STRATENITY INC.

A Corporation Duly Incorporated in the State of Delaware Business License No. 2026703889 · Active 2810 N Church St, Wilmington, DE 19802-4447


VELORSTRATEGY PRIVACY POLICY How Stratenity Inc. collects, uses, and protects personal data for the VelorStrategy Workspace · Effective May 29, 2026 · Google integration disclosures added 16 July 2026


AT-A-GLANCE

WhatHow we handle it
Who controls your dataStratenity Inc. (operator of VelorStrategy)
What we collectAccount info, billing data, usage/analytics
What we do NOT doSell your data · use it to train AI (see below)
Google Calendar dataUsed only for calendar features · never sold, shared, or used to train AI (Limited Use)
Legal bases (EEA/UK)Contract performance (Art. 6(1)(b)) + legitimate interest (Art. 6(1)(f))
RetentionWhile your account is active + a reasonable period after, or as law requires
Your rightsAccess, correction, deletion, portability, objection (where applicable)
Contactadvisory@velorstrategy.com

This Privacy Policy explains how Stratenity Inc. ("Stratenity," "we," "us") collects, uses, and protects personal data in connection with the VelorStrategy Workspace (the "Service"), operated at velorstrategy.com. VelorStrategy is a product of Stratenity Inc. This Policy is incorporated into the Stratenity Master Subscription Terms of Service.

1. WHAT WE COLLECT

(a) Account data. Your name (if provided), email address, password (stored hashed), and account settings.

(b) Billing data. Subscription tier, billing history, and payment-method tokens. Card details are handled by our payment processor, Stripe Payments, Inc.; we do not store full card numbers.

(c) Usage and analytics data. Information about how you access and use the Service — log data, device and browser information, IP address, feature usage, and timestamps.

(d) Communications. Messages you send to us (e.g., support requests).

We do not intentionally collect special-category personal data (such as health, biometric, or political data) through the Service in v1.0.

2. HOW WE USE IT

We use personal data to:

(a) provide, operate, and maintain the Service;

(b) process subscriptions, billing, and payments;

(c) communicate with you about your account, security, and service changes;

(d) provide support;

(e) monitor, secure, and improve the Service; and

(f) comply with legal obligations.

3. WHAT WE DO NOT DO

(a) We do not sell your personal data.

(b) We do not use your data to train AI. Consistent with the Stratenity AI Training Non-Use Representation (Master Terms §9), we do not use your data or deliverables furnished to you to train, fine-tune, evaluate, or improve any AI system, except for fully de-identified aggregated metadata used solely for service operations and security, or as you expressly authorize in writing.

(c) We do not share your data for others' marketing.

4. LEGAL BASES (EEA / UK SUBSCRIBERS)

Where the EU or UK GDPR applies, we process personal data on the bases of: performance of our contract with you (Article 6(1)(b)) for account, billing, and core service operation; and our legitimate interests (Article 6(1)(f)) in securing, maintaining, and improving the Service, where those interests are not overridden by your rights. Where required, we rely on your consent (Article 6(1)(a)), which you may withdraw at any time.

5. SHARING & PROCESSORS

We share personal data only with service providers that process it on our behalf under contract, including: Stripe Payments, Inc. (payment processing), and our hosting and infrastructure providers. We may disclose data where required by law or to protect our rights.

6. GOOGLE CALENDAR & GOOGLE API SERVICES USER DATA

Applies to the VelorStrategy Sales Desk (sales.velorstrategy.com).

Connecting Google Calendar is optional and is started only by you, in the Sales Desk under Settings → Calendar. When you connect, you authorize the Service to use a single Google OAuth scope, https://www.googleapis.com/auth/calendar.events, used only for the two features below:

What we accessGoogle scopeWhy
Create events on your primary Google Calendarcalendar.eventsWhen you schedule a meeting from a follow-up, we add the matching event to your calendar.
Read your upcoming primary-calendar events (about the next 30 days)calendar.eventsTo show your upcoming meetings in the Sales Desk and let you anchor a follow-up to a real meeting.

We request calendar.events because it is the narrowest single scope that supports both creating and reading events; we do not request read-only or full-account calendar scopes.

How this data is stored and shared

We store your Google OAuth tokens so the connection persists; tokens are held per user, protected by row-level security, and used only to call the Google Calendar API on your behalf. We read your upcoming events live to display them and do not build a durable copy of your calendar. Your Google Calendar data is never sold, is never used to train, fine-tune, or evaluate any AI model, and is never sent to our AI provider. You can disconnect at any time in Settings → Calendar (which deletes your stored tokens), or revoke access at myaccount.google.com/permissions.

Limited Use. VelorStrategy’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide and improve the user-facing calendar features described above; is not transferred to others except as necessary to provide those features, to comply with applicable law, or in connection with a merger or acquisition; is not used for advertising; and is not read by humans except with your affirmative consent, for security or to comply with law, or in de-identified/aggregated form for internal operations, as permitted by the policy.

7. RETENTION

We retain personal data while your account is active and for a commercially reasonable period afterward, then delete or anonymize it, except where longer retention is required by law (for example, tax and accounting records).

8. SECURITY

We use commercially reasonable administrative, technical, and organizational measures to protect personal data. No system is perfectly secure; we cannot guarantee absolute security.

9. YOUR RIGHTS

Depending on your location, you may have the right to access, correct, delete, port, or restrict processing of your personal data, and to object to certain processing. California residents have rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of "sale"/"sharing" (we do not sell or share for cross-context behavioral advertising). EEA/UK residents have rights under the GDPR. To exercise any right, contact advisory@velorstrategy.com. We will respond within the timeframe required by applicable law.

10. COOKIES

The Service uses cookies and similar technologies necessary to operate the Service and to understand usage. See our Cookie Policy for details. Where required, we obtain consent for non-essential cookies.

11. INTERNATIONAL TRANSFERS

We are based in the United States. If you access the Service from outside the U.S., your data may be transferred to and processed in the U.S. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) for international transfers.

12. CHANGES

We may update this Policy by posting a revised version with a new effective date. Material changes will be communicated to active Subscribers.

13. CONTACT

Stratenity Inc., 2810 N Church St, Wilmington, DE 19802-4447 · advisory@velorstrategy.com