Your data, kept small.
We collect as little as we can: just your email, if you join the waitlist. This page explains what we do with it and your rights under the GDPR.
Last updated 24 September 2026
Who is responsible for your data
OnDosis AB, based in Gothenburg, Sweden, is the data controller for personal data collected through the OnVeil website and waitlist. That means we decide how and why it is used, and we are responsible for protecting it under the EU General Data Protection Regulation (GDPR) and Swedish data protection law.
The short version
- The only personal data we ask for is your email address, and only if you join the waitlist.
- We use it for one thing: to tell you when it is your turn to try OnVeil.
- The website uses no cookies, no analytics and no advertising or tracking tools.
- The website never asks about your health.
- We never sell your data. You can leave the waitlist and have your email deleted at any time.
What we collect, why, and on what legal basis
| Data | Why we use it | Legal basis (GDPR) | How long we keep it |
|---|---|---|---|
| Your email address, if you join the waitlist | To tell you when it is your turn to try OnVeil and send your beta invitation. | Your consent (Article 6(1)(a)). You can withdraw it at any time. | Until you leave the waitlist, or at most 12 months after the OnVeil beta launches. |
| Technical data sent by your browser: IP address, browser type, the page requested and the time | To deliver the website, keep it secure, and stop abuse such as automated sign-ups (we limit how often one IP address can use the waitlist form). | Our legitimate interest in running a secure website (Article 6(1)(f)). | Up to 10 minutes in memory for abuse prevention. Our host keeps short-term server logs under its own retention policy. |
We do not make any decisions about you based solely on automated processing, and we do not profile you.
What we don’t collect
- No cookies or similar technologies. The website doesn’t set cookies or store anything on your device, so there is no cookie banner.
- No analytics, advertising or social media trackers. Our fonts and images are served from our own website, so your browser doesn’t contact Google or other third parties when you visit.
- No health data. The website never asks about your health, symptoms, cycle or medication. Joining the waitlist doesn’t tell us whether you have ADHD, and we don’t draw conclusions about your health from it.
Transfers outside the EU
Where a processor is based outside the European Economic Area, we only transfer data with the safeguards the GDPR requires: an EU adequacy decision (such as the EU–US Data Privacy Framework for certified companies) or the European Commission’s Standard Contractual Clauses. Vercel Inc.: EU–US Data Privacy Framework and Standard Contractual Clauses. You can ask us for a copy of the safeguards we rely on.
How we protect it
The website is only served over encrypted connections (HTTPS), uses strict browser security settings, and limits access to personal data to the people at OnVeil who need it. We collect as little as possible in the first place. If a data breach puts your rights at risk, we will notify the Swedish Authority for Privacy Protection and, where required, tell you directly.
Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you and get a copy of it.
- Correct data that is wrong or incomplete.
- Delete your data (“right to be forgotten”).
- Restrict how we use your data, for example while a complaint is looked into.
- Object to processing based on our legitimate interests.
- Data portability: receive your data in a common, machine-readable format.
- Withdraw your consent at any time. This doesn’t affect anything we did before you withdrew it.
To use any of these rights, use the contact details we will publish on this page before the OnVeil beta launches. It’s free. We will reply within one month, and may ask you to confirm your identity first, for example by replying from the email address on the waitlist.
Complaints
If you’re unhappy with how we handle your data, please tell us first so we can put it right. You also have the right to complain to a data protection authority. In Sweden, that is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se. If you live elsewhere in the EU, you can also contact the authority in your country.
Children
The waitlist is only for people aged 18 or over. We don’t knowingly collect data from children. If you believe a child has joined, contact us and we will delete their details.
The OnVeil app
This policy covers the website and waitlist only. The OnVeil app will handle more sensitive information, such as your check-ins, cycle and medication, which the GDPR treats as health data. The app will have its own privacy policy, and we will only process that data with your explicit consent. You will be able to read the app’s policy before you share anything.
Changes to this policy
We will update this policy when anything changes, for example when we choose a waitlist email provider. We’ll change the “last updated” date at the top, and if a change significantly affects how we use your data, we will tell you by email before it takes effect.
Contact us
For any question about your data or this policy, use the contact details we will publish on this page before the OnVeil beta launches.