# GDPR compliance

_Updated 16 Aug 2026._

Canonical: https://peeve.ai/legal/gdpr/

How Peeve helps you meet the EU and UK GDPR. For the customer data you send through the Service, you are the Controller and Peeve (Veltron LLC) is the Processor: we process it only on your documented instructions. The binding terms are in our Data processing agreement; this page is the plain-language summary.

## Our role

You decide why and how your users' data is processed, so you are the Controller; Peeve processes it on your behalf as a Processor under Article 28 GDPR. A signed Data processing agreement, with the EU Standard Contractual Clauses and UK Addendum built in, is available on the Scale plan and to any customer who needs one.

> We never train AI models on your data or your users' data, and Peeve captures no images of your users' screens.

## What we process, and data minimization

Peeve monitors and understands sessions to run: it reads the structure of your interface (element roles, accessible names, positions) and records a trace of each session (the steps attempted and their confidence). It does not capture an image of your users' screens, and it never collects passwords, session tokens, or the contents of fields you mask. We process the minimum needed to answer, guide, and hand off, and nothing is used to train models.

## Lawful basis

Peeve does not determine the lawful basis for your users' data; you do, as the Controller. Typically Peeve's processing supports your legitimate interest in providing support, or the performance of your contract with your users. Peeve processes only on your instructions and helps you honor the basis and consents you have set.

## Data subject rights

GDPR gives your users the right to access, rectification, erasure, restriction, data portability, and objection. You can exercise these for your workspace at any time from within the Service, and Peeve assists you with appropriate technical measures. If a data subject contacts Peeve directly, we do not act unilaterally: we promptly notify you (the Controller) and act on your instructions. Verified requests are actioned without undue delay, and within 30 days where GDPR or CCPA applies.

## International transfers

Where personal data leaves the EEA or UK, the transfer is made under an appropriate mechanism, including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, incorporated by reference in the Data processing agreement. Our sub-processors are engaged under equivalent safeguards.

## Sub-processors

Peeve engages a small set of sub-processors, each under a data-processing agreement with GDPR-appropriate safeguards. The current list, with each one's purpose and region, is published at peeve.ai/legal/sub-processors, and we give notice before a new sub-processor begins processing customer personal data so you can object on reasonable grounds.

## Security

Peeve maintains measures appropriate to the risk: encryption of data in transit and at rest, role-based least-privilege access, authentication and secrets management, network and application security, audit logging, and backup and recovery. Credentials are isolated from the model, which requests capabilities by name and never sees a token.

## Retention and deletion

Session-level records are kept only for the retention window you configure, up to a maximum of 90 days. Deleting a workspace purges its route map, fingerprints, and session traces on that schedule, and residual copies in encrypted backups are purged on the standard backup rotation. On termination, Peeve deletes or returns all personal data at your choice, unless retention is required by law.

## Breach notification

If Peeve becomes aware of a personal-data breach affecting your data, we will notify you without undue delay and provide the information reasonably available to help you meet your own notification obligations under Articles 33 and 34 GDPR.

## Complaints and contact

For data-protection questions, a signed DPA, or to exercise a right, email legal@peeve.ai. You also have the right to lodge a complaint with your local supervisory authority. Related documents: the Data processing agreement (/legal/dpa/), the Privacy policy (/legal/privacy/), Data handling (/legal/data-handling/), and the Sub-processors list (/legal/sub-processors/).
