Privacy

Privacy Policy

Last updated: 2026-08-16

This Privacy Policy explains how Apraiz Europe OÜ ("Veted", "we", "us") collects, uses, shares, and protects personal data when you use Veted.eu, and what you can ask us to do about it.

We are based in the European Union and we write this policy to the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Estonian Personal Data Protection Act, and the EU ePrivacy rules on cookies. Because the site is reachable from the United States, we also give US residents the notice and the rights their state privacy laws provide. Section 15 is written for US residents, and section 16 sets out how we meet the EU AI Act transparency rules for the AI-written summaries on this site.

1. Who we are, and how to reach us

Apraiz Europe OÜ is the data controller for the processing described here, and the "business" for the purposes of US state privacy law.

  • Apraiz Europe OÜ, a private limited company registered in Estonia
  • Peetri 11
  • Tallinn, Estonia, European Union
  • Privacy contact: privacy@veted.eu

We are established inside the EU, so we do not need an Article 27 representative. We are not required to appoint a Data Protection Officer, because our core activity is not large-scale monitoring of individuals or large-scale processing of special-category data. Privacy questions go to the address above and reach a person who can act on them.

2. What this policy covers

It covers Veted.eu and the emails we send. It does not cover the websites of the businesses we list, or Google, or any other third-party site you reach from ours. Those have their own policies.

Most of what Veted publishes is business information, not consumer information. Where a business is a sole trader or a one-person company, that business information is also personal data about a person, and we treat it that way. Section 6 explains this.

3. Personal data we collect from you

  • Account sign-in. If you sign in, you do so with Google. We receive your email address and basic profile information from Google, and we store your email address to link saved listings to you. We never receive or store your Google password.
  • Saved listings. The listings you save, stored against your email address.
  • Email sign-up. Your name, email address, and the country you select, when you submit the sign-up form. The country is the one you tell us, not one we infer from your IP address.
  • Contact form. Your name, email address, subject, and message. This is emailed to our support inbox rather than stored in our database.
  • Business claim requests. If you claim a listing: your full name, your role at the business, email, phone, and optionally VAT number and country, licence number, website, and any notes you add. We check the VAT number against the EU VIES service and record whether the check matched.
  • Contractor applications and questionnaires. Business and contact details, declared years in business, team size, declared licence and insurance information, any documents you upload, dispute process, client references, and any declared licensing violations.
  • Payment data. For paid listings, payment is handled by Stripe. We store the Stripe customer and subscription identifiers and the subscription status. We never see or store your card number.

4. Data we collect automatically

  • Server logs. IP address, user-agent, request path, and timestamp. Kept for 30 days for security, abuse prevention, and debugging.
  • Cookieless analytics (Umami). Page URL, referrer, country, browser, device type, and screen size. No cookies are set and nothing is stored on your device. See section 8.
  • Google Analytics 4. Only if you accept analytics cookies. See section 8.
  • Google Maps. If you open the map view on a directory page, your browser loads Google Maps directly from Google, which means Google receives your IP address and device information. The map is not loaded until you open it.
  • Email open tracking. Emails we send to businesses we have contacted may record whether the email was opened. See section 9.

5. Why we use it, and our legal basis

We only use personal data for these purposes, on these legal bases under GDPR Article 6:

  • Running the directory (publishing listings, search, ranking, review summaries). Legitimate interests, Art. 6(1)(f): operating a useful public directory of businesses. You can object, see section 14.
  • Your account and saved listings. Contract, Art. 6(1)(b).
  • Answering your messages. Legitimate interests, Art. 6(1)(f), or contract where your message concerns a listing you pay for.
  • Processing claim requests and contractor applications (including the VAT check). Steps taken at your request before a contract, Art. 6(1)(b), and our legitimate interest in a directory that is not full of false claims.
  • Paid listings and billing. Contract, Art. 6(1)(b), and legal obligation for accounting and tax records, Art. 6(1)(c).
  • Google Analytics and any other non-essential cookie. Consent, Art. 6(1)(a), and consent under the ePrivacy rules. You can withdraw it at any time.
  • Cookieless analytics. Legitimate interests, Art. 6(1)(f): knowing how many people use the site. No consent is required because nothing is read from or written to your device.
  • Marketing email to businesses. Legitimate interests, Art. 6(1)(f), see section 9.
  • Security, abuse prevention, and debugging. Legitimate interests, Art. 6(1)(f).
  • Meeting our legal obligations. Art. 6(1)(c).

