Privacy Policy
This policy explains what personal data Veredus Analytics collects when you use veredusanalytics.com, why, who processes it on our behalf, how long we keep it, and the rights you have over it. We collect little, and we say plainly where each piece goes.
1. Who is responsible
The data controller is Veredus Analytics, operating from the United Kingdom. For anything in this policy, including exercising your rights, email [email protected] or use the contact form.
2. What we collect, and why
| Data | When | Why (lawful basis) |
|---|---|---|
| Account identity: your sign-in identifier, name and email address as supplied by your sign-in provider, and whether the email is verified | When you create an account | To run your account and send account emails (performance of our contract with you) |
| Subscription state: your plan, billing status, renewal date, and the identifiers Stripe issues for your customer and subscription records. We never hold card details. | When you subscribe | To provide what you have paid for and to manage billing (contract) |
| Usage records: the pages and data you request while signed in, with timestamps, kept as server logs | Whenever you use the platform | To operate the service securely, apply plan limits and investigate faults (legitimate interests) |
| Contact-form messages: your name, email and the message | When you write to us | To reply (legitimate interests) |
| AI research assistant: the questions you ask, the answers given, and your helpful / not-helpful feedback | When you use the assistant (Max plan) | To answer, to let you revisit your conversations, and to review answer quality and compliance (contract and legitimate interests) |
| Aggregate site analytics: page views and referrers, with no cookies and no identifier that persists beyond the day | Whenever you visit | To understand which pages are useful (legitimate interests) |
We do not buy, enrich or sell personal data, and we do not use it for advertising.
3. Who processes it for us
We use a small number of providers, each acting on our instructions under a written agreement:
| Provider | Role | Data |
|---|---|---|
| Auth0 (Okta) | Sign-in and account identity | Sign-in identifier, name, email |
| Stripe | Payments and billing | Email, card details (held by Stripe only), billing history |
| Microsoft Azure | Hosting, databases, logs and transactional email (Azure Communication Services) | Everything in section 2, stored in the UK/EU regions we operate in |
| Plausible Analytics | Privacy-friendly site analytics | Aggregate page views only — no cookies, no cross-day identifiers |
| An AI model provider (currently Anthropic) | Generating the AI research assistant's answers | The text of your questions and the analytics needed to answer them. Your question leaves our infrastructure to be processed; it is not used to train the provider's models under our agreement. |
Some of these providers process data outside the UK. Where they do, transfers rely on the UK International Data Transfer Agreement or the UK addendum to the EU standard contractual clauses, or on an adequacy decision.
4. Cookies
The site sets only the cookies it needs to keep you signed in. Our analytics tool does not use cookies, which is why there is no cookie banner. We do not use advertising or tracking cookies.
5. How long we keep it
- Account and subscription records: for as long as you have an account, then deleted within 90 days of closure — except the minimum billing records the law requires us to keep, for six years.
- Usage logs: 90 days.
- Contact-form messages: up to 12 months after the conversation ends.
- AI assistant conversations: for as long as you have an account (so you can revisit them); compliance review copies for 12 months.
- Aggregate analytics: indefinitely, as they identify nobody.
6. Your rights
Under UK GDPR you can ask us to: give you a copy of your data; correct it; delete it; restrict or object to how we use it; or provide it in a portable form. You can also withdraw consent where consent is the basis. Email [email protected]; we respond within one month. To close your account and delete your data, contact us the same way. If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office (ico.org.uk).
7. Security
Data is encrypted in transit and at rest. Sign-in is delegated to Auth0; payments to Stripe; secrets are held in a managed vault; access to production systems is limited to the people who run the platform. No system is perfectly secure, and if a breach affects your data we will tell you and the ICO as the law requires.
8. Changes to this policy
We will post changes here with a new version number and date, and email account holders about any change that affects how their data is used.
