access to one workspace is not access to the others.
Analysis without personal reference
Staff-related analysis is aggregated by default. “Shrinkage & voids” works without personal reference; it can only be switched on under defined conditions — so that hard-working staff do not automatically look like a problem.
Automation
What a helper may do — and what it may not
Observing and proposing is not the same as executing. That is not a phrasing, it is the permission model.
Three levels of trust
Observe, propose, execute. You set which one applies per helper. None starts at the highest level.
Five checks before anything runs
Remit, trust level, limits, objection window and quota. If one of them fails, nothing happens.
Objection beats proposal
If you object, it does not happen. Repeatedly declined proposals automatically reduce how much a helper does on its own.
Only its own data
Every role sees only the data of its remit. Ben sees purchasing and stock, not the guest profiles.
Emergency stop
The helpers can be switched off — all of them, or one at a time.
Your data
Getting it out and deleting it
Export while running
Analytics gives a CSV export, and several modules export their own data — customer records, hygiene, shrinkage & voids. That is a sheet of numbers, not a bookkeeping file; the Hub does not produce a DATEV posting batch.
Export after the contract ends
After the contract ends, an export remains possible for 30 Tage. After that the data is returned or deleted, as you choose.
Statutory retention
Where a statutory retention duty applies, processing is restricted for its duration instead of the data being deleted. That is not an exception in Veydex's favour but what the law requires.
Applications
Documents from the job application form sit in a private object store with a deletion rule. What is promised is deletion at the latest six months after the procedure ends.
Website
What this website itself does
The rest of this page is about the Hub. This section is about the page you are on — and it is deliberately built narrow.
No consent banner, because nothing is stored
Reach measurement runs on a self-hosted Umami instance without cookies. The origin of a visit — campaign, referrer — lives only in the tab's memory and not on your device. That is why the site needs no banner.
Fonts are served locally
No fonts from a third-party server, so no transmission of your IP address to one.
No captcha
Automated requests are caught by a hidden field, not by a service that analyses visitors.
Appointments over Cal.com
Appointment booking runs over Cal.com. What is transmitted stands in the privacy policy — the service is used only for appointments on this website and not in the Hub.
Data processing
If you use the Hub, Veydex processes personal data on your behalf — guests, staff, transactions. There is a data processing agreement for that, with annexes on technical measures and sub-processors. It exists as a draft and should be requested before signing; legal review is still outstanding, and the document says so itself.
What is not answered here yet
These details do not yet exist internally in a form we could commit to publicly. They stand here rather than being absent — anyone who needs them for a decision gets them in conversation, and they come onto this page once they are settled.
- Who runs the application and where the servers stand
- Who runs the object store the files sit in
- Which provider messages are sent through
- The competent data protection authority
- Encryption methods for stored data, named individually
- Backups and recovery: frequency, retention, tested target times
- Availability and a public status page
- Which AI providers stand behind phone AI and the helpers, and where they process
- Reporting route and deadlines for a security incident, stated publicly
- Certifications and audit reports — none exist, and this page claims none
Questions that are not answered here?
If you need a detail for a decision that this page leaves open, ask for it. An honest answer in conversation is worth more than a sentence on a page that nobody can back up.
Note: the interface shown on this page is the Veydex Hub. The names, figures and bookings inside it are synthetic demo data and do not describe a real business.