Privacy Policy
verifuse — Last updated: July 2026
PUBLIC_LEGAL_IDENTITY in constants/site-config.ts and obtain legal review before public launch.Table of Contents
1. Controller and Data Protection Officer
2. Collection and Processing of Personal Data
3. Purposes and Legal Bases for Processing
4. Categories of Processed Data
5. Cookies and Tracking Technologies
6. Disclosure of Data to Third Parties
7. International Data Transfers
8. Retention Periods and Data Deletion
9. Your Rights (Data Subject Rights)
10. Automated Decision-Making and Profiling
13. Data Protection for AI Services
15. Privacy Notices for Specific Processing Activities
1. Controller and Data Protection Officer
Controller pursuant to Art. 4 No. 7 GDPR:
verifuse
Operator identity not yet configured
Email: contact@verifuse.app
Represented by: Operator representative not configured
Data Protection Officer (DPO):
The Data Protection Officer can be reached via the privacy email below.
Email: contact@verifuse.app
2. Collection and Processing of Personal Data
2.1 Personal data means any information relating to an identified or identifiable natural person (Art. 4 No. 1 GDPR). This includes both direct identifiers (such as name, work email) and indirect identifiers (such as correlation IDs, IP address, hashed tokens).
2.2 We collect personal data in the following ways:
- Directly from you: When joining the waitlist, booking a demo, contacting us through the contact form, or consenting to receive product-launch updates.
- Automatically: Through your use of our public website, technical data such as IP address, request time, browser and user-agent information, device type and access logs are captured for security and abuse prevention.
- From third parties: From self-hosted identity (ZITADEL), payment processors (Stripe), email delivery (Amazon SES), the AI-Gateway provider and integration partners that you actively connect.
- From public sources: To the extent permitted by law, we may also process data from publicly available sources when verifying counterparty or product information.
2.3 We only process personal data that is strictly necessary for the stated purposes (data minimisation, Art. 5(1)(c) GDPR).
3. Purposes and Legal Bases for Processing
3.1 We process your personal data for the following purposes and on the basis of the stated legal grounds:
a) Contract performance and service delivery (Art. 6(1)(b) GDPR)
- Operation of the public verifuse landing, waitlist proxy and cookie banner
- Operation of the invite-only product under a negotiated subscription
- Invitation, authentication and tenant membership management
- Customer support during onboarding and ongoing operations
b) Legitimate interests (Art. 6(1)(f) GDPR)
- Operational security, fraud and abuse prevention
- Aggregated cookieless measurement of page performance
- Enforcement of legal claims and defence of contract terms
- Improvement of documentation, onboarding and product features
c) Consent (Art. 6(1)(a) GDPR)
- Double-opt-in waitlist and product-launch emails
- Optional analytics (Vercel Web Analytics) on the public landing
- Any AI-driven mappings, drafts or recommendations within the product
d) Legal obligations (Art. 6(1)(c) GDPR)
- Tax and accounting retention (where invoicing applies)
- Cooperation with competent supervisory authorities
- Incident-response, breach notification and audit evidence preservation
3.2 Where we process special categories of personal data (Art. 9 GDPR) — for example because they appear in user evidence — we do so on the basis of Art. 9(2)(a), (b), (f) or (g) GDPR only to the extent strictly required by the service.
4. Categories of Processed Data
a) Waitlist and early-access data
- Name, work email, optional company, consent version and timestamp
- Confirmation status, source and unsuppression record
- Email-delivery audit metadata (per-message correlation IDs)
b) Account and identification data
- Operator-invited identity (managed by self-hosted ZITADEL)
- Tenant membership, role, last login and password hash (never in plaintext)
- Email and display name as supplied by the operator or the identity provider
c) Product and evidence data
- Products, components, markets, owners and accountable teams
- Evidence objects (SBOMs, documents, scans, technical files)
- Decisions, approvals and audit-log entries
- Object storage references (S3-compatible), versions and retention
d) Billing and payment data
- Billing address, VAT ID and contract reference
- Payment references returned by Stripe (PCI-DSS compliant processing)
- Invoice history, payment status and outstanding balances
e) Technical access data
- IP address, request timestamps and correlation identifiers
- Browser / user-agent, device family and operating system
- Application security events and login history
f) AI processing data
- Inputs to AI agents and the AI-Gateway (prompts, instructions, context)
- Drafts, mappings and reviewable proposals produced by the model
- Filter and redaction metadata required for policy enforcement
Note: AI processing data is retained only as long as required by the active workflow and the documented retention periods (see Section 8).
