Privacy policy.
This policy describes how Vedio collects, uses, stores, shares and protects information when you visit vedio.dk, create an account, buy a subscription, order a video or contact us (together, the "Services").
1 · Data controller & contact
Vedio Labs ApS
CVR: 45979342
Stagehøjvej 19a, 8600 Silkeborg, Denmark
Privacy questions: info@vedio.dk
General: info@vedio.dk
2 · Our role: when we are data controller and when we are data processor
2.1 Vedio as data controller
We are typically data controller for personal data about: account and user information (name, email, login, role, seats), billing and subscription data, support correspondence, platform usage, security signals, and marketing communications.
2.2 Vedio as data processor (your project content)
When you upload material for editing (video, audio, images, scripts, brand assets), the material may contain personal data — people on camera, voices, names visible in screen recordings, etc. In those cases Vedio acts as data processor for you (or your organization), and you are the controller. You are responsible for having a lawful basis (consent, contract, legitimate interest) for sharing that material with us.
A data processing agreement (DPA) is available on request for business customers — email info@vedio.dk.
3 · What we collect
- Account & identity — name, email, hashed credentials, role, seats, company.
- Billing — invoice address, payment status, transaction references. Card data is processed by our payment provider; we never see full card numbers.
- Communications — briefs, feedback, comments, support tickets.
- Project content / uploads — video, audio, image and text files, metadata, brand kits, scripts, voice samples, references and any feedback notes.
- Generated content — scripts, edits, captions and suggestions produced for you by Vee and our human editors.
- Usage signals — which suggestions you accept or reject, time per stage, navigation paths, edit-loop behaviour.
- Technical & security data — IP, browser, device, language, log and event data, abuse-prevention signals.
Sensitive data: uploaded material may contain special-category data (health, political opinion, sexual life, etc.) if you upload it. We strongly advise you to avoid uploading sensitive data unless it is necessary and you have a clear lawful basis under GDPR Art. 9.
4 · How we use your data
- Account creation, access control and seat management.
- Delivering the Services — receiving briefs, processing projects, editing and shipping output.
- Billing, subscriptions and bookkeeping.
- Customer support and incident response.
- Security, fraud prevention and abuse mitigation.
- Improving the platform — analytics on performance, errors, UX.
- Service-related communications (always sent) and marketing communications (subject to applicable consent / soft opt-in rules).
- Compliance with legal obligations (bookkeeping, lawful requests, IP enforcement).
5 · AI training, model improvement & ownership of improvements
Plain-English summary. When you sign up to Vedio, you authorize us to use the raw and processed material associated with your account — uploaded video, audio, scripts, brand kits, voice samples, performance signals and feedback — to train, refine and improve our internal AI models, datasets and orchestration intelligence. The improvements (model weights, derived datasets, voice-style profiles, prompt libraries and any other intelligence created from this training) are owned exclusively by Vedio.
By creating an account or otherwise activating the Services, you grant Vedio a worldwide, royalty-free, sublicensable license to host, process, transcribe, edit, adapt and analyse the material described above for the purposes of operating, securing, evaluating and improving the platform — including training the editorial, voice, scheduling and analytics models that power Vee. This license lasts as long as is reasonably necessary to fulfil those purposes.
You retain full ownership of the original content you upload and of the finished videos Vedio delivers to you. Vedio retains all rights, title and interest in the platform itself and in any improvements, model weights, datasets, embeddings and intelligence derived from training on customer material — none of which are returned to or licensable by individual customers on termination.
We do not sell raw customer content, and we do not feed customer content into public third-party foundation models (OpenAI, Anthropic, Google, Meta etc.) for their training. Any third-party model we call at inference time is governed by zero-retention or equivalent contractual terms.
6 · Lawful bases (GDPR Art. 6)
- Contract (Art. 6(1)(b)) — to deliver the Services: account, orders, delivery, support.
- Legal obligation (Art. 6(1)(c)) — bookkeeping, statutory record-keeping, lawful authority requests.
- Legitimate interest (Art. 6(1)(f)) — operating, securing, preventing abuse, improving the platform, statistics, limited B2B direct marketing under the soft-opt-in rules.
- Consent (Art. 6(1)(a)) — non-essential cookies, marketing where required, customer-case showcases.
7 · Retention
- Account data: while the subscription is active, plus up to 12 months after termination.
- Billing & invoice records: 5 years + the current calendar year, as required by Danish bookkeeping law.
- Support correspondence: up to 24 months from last contact, longer if needed for an active dispute.
- Project content (raw uploads, working drafts, deliverables): up to 12 months after termination, then deleted from production storage and rotated out of backups. You can request earlier deletion (see §9).
- Aggregated and de-identified signals used to train our models are retained beyond that point because the resulting derivatives can no longer be linked to individual customers.
8 · Sharing & sub-processors
We never sell personal data. We share with:
- Internal team and editors — only to the extent needed to deliver the Services.
- Sub-processors — EU-based cloud hosting, email delivery, error monitoring, payment processing, support tools. The current list is published at /security.
- Professional advisors (auditor, legal counsel) when needed.
- Public authorities only when legally required.
We sign DPAs with sub-processors where GDPR requires it.
9 · Your rights (GDPR)
- Right of access
- Right to rectification
- Right to erasure ("right to be forgotten"), subject to retention obligations
- Right to restrict processing
- Right to data portability
- Right to object — including to processing based on legitimate interest and to direct marketing
- Right to withdraw consent at any time, without affecting prior lawful processing
To exercise any right, email info@vedio.dk. We may ask for proof of identity for security. We respond as quickly as possible and within 30 days at the latest.
You may also lodge a complaint with the Danish Data Protection Agency: Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby.
10 · International transfers
Some sub-processors may process data outside the EU/EEA. Where this happens, we rely on the European Commission's Standard Contractual Clauses (SCCs) and equivalent safeguards under GDPR Chapter V. You can request information about the specific transfer mechanism by emailing info@vedio.dk.
11 · Security
We apply technical and organisational safeguards including TLS 1.2+ in transit, AES-256 at rest, role-based access, audit logging, abuse monitoring, regular backups and incident-response drills. No system is 100% secure — keep your credentials safe.
12 · People in your uploads
If your uploads include other people (employees, customers, talent, members of the public) you are responsible for ensuring they have given the necessary consent for their image, voice and likeness to be processed and published. We may refuse to deliver content where consent appears to be missing.
13 · Children
The Services are not directed at users under 16. We do not knowingly collect data from minors. If we discover we have, we delete it.
14 · Marketing & communications
- Service messages (operations, security, billing, deliveries) are part of the Services and cannot be opted out of without ending the Services.
- Marketing — you can unsubscribe via the link in every email or by writing to us.
15 · Third-party links and services
vedio.dk may link to or embed third-party services (Calendly, Google Fonts, etc.). We are not responsible for those parties' processing — please review their privacy policies.
16 · Changes
We may update this policy. For material changes, we'll notify active customers by email at least 30 days before the change takes effect. The latest version is always at this URL with the updated date.
17 · Contact
Privacy: info@vedio.dk
Legal: info@vedio.dk
Postal: Vedio Labs ApS, Stagehøjvej 19a, 8600 Silkeborg, Denmark · CVR 45979342