Legal

Privacy policy

Veesie is a ClickForest product. This privacy policy explains which personal data we process, why, and what rights you have. Version 1.1, effective from 11 September 2026.

1. Data controller

The data controller for Veesie is:

Manon BV (trading as ClickForest)
Zwarte Leeuwstraat 78A, 2820 Bonheiden, Belgium
Company number / VAT: BE 0549.803.522
Email: hello@veesie.com
Website: veesie.com

2. Which personal data do we process?

CategoryExamplesSource
Account dataEmail address, name, hashed passwordYou provide them yourself at registration
Organization dataCompany name, chosen plan, onboarding statusCreated at first login
Service usageClients, prompts, run results, AI answers, tokens, cost per callGenerated by using Veesie
BillingPayment reference, Stripe customer IDVia Stripe Checkout (only on a paid plan)
Technical dataIP address for rate limiting (not stored, except for chat conversations: see the row below), browser session tokenAutomatically via Cloudflare Workers
Trial hashSHA-256 hash of the email addressCreated on completing onboarding (see section 5)
Chat conversationsYour questions and the assistant's answers, the IP address, and for the dashboard chat your email addressWhen you use the chat on the website or in the dashboard

We process no special categories of personal data (such as health data, political opinions or biometric data).

3. Purposes and legal bases

PurposeLegal basis (GDPR)
Delivery of the service (dashboard, runs, analytics)Art. 6(1)(b): performance of the contract
Authentication and session managementArt. 6(1)(b): performance of the contract
Billing and subscription managementArt. 6(1)(b) + Art. 6(1)(c): legal obligation (accounting law)
Email notifications about runs and alertsArt. 6(1)(b): performance of the contract
Anti-abuse: preventing repeated free trialsArt. 6(1)(f): legitimate interest (see section 5)
Internal operational statistics (cost, usage)Art. 6(1)(f): legitimate interest
Chat assistant: answering questions, preventing abuse and improving the answersArt. 6(1)(f): legitimate interest

4. Retention periods

DataRetention period
Account data, clients, prompts, run resultsAs long as your account is active. After deletion: erased immediately (cascade).
Invoice data7 years (legal accounting retention obligation)
Trial hash (SHA-256)Indefinite (see section 5 for explanation and right to object)
Operational cost logs (usage_events)12 months, then deleted automatically
Chat conversations (chat_logs)6 months, then deleted automatically

5. Trial history: SHA-256 anti-abuse hashing

What do we do? When you complete onboarding, we store a SHA-256 hash of your email address in a separate table (trial_history). This is a pseudonymous, non-reversible fingerprint. The original email address cannot be recalculated from this hash.

Why?

Veesie offers a free trial on sign-up. Without a measure, a user could delete their account and sign up again with the same email address to get a new free trial. The hash registration prevents this abuse: on a new sign-up we check whether the hash already exists. If so, the new trial starts immediately as expired.

Legal basis

Art. 6(1)(f) GDPR: legitimate interest. Our interest is the commercial integrity of the trial model and preventing systematic abuse. We weigh this against your privacy interest: the hash is pseudonymous (not directly identifiable), the email address itself is not stored, and its only function is binary detection (has this address ever had a trial: yes/no).

Objecting (Art. 21 GDPR)

You can object at any time to the processing of your trial hash via hello@veesie.com. We assess your request within 30 days. If the objection is well-founded, we delete the hash from trial_history.

6. Recipients and subprocessors

SubprocessorFunctionLocation
Supabase (Postgres + Auth)Database, authenticationEU (Frankfurt)
Cloudflare (Workers)Application hosting, edge processingGlobal network: a request runs through the data centre closest to the visitor, which for European visitors is normally in Europe. Cloudflare, Inc. (US), based on SCCs
ResendTransactional email (notifications, reports)EU region
StripePayment processing (only on a paid plan)Ireland (EU)
SentryError monitoring (error tracking)EU (Frankfurt, Germany)
Google Analytics 4Website statistics for the public website. Without your consent it runs without cookies, and never inside the dashboardUS (Google LLC), based on SCCs
Microsoft ClarityUsage analysis of the public website: heatmaps and recordings of mouse movement and clicks. Without your consent it runs without cookies, and never inside the dashboardUS (Microsoft Corporation), under SCCs
OpenAI, Anthropic, Google, PerplexityLLM calls (prompts are sent to the providers)US / EU (depending on the provider). Answers are stored in the EU DB.
DataForSEOMeasuring Google AI Overviews (your questions are sent to Google as a search query)EU (Estonia), with sub-processors partly in the US, based on SCCs
InngestRunning the measurements (queue, retries and the intermediate results of each step)US (Inngest Inc, AWS servers in the US)

Note on LLM providers: the prompts you configure in Veesie are forwarded to the relevant AI providers for processing. They usually contain no personal data (they are questions about your brand, not about people). Do check that your prompts themselves contain no personal data.