5. Cookies and Tracking Technologies
5.1 The public verifuse landing is designed to operate without advertising or third-party tracking cookies. We use cookies and similar storage technologies to keep the website functional and, with your consent, to measure aggregated traffic.
5.2 Cookie categories used:
Necessary cookies (essential)
These cookies keep the public landing functional, including theme preference and the saved analytics choice. Without them, some features cannot be provided.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest)
Functional preferences
Stored only with your consent. Used to remember language choice, theme preference and any opt-in analytics decision so the preference survives navigation.
Legal basis: Art. 6(1)(a) GDPR (consent)
Analytics and performance cookies
Loaded only after you choose “Allow analytics” in the cookie banner. We use Vercel Web Analytics, which records aggregated, cookieless page-views under a daily rotating visitor hash.
Legal basis: Art. 6(1)(a) GDPR (consent)
Marketing cookies
We do not use marketing, profiling or cross-site tracking cookies on the public landing. If this changes, we will update this notice and re-request consent.
5.3 You can change your analytics choice at any time through the cookie banner on the public landing or via your browser settings. Detailed information about the cookies used can be found in our Cookie Directory.
6. Disclosure of Data to Third Parties
6.1 We only disclose your personal data to third parties in the following cases:
a) Processors (Art. 28 GDPR)
Carefully selected processors process personal data on our behalf:
- Cloud infrastructure: Hetzner Online (hosting) and Vercel Inc. (landing edge)
- Identity: self-hosted ZITADEL (tenant authentication)
- Object storage: S3-compatible MinIO cluster, versioning and Object Lock
- Email delivery: Amazon Web Services SES (EU region)
- AI services: AI-Gateway with a single wired-up model provider
- Payments: Stripe Technology Europe Ltd.
- External scheduling: Cal.com when you choose to book a call
Data processing agreements (DPAs) pursuant to Art. 28 GDPR have been concluded with all processors, ensuring the protection of your data.
b) Independent controllers
- Authorities and institutions: As required by law (e.g. tax authorities, courts, law enforcement)
- Auditors: In the context of annual audits and assurance reports (when applicable)
c) Workspace members
Within a tenant, certain personal data (name, email, role, last activity) is visible to authorised workspace members. This is required for collaboration and is governed by tenant membership and row-level isolation.
6.2 We do not sell your personal data and do not disclose it to third parties for advertising purposes.
6.3 A complete list of all sub-processors pursuant to Art. 28(2) GDPR can be requested by sending an email to contact@verifuse.app.
7. International Data Transfers
7.1 Core verifuse business data (waitlist, evidence, audit logs, billing) is intended to remain in EU regions. If personal data is transferred to a country outside the EU/EEA, this only happens under Chapter V GDPR safeguards.
7.2 The following third-country transfers may currently occur:
- United States (Vercel, Stripe, AI-Gateway): Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR, supplemented by technical and organisational measures.
- United States (Cal.com, LinkedIn): only when you explicitly activate the external link or booking flow.
7.3 For transfers to the USA we rely on the EU Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) in its current version. We additionally implement technical protective measures (TLS 1.3 in transit, AES-256 at rest, pseudonymisation where feasible) and ensure that recipients provide adequate data-protection guarantees.
7.4 A copy of the applicable Standard Contractual Clauses can be requested from us at: contact@verifuse.app.
8. Retention Periods and Data Deletion
8.1 We store personal data only as long as necessary to achieve the processing purposes or as required by legal retention obligations.
8.2 Specific retention periods:
- Unconfirmed waitlist entries: 30 days after confirmation token expiry.
