Privacy Policy
Last updated: 5 August 2026Veloro ("Veloro", "we", "us") is an email marketing agency based in Zagreb, Croatia, providing Klaviyo email marketing services to e-commerce businesses. This policy explains how we handle personal data in two situations: when you visit this website or contact us, and when we process subscriber data on behalf of our clients.
1. Who we are
Veloro is operated by its founder, Marko, in Zagreb, Croatia. For any privacy question or request, contact us at [email protected].
2. Data we collect from website visitors
This website is intentionally simple. We collect:
- Contact data you send us. If you email us, we receive your name, email address, and whatever you include in your message. We use it only to reply and to discuss working together.
- Basic technical data. Our hosting provider may log standard technical information (such as IP address, browser type, and pages visited) for security and to keep the site running.
We do not run advertising trackers on this site, and we do not sell or rent personal data to anyone.
3. Subscriber data we process for clients
When we manage email marketing for a client, we work inside the client's own Klaviyo account with subscriber data that the client has collected. In legal terms, the client is the data controller of its subscriber list, and Veloro acts as a data processor, handling that data only on the client's instructions.
In this role:
- We work only with subscriber lists that clients own and have collected with the subscribers' explicit, verifiable consent (for example, through signup forms or checkout opt-ins on the client's store).
- We never accept, upload, or send to purchased, rented, scraped, or otherwise third-party contact lists, and we do not send cold or unsolicited email.
- We use subscriber data solely to plan, build, and send the client's email marketing (segmentation, flows, and campaigns) and to report on results.
- We honor unsubscribes, bounces, and spam complaints immediately, and maintain the client's suppression lists — including importing suppression lists when a client migrates from another email platform.
- We do not copy subscriber data out of the client's Klaviyo account except where strictly needed to perform the agreed services, and we delete any working copies when an engagement ends.
Subscribers who have questions about a specific brand's emails should contact that brand directly, since it controls the list. If a subscriber contacts us instead, we will forward the request to the relevant client and support them in resolving it.
4. Legal bases (GDPR)
Veloro is based in the European Union and complies with the General Data Protection Regulation (GDPR). We rely on the following legal bases:
- Legitimate interest — responding to business inquiries and operating this website securely.
- Contract — processing needed to deliver services to our clients.
- Consent — email marketing to subscribers is always based on the consent those subscribers gave to our client, which can be withdrawn at any time via the unsubscribe link in every email.
5. Where data is stored and shared
Client subscriber data lives in the client's Klaviyo account and is subject to Klaviyo's own privacy terms. We share personal data only with service providers necessary to run our business (such as email and hosting providers), and never for their own marketing purposes. Where data is transferred outside the EU (for example, to Klaviyo's US infrastructure), transfers rely on recognized safeguards such as Standard Contractual Clauses.
6. Retention
- Business correspondence is kept for as long as needed to manage our relationship and meet legal obligations.
- Client subscriber data is retained by the client in its own Klaviyo account; we hold no independent copy after an engagement ends.
7. Your rights
Under the GDPR you can request access to, correction of, or deletion of your personal data, object to or restrict processing, and request data portability. To exercise these rights, email [email protected]. You also have the right to lodge a complaint with your local supervisory authority; in Croatia, this is AZOP (Agencija za zaštitu osobnih podataka).
8. Changes to this policy
If we change this policy, we will update the date at the top of this page. Significant changes will be noted clearly on this website.
Questions? Write to [email protected].