Last Updated: August 4, 2026
OpenLegion LLC, doing business as Velvy.ai (“Velvy,” “Company,” “we,” “us,” or “our”), provides website development, hosting, artificial intelligence, communications, automation, marketing, consulting, and related technology services.
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you:
For website visitors, prospective clients, clients, vendors, and business contacts, Velvy generally determines why and how personal information is processed. In privacy-law terminology, Velvy acts as the controller, business, or equivalent responsible organization.
Our clients may use our Services to collect or process information about their callers, customers, leads, employees, contractors, website visitors, and other individuals.
For that “Client Service Data”:
The client’s privacy policy, notices, and instructions govern its use of Client Service Data.
Individuals seeking to exercise rights concerning Client Service Data should normally contact the relevant client directly. We will assist our client as required by our agreement and applicable law.
The information we collect depends on how you interact with us and which Services are used.
We may collect:
We may collect:
When you make a purchase, we may collect:
Payment transactions may be processed by Stripe or another payment provider.
We generally do not receive or store complete card numbers, card-security codes, or payment authentication credentials.
Payment providers process payment information under their own privacy notices and legal obligations.
When you interact with an AI receptionist, voice demonstration, chatbot, support system, telephone system, or communications workflow, we may collect or process:
Where we provide these systems for a client, the client determines whether recordings are enabled, what notices are provided, and how the information is used, subject to our agreement.
Do not provide sensitive information during a demonstration unless it is necessary and you are authorized to do so.
Depending on a client’s configuration, our Services may process:
This information is normally Client Service Data processed on behalf of the client.
If you connect or authorize a third-party service, we may receive information made available through that integration, such as:
We use integration information to provide the requested connection and Services.
You are responsible for ensuring that you are authorized to connect the account and provide access to the associated information.
We may automatically collect:
We may collect:
Our standard Services are not designed for the intentional collection of:
Do not provide these categories unless we have expressly agreed in writing to process them and appropriate safeguards and contractual terms are in place.
A caller or user may voluntarily disclose sensitive information during a call or communication. Where we process that interaction for a client, the client is responsible for configuring appropriate notices, minimization, retention, and deletion procedures.
We may obtain personal information:
We may use personal information to:
We do not use Client Service Data for unrelated independent marketing.
We do not use Client Service Data to train generalized AI models owned by Velvy unless the applicable client expressly agrees in writing.
Where laws such as the European Economic Area or United Kingdom data-protection laws require a legal basis, we may process personal information based on:
We process information when necessary to enter into or perform a contract, provide requested Services, process payment, or manage a business relationship.
We may process information for legitimate business interests, including:
We consider the potential impact on individuals before relying on legitimate interests.
We may rely on consent for certain marketing, recording, cookie, communications, or optional processing activities.
Consent may be withdrawn where legally applicable, but withdrawal does not affect processing already lawfully completed.
We may process information to comply with tax, accounting, regulatory, court, law-enforcement, sanctions, and other legal requirements.
For Client Service Data, our client determines the applicable legal basis. We process the information under the client’s instructions and our agreement with the client.
We may use artificial intelligence and machine-learning providers to:
AI systems can produce inaccurate or unexpected results. We may use automated processing to support the Services, but we do not make solely automated decisions about individuals that produce legal or similarly significant effects on behalf of Velvy.
A client may configure its own use of automation. The client is responsible for determining whether human review, consent, notices, impact assessments, or other safeguards are legally required.
We may send information to third-party AI providers acting as service providers or subprocessors. Their processing is governed by our arrangements with them, the relevant technical configuration, and applicable law.
Where available and appropriate, we use commercial or API configurations designed to restrict providers from using Client Service Data to train generalized public models.
We may disclose personal information to the following categories of recipients.
Where you interact with a system operated for a client, we disclose the interaction and associated information to that client.
This may include recordings, transcripts, messages, summaries, contact details, appointment information, and communication metadata.
We may use providers for:
These providers may process information only as necessary to perform services for us, subject to their contractual and legal obligations.
When a client connects a CRM, calendar, telephone, messaging, payment, accounting, advertising, review, social-media, or other platform, we disclose information to that platform as directed by the client.
The third party’s own privacy policy applies to its independent processing.
We may disclose information to lawyers, accountants, insurers, auditors, consultants, and other advisers where reasonably necessary.
We may disclose information when we reasonably believe disclosure is necessary to:
Information may be disclosed or transferred in connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction.
We may disclose information when you direct us to do so or provide consent.
As of the Last Updated date:
Certain analytics or advertising technologies may be treated as a “sale,” “sharing,” or targeted advertising under some privacy laws even when no money is exchanged.