We do not sell personal data, rent it, share it with data brokers, or use it for cross-context behavioural advertising. We run no advertising trackers and no ad network pixels.

We do not process special-category data (GDPR Art. 9) or "sensitive personal information" as US state laws define it, and we do not ask you for any.

6. Business data we collect from other sources (GDPR Art. 14)

Most listings on Veted were not submitted by the business. We build them from public sources. Where that data identifies a person, this section is your Article 14 notice.

What we collect, and where from:

  • Google Places API. Business name, address, phone number, website, opening information, photos, geographic coordinates, aggregate rating, and review count.
  • Public Google reviews, obtained through the Places API and through the SearchApi.io search-results service. This includes the review text, the star rating, the publication date, and the review author's public display name and public profile picture.
  • Business websites. We collect publicly published business contact email addresses from business websites, and record where and when we found each one.
  • The EU VIES service, when a VAT number is submitted with a claim request: the registered name and address held against that VAT number.

Why. To build and keep current a directory of home-services and property businesses, and to contact businesses about their listing. Our legal basis is legitimate interests, Art. 6(1)(f). Who sees it. Listing data and review content are published on Veted.eu and are therefore public. Business email addresses collected from websites are not published.

Why we did not write to you first. Under Art. 14(5)(b) we do not send an individual notice where contacting every business in a directory of this size would involve disproportionate effort. This page is the notice instead, and it is linked from every page of the site.

If you are a business owner or a review author and you want your listing, your review, or your details corrected or removed from Veted, write to privacy@veted.eu. We will action it within 30 days, and usually much sooner. Removing it from Veted does not remove it from Google. To do that, contact Google through your Google Business Profile or through Google's own removal process.

7. Cookies and similar technologies

Veted sets very few cookies, and none for advertising.

Strictly necessary. Set for everyone, no consent required:

  • next-auth.session-token and related NextAuth cookies, to keep you signed in. Session length, removed when you sign out.
  • next-auth.csrf-token, to protect sign-in against cross-site request forgery.

Preference storage. Set for everyone, no consent required:

  • veted-cookie-consent, a browser localStorage entry holding your cookie choice so we do not ask again. Nothing is sent off your device.

Analytics, consent required. Set only after you press Accept:

  • _ga and _ga_*, set by Google Analytics 4, up to 2 years. We turn off Google Signals and ad personalisation, and enable IP anonymisation.

Changing your mind. Use in the footer of any page. Withdrawing is one click, exactly like giving consent, and it takes effect immediately without a page reload. If your browser sends a Global Privacy Control signal we treat that as a rejection automatically and do not show you the banner at all.

8. Analytics

We run two analytics tools, and they are not the same in privacy terms.

  • Umami (cookieless). Runs for every visitor. It sets no cookies, stores nothing on your device, and does not build a cross-site profile of you. Your IP address is used in transit to derive an approximate country and is not retained in identifiable form. This is what we use for the visitor numbers we quote to businesses. Legal basis: legitimate interests.
  • Google Analytics 4. Loads only after you accept analytics cookies, and never before. We configure it with IP anonymisation on, Google Signals off, and ad personalisation off, so the data is not used to target advertising at you. It still involves a transfer to Google, see section 11. Legal basis: your consent.

9. Email we send

  • Service email. Confirmations, verification links for claim requests, billing notices. These are part of the service and you cannot unsubscribe from them while you have an active account or an open request.
  • Sign-up list. If you gave us your email through a sign-up form, we may email you about Veted. Every one of those emails carries a one-click unsubscribe link, and we honour it promptly.
  • Business outreach. We email businesses we have listed, at the business email address published on their own website, about their Veted listing. This is business-to-business contact on the basis of our legitimate interests. We log what we sent, when, and whether it was opened or replied to, so we do not contact the same business twice. Every outreach email includes an unsubscribe link, and replying to ask us to stop is enough. Ask and we will suppress the address.

For US recipients, our commercial email complies with the CAN-SPAM Act: we identify the message as commercial, use accurate headers and subject lines, give a valid postal address, and honour opt-outs within 10 business days. In practice we process them within 72 hours.

10. Who we share data with

We share personal data only with the service providers we need to run Veted. Each acts as our processor under a written data processing agreement, and none of them may use your data for their own purposes.

