Last updated 2 October 2026
In short: your organization owns the data it puts into VeridLock. We process it to run the service, we never sell it, we never train models on it, and nothing is sent to an external provider unless your organization turns that provider on.
This policy explains what personal data VeridLock Security ("VeridLock", "we") processes when you visit our website, register an organization, or use the VeridLock platform, and what rights you have in relation to that data.
Where your organization subscribes to VeridLock, your organization is the controller of the data it processes through the platform and VeridLock acts as its processor, handling that data only on your organization's documented instructions. For our own website, marketing and billing records, VeridLock is the controller.
Account data. The organization name, industry, work email address, telephone number, worker number and role of each user, together with authentication credentials, which are stored only as irreversible hashes.
Subscription and billing data. The plan selected, billing period, payment method type, transaction references, amounts, dates and the status of each payment. We do not store full payment card numbers or card security codes.
Platform content. The counterparty addresses, message subjects, message bodies, headers, attachment metadata and any text extracted from attachments that your organization submits for analysis, together with the resulting scores, findings and decisions.
Trust registry data. The trusted domains, blocked domains, verified recipient addresses and vendor bank account details your organization records.
Operational data. Audit log entries recording who performed which action and when, the originating IP address, security events raised by the application firewall, and communication history aggregated per counterparty.
Website data. Information you provide through our contact form, and the technical data necessary to serve and secure the site.
To provide the service you have subscribed to, including analysing outbound and inbound messages, verifying recipients, routing approvals and maintaining the audit trail.
To administer your subscription, take payment, and provide support.
To secure the platform, detect abuse and investigate incidents, which is our legitimate interest and, where the platform is used for security purposes, also yours.
To meet legal, accounting and regulatory obligations.
To communicate with you about the service. Marketing communications are sent only where you have consented or where we may lawfully do so, and you can withdraw at any time.
We do not sell personal data, and we do not share it with third parties for their own marketing purposes.
We do not use your platform content to train machine learning models, whether our own or a third party's.
We do not transmit your message content to any external provider unless your organization has explicitly enabled that provider. Every external integration in the platform — AI classification, threat intelligence feeds, domain age lookups, verification channels and attachment text extraction — ships disabled, and paid providers additionally require an entitling subscription before they can be invoked.
We do not permit data to cross between customer organizations. Every record belongs to exactly one organization and every query is scoped to it.
Where your organization enables an optional integration, the corresponding provider processes only the data necessary for that function: a messaging provider receives the recipient telephone number and the verification code; a threat intelligence feed receives a domain name; a domain registration lookup receives a domain name; an AI classification provider receives the message text submitted for analysis.
We also use infrastructure and hosting providers to operate the platform, and a payment processor to take payment. We maintain a current list of sub-processors and will provide it on request.
Account, subscription and billing records are retained for the life of the relationship and afterwards for as long as required by applicable accounting and limitation periods.
Scans, approval requests, verification records and audit log entries are retained for the life of your subscription so that investigations and audits have a complete record. Your organization may request deletion of specific records, subject to any legal obligation to retain them.
On termination, platform data is deleted or returned in accordance with the Terms & Conditions and any data processing agreement in place.
Access to the platform requires authentication and is constrained by role. Passwords are stored only as irreversible hashes, and temporary credentials issued to newly created users are encrypted at rest and cleared the moment the user sets their own password.
All traffic is served over encrypted transport, and the application applies a strict set of response security headers. An application firewall inspects incoming requests against attack signatures and records blocked attempts as security events.
Tenant isolation is enforced on every query rather than relying on interface restrictions, and administrative accounts are protected from modification by organization administrators.
Where personal data is transferred outside the jurisdiction in which it was collected, we rely on an appropriate transfer mechanism, such as standard contractual clauses or an adequacy decision, and we assess the destination before transferring.
Subject to applicable law, you may request access to your personal data, correction of inaccurate data, deletion, restriction of processing, portability, and you may object to processing carried out on the basis of legitimate interests. You may also withdraw consent where processing relies on it, without affecting processing carried out before withdrawal.
If you are a user of a customer organization, please direct requests concerning platform data to that organization in the first instance; we will assist it in responding.
You have the right to lodge a complaint with your supervisory authority.
We use cookies that are strictly necessary to operate the site and keep your session secure, including the session cookie and the cross-site request forgery token. These cannot be disabled without breaking authentication.
We do not set advertising cookies. Where we use analytics, it is limited to aggregate usage measurement.
We may update this policy to reflect changes to the platform or to legal requirements. Material changes will be notified to subscribing organizations before they take effect, and the revision date below will be updated.
Questions about this policy, or requests concerning your personal data, can be sent to us through the contact form on this site and will be routed to our privacy team.