Vesopa Vesopa

Last updated 2026-09-08

Your Data Rights

UK data protection law gives you a set of rights over the personal data we hold about you. They are not a courtesy we extend. They are yours, they are free to use, and asking us to honour one will never count against you.

This page says what each right is and exactly how to use it.

The fastest route

Email privacy@vesopa.com from the address on your account, say what you want, and we will do it. That covers every right on this page.

Several of them you can exercise yourself, immediately, without asking anyone — see section 3.

1. Your rights, one by one

Right What it means How to use it
Access A copy of the personal data we hold about you, plus an explanation of why we hold it, who we share it with and how long we keep it. Ask us, or export it yourself from your account.
Rectification Have inaccurate data corrected, and incomplete data completed. Edit your profile yourself, or ask us.
Erasure Have your data deleted, where no legal obligation makes us keep it. Delete your account yourself, or ask us. See Data retention and deletion.
Restriction Make us pause processing while a dispute about accuracy or lawfulness is sorted out. Your data stays but sits still. Ask us, and say what you are disputing.
Portability Receive the data you gave us in a structured, commonly used, machine-readable form — and have it sent straight to another provider where that is technically possible. Ask us, and say which format you want.
Object Object to processing we base on legitimate interests. We stop unless we have compelling grounds that override your objection. For direct marketing you can object absolutely, and we stop, full stop. Ask us, or use the unsubscribe link.
Withdraw consent Where we rely on your consent — a linked social account, a profile image, a remembered device, marketing email — take it back at any time. Withdrawing it does not make what happened before unlawful. Turn the thing off in your account, or ask us.
Automated decisions Not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. See section 6.
Complain Take it to the regulator. See section 9.

2. What we hold, so you know what to ask for

The complete list is in section 3 of the privacy policy: your name, email address, phone number, date of birth, profile image, a hash of your password, your MFA enrolments and passkey public keys, IP addresses, user-agent and device information, sign-in timestamps and outcomes, and the list of applications you have connected.

There is nothing else. If you ask for everything, that is what you get.

3. What you can do yourself, right now

No request, no waiting, no identity check beyond being signed in:

Want to Where
See and edit your name, date of birth and profile image Profile
Change your email address or phone number Profile
See every sign-in, with time, IP address and outcome Login history
See and revoke every remembered device and active session Devices
See and revoke every connected application Connected apps
Unlink Google, Apple, Microsoft or GitHub Linked accounts
Change your password, add or remove MFA, add or remove a passkey Security
Download a copy of your data Security
Delete your account and everything with it Security, then Delete my account — direct link https://auth.vesopa.com/account/delete

4. Making a request to us

Email privacy@vesopa.com. To get you an answer quickly rather than a round of questions, include:

If you cannot sign in and cannot email from the account address, write to us anyway and explain. We will find another way to establish who you are.

5. How we check it is you

We will ask you to confirm the request from the email address or phone number on the account. That is normally the whole check.

If we still have a genuine doubt — the request comes from somewhere else, or asks for a large amount of data — we may ask for one more piece of proof. We will ask for the minimum, we will not demand a passport for a routine request, and anything you send for the check is deleted once it is done.

This is an identity check, not an obstacle. Handing someone else's sign-in history to a stranger who asked politely would be a breach in its own right.

6. Automated decisions and profiling

We run automated checks on sign-in attempts — an unfamiliar device, an unusual location, an impossible journey between two sign-ins, a run of failed attempts. A check can require a second factor or block the attempt.

This is security, not profiling for commercial ends, and it has no legal or similarly significant effect on you beyond having to prove it is you. We do not use your data to score, rank or profile you for any other purpose, and we make no automated decision about you that has a legal effect.

If a check has locked you out and you think it is wrong, write to privacy@vesopa.com. A person will look at it, explain what happened, and put it right if we got it wrong.

7. How long we take, and what it costs

8. Someone else acting for you

You can ask someone to make a request for you — a solicitor, a relative, a friend. Send written authority with the request, or confirm it to us yourself from the account address. We will still verify the account holder's identity, and we will send the data to the account holder unless they have told us otherwise.

9. Complaints

Come to us first, at privacy@vesopa.com. Say what we got wrong. Most of these are a misunderstanding we can fix the same day, and we would rather fix it than have you go through a regulator to make us.

If you are not satisfied, you have the right to complain to the Information Commissioner's Office, the UK supervisory authority, at ico.org.uk/make-a-complaint or on 0303 123 1113.

Information Commissioner's Office Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF Helpline: 0303 123 1113 ico.org.uk/make-a-complaint

You can go to the ICO without coming to us first. We would rather you gave us the chance, but it is your right either way, and using it costs you nothing.

You also have the right to seek a judicial remedy through the courts, and to claim compensation if you have suffered damage from a breach of data protection law.

10. Requests about a third-party application

If your question is about what an application did with your data after you signed into it, that application's operator is the controller for it and holds the answer. Their privacy policy has their contact details.

If you cannot find them, write to privacy@vesopa.com with the application name and we will point you at the operator. For Vesopa's own products — the EPOS till, the menu, the back office, the hosting panel — write to us and we will deal with the whole thing in one go.

11. Who we are

Vesopa Software Ltd, a company registered in the United Kingdom, company number 17362206, registered office Baglan, Port Talbot, SA12 7AX, Wales. We are the data controller for your Vesopa OAuth account.

privacy@vesopa.com reaches the person responsible for data protection at Vesopa.


Questions about any of this: privacy@vesopa.com. All our policies are listed at /policies.