1. Who we are
VeriOne ("we", "us") provides AI-powered business assessments and benchmarks for SMEs. This policy explains what personal data we process, why, and your rights under the GDPR and equivalent laws.
2. Data we collect
- Account data: name, email, password hash, company name, role.
- Assessment data: answers, uploaded documents, derived scores and recommendations.
- Billing data: processed by our payment provider (Stripe). We never see full card numbers.
- Usage data: device, IP, pages viewed, and aggregated analytics for product improvement.
3. How we use it
- Deliver assessments, scores, monitoring, and recommendations.
- Authenticate, secure, and support your account.
- Anonymized benchmarking against peer cohorts (never individually identifiable).
- Service emails (receipts, score updates). Marketing only with opt-in.
4. Legal bases (GDPR)
Contract (delivering the service), legitimate interest (security, anonymized analytics), consent (marketing, optional cookies), and legal obligation (tax/invoicing).
5. Sharing
We share data only with vetted sub-processors: cloud hosting, payment processing, email delivery, and AI inference. We do not sell personal data.
6. Retention
Account & assessment data is kept while your account is active and up to 24 months after closure (or sooner on request). Invoices are kept 10 years for tax law.
7. Your rights
Access, rectification, erasure, portability, restriction, and objection. Email privacy@verione.ai — we respond within 30 days.
8. International transfers
Data is hosted in the EU. Where transfers occur (e.g. to a US sub-processor), we rely on Standard Contractual Clauses.
9. Security
Encryption in transit (TLS) and at rest, RLS-isolated tenant data, least-privilege access, and continuous monitoring.
10. Contact
Data Protection: privacy@verione.ai. See also our Terms and Cookie Policy.
