Legal
Privacy Policy
How we handle personal data when you use VeraScutum, including workforce compliance records, authentication, and AI-assisted features.
Last updated: 17 June 2026
Overview
VeraScutum (“we”, “us”, “our”) provides workforce compliance software for regulated organisations. This Privacy Policy explains how we handle personal data when you visit our website, create an account, or use the VeraScutum platform (the “Service”).
We are committed to processing personal data lawfully, fairly, and transparently in line with UK GDPR and the Data Protection Act 2018.
Who is responsible for your data
For website visitors and account holders who sign up directly with VeraScutum, we act as the data controller for account and billing information we collect.
When your employer or organisation uses VeraScutum, that organisation is usually the data controller for employee and workforce compliance data (names, training records, certifications, HR fields, and similar). We process that data as a data processor on the organisation’s instructions, under our agreement with them and their internal policies.
If you are an employee using VeraScutum through your employer, please contact your organisation’s privacy or HR contact for questions about how your employer uses your data. You may also contact us using the details below.
Information we collect
Account and profile data: name, work email, job title, department, role, authentication identifiers, and preferences you provide when registering or updating your profile.
Workforce compliance data: training assignments, course progress, certification evidence, gap findings, audit events, policy acknowledgements, and related metadata uploaded or generated in the Service.
Technical and usage data: IP address, browser type, device information, session cookies, log files, and product usage events needed to operate, secure, and improve the Service.
Communications: messages you send to Vera (our in-product assistant), support enquiries, and feedback you choose to provide.
Integrations: where enabled by your organisation, data imported from HR systems, identity providers, learning platforms, or regulatory sources connected to your tenant.
How we use information
We use personal data to provide and maintain the Service, authenticate users, enforce access controls, run compliance workflows (matrices, gap analysis, approvals, exports), and deliver notifications your organisation configures.
We use audit logs and security monitoring to protect accounts, detect abuse, and maintain traceability for compliance purposes.
We may use aggregated or de-identified analytics to understand product performance. We do not sell personal data.
AI features (Vera and document analysis)
Certain features send content to third-party AI providers to generate responses or summaries. This includes Vera chat (org context and your messages), certificate evidence analysis (PDFs and images you upload), and regulatory text extraction when an administrator imports public web pages.
We send only what is necessary for each feature. Vera conversations are not stored in our database as chat history; recent messages are held in your browser session and resent with each request. Tool actions may be recorded in your organisation’s audit log.
AI outputs are assistive only. Your organisation remains responsible for compliance decisions, approvals, and records of processing.
Sub-processors and sharing
We use trusted infrastructure and service providers to run VeraScutum, including hosting, database and authentication (Supabase), deployment (Vercel), email delivery, AI inference (Anthropic), text embeddings (OpenAI), and SCORM delivery where configured.
We share data with these providers only to deliver the Service, under contractual safeguards. We may also disclose information where required by law or to protect rights, safety, and security.
We do not share workforce compliance data with advertisers.
Retention
We retain personal data for as long as your organisation’s subscription is active and as needed to provide the Service, meet legal obligations, resolve disputes, and enforce agreements.
When an organisation terminates use of VeraScutum, we delete or anonymise tenant data in accordance with our data retention schedule and contractual terms, subject to backups and legal hold requirements.
Security
We apply technical and organisational measures appropriate to the sensitivity of compliance data, including encryption in transit, access controls, tenant isolation, and audit logging. No online service can guarantee absolute security; please use strong passwords and report suspected incidents promptly.
Your rights
Under UK GDPR you may have rights to access, rectify, erase, restrict, or object to processing of your personal data, and to data portability where applicable. You may also lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.
To exercise rights relating to data we control directly, contact privacy@verascutum.com. For employee data controlled by your employer, contact them in the first instance.
International transfers
Some sub-processors may process data outside the UK. Where this occurs, we rely on appropriate safeguards such as UK International Data Transfer Agreements or equivalent mechanisms approved under UK GDPR.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the “Last updated” date. Material changes may be notified through the Service or by email where appropriate.
Contact
VeraScutum — privacy enquiries: privacy@verascutum.com
For data protection requests, include enough detail for us to verify your identity and locate relevant records.
Questions? privacy@verascutum.com · Back to home