Veylo

Privacy policy

Last updated 30 September 2026

In short

Veylo runs in your browser and keeps your boards on your device. There are no accounts, no cookies, no analytics and no advertising, and the site loads nothing from third parties. The only personal data we process is the technical data your browser sends to our web server when you open the site, and any message you send us yourself.

Who is responsible

The controller under Art. 4 (7) GDPR is:

Name
Johannes Müller
Address
Dr.-Reinhard-Weg 2
88281 Schlier
Germany
Email
mail@jotrorox.com
Phone
+49 177 3149134

Hosting and server log data

This website is hosted by Railway (Railway Corporation, USA, railway.com). We have chosen the EU region in the Netherlands as the server location. When you open a page, the web server automatically processes the following technical data:

We process this data to deliver the website to you and to keep it secure and stable. The legal basis is Art. 6 (1) (f) GDPR, our legitimate interest in running the site reliably and safely. The web server software we run does not keep its own request log. We do not combine the data with other data and do not use it to identify you. The hosting provider stores log data only for a limited period and then deletes it.

Railway processes this data on our behalf under a data processing agreement pursuant to Art. 28 GDPR. Railway is a company based in the United States. Although we chose an EU server location, access from outside the EU by Railway or its sub-processors cannot be ruled out. Where personal data is transferred to a third country, the transfer relies on appropriate safeguards under Art. 44 ff. GDPR, such as an adequacy decision or standard contractual clauses.

Data stored in your browser

Veylo saves your boards, columns, cards, tags, subtasks, due dates and display settings, such as the sidebar and the board or list view, in your browser’s local storage. This data stays on your device. It is not sent to us or to anyone else, and we cannot see it.

Local storage is needed to provide the function you asked for, so no consent is required under § 25 (2) no. 2 TDDDG. Because the data lives only in your browser, it does not sync between devices. To delete it, remove your boards in Veylo or clear this site’s data in your browser settings.

Cookies, analytics and third parties

Veylo does not set cookies and does not use analytics, tracking, advertising or social media plugins. Fonts, styles and scripts are served from this website itself, so your browser does not contact any other server when you use it. The web server also instructs your browser not to send referrer information and to block connections to other sites.

Contacting us

If you write or call us, we process your contact details and your message to answer you. The legal basis is Art. 6 (1) (b) GDPR if your request relates to a contract or steps before one, and otherwise Art. 6 (1) (f) GDPR, our legitimate interest in answering enquiries. We delete the data once your request is dealt with, unless we are legally required to keep it.

Recipients and storage periods

Your data is passed on only to the hosting provider described above. We do not sell it or share it with anyone else. Server log data is deleted by the hosting provider after a limited period. Messages you send us are kept until your request is dealt with, plus any period the law requires. Data in your browser stays until you delete it.

No obligation to provide data, no automated decisions

You are not obliged to provide personal data to use Veylo. Your browser sends the technical data listed above automatically because it is needed to load the site. We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.

Your rights

You have the right to:

To use any of these rights, contact us at the address above. If you object to processing based on Art. 6 (1) (f) GDPR, we will stop it unless we can show compelling legitimate grounds that override your interests.

Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the EU member state of your habitual residence, your place of work or the place of the alleged infringement. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg), baden-wuerttemberg.datenschutz.de. If you follow that link, your browser connects to the authority’s website, which has its own privacy policy.

Security

This website is delivered over an encrypted HTTPS connection.

Changes to this policy

We will update this policy if the website or the law changes. The current version is always available on this page.