If we begin using technologies that trigger an opt-out obligation, we will provide the required notice and opt-out mechanism and update this Policy.
Where legally required and technically applicable, we will process recognized opt-out preference signals, such as Global Privacy Control.
We may use cookies, pixels, local storage, software development kits, and similar technologies.
These technologies may be used for:
You can control cookies through browser settings and any cookie-management tools we make available.
Blocking cookies may affect website functionality.
Browser “Do Not Track” signals are not interpreted consistently across the industry. We respond to legally required preference signals where applicable.
We may send business and marketing communications where permitted by law.
You may unsubscribe from marketing email by using the unsubscribe link or contacting hello@velvy.ai.
You may opt out of SMS marketing by following the instructions in the message, such as replying STOP, where applicable.
We may continue sending non-marketing communications concerning:
Where we send communications for a client, the client is responsible for the recipients, content, consent, and legal basis. We process suppression and opt-out instructions according to the client’s configuration and our agreement.
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including to:
Retention periods vary according to:
Client Service Data is retained according to the applicable agreement, client settings, and lawful instructions.
After termination, Client Service Data may be deleted or returned subject to the applicable agreement. Residual copies may remain temporarily in secure backups until overwritten according to our backup cycle.
We may retain aggregated or de-identified information that does not reasonably identify an individual.
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information.
Depending on the Services, safeguards may include:
No internet transmission, telecommunications network, AI system, cloud service, or storage system can be guaranteed completely secure.
You are responsible for:
Velvy is based in the United States and may use providers operating in the United States and other countries.
Personal information may therefore be transferred to and processed in countries whose privacy laws differ from those of your location.
Where legally required, we use appropriate safeguards for international transfers, which may include:
A client is responsible for determining whether its use of the Services requires additional transfer disclosures, contractual terms, or approvals.
Depending on your location and applicable law, you may have rights to:
These rights are not absolute. Exceptions may apply, including where information must be retained for security, legal compliance, contract performance, freedom of expression, or legal claims.
Submit a request to:
Include sufficient information for us to understand the request and identify the relevant relationship or account.
We may request reasonable verification of identity and authority before responding.
Authorized agents may submit requests where permitted by law. We may require evidence of authorization and direct identity verification.
If your information was collected through a Velvy system operated for one of our clients, submit your request to that client.
Identify the relevant business when contacting us. We may forward the request to the client or tell you how to contact it.
Where applicable law provides an appeal right, you may appeal a denied request by replying to our decision or contacting hello@velvy.ai with the word “Privacy Appeal” in the subject line.
During the preceding 12 months, we may have collected the categories described in Section 2, including:
We collect these categories from the sources described in Section 3, use them for the purposes described in Sections 4 and 6, and disclose them to the categories of recipients described in Section 7.
We retain each category as described in Section 11.
We do not use sensitive personal information to infer characteristics about individuals for unrelated purposes.
We do not offer financial incentives in exchange for personal information unless we provide a separate legally required notice.
Individuals in Australia or New Zealand may request access to or correction of personal information by contacting hello@velvy.ai.
Personal information may be processed in the United States and other countries where our providers operate.
Where we process personal information for an Australian or New Zealand client, that client remains responsible for determining its obligations concerning:
We will provide reasonable assistance consistent with our agreement and applicable law.
Individuals in the European Economic Area or United Kingdom may have the rights described in Section 14.
You may also lodge a complaint with the data-protection authority in the country where you live, work, or believe an infringement occurred.
Where Velvy processes Client Service Data on behalf of a client, the client is responsible for providing the applicable privacy notice and identifying its legal basis.
Where required, Velvy and the client will enter into a Data Processing Agreement addressing processor obligations and international transfers.
Our website and Services are intended for businesses and adults and are not directed to children.
We do not knowingly collect personal information directly from children under 13 for our own purposes.
Clients must not configure the Services to intentionally collect information from children without Velvy’s prior written approval and all legally required notices, consents, and safeguards.
Contact hello@velvy.ai if you believe a child has provided personal information to us improperly.
Our website and Services may link to or integrate with third-party websites and services.
We do not control their independent privacy or security practices.
Review the privacy policies and terms of those third parties before providing information or enabling an integration.
We may update this Privacy Policy to reflect changes in our Services, providers, legal obligations, or practices.
We will publish the updated Policy with a revised Last Updated date.
Where required by law or contract, we will provide additional notice of material changes.
Changes do not retroactively authorize materially different processing where additional consent is legally required.
OpenLegion LLC, doing business as Velvy.ai
30 N Gould St Ste R
Sheridan, WY 82801
United States
Email: hello@velvy.ai
Website: velvy.ai
For privacy requests, use the subject line: Privacy Request.