PRIVACY POLICY

Privacy Policy

Last updated: August 2026

1. Introduction

The VEON Legal & Compliance Portal ("Portal") is operated by VEON Ltd. and its subsidiaries. We are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable local privacy laws.

2. Data We Collect

We collect and process the following categories of personal data:

  • Account information: Name, corporate email address, operating company, role, and department.
  • Authentication data: Login timestamps, session tokens, and password hashes (we never store plain-text passwords).
  • Usage data: Policy acknowledgments, training completions, and portal activity logs for audit purposes.
  • Device information: Browser type, IP address, and device type for security monitoring.

3. How We Use Your Data

Your personal data is used exclusively for:

  • Authenticating your identity and managing portal access.
  • Tracking policy acknowledgments and compliance training progress.
  • Generating anonymised compliance analytics and reporting.
  • Maintaining audit logs as required by VEON's compliance framework.
  • Communicating compliance-related updates and notifications.

4. Data Storage & Security

All data is stored on Supabase infrastructure in the Frankfurt (EU) region, ensuring GDPR-compliant data residency. Data is encrypted at rest and in transit using industry-standard TLS 1.3 encryption. Access is controlled through role-based permissions with full audit logging.

5. Data Sharing

We do not sell, rent, or share your personal data with third parties for marketing purposes. Data may be shared with:

  • VEON Group entities: For compliance monitoring and reporting within the corporate group.
  • Service providers: Supabase (database hosting), Vercel (web hosting), and Resend (transactional emails), all bound by data processing agreements.
  • Regulators: When required by law or regulatory obligation.

6. Cookies

This portal uses only essential cookies required for authentication and session management. We do not use tracking cookies, advertising cookies, or analytics cookies.

7. Your Rights

Under GDPR, you have the right to:

  • Access your personal data held by us.
  • Request correction of inaccurate data.
  • Request deletion of your data (subject to legal retention requirements).
  • Object to or restrict processing of your data.
  • Receive your data in a portable format.

To exercise any of these rights, contact the Group Legal & Compliance team at compliance@veon.com.

8. Data Retention

Personal data is retained for the duration of your employment with VEON or its operating companies, plus any additional period required by applicable law or regulation. Audit logs are retained for a minimum of 7 years in line with VEON's records retention policy.

9. Contact

For questions about this Privacy Policy or your personal data, please contact:

Group Legal & Compliance
Email: compliance@veon.com
VEON Ltd., Claude Debussylaan 88, 1082 MD Amsterdam, Netherlands