Velora Connect

Privacy Policy

Last updated: 25 September 2026

Publisher: Velora IT Solutions (Pvt) Ltd (Reg. No PV 00348345), D3/4, Naranwatta, Atale, Sri Lanka.

1. Who we are

Velora Connect is a software service provided by Velora IT Solutions (Pvt) Ltd, a company registered in Sri Lanka (Reg. No PV 00348345), D3/4, Naranwatta, Atale, Sri Lanka. This policy explains what personal data we collect when you or your customers interact with Velora Connect, why we collect it, and what rights you have.

2. Scope

This policy applies to the veloraconnect.lk website, the Velora Connect client dashboard (app.veloraconnect.lk), and the Velora Connect service that integrates with the WhatsApp Cloud API on behalf of businesses ("Merchants") who have signed up. Where a Merchant uses Velora Connect to communicate with their own customers ("End Users"), the Merchant is the data controller for those messages and Velora Connect is a data processor.

3. Data we collect

From Merchants: business name, category, address, contact details, tax/registration numbers where provided, login credentials (hashed passwords), WhatsApp Business Account (WABA) ID and phone number IDs, encrypted access tokens, product and delivery information, staff user accounts and roles, payment records (bank slip images, PayHere reference numbers), and usage logs.

From End Users (via the Merchant's WhatsApp number): WhatsApp phone number (WA ID), display name, message content and media the End User sends, delivery address and city if the End User provides them to place an order, and any tags or notes the Merchant's staff attach to that contact.

Automatically: browser, IP address, referrer and pages visited on veloraconnect.lk for analytics and security. We do not use invasive tracking on the marketing site.

4. Why we process this data

  • To operate the service — deliver, receive, store and reply to WhatsApp messages on behalf of the Merchant.
  • To generate AI-drafted replies using a third-party language model (currently Google Gemini). We send message content and business profile context to the provider strictly to produce the reply. The provider is accessed through a paid API tier and does not use our request data to train its models.
  • To integrate with the Merchant's VeloraOMS instance (bundle plans) — checking stock, creating orders, updating order statuses.
  • To bill and invoice the Merchant, and to detect fraud and abuse.
  • To improve service quality, monitor error rates, and comply with our legal obligations.

5. Legal basis and PDPA compliance

Our lawful bases are contract (with Merchants), legitimate interest (fraud prevention, service security), and consent (marketing communications, optional analytics). Merchants are responsible for having their own lawful basis for messaging End Users through Velora Connect and for complying with WhatsApp Business Messaging Policy.

Velora Connect complies with Sri Lanka's Personal Data Protection Act, No. 9 of 2022. We act as a data controller for Merchant account information and as a data processor for End User messages Merchants send or receive through the platform. You may exercise your rights under the Act by contacting us at the address in section 12.

6. Third parties we use

  • Meta Platforms, Inc. and its affiliates — WhatsApp Cloud API for message delivery.
  • Google LLC — Gemini language model for generating AI replies (paid API tier; provider does not use our request data to train its models).
  • PayHere (LankaClear (Pvt) Ltd) — for card payments where selected.
  • Cloud hosting — servers located in Singapore.

We do not sell personal data. We do not share data with third parties for their own marketing.

7. Retention

We retain Merchant account data for the life of the subscription plus 12 months. Message content is retained for as long as the Merchant keeps their account, unless the Merchant deletes a conversation. Billing records are retained for 7 years to comply with tax regulations. On request, we will delete personal data of an End User from a specific Merchant's records within 30 days — see our Data Deletion page.

8. Security

Access tokens and API keys are encrypted at rest using AES-256-GCM. Passwords are hashed with bcrypt. All web traffic is served over HTTPS. Access to production systems is restricted to a small number of authorised engineers, all actions are audited, and administrator accounts require two-factor authentication.

9. Your rights

Depending on your jurisdiction you may have the right to access, correct, delete or export your personal data, to object to certain processing, or to lodge a complaint with a data protection authority. Contact us at info@veloraconnect.lk to exercise these rights.

10. Children

Velora Connect is not directed to children under 16. We do not knowingly collect data from children.

11. Changes

We may update this policy. Material changes will be announced in the client dashboard at least 14 days in advance.

12. Contact

Velora IT Solutions (Pvt) Ltd, D3/4, Naranwatta, Atale, Sri Lanka. Email: info@veloraconnect.lk. Phone: 074 084 3090.