Legal
Privacy Policy
Last updated: July 28, 2026
1. Overview
This Privacy Policy explains how Verity Audit ("Verity", "we", "us") collects, uses, stores and protects information when you use our marketing website and the Verity Audit application (together, the "Service"). It applies to visitors of this website and to organisations and users of the Service.
2. Information we collect
Account & organisation data: name, work email, organisation name and role, collected when you sign up or are invited to an organisation.
Audit content: the audit universe, risk assessments, engagements, working papers, evidence attachments, issues and reports your organisation creates and stores in the Service. This content belongs to your organisation.
Usage data: log data such as IP address, browser type, pages visited and timestamps, collected automatically to operate and secure the Service.
Communications: information you provide when you contact us for support, sales or security questions.
3. How we use information
To provide, maintain and secure the Service, including authenticating