GDPR Privacy Rights
If you are in the European Economic Area, the United Kingdom, or Switzerland, data protection law gives you specific rights over your personal data. This page explains what they are and exactly how to use them with VERA. It supplements the Privacy Policy rather than replacing it.
- Version
- 1.0
- Effective
- July 28, 2026
- Last updated
- July 28, 2026
- Revisions
- 1
On this page (6 sections)
1. Who to ask
If you hold a VERA account, VERA is the controller of your account, billing, and usage data. Send your request to us at support@myvera.io.
If your personal data is in VERA because a business you dealt with entered it (you are their customer, lead, or contact), that business is the controller and VERA is its processor. Ask them first. If you contact us instead, we will tell you we cannot act on the request directly, and we will pass it to the account holder and help them respond, as the Data Processing Addendum requires.
2. Your rights
- Access (Article 15). Ask what personal data we hold about you and get a copy. Signed-in account holders can produce most of this immediately using the data export in Settings.
- Rectification (Article 16). Correct inaccurate data or complete data that is incomplete. Most account and business fields can be edited directly in the app.
- Erasure (Article 17). Have your personal data deleted where there is no overriding reason to keep it. Deleting your account in Settings performs a hard delete of your records; see the Account Deletion Policy for exactly what is removed and what is not.
- Restriction (Article 18). Ask us to limit processing while a dispute about accuracy or legitimate interests is resolved. In practice we do this by suspending the account, which keeps the data intact and stops it being processed further.
- Portability (Article 20). Receive the data you provided in a structured, commonly used, machine-readable format. The Settings export produces JSON.
- Objection (Article 21). Object to processing based on legitimate interests, including profiling. We will stop unless we can show compelling grounds that override your interests, or the processing is needed for legal claims.
- Withdraw consent (Article 7). Where processing rests on consent, withdraw it at any time. This does not affect processing already carried out.
- Automated decision-making (Article 22). VERA does not make decisions that produce legal or similarly significant effects about you by automated means alone. VERA generates suggestions, rankings, and drafts; a person approves them.
- Complain to a supervisory authority. You can lodge a complaint with the data protection authority in your country of residence, place of work, or where the alleged infringement happened. In the UK that is the Information Commissioner's Office. We would appreciate the chance to resolve it first.
3. How to make a request
Email support@myvera.io with the subject line "GDPR request". Tell us which right you are exercising, the email address associated with the data, and enough detail for us to find it.
We verify that a request comes from the right person before we act on it, because acting on a forged request would itself be a breach. For account holders we verify through the email address on the account and, where the request is high risk (deletion or a broad export), we may ask you to confirm from within a signed-in session. We do not ask for identity documents.
An authorized agent may act for you if they provide written authorization signed by you. We may still contact you directly to confirm.
4. Timing and cost
We respond within one month of receiving a verifiable request. Where a request is complex or you have made several, we may extend by up to two further months and will tell you why within the first month.
There is no charge. We may charge a reasonable fee, or refuse, if a request is manifestly unfounded or excessive, particularly if it is repetitive, and we will explain our reasoning if we do.
5. International transfers
VERA is based in the United States and processes data there. For transfers out of the EEA, the UK, or Switzerland we rely on the European Commission's Standard Contractual Clauses, with the UK International Data Transfer Addendum where the UK GDPR applies. They are incorporated into the Data Processing Addendum, which you can accept without contacting us.
VERA has not certified to the EU-US Data Privacy Framework.
6. For business customers
If you are a controller using VERA to process your own customers' personal data, the Data Processing Addendum sets out our Article 28 obligations: processing only on your instructions, confidentiality, security measures, subprocessor terms, assistance with data subject requests and breach notification, deletion at the end of the relationship, and audit rights.
The current list of subprocessors, with what each one receives and where it is located, is published on the Subprocessor List.
Change history
Every revision of this document, newest first. Material changes are notified to account holders before they take effect where practicable.
- v1.0July 28, 2026
Initial GDPR rights notice published.
Questions about this document?
Legal and contracts: support@myvera.io. Privacy and data rights: support@myvera.io. Security reports: support@myvera.io.
Related
This document is a carefully drafted policy written against how VERA actually works. It is not legal advice, and it should be reviewed by a licensed attorney in your jurisdiction before you rely on it.
