Pricing
You are billed for pages redacted. Nothing else.
A billable page is one page of the output bundle Veil generates for you. Pages are counted from the generated output at the moment you release a case, and never from the file you uploaded. A document that you do not release is never billed, and a document the verifier withholds is never billed. An email attachment, and a file inside an archive, is its own document with its own pages. Every document counts as at least two pages. A spreadsheet counts as at most fifty pages, however many rows it holds.
Not billed
- Pages of the file you uploaded
- Entities found or decisions made
- Re-rendering after you resolve a flag
- Documents withheld before release
- Seats, up to your plan's limit
Three plans, and no reduced tier.
Pay as you go
For the team that answers a handful of requests a year.
EUR0.50per page, no monthly fee
0.25 per page beyond 750 in one case, metered monthly
- Documents per case
- Up to 2,000
- Active cases
- 2
- Retention window
- Up to 30 days
- Seats
- 3
- The full detection capability, no reduced tier
- Independent verification on every document
- Bundle, manifest and quality report
- Spot checks on by default
Team
Most casesFor a privacy function with a steady request load.
EUR600per month, 2,300 pages included
0.26 per page beyond the included volume
- Documents per case
- Up to 2,000
- Active cases
- 10
- Retention window
- Up to 60 days
- Seats
- 10
- Everything in pay as you go
- REST API and typed client
- Case webhooks, HMAC signed
- Per-organisation spot check policy
- Priority email support
Business
For high volume, or for a case that arrives without warning.
EUR1,800per month, 9,200 pages included
0.16 per page beyond the included volume
- Documents per case
- Unlimited
- Active cases
- Unlimited
- Retention window
- Up to 90 days
- Seats
- Unlimited
- Everything in Team
- No document cap on a case, however large the disclosure
- No cap on active cases, however many arrive together
- Unlimited seats, viewers included
- SAML single sign-on, with a DNS-verified domain and an organisation-wide requirement
Worked example
Every document counts as at least two pages, so a 200 document access request is 400 billable pages at least, and costs 200 on pay as you go. On Team the same case is inside the included volume.
Enterprise
Enterprise
Annual page commitment at a volume rate, with the controls a security review asks for.
- SAML single sign-on, with a DNS-verified domain and an organisation-wide requirement
- Dual control on bundle release and on marking an entity as the subject, committed in the agreement and not yet released
- Negotiated retention and residency
- Data processing agreement and sub-processor pack
- Named support contact
Not ready to commit? You can ask us for a trial after you sign up, and we will come back to you. Sign up
Costing this against reading the documents by hand? The two methods, question by question sets out what changes and what does not, including the requests where doing it by hand is still the right answer.
Billing, cancelling and integrating.
How long do you keep the documents?
As long as your retention window, which you set and your plan caps. When a case purges, the objects, the extractions and the entity mentions are deleted and the case encryption key is destroyed, which makes what was encrypted under it unrecoverable, including in backups. A few fields are held without that encryption, among them the display name of each entity and the case's external reference: the purge deletes them, and a database backup taken before it holds them for as long as that backup can be restored, which is seven days. What survives is a tombstone holding the case reference, the dates, the counts and the quality summary, with no personal data in it.
What happens if I cancel?
You keep everything to the end of the period you have paid for, and nothing changes before then. After that, your organisation is read only, as clause 11.5 of the Terms describes: you cannot open a case, upload or import documents, start processing or release a bundle. Everything else stays where it is. You can still sign in, read every case, export your organisation's data and download a bundle you released earlier. Nothing is deleted early to make a point. Each released case still purges on the retention clock it was stamped with when it left, exactly as it would have done had you stayed. Cancelling the subscription does not close your account, though: an owner does that under Settings, Organization, and it is closing, not cancelling, that starts the 30 days in which you can export your bundles and audit records before your data is deleted under clause 11.4 of the Terms.
Where do I find my invoices?
In the Stripe billing portal, which you open from the billing page in settings. It holds every invoice issued to you, and it is also where you update the payment method or the billing address and where you cancel. Changing plan is not done there: ask us and we move you, so that a change of plan is never an accidental click.
Why does pay as you go ask for a card?
Because pay as you go is a subscription like every other plan, and the one that carries no monthly fee. You are billed once a month, in arrears, for the pages of everything you released in that calendar month, and a month in which you release nothing costs nothing. The card is on file so that invoice can be settled. It is not charged when you sign up.
Can I integrate this with something else?
Yes, from the Team plan up. A REST API with a typed client covers cases, subject anchors, documents, processing, entity decisions, release, bundle and quality report, and HMAC signed webhooks carry no personal data in the payload. Cases can also be pulled straight from a SharePoint folder.
ReleaseManifest and quality report attached
Nothing
underneath.
Open a case, declare the subject, drop the documents in. Veil redacts, raises what it is not sure of, and shows you its working.
Reference
The Access Request Desk
The practitioner's reference for data subject access requests: what the law says in each jurisdiction, how a request is run, and what a redaction actually removes.
Guides
Long-form answers on redacting a data subject access request: what the law requires, whose data comes out and whose stays, and how to check what you release.
API documentation
The Pritect Veil API: bearer authentication and scopes, the error shape, cursor pagination, idempotency, every endpoint with examples, five webhook events.