Velora

Privacy Policy

Last updated: October 3, 2026

This Privacy Policy explains how Velora Health S.L. (“Velora”, “we”) handles personal data in the Velora bed-exit monitoring and on-call escalation service: the web dashboard, the Velora On-Call mobile app, the bed sensors and the alerts they trigger.

It provides the information required by Articles 13 and 14 of the EU General Data Protection Regulation (GDPR) and by the Spanish Organic Law 3/2018 on Data Protection and Guarantee of Digital Rights (LOPDGDD).

1. Who is responsible for your data

Velora is used by care facilities such as nursing homes, hospitals and similar organisations (“customers”). Who decides what happens to your data depends on which data it is:

  • Data about residents and patients, and about the facility’s staff as they use the service, is processed on behalf of the customer. The customer is the data controller and we act as its data processor under Article 28 GDPR, bound by a data processing agreement (DPA). We only process that data on the customer’s documented instructions.
  • Data we need to run our own business, such as securing accounts, keeping the service working, answering support requests and managing our contract with the customer, is processed by Velora Health S.L. as data controller.

Controller: Velora Health S.L., tax ID B00000000, Barcelona, Spain. Privacy contact: privacy@velora.health.

If you are a resident, patient or family member, the facility that cares for you is your first point of contact. If you write to us instead, we will pass your request to the facility and help it answer.

2. What data we process

Depending on how you use Velora, we process:

  • Staff account data: name, email address, phone number (only once you have verified it), role and organisation membership, language and time zone, password (stored only as a salted hash) and two-factor authentication settings.
  • On-call data: shift schedules, escalation policies, notification preferences, and the record of who was alerted, through which channel, and who acknowledged or resolved each alert.
  • Resident and patient data entered by the facility: name, weight, free-text care notes, admission and discharge dates, and the assigned bed and room.
  • Sensor data: bed occupancy and bed-exit events measured by the Velora sensor, the alerts they generate, and the technical status of the device (identifier, connectivity and firmware version).
  • Mobile app data: a push notification token, the device model, operating system version and app version.
  • Technical and security data: IP address, browser type, timestamps of sign-ins and requests, and error logs.

We do not collect data for advertising, we do not sell personal data, and we do not use resident or patient data to train artificial intelligence models.

3. Why we process it and on what legal basis

As processor, we process customer data only to provide the service the customer has contracted: monitoring beds, raising alerts, escalating them to on-call staff by push notification, SMS or phone call, and keeping the alert history the facility needs.

As controller, we process data for these purposes:

  • To create and manage your account, authenticate you and provide the service: performance of the contract with you or with your organisation (Article 6(1)(b) GDPR).
  • To send service messages such as invitations, verification codes, password resets and important notices about the service: performance of the contract (Article 6(1)(b)).
  • To keep the service secure, detect abuse, investigate incidents and keep audit logs: our legitimate interest in protecting the service, its users and the people it monitors (Article 6(1)(f)).
  • To answer support requests and manage our relationship with customers: performance of the contract and our legitimate interest (Articles 6(1)(b) and 6(1)(f)).
  • To improve the reliability of the service using aggregated, de-identified usage and performance metrics: our legitimate interest (Article 6(1)(f)).
  • To meet legal, tax and accounting obligations and respond to lawful requests from authorities: legal obligation (Article 6(1)(c)).

Where we rely on legitimate interest, we have weighed it against your rights and freedoms, and you can object at any time (see “Your rights”).

4. Health data

Bed occupancy, bed-exit alerts and care notes can reveal information about a person’s health, a special category of data under Article 9 GDPR. The customer, as controller, processes it to provide health or social care (Article 9(2)(h) GDPR) and, where applicable, to protect the vital interests of a person who cannot give consent (Article 9(2)(c)), through professionals bound by a duty of confidentiality.

We apply additional safeguards to this data: it is visible only to facility staff whose role requires it, it is never used for any purpose other than delivering the service, alerts are only sent to phone numbers their owner has verified, and alert messages carry only what staff need to respond.

5. Who we share data with

We share personal data only with the service providers (sub-processors) we need to run Velora, each bound by a data processing agreement and confidentiality obligations:

  • Amazon Web Services (AWS): hosting, databases, sensor connectivity and logs, in the European Union (Frankfurt, Germany).
  • Twilio: delivery of the SMS messages and phone calls used to escalate alerts.
  • Resend: delivery of transactional emails such as invitations and password resets.
  • Expo (650 Industries), Apple and Google: delivery of push notifications to the mobile app.

