veydex

Security & data

What happens to your operating data.

This page describes the state of things, not the intention. What is established stands here with its reason. What is still open stands below as an open point — not as a promise nobody could redeem.

Where the data comes from and where it goes

Four stations. At each one it says what happens there and what does not.

  1. Your till

    The data arises where sales happen — in the till system already at your place. Veydex changes nothing about that: if you link it over Connect, the recording duty under TSE, GoBD and Kassensicherung stays with your till system.

  2. Veydex Connect

    Connect collects it — over one of five routes: cloud API, OAuth, a local connector, direct push or the legally mandated DSFinV-K export. We do not ask for your till password; with OAuth you grant access in your provider's account and can revoke it there.

  3. Veydex Hub

    In the Hub it sits separated per workspace. A workspace is one business: own settings, own team, own modules. Anyone running several businesses has one login and still separate sets of data.

  4. Modules and helpers

    What computes on it computes only on what has been booked. A module you have not booked processes nothing, and a helper sees only the data of its remit.

Access

Who in the business may see what

At Veydex, authorisation is not a setting applied afterwards but part of every access.

Three roles

Owner, admin and staff. The role applies per workspace, not per login — whoever runs one site and helps out at another has the right role at both. Changes take effect immediately.

Checked on every access

Authorisation is checked on every access, not only at sign-in. A withdrawn role therefore takes effect in an open session too.

Separated per workspace

The data of several businesses sits separately. Access to one workspace is not access to the others.

Analysis without personal reference

Staff-related analysis is aggregated by default. “Shrinkage & voids” works without personal reference; it can only be switched on under defined conditions — so that hard-working staff do not automatically look like a problem.

Automation

What a helper may do — and what it may not

Observing and proposing is not the same as executing. That is not a phrasing, it is the permission model.

Three levels of trust

Observe, propose, execute. You set which one applies per helper. None starts at the highest level.

Five checks before anything runs

Remit, trust level, limits, objection window and quota. If one of them fails, nothing happens.

Objection beats proposal

If you object, it does not happen. Repeatedly declined proposals automatically reduce how much a helper does on its own.

Only its own data

Every role sees only the data of its remit. Ben sees purchasing and stock, not the guest profiles.

Emergency stop

The helpers can be switched off — all of them, or one at a time.

Your data

Getting it out and deleting it

Export while running

Analytics gives a CSV export, and several modules export their own data — customer records, hygiene, shrinkage & voids. That is a sheet of numbers, not a bookkeeping file; the Hub does not produce a DATEV posting batch.

Export after the contract ends

After the contract ends, an export remains possible for 30 Tage. After that the data is returned or deleted, as you choose.

Statutory retention

Where a statutory retention duty applies, processing is restricted for its duration instead of the data being deleted. That is not an exception in Veydex's favour but what the law requires.

Applications

Documents from the job application form sit in a private object store with a deletion rule. What is promised is deletion at the latest six months after the procedure ends.

Website

What this website itself does

The rest of this page is about the Hub. This section is about the page you are on — and it is deliberately built narrow.

No consent banner, because nothing is stored

Reach measurement runs on a self-hosted Umami instance without cookies. The origin of a visit — campaign, referrer — lives only in the tab's memory and not on your device. That is why the site needs no banner.

Fonts are served locally

No fonts from a third-party server, so no transmission of your IP address to one.

No captcha

Automated requests are caught by a hidden field, not by a service that analyses visitors.

Appointments over Cal.com

Appointment booking runs over Cal.com. What is transmitted stands in the privacy policy — the service is used only for appointments on this website and not in the Hub.

Data processing

If you use the Hub, Veydex processes personal data on your behalf — guests, staff, transactions. There is a data processing agreement for that, with annexes on technical measures and sub-processors. It exists as a draft and should be requested before signing; legal review is still outstanding, and the document says so itself.

What is not answered here yet

These details do not yet exist internally in a form we could commit to publicly. They stand here rather than being absent — anyone who needs them for a decision gets them in conversation, and they come onto this page once they are settled.

  • Who runs the application and where the servers stand
  • Who runs the object store the files sit in
  • Which provider messages are sent through
  • The competent data protection authority
  • Encryption methods for stored data, named individually
  • Backups and recovery: frequency, retention, tested target times
  • Availability and a public status page
  • Which AI providers stand behind phone AI and the helpers, and where they process
  • Reporting route and deadlines for a security incident, stated publicly
  • Certifications and audit reports — none exist, and this page claims none

Questions that are not answered here?

If you need a detail for a decision that this page leaves open, ask for it. An honest answer in conversation is worth more than a sentence on a page that nobody can back up.

Note: the interface shown on this page is the Veydex Hub. The names, figures and bookings inside it are synthetic demo data and do not describe a real business.