- Confirmed waitlist contacts: until you withdraw consent or unsubscribe.
- Unsubscribed contacts: only the minimal suppression record where legally justified.
- Waitlist message audit: approximately 24 months, subject to legal review.
- Account and profile data: for the duration of the subscription and until deletion is complete (max. 90 days after contract end, unless legal retention obligations apply).
- Payment data and invoices: 10 years pursuant to § 147 AO, § 257 HGB.
- Application security logs: generally 30 days unless an incident requires preservation.
- Audit log: 5 years for compliance and documentation purposes.
- AI inputs and outputs: 30 days by default, faster deletion available on request.
- Web Analytics: aggregated according to the retention controls of the configured Vercel plan; the visitor-identification hash resets daily.
8.3 After the retention periods expire, data is routinely and lawfully deleted or blocked. Data that remains necessary for other purposes (for example legal hold) remains stored in blocked form.
8.4 Further information on account deletion can be found in our Terms of Service, Section 12.
9. Your Rights (Data Subject Rights)
9.1 As a data subject, you have the following rights:
a) Right of access (Art. 15 GDPR)
You have the right to obtain confirmation from us as to whether personal data concerning you is being processed. If so, you have the right to access this data and additional information (purposes, categories, recipients, retention, source).
b) Right to rectification (Art. 16 GDPR)
You have the right to obtain rectification of inaccurate or incomplete personal data without undue delay.
c) Right to erasure (Art. 17 GDPR)
You have the right to request erasure of your personal data, provided no legal retention obligations or other grounds oppose deletion. Please note Section 8 and Terms of Service, Section 12.
d) Restriction of processing (Art. 18 GDPR)
You have the right to request the restriction of processing where the conditions of Art. 18(1) GDPR are met.
e) Right to data portability (Art. 20 GDPR)
You have the right to receive your personal data in a structured, commonly used and machine-readable format and to transmit it to another controller. Further information can be found in Terms of Service, Section 13.
f) Right to object (Art. 21 GDPR)
You have the right to object, on grounds relating to your particular situation, at any time to processing based on Art. 6(1)(e) or (f). We will then no longer process your data unless we can demonstrate compelling legitimate grounds that override your interests.
In particular, for processing for marketing purposes, you have an unrestricted right to object at any time (Art. 21(3) GDPR).
g) Withdrawal of consent (Art. 7(3) GDPR)
You may withdraw your consent at any time with effect for the future. The lawfulness of processing carried out before withdrawal remains unaffected.
9.2 To exercise your rights, please send an email to contact@verifuse.app or a letter to our postal address. We will respond to your request within 30 days.
9.3 In case of reasonable doubts about your identity, we may request additional information to verify your identity.
10. Automated Decision-Making and Profiling
10.1 We do not use automated decision-making on the public landing or the waitlist that produces legal effects or similarly significantly affects you (Art. 22(1) GDPR).
10.2 Within the invite-only product we may draft AI-assisted proposals (control mappings, evidence triage, vulnerability classification). These drafts are always subject to policy evaluation and an accountable human approval before any consequential business-state change.
10.3 Whenever profiling is used, you have the right to human intervention, to express your point of view and to contest the decision (Art. 22(3) GDPR). Please contact contact@verifuse.app.
11. Children and Adolescents
11.1 The verifuse website and waitlist are exclusively aimed at persons who have reached the age of 18 and are authorised to act on behalf of a business or organisation.
11.2 We do not knowingly collect personal data from persons under 18. If we become aware that data from minors has been inadvertently collected, we will delete it without undue delay.
11.3 If you are a parent or guardian and become aware that your child has provided us with personal data without your consent, please contact us immediately at contact@verifuse.app.
12. Data Security
12.1 We implement appropriate technical and organisational measures (TOMs) pursuant to Art. 32 GDPR to ensure a level of security appropriate to the risk for personal data.
12.2 The implemented security measures include, but are not limited to:
- Encryption: TLS 1.3 for all data transmissions; AES-256 encryption for stored data.
- Identity & access control: invite-only identity (ZITADEL), invite-only provisioning, role-based access control (RBAC), membership-backed tenant context.
