Privacy Policy

Effective Date: August 21, 2026

Veil Group, LLC (“Veil,” “we,” “our,” or “us”) respects the privacy of individuals who visit our website, contact us, or interact with us in connection with our business.

This Privacy Policy explains how Veil collects, uses, discloses, and protects personal information through veilgrp.com and in connection with our own business activities.

It also explains how we handle information that clients provide to us in connection with contracted services.

1. Information Covered by This Policy

This Policy applies to personal information Veil collects for its own business purposes, including information relating to:

  • Visitors to veilgrp.com.
  • Individuals who contact Veil.
  • Prospective clients.
  • Client representatives and business contacts.
  • Vendors and other business partners.

Veil also processes information on behalf of clients while providing professional services. Our handling of that information is addressed separately under Client Data below.

This Privacy Policy does not replace any confidentiality, data-processing, business associate, engagement, or other contractual agreement between Veil and a client.

2. Information You Provide to Veil

We may collect information that you voluntarily provide to us, including:

  • Name.
  • Business email address.
  • Telephone number.
  • Company or organization.
  • Services in which you are interested.
  • Information included in an inquiry or other communication.
  • Other business information necessary to respond to you or establish a client relationship.

We use this information to:

  • Respond to inquiries.
  • Evaluate prospective engagements.
  • Prepare proposals and agreements.
  • Communicate with clients and prospective clients.
  • Provide requested services.
  • Maintain business and relationship records.
  • Protect Veil’s legal, security, and business interests.

Sensitive Information

Do not submit passwords, authentication credentials, private keys, seed phrases, personal health information, privileged materials, detailed evidence, or other sensitive information through our public website forms.

If sensitive information is necessary for an engagement, Veil will arrange an appropriate transfer method.

3. Information Collected Through the Website

When you use veilgrp.com, Veil and its service providers may automatically collect limited technical and usage information, such as:

  • Internet Protocol address.
  • Browser and device information.
  • Operating system.
  • Approximate geographic information derived from an IP address.
  • Pages viewed.
  • Referring pages or websites.
  • Date and time of visits.
  • Links or website features used.
  • General website-performance and diagnostic information.

We use this information to:

  • Operate and secure the website.
  • Understand general website usage.
  • Identify technical problems.
  • Improve website performance and usability.
  • Detect malicious or fraudulent activity.

4. Analytics and Cookies

Veil uses Google Analytics 4 to understand general website usage and performance.

Google Analytics may use cookies or similar technologies and may receive technical information about your browser, device, and interaction with veilgrp.com.

Veil configures website analytics for analytics and website-improvement purposes and does not use information collected through veilgrp.com for cross-context behavioral advertising.

We may also use cookies or similar technologies that are necessary for website security, functionality, form processing, or fraud prevention.

Website security, bot detection, and form anti-spam protection on veilgrp.com are provided by Cloudflare, which sets the security cookies listed below.

The cookies veilgrp.com may set are:

  • _ga and _ga_<id> (Google Analytics, up to 400 days) — distinguish visitors and sessions for usage measurement. Set only where analytics is permitted; not set if you decline analytics or send a recognized opt-out signal.
  • veil_consent (Veil Group, 180 days) — records your cookie choice so you are not asked again. Necessary; it is what makes a refusal persist.
  • cf_clearance (Cloudflare, up to 1 year) — records that a security or anti-bot check was passed. Necessary for website security.
  • __cf_bm (Cloudflare, approximately 30 minutes) — bot management. Necessary for website security.

Cookies necessary for security and functionality are set when you visit the website, including before any analytics choice is made, because the website cannot be protected without them.

Where applicable law requires consent before non-essential analytics technologies are used, Veil will request that consent before enabling those technologies.

You can also control cookies through your browser settings. Blocking some cookies may affect website functionality.

5. Online Tracking and Privacy Signals

Some browsers provide privacy signals that communicate a user’s preference regarding certain uses of personal information.

Veil recognizes legally applicable universal opt-out mechanisms, including Global Privacy Control, where required by law.

When Veil receives a legally recognized opt-out preference signal, we treat it as a request to opt out of the types of processing to which the signal applies.

Veil does not currently sell personal information or use personal information collected through veilgrp.com for cross-context behavioral advertising or targeted advertising.

Legacy browser “Do Not Track” signals do not have a universally accepted technical or legal meaning. Veil does not separately respond to legacy Do Not Track signals unless required by applicable law.

Third-party service providers used on veilgrp.com may collect information as described in this Policy and their respective privacy notices.

6. Client Data

As part of our professional services, clients may provide Veil with information relating to individuals.

Depending on the engagement, Client Data may include personal information, confidential information, regulated information, protected health information, litigation materials, breach-related information, or other sensitive data.

For Client Data, Veil generally acts on behalf of and under the instructions of the client that provided or authorized Veil to receive the information.

Veil uses Client Data to perform the contracted services and for other purposes permitted by the applicable agreement or law.

Client Data may be governed by:

  • Statements of work.
  • Master services agreements.
  • Business associate agreements.
  • Data-processing agreements.
  • Confidentiality agreements.
  • Protective orders.
  • Client instructions.
  • Applicable laws and regulations.

If you believe Veil possesses your personal information because it was provided to us by one of our clients, you may contact us. Where appropriate, we may refer your request to the client that controls the information.

