Trust + Compliance

Data protection, security, and privacy at Veysa

Every data point in Veysa carries source attribution by design. This isn't a compliance feature bolted on after launch. It's how the product works. The same transparency your reps use for prospecting is what your legal team uses for data subject requests.

Data protection compliance

Frameworks

Compliant with the UAE Personal Data Protection Law (PDPL). Legitimate interest basis with full source transparency. EU-region data centres.

Verified contact data

Every email is verified via SMTP probe before it appears in your account. Confidence scores and named-source attribution on every field.

Data subject requests

Public opt-out page for data subjects at app.veysa.ae/opt-out. Automated request processing with status tracking. Deletion confirmed within 30 days.

Public DPA, named DPO

Standard DPA available to any customer, on request, no minimum plan. DPO at dpo@veysa.ae. Sub-processor list available on request.

Registry data includes open government and open-licence datasets, used with attribution: Dubai Pulse open data (Dubai DET and Dubai Land Department, Dubai Open Data Licence), the Australian Business Register bulk extract (CC BY 3.0 AU), and the People Data Labs Free Company Dataset (CC BY 4.0). Registry and authority names identify data sources only; no government affiliation or endorsement is implied. Full attribution list available on request.

See source attribution live Compliance by design, not bolted on

Security and infrastructure

Your data stays in the EU, encrypted, and isolated from every other customer.

Transport

TLS 1.2+ on all traffic. HSTS enforced. API endpoints require authentication. Webhooks are HMAC-signed for integrity.

Infrastructure

EU-region data centres for application and database hosting. Credentials encrypted at rest with AES-256. No customer data in application logs.

Application

CSP headers, X-Frame-Options, rate limiting (120 req/min). Session cookies: secure, httpOnly, sameSite=lax. API docs hidden in production.

Access control

Tenant-isolated data model. Customers access only their enriched contacts. Global company graph is read-only. No cross-tenant data leakage by design.

Data retention

Company data from UAE government registries is refreshed on crawl cycles. Contact data is retained while the customer account is active. On account deletion, all tenant data is permanently removed.

Incident response

Data breach notification within 72 hours. Affected customers notified directly. Post-incident review published to affected parties.

Trust + compliance FAQ

Is Veysa data protection compliant?

Yes. Veysa is compliant with the UAE Personal Data Protection Law (PDPL). Every data point carries named-source attribution for compliance requests. Infrastructure is hosted in the EU region.

Where is my data stored?

Application hosting and database are in EU-region data centres. Payment processing via Stripe keeps EU data in the EU. AI intelligence generation uses Anthropic (US) but no personal data is stored by the AI provider.

Can I get a DPA?

Yes. A standard Data Processing Agreement is available to any customer, no minimum plan required. Email dpo@veysa.ae and we'll send it within 24 hours.

Does Veysa scrape LinkedIn?

Veysa does not scrape LinkedIn directly. We source professional profile data through third-party data providers and public sources. UAE company data comes from government registries (DMCC, DLD, DFSA, DED). For any data subject request, we provide named-source attribution via your account's compliance export.

Questions about compliance?

Email dpo@veysa.ae for DPA requests, data protection questions, or to discuss your specific compliance requirements.

Start trial

No match = no charge · UAE PDPL · 650,000+ companies