We never share personal data with third parties for marketing or profiling purposes.

Role with customer data: you are responsible for the lawfulness of the data you enter into Veesie. For personal data you provide as a customer and that we process on your behalf, we may act as a processor within the meaning of the GDPR. A data processing agreement is available on request via hello@veesie.com.

7. International transfers

The core data (account, clients, results) is stored in the EU (Supabase Frankfurt). LLM calls go to providers outside the EU (including OpenAI and Anthropic in the US). Google Analytics 4 and Microsoft Clarity, which run on the public website only (without cookies until you consent, and never inside the dashboard), also process data in the US. These transfers happen on the basis of the Standard Contractual Clauses (SCCs) offered by the relevant providers. In addition, Inngest runs the measurements on AWS servers in the US: during a measurement, your questions, your brand name and website, the names of your competitors and the generated recommendations also pass through it.

8. Your rights

Under the GDPR you have the following rights:

Send your request to hello@veesie.com. We respond within 30 calendar days.

You also have the right to lodge a complaint with the Belgian Data Protection Authority (DPA).

9. Cookies and tracking

Strictly necessary cookies (no consent required): a session cookie for authentication (Supabase Auth) and security cookies from Cloudflare and Cloudflare Turnstile (bot protection on the sign-up and contact pages). We also set a cookie holding only the language you arrived in (nl, en or fr), so that an account you create starts in that language. It contains no identifier and is not shared with anyone.

Analytics cookies: for website statistics we use Google Analytics 4 and Microsoft Clarity, and both run on the public website only, never inside the dashboard. Without your consent both measure without cookies: Google Analytics then provides only aggregated, estimated figures, and Clarity uses a separate identifier per page view, so we cannot tell that different visits come from the same person. Clarity records anonymous mouse movement, clicks and scrolling so we can see where visitors get stuck. If you do consent, both may set cookies and follow a visit across several pages. If you withdraw your choice, that stops again and Clarity deletes its cookies. We do not do remarketing and do not build advertising profiles.

Advertising measurement: if you reach our site via an ad, the URL contains a click identifier (Google calls it gclid, gbraid or wbraid). If you consent, we keep it for up to 90 days in a cookie of our own and link it to your organisation once you sign up. That tells us which ad led to a customer, without following you across other websites. If you decline, we do not store that identifier. Once we actually advertise, Google may, with your consent, also set its own advertising cookies for that same measurement; as long as no campaigns are running, that does not happen.

10. Google user data (Analytics connection)

If you connect your Google Analytics account to Veesie, we read only the data of the property you select, through the Google Analytics API. We request read-only access (analytics.readonly). We use that data for a single purpose: showing how many visitors your website receives from AI tools such as ChatGPT, Perplexity and Claude.

What we store: the email address of the Google account you connect with, the selected property ID, and Google's access tokens. Those tokens are stored encrypted (AES-256-GCM). We also keep a copy of the requested report for up to fifteen minutes, so your dashboard does not have to call Google on every page view. We do not retrieve or store data about individual visitors.

What we do not do: we do not sell this data, do not use it for advertising, do not share it with third parties, and do not use it to train AI models. No one at Veesie reads it, except when you ask for support or the law requires it. Veesie's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Revoking access: the Disconnect button on the Traffic page in your dashboard ends the connection, after which we immediately delete the stored tokens and the cached report. You can also revoke access directly with Google, through your Google account's security settings.

11. How we protect your data

We take appropriate technical and organisational measures to protect your data, as required by Art. 32 GDPR. For sensitive data, such as your password and the access tokens of your Google account, the following applies in particular:

If we identify a data breach that poses a risk to your rights and freedoms, we report it to the Belgian Data Protection Authority within 72 hours and inform you where the GDPR requires it. A fuller description of our measures is on our security page.

12. Changes

For material changes to this policy we send an email notification to all active users and update the date at the top. Minor editorial changes are made without separate notice.

13. Contact

For questions, requests or complaints about privacy: hello@veesie.com.

Back to veesie.com