Privacy policy
Last updated 2 September 2026
What we collect, why we collect it, who else sees it, how long we keep it, and how to make us stop. Written to be read rather than to be survived.
The short version. We collect what you send us — your name, your email, what you asked for — and what our server needs to log to stay up. We do not use advertising cookies, we do not track you across other websites, we do not sell or rent your data to anybody, and we never will. You can have a copy of everything we hold, or have it deleted, by writing one email.
1. Who is responsible
Vesopa Software Ltd is the data controller for the personal data described in this policy. We are registered in England and Wales under company number 17362206, at Baglan, Port Talbot, SA12 7AX, Wales, United Kingdom.
For anything about your data, write to support@vesopasoftware.com or support@vesopasoftware.com. Both reach a person.
Where we build or host a system for a client, personal data belonging to their customers is processed by us as a processor on that client's instructions; the client is the controller and their own privacy policy applies to it.
2. What we collect
Your name, email address, and optionally your phone number and company name, when you request an estimate, send an enquiry, contact support, or create a portal account.
The content of what you write to us, including messages, project files and attachments you upload.
Billing details — company name, billing address, VAT and company numbers — where you are invoiced.
Inside the portal: projects, tasks, messages, files, invoices, receipts and the record of what changed and when.
Standard server logs — IP address, date and time, the page or endpoint requested, the response, your browser's user-agent string. These are what tell us the site is up and let us investigate abuse.
One strictly necessary cookie, and the size you last dragged the AI panel to, which is stored in your own browser. See the cookie policy.
We do not collect special category data (health, biometrics, beliefs, and so on), we do not build advertising profiles, we do not use tracking pixels or third-party analytics, and we do not take card or bank details through this website.
3. Why, and on what legal basis
To reply to an enquiry, quote or support request. Legitimate interests — you asked us a question and expect an answer — or steps prior to a contract where you are asking us to price work.
To run your account, your projects and your support. Performance of a contract.
To issue invoices, record payments and keep accounts. Contract, and legal obligation for the accounting records themselves.
Logging, backups, rate limiting, and investigating abuse. Legitimate interests in a secure, available service.
Service messages about your own account are part of the contract. Marketing email is sent only with your consent, and every one carries an unsubscribe link that works.
Where the law requires us to keep or disclose something. Legal obligation.
Where we rely on legitimate interests, we have weighed them against your rights and concluded they do not override them. You can object at any time — see your rights.
4. Data in the Vesopa applications
Vesopa EPOS, Vesopa Kitchen and Vesopa Customer Display run on the venue's own devices and hold the venue's own trading data — products, prices, orders, staff logins, takings. That data belongs to the venue. Where the venue uses our hosted back office, it is stored on our servers on the venue's behalf and we act as their processor.
The applications do not require an end customer of the venue to identify themselves, and they do not collect data from the diner or shopper beyond what the venue itself enters into an order.
The applications do not contain advertising SDKs and do not share data with advertising networks.
5. The AI assistant
The assistant on our website answers questions about Vesopa. What you type into it is sent to our server and from there to Microsoft Azure AI Foundry, which runs the model that produces the answer. Your message and the answer are processed to generate that answer.
The assistant is anonymous: it does not require an account and we do not attach your identity to what you type. Please do not paste passwords, card numbers or anybody else's personal data into it.
6. Who else sees it
We do not sell, rent or trade personal data. We share it only with the service providers we need in order to operate, each under a contract that limits them to our instructions:
Google Cloud Platform — our servers and databases, in the United States.
SMTP2GO — delivers the mail we send you.
Microsoft Azure AI Foundry — processes assistant conversations only.
Google Fonts serves the typefaces on this site. Your browser requests them directly, which discloses your IP address to Google. No cookie is set by that request.
Microsoft, where you install an application through the Microsoft Store. Your relationship for that download is with them and their privacy notice covers it.
Our accountants and, if ever needed, our lawyers and insurers.
Where the law compels us. We will tell you unless we are prohibited from doing so.
If our business is ever sold or reorganised, personal data may transfer as part of it. You would be told, and this policy would continue to apply until you were given a new one.
7. International transfers
Some of the providers above process data outside the UK, principally in the United States. Where that happens we rely on the UK International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, or on UK adequacy regulations where they apply, together with the technical measures described below. You can ask us for details of the safeguards used for any particular transfer.
8. How long we keep it
24 months from your last contact, then deleted — unless they turned into a project.
For as long as the account is open, and 12 months after it closes.
Six years from the end of the financial year they fall in. This one is not our choice: UK tax law requires it, and it survives a deletion request.
24 months — it is how we prove a message was or was not delivered.
90 days, then rotated away.
Up to 35 days. Deleted data disappears from backups as they age out.
9. How we protect it
- Everything is served over HTTPS, and HTTP is redirected to it.
- Passwords are stored only as salted hashes; nobody at Vesopa can read yours.
- Session cookies are
HttpOnly,SecureandSameSite=Lax, and every state-changing form carries a CSRF token. - Public submission endpoints are rate limited.
- Access to the production server and database is restricted to the people who need it.
- Backups are taken regularly and their restoration is tested.
No system is perfectly secure. If a breach ever puts your rights at risk we will tell the Information Commissioner within 72 hours and tell you without undue delay.
10. Your rights
Under the UK GDPR you have the right to:
- Access — a copy of the personal data we hold about you;
- Rectification — have inaccurate data corrected;
- Erasure — have data deleted, where no legal obligation makes us keep it;
- Restriction — have us pause processing while a dispute is resolved;
- Portability — receive the data you gave us in a machine-readable form;
- Object — to processing based on legitimate interests, and absolutely to direct marketing;
- Withdraw consent — at any time, without affecting what was done before you withdrew it.
Write to support@vesopasoftware.com, or use the data request form. We answer within one month and it costs nothing. We will ask you to confirm the request from the email address concerned, which is an identity check rather than an obstacle.
11. Deleting your data
There is a page for exactly this: what deletion means, what survives it and why, with a form at /delete-my-data.
12. Cookies
This site sets one strictly necessary cookie and uses no analytics, advertising or tracking cookies at all. The detail is on the cookie policy.
13. Children
Our services are for businesses. They are not directed at children and we do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, write to support@vesopasoftware.com and we will delete it.
14. Changes
We may update this policy. The date at the top is always the current version. Where a change materially affects how we use your data, we will tell you by email or in your portal before it takes effect.
15. Complaints
Please come to us first — most things are a misunderstanding we can fix the same day. If you are still unhappy, you can complain to the UK's supervisory authority:
Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF · 0303 123 1113 · ico.org.uk/make-a-complaint
Vesopa Software Ltd, Baglan, Port Talbot, SA12 7AX, Wales, United Kingdom · Company number 17362206