Within the customer’s organisation, data is visible to users according to the roles and permissions the customer assigns. We may also disclose data when required by law, to a court or competent authority, or to protect the vital interests of a person. An up-to-date list of sub-processors is available on request at privacy@velora.health.

6. International transfers

Our infrastructure, including every database, is hosted in the European Union (AWS, Frankfurt region). Some of the providers listed above, namely Twilio, Resend, Expo, Apple and Google, may process limited data in the United States or other countries outside the European Economic Area: a phone number, an email address or a notification token, and the message being delivered.

Those transfers are covered by a European Commission adequacy decision, such as the EU–US Data Privacy Framework for certified providers, or by the Commission’s Standard Contractual Clauses with supplementary measures where needed. You can request a copy of the relevant safeguards at privacy@velora.health.

7. How long we keep data

We keep personal data only as long as necessary for the purposes described:

  • Raw sensor readings: 90 days, after which they are deleted automatically.
  • Alerts and their escalation history: for the duration of the customer’s contract, because they form part of the facility’s care and incident records. The customer can ask for earlier deletion.
  • Resident and patient records: until the customer deletes them, or until the end of the contract.
  • Staff accounts: while the account is active. When a user is removed or the account is deleted, the data is deleted or anonymised, except for the audit records the customer needs to keep.
  • Security and technical logs: up to 12 months.
  • Invoicing and contractual records: for the periods required by tax and commercial law (generally six years in Spain).

When a contract ends, we return or delete the customer’s data as set out in the DPA, normally within 90 days. Backups are overwritten on a rolling basis and expire within 35 days.

8. How we protect data

We apply technical and organisational measures appropriate to the sensitivity of the data, including:

  • Encryption in transit (TLS) and at rest.
  • Hosting in the European Union, in ISO 27001-certified data centres.
  • Role-based access control, so each person sees only what their role requires.
  • Passwords stored as salted hashes, and two-factor authentication.
  • Verification of phone numbers before they can receive alerts.
  • Logging of access and changes, and restricted, audited administrative access for our own staff.

If a personal data breach occurs, we notify the customer without undue delay so it can meet its obligations. Where we are controller, we notify the competent supervisory authority within 72 hours, and the people affected when the law requires it.

9. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Rectify data that is inaccurate or incomplete.
  • Erase your data when it is no longer needed or was processed unlawfully.
  • Restrict processing in certain circumstances.
  • Data portability: receive the data you provided in a structured, machine-readable format, or have it sent to another controller.
  • Object to processing based on our legitimate interest.
  • Withdraw your consent at any time where processing is based on consent, without affecting processing carried out before.

To exercise these rights, write to privacy@velora.health. We answer within one month, which may be extended by two further months for complex requests, and we may ask you to confirm your identity. If the request concerns data we process on behalf of a care facility, we will forward it to the facility and help it respond.

You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU country where you live or work. In Spain this is the Agencia Española de Protección de Datos (https://www.aepd.es).

10. Cookies

Velora uses only cookies that are strictly necessary for the service to work, which do not require consent:

  • session: indicates that you are signed in.
  • org-id and selected-organization: remember which organisation you are working in.
  • locale: remembers the language you chose.

We do not use analytics, advertising or third-party tracking cookies. If we ever introduce non-essential cookies, we will ask for your consent first.

11. The mobile app

The Velora On-Call app asks for these permissions, which you can change at any time in your device settings:

  • Notifications: to deliver alerts and on-call reminders. Without this permission you will not receive push alerts.
  • Contacts (optional): to save Velora’s caller numbers to your address book, so alert calls are recognised and can get through Do Not Disturb. The app reads your address book only on the device, to avoid duplicating those entries, and never uploads or stores your contacts on our servers.

Sign-in tokens are kept in the device’s secure storage. When you sign out, the app stops receiving alerts for that facility.

12. Automated decisions

Velora generates alerts automatically from sensor readings and escalates them according to rules set by the facility. These alerts support care staff; they are not decisions with legal or similarly significant effects within the meaning of Article 22 GDPR, and we do not carry out profiling.

13. Children

Accounts are intended for professionals and are not offered to children. A facility may monitor residents or patients who are minors; in that case it processes their data under its own legal basis and responsibility, and we process it only on its instructions.

14. Changes to this policy

We may update this policy to reflect changes in the service or the law. The date of the current version appears at the top of this page and, when changes are significant, we will tell customers and users by email or in the app before they take effect.

15. Contact

For any question about this policy or how we handle personal data, contact us at privacy@velora.health or write to Velora Health S.L., Barcelona, Spain.