  • Railway (United States), application hosting and the Postgres database.
  • Resend (United States), transactional and outreach email delivery.
  • Google LLC / Google Ireland Ltd, Places API for business data, Google Maps for the map view, Google Sign-In for authentication, and Google Analytics 4 where you have consented.
  • Umami Software, Inc. (United States), cookieless analytics.
  • Anthropic PBC (United States), AI summarisation and translation. Inputs are public business and review text only. No account data, contact-form message, or payment data is ever sent. Anthropic does not train its models on this data.
  • SearchApi.io, retrieval of public Google review content.
  • Stripe, Inc. (United States, with an Irish entity for EU customers), payment processing for paid listings. Stripe is an independent controller for its own fraud-prevention and regulatory purposes.

We also disclose personal data where the law requires it: to a court, regulator, or law enforcement body acting under a valid legal instrument. If Veted is ever sold or merged, personal data may pass to the buyer, and we will tell you before that happens and before any new use of your data.

11. Sending data outside the EEA

Several of the providers in section 10 are in the United States, so some personal data is transferred there. We rely on the following safeguards under GDPR Chapter V:

  • The European Commission's Standard Contractual Clauses (2021/914) with each US provider, backed by a transfer impact assessment;
  • Where a provider is certified under the EU-US Data Privacy Framework, that adequacy decision as an additional basis. We do not rely on it alone, because it is under legal challenge, so the Clauses stay in place regardless of the outcome;
  • Encryption in transit for all transfers, and access controls limiting who at each provider can reach the data.

You can ask us for a copy of the safeguards that apply to a specific transfer by writing to privacy@veted.eu.

12. How long we keep it

  • Saved listings and your sign-in email. Until you delete them or ask us to close your account.
  • Sign-up list. Until you unsubscribe, then we keep a suppression record so we do not email you again.
  • Contact-form messages. Held in our support mailbox for 12 months.
  • Claim requests. 24 months from the decision, so we can show why a listing was transferred.
  • Contractor accounts and questionnaires. While the listing is live, and 24 months after cancellation.
  • Billing and accounting records. 7 years, as Estonian accounting law requires.
  • Outreach logs. 24 months, then deleted, except for suppression records which we keep so we can honour your opt-out.
  • Server logs. 30 days.
  • Published listing and review data. For as long as the listing is published, or until you ask us to remove it under section 6.
  • Aggregated analytics that identifies no one. Indefinitely.

13. Security

We apply the technical and organisational measures GDPR Art. 32 requires, in proportion to a directory of public business data: TLS encryption for all traffic, encryption at rest for the database, access limited to the small number of people who need it, an administrator allowlist for every privileged area, secrets held outside the codebase, and dependency updates.

No system is perfectly secure. If a breach happens that is likely to put your rights at risk, we will notify the Estonian Data Protection Inspectorate within 72 hours of becoming aware of it, and tell affected individuals without undue delay, as required by GDPR Arts. 33 and 34 and by the US state breach-notification laws that apply.

14. Your rights in the EU, EEA, and UK

Under GDPR Arts. 15 to 22 and the UK GDPR, you have the right to:

  • Know what we hold about you and get a copy of it;
  • Have inaccurate data corrected, and incomplete data completed;
  • Have your data erased, the "right to be forgotten";
  • Restrict how we use it while a dispute is resolved;
  • Object to processing based on legitimate interests, including our publication of business data. You do not have to give a reason to object to direct marketing, and we will stop;
  • Receive the data you gave us in a portable, machine-readable format, and have it sent to another provider;
  • Withdraw consent at any time, without affecting what we did lawfully before you withdrew it;
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you. We make no such decisions, see section 16;
  • Complain to a supervisory authority, see section 17.

To exercise any of these, write to privacy@veted.eu or use the GDPR rights page. We answer within 30 days, and if a request is genuinely complex we may extend by two further months and will tell you why within the first 30 days. It is free. We may ask you for enough information to confirm who you are, and no more.

15. Your rights in the United States

This section applies if you live in a US state with a comprehensive privacy law, including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island. We give these rights to all US residents, whether or not we meet a given statute's revenue or volume threshold.

Notice at collection. In the last 12 months we have collected these categories of personal information, as the California Consumer Privacy Act defines them:

  • Identifiers: name, email address, phone number, postal address, IP address. Sources: you, Google Sign-In, public business websites and listings. Purpose: sections 5 and 6.
  • Commercial information: listings you save, subscription and billing status. Sources: you, Stripe.
  • Internet activity: pages viewed, referrer, browser and device type. Source: automatic collection, section 4.
  • Geolocation: the country you select at sign-up, and an approximate country or city derived from IP address. We do not collect precise geolocation.
  • Professional information: business name, role, licence and insurance declarations, VAT number. Sources: you, public registries.
  • Inferences: none. We build no profiles about individuals.