Nothing in this Privacy Policy changes Veil’s contractual obligations to its clients or permits Veil to act contrary to lawful client instructions.

7. How We Disclose Information

Veil may disclose personal information in the circumstances described below.

Service Providers

We may provide information to service providers that support functions such as:

  • Website hosting.
  • Cybersecurity.
  • Communications.
  • Business productivity.
  • Analytics.
  • Form processing and anti-spam protection.
  • Accounting and other business operations.

We limit such disclosures to information reasonably necessary for those services and use contractual or other safeguards where appropriate.

Client-Directed Disclosures

When performing services for a client, Veil may disclose Client Data as authorized or directed by the client, including to counsel, insurers, consultants, regulators, law enforcement, service providers, or other parties involved in the engagement.

We may disclose information when reasonably necessary to:

  • Comply with applicable law.
  • Respond to valid legal process.
  • Respond to governmental or regulatory requests.
  • Protect the rights, property, or safety of Veil, our clients, or others.
  • Investigate fraud, security incidents, or misuse of our systems.
  • Establish, exercise, or defend legal claims.

Business Transactions

Information may be transferred as part of a merger, acquisition, financing, restructuring, sale of assets, or similar business transaction, subject to applicable legal requirements.

8. No Sale of Personal Information

Veil does not sell personal information.

Veil does not operate as a data broker.

Veil does not sell Client Data.

Veil does not use personal information collected through veilgrp.com for targeted advertising based on an individual’s activity across unrelated websites or services.

Veil does not use website visitor information to make decisions producing legal or similarly significant effects concerning an individual.

9. Data Security

Veil maintains administrative, technical, and physical safeguards designed to protect personal information based on the nature of the information and the risks associated with its processing.

No security control or method of electronic transmission or storage can eliminate all risk. Accordingly, Veil does not represent or guarantee that information can never be accessed, altered, disclosed, or lost without authorization.

Sensitive client information should not be transmitted through the public contact form. Veil will provide an appropriate transfer method when sensitive information is necessary for an engagement.

10. Data Retention

Veil retains personal information for periods reasonably necessary for the purposes for which it was collected, including:

  • Responding to inquiries.
  • Providing services.
  • Maintaining business and client records.
  • Meeting contractual requirements.
  • Protecting security and legal interests.
  • Resolving disputes.
  • Complying with applicable legal, regulatory, accounting, or recordkeeping obligations.

The appropriate retention period depends on the nature of the information, the relationship involved, applicable contracts, legal requirements, and the purpose for which the information is maintained.

Client Data is retained and disposed of in accordance with applicable agreements, client instructions, Veil’s retention practices, and legal requirements.

When information is no longer reasonably required, Veil may delete it, de-identify it, or otherwise restrict access to it as appropriate.

11. Privacy Rights

Depending on where you reside and the laws applicable to Veil’s processing of your information, you may have rights concerning your personal information.

Those rights may include the ability to:

  • Confirm whether Veil processes your personal information.
  • Access certain personal information.
  • Correct inaccurate personal information.
  • Request deletion of certain personal information.
  • Obtain a portable copy of certain personal information.
  • Opt out of certain sales, targeted advertising, or qualifying profiling.
  • Appeal certain decisions relating to a privacy request.
  • Exercise privacy rights without unlawful discrimination.

The availability and scope of these rights vary by jurisdiction and may be subject to exceptions.

To submit a request, use Veil’s Privacy Request form or contact:

Email: info@veilgrp.com

Veil may need to take reasonable steps to verify your identity before fulfilling certain requests.

Where permitted by law, an authorized agent may submit a request on your behalf. Veil may request information reasonably necessary to verify the agent’s authority.

If Veil denies a request and applicable law provides a right to appeal, you may submit an appeal through the Privacy Request form or by emailing us and identifying the request as a privacy appeal.

Veil will respond to requests and appeals within the periods required by applicable law.

Client Data Requests

Privacy rights relating to information Veil processes solely on behalf of a client may need to be exercised through that client.

If appropriate, Veil will direct the request to or coordinate with the applicable client.

12. Children’s Privacy

Veil’s website and services are intended for businesses and professional users and are not directed to children.

Veil does not knowingly use veilgrp.com to collect personal information from children under 13.

If we learn that a child has provided personal information through the website in circumstances prohibited by applicable law, we will take reasonable steps to address the information as required.

13. International Visitors

Veil is based in the United States and primarily provides services in the United States.

Information collected through veilgrp.com or provided to Veil may be processed in the United States and in other locations where Veil’s authorized service providers operate.

Visitors accessing the website from outside the United States should understand that privacy and data-protection laws in the United States may differ from those in their jurisdiction.

Where applicable law imposes additional requirements concerning international processing or transfer, Veil will address those requirements as applicable to the relevant processing activity.

14. Changes to This Privacy Policy

Veil may update this Privacy Policy when our practices, services, technologies, or legal obligations change.

When we update the Policy, we will revise the Effective Date shown at the top of this page.

Where required by applicable law, Veil may provide additional notice regarding material changes.

15. Contact Us

Questions regarding this Privacy Policy or Veil’s privacy practices may be directed to:

Veil Group, LLC
316 W 12th St., Suite 400
Austin, Texas 78701

Email: info@veilgrp.com
Phone: (512) 386-1413