- Row-level security: database RLS with a runtime role that cannot bypass tenant policies.
- Network security: firewall, DDoS protection, network segmentation, mTLS or signed tokens between apps.
- Storage safety: S3-compatible bucket versioning, Object Lock retention, off-host backups.
- Operational monitoring: OpenTelemetry, Prometheus, Grafana, Loki; documented incident-response procedure.
- Audit: correlation identifiers, append-only audit events, regular penetration tests later in the release plan.
12.3 Despite all security measures, no 100% guarantee can be given for the absolute security of data transmissions over the internet. We cannot fully guarantee the security of data you transmit to us electronically.
13. Data Protection for AI Services
13.1 The verifuse product uses an AI-Gateway that wraps a single LLM provider. The processing of your data by this provider occurs under the provider's responsibility as an independent controller.
13.2 When AI is used, the following data is processed:
- Your inputs (prompts, instructions, evidence excerpts, context information)
- Outputs and reviewable proposals generated by the model
- Re-prompt, redaction and policy-filter metadata
13.3 We have entered into contractual agreements with the AI provider to ensure that:
- Your data is not used for training the model (except with explicit consent)
- Adequate security measures are implemented
- Applicable data-protection laws are complied with
13.4 Important: You should avoid including personal data or confidential information in AI inputs that you are not prepared to share with the AI provider. While we filter inputs and outputs through the policy engine, ultimate responsibility for the content you send to the AI remains with you.
14. Third-Party Integrations
14.1 The verifuse product enables integration with third-party services that you actively connect. When using these integrations, the data-protection provisions of the respective provider also apply.
14.2 The following integration patterns are subject to additional terms:
- OAuth authorisation: when connecting with OAuth-enabled services, you will be asked to grant verifuse access to specific data. The scope is limited to the minimum required by the integration.
- API keys: API keys you provide for third-party providers are stored encrypted and used only for the specified integration.
- Webhook data: when using webhooks, data is transmitted to the endpoints you specify. Please ensure that your endpoints are secured.
14.3 We assume no responsibility for the data-protection practices of integrated third-party providers. We recommend reading the privacy policies of the respective services.
15. Privacy Notices for Specific Processing Activities
a) Newsletter and product-launch emails
We send product-launch emails only with your consent (Art. 6(1)(a) GDPR). You can withdraw this consent at any time via the unsubscribe link in any email or by contacting us.
Per-message delivery metadata is retained for a maximum of 24 months to demonstrate consent and trace any technical issues.
b) Customer support
For support requests, we process the information you provide to handle your request. Support communication is stored for 3 years after the case is resolved.
c) Payment processing
Payments are processed via Stripe Technology Europe Ltd. verifuse only receives encrypted payment references. Complete payment data remains with Stripe. More information: Stripe Privacy Policy.
d) Decision logging (Audit Trail)
The verifuse product logs AI-assisted proposals and the decisions that follow as part of the Audit Trail. These logs contain timestamps, triggering events, accountable reviewer and results. They are retained for 5 years according to Section 8.2 to fulfil compliance obligations.
16. Changes to this Privacy Policy
16.1 We reserve the right to update this Privacy Policy from time to time. Significant changes will be communicated to you by email at least 30 days before they take effect.
16.2 The current version is available at /privacy.
16.3 If changes may materially affect the processing of your data, we will additionally inform you of the most important changes and give you the opportunity to object or close your account.
17. Contact and Complaints
17.1 For questions about data protection or to exercise your data subject rights, please contact:
Email: contact@verifuse.app
Postal address: verifuse, Privacy Team, Operator identity not yet configured
17.2 You have the right to lodge a complaint with a data-protection supervisory authority regarding our processing of your personal data. The supervisory authority responsible for us must be supplemented with the registered seat once the legal entity is finalised.
17.3 You may also contact the supervisory authority of your country of residence or any supervisory authority in the EU.
Last updated: July 2026
© 2026 verifuse. All rights reserved.
This document was prepared with the utmost care. It serves informational purposes and does not constitute legal advice.