Retention periods for each are in section 12. Categories disclosed to service providers are in section 10.

We do not sell or share your personal information, and we have not in the preceding 12 months. We do not share it for cross-context behavioural advertising, and we do not use or disclose sensitive personal information for any purpose that would give you a right to limit it. We have never knowingly sold or shared the personal information of anyone under 16.

Your rights. Depending on your state, you can:

  • Confirm whether we process your personal information, and access it;
  • Know the categories we collected, the sources, the purposes, and who we disclosed it to;
  • Get a portable copy;
  • Correct inaccurate personal information;
  • Delete personal information we hold about you;
  • Opt out of sale, sharing, targeted advertising, and profiling with legal or similarly significant effects. We do none of these, so there is nothing to opt out of, but the request will always be honoured;
  • Limit the use of sensitive personal information. We collect none;
  • Not be discriminated against or retaliated against for exercising any of these rights. We will not deny you service, change your price, or degrade what you get.

Global Privacy Control. We honour the GPC browser signal automatically as an opt-out preference signal, as California, Colorado, Connecticut, Texas, and other states require. If your browser sends GPC, we treat analytics consent as refused without asking you.

How to make a request. Email privacy@veted.eu with the state you live in and what you want. We respond within 45 days, and may extend once by a further 45 days where the request is complex, telling you why. We verify your identity by matching the information you give us to what we already hold, and ask for no more than that. An authorised agent may act for you with written permission, and California residents may use a valid power of attorney.

Appeals. If we refuse your request, you may appeal by replying to our decision with the word "appeal" and your reasons. We will answer the appeal within 45 days with a written explanation. If we deny the appeal, you can complain to your state Attorney General, and we will tell you how in that reply. Colorado, Connecticut, Virginia, and several other states give you this right by statute.

California Shine the Light. We disclose no personal information to third parties for their own direct marketing purposes, so there is nothing to report under Cal. Civ. Code § 1798.83.

Nevada. We do not sell covered information as Nevada SB 220 defines it. You may still send an opt-out to the address above and we will record it.

16. Automated decisions and AI (EU AI Act Art. 50)

Veted uses AI in two places, and we want to be plain about both. This is our transparency notice under Article 50 of the EU AI Act (Regulation (EU) 2024/1689), which has applied since 2 August 2026.

  • Review summaries. The summary, the "what people love" and "common complaints" lists, and the scoring bars on a listing are generated by an AI model(Anthropic's Claude) from that business's public reviews. They are AI-written, not written by our staff, and they may contain errors. We do not edit, hide, or invent review content, and the underlying reviews are shown alongside the summary so you can check it yourself. Each summary records the model version and the date it was produced.
  • Translation. Business names and some content on our German-language pages are machine-translated. Translations may be imperfect.

No automated decisions about you. We do not use AI, or any other automated process, to make decisions that produce legal effects on you or similarly significantly affect you, in the sense of GDPR Art. 22. Directory ranking is an algorithm applied to businesses, not a decision about an individual, and claim requests and contractor applications are decided by a person.

We operate no chatbot, no emotion-recognition system, no biometric categorisation, and we publish no deepfakes or synthetic images of real people.

17. Children

Veted is a directory for people hiring trades and property professionals. It is not directed at children, and we do not knowingly collect personal data from anyone under 16 in the EU or under 13 in the United States, as the Children's Online Privacy Protection Act defines it. If you believe a child has given us personal data, write to privacy@veted.eu and we will delete it.

18. Complaints

Please come to us first. If we cannot put it right, our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, AKI):

If you are in another EU or EEA state, you may complain to your own national authority instead. In the UK, that is the Information Commissioner's Office. In the United States, you may complain to your state Attorney General, and California residents may also contact the California Privacy Protection Agency.

19. Changes to this policy

We update this policy when what we do changes. The "Last updated" date at the top always reflects the current version. If a change materially affects your rights or how we use your data, we will say so on the home page for 14 days before it takes effect, and email you where we hold your address and the change requires it.

20. Contact

Any privacy question, request, or complaint: privacy@veted.eu. You can also use the rights request page or the contact form.