Vera is operated by aiwerkers B.V. (trading as ai-werkers), having its registered office in Utrecht, the Netherlands, registered with the Dutch Chamber of Commerce under number 42114106 (RSIN 869793627). Vera helps you schedule meetings with your clients via email. This policy describes what personal data we process, why, how long, and your rights. Questions go to privacy@ai-werkers.nl.
1. Data we process
- Account data. Your name, email, language, timezone, working hours, signature, optional MFA secret.
- Email content Vera handles. Inbound messages you CC Vera on, and Vera's outbound replies. Body content is encrypted at rest (AES-256-GCM) with a per-customer key.
- Google user data — see section 4 for the full breakdown and Limited Use disclosure.
- Technical data. Limited: IP (login + webhook only, for abuse prevention), user-agent, login timestamps, anonymised session cookie. No third-party tracking cookies.
2. Why we use it
- To provide Vera's scheduling functionality.
- Security: abuse detection, rate-limiting, audit log.
- Legal obligations (e.g. tax retention for invoices).
- Not for training generalised AI models (see section 4), and not for advertising or resale.
3. Sub-processors
Vera runs on a small, EU-focused set of sub-processors, each under a signed Data Processing Agreement:
- Railway (US, EU region Frankfurt) — application and database hosting. Encrypted at rest.
- Brevo (France, EU) — inbound and outbound email.
- Mistral AI (France, EU) — LLM classifier and drafter for Vera's replies.
- Mollie (Amsterdam, NL/EU) — billing and payments.
- Google — only when you connect your own Google Calendar. We then talk to Google's Calendar API on your behalf; no data is shared with other Google products.
- Microsoft — only when you connect your own Microsoft 365 or Outlook calendar. We then talk to Microsoft Graph (Calendars.ReadWrite) on your behalf; no data is shared with other Microsoft products.
Demo-only: the "Talk to Vera" page lets you optionally pick OpenAI as an alternative LLM. That demo does not send mail or store data, but the chosen LLM does briefly process your pasted text. The actual production pipeline only uses Mistral; OpenAI never touches real customer data from connected Google/Microsoft accounts.
4. Google user data — Limited Use Disclosure
When you connect your Google account for calendar access, we process the following Google user data:
- OAuth refresh token, encrypted at rest with AES-256-GCM and a key unique to your tenant.
- Email and name from your Google profile (to show which Google account is connected).
- Free/busy information from your primary calendar — to propose slots that match your availability.
- Event metadata only for events Vera itself created (title, time, attendees). We do not read events created by others beyond what's needed for the free/busy check.
Limited Use: Vera's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data exclusively to provide the scheduling functionality you requested.
- We do not transfer Google user data to others except as necessary to provide the service, comply with applicable law, or as part of a merger / acquisition with adequate safeguards.
- We do not use Google user data to develop, improve, or train generalised AI or machine-learning models. The LLM (Mistral) that drafts Vera's replies receives only the immediate email context for that specific reply and retains no data across sessions.
- We do not allow humans to read Google user data unless: (a) we have your explicit consent; (b) it's necessary for security-incident investigations that we're legally required to perform; (c) we must comply with applicable law; or (d) the data is aggregated/ anonymised and used for internal operations strictly necessary for service delivery.
5. Retention
- Account data: while your account is active and for 30 days after cancellation. Then permanently deleted, except items we're legally required to retain (e.g. invoicing, 7 years).
- Email content and threads: 90-day rolling window; older threads auto-deleted unless you choose a longer retention window in preferences.
- Google OAuth refresh token: until you click "Disconnect calendar" in the dashboard, or revoke access via myaccount.google.com/permissions.
- Technical logs: 30 days, then auto-purged.
- Audit log: 12 months, then aggregated for metrics and individual entries deleted.
6. Security
- EU data centres (Frankfurt).
- Encryption at rest with AES-256-GCM.
- Envelope encryption: one master key (KEK) wraps a per-tenant data key (DEK). Compromising one tenant does not impact others.
- MFA mandatory for production accounts.
- HTTPS-only, HSTS, secure + httpOnly + SameSite cookies.
- Staff access is need-to-know and logged in our audit trail.
7. Your rights (GDPR)
As a data subject you have the right to:
- Know what data we hold (access).
- Correct inaccurate data.
- Delete your data (right to erasure) — available directly via the "Delete account" button in your dashboard, or by emailing privacy@ai-werkers.nl.
- Restrict processing or withdraw consent.
- Receive your data in a portable format.
- Object to specific processing.
- File a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl).
8. GDPR roles
For processing your customers' email content, you are the controller and we are the processor. At signup you sign a Data Processing Agreement (DPA) with us. For our own account administration we are the controller.
9. Cookies
We use only functional cookies (session, theme, cookie-consent itself) and anonymised Google Analytics 4 — only after you explicitly accept the cookie banner. No advertising cookies, no tracking pixels, no Facebook cookies.
10. Changes
Material changes to this policy are announced to active users by email and a dashboard banner, at least 14 days before they take effect.
Contact
Questions, data-breach reports, or access requests? privacy@ai-werkers.nl. We respond within 48 hours on business days.