Skip to Content

Privacy Policy

How Veya collects, uses, and protects your data — including the Google account data behind calendar sync. Written to be read, not just agreed to.

  • Effective: July 28, 2026
  • Applies to: Veya app & Google Calendar sync
  • Contact: admin@veya.com.my

Contents

  1. Overview
  2. Information we collect
  3. How we use your data
  4. Google user data
  5. How we protect your data
  6. Third-party sharing
  7. Your rights
  8. Cookies & tracking
  9. Changes to this policy
  10. Contact

1. Overview

This Privacy Policy explains what data Veya collects, how we use it, and how we keep it safe when you use our platform. It applies to the Veya application and to any Google account data used by our Google Calendar integration. Where a section concerns data obtained from Google APIs, the additional terms in “Google user data” below take precedence.

2. Information we collect

We collect information you provide directly — such as your name, email, and organization details when you sign up — along with data you create while using the product, and standard technical information (device, browser, and usage events) needed to operate and secure the service.

3. How we use your data

We use your data to provide, secure, personalize, and improve the product: to run the features you use, keep your account safe, respond to support requests, and understand how the platform is used so we can make it better. These uses apply only to data you provide directly and to product usage data — they do not extend to Google user data, which is used exclusively as described in the “Google user data” section below.

4. Google user data

The following disclosures apply specifically to data accessed through Google APIs when you connect your Google account to enable calendar synchronization.

Google Calendar API — data handling

Access

If you choose to connect your Google account, we access your Google Calendar data through the Google Calendar API: the list of calendars in your account (read-only) and the events in the calendar you select to sync — including event titles, descriptions, dates and times, and attendees (view, create, edit, and delete). We access this data only after you explicitly authorize it, and only for the calendar you choose.

Use

We use this data solely to provide and improve the user-facing calendar-sync feature you requested: displaying your Google Calendar events inside our application and keeping events in two-way sync between Google Calendar and our application. We do not use Google user data for any other purpose. It is never used for advertising (including personalized, retargeted, or interest-based advertising), marketing, or profiling; it is never sold or transferred to data brokers or information resellers; and it is never used to determine credit-worthiness or for lending purposes.

AI / ML

Google user data is NOT used to develop, improve, or train any generalized artificial-intelligence or machine-learning models. Google Calendar data is never fed into AI/ML training pipelines and is not transferred to any third-party AI/ML service. Any AI features in our application run on pre-trained models that do not learn from or incorporate your Google Calendar data. Our AI features are provided by Google (Gemini), OpenAI, and Anthropic, and are used only for features you actively invoke — such as document processing and in-app assistance — on data you supply for that purpose. Google Calendar data is not sent to any of these providers. Where we use these providers, we do so on an inference-only basis under terms that prohibit the use of our data for training their models.

Sharing

We do not sell your Google user data and do not share it with third parties, including data brokers, advertisers, or third-party AI/ML services. Google data is not transferred to any party except as strictly necessary to operate the calendar-sync feature you enabled.

Protection

Google OAuth access and refresh tokens are encrypted at rest, transmitted only over secure HTTPS/TLS connections, and access is restricted to your own authenticated account.

Retention

We retain Google data only while your account is connected. When you disconnect your Google account or delete your account, the stored Google tokens and synced Google Calendar data are deleted. You may also revoke our access at any time from your Google Account settings at myaccount.google.com/permissions.

Limited Use commitment

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

5. How we protect your data

We apply administrative and technical safeguards to protect your information, including encryption of sensitive credentials at rest, encrypted (HTTPS/TLS) transport, and access controls that restrict data to your own authenticated account and authorized team members.

6. Third-party sharing

We share data only with trusted service providers that help us operate the platform — for example payment processing, email delivery, and analytics — under agreements that require them to protect your data and use it only for the services they provide to us. We do not sell your personal data. Google user data is never shared with these providers: it is not sent to payment, analytics, advertising, or AI/ML services, and is disclosed to no one except as strictly necessary to operate the calendar-sync feature you enabled.

7. Your rights

You can access, update, export, or delete your personal data at any time from your account, and you can opt out of marketing communications. To exercise any of these rights, contact us using the details below.

8. Cookies & tracking

We use cookies and similar technologies to keep you signed in, remember your preferences, and understand usage patterns so we can improve the product. You can control cookies through your browser settings.

9. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes we will update the effective date above and, where appropriate, notify you. Continued use of the platform after an update constitutes acceptance of the revised policy.

10. Contact

Questions about this policy or your data? Reach us and we’ll help.

admin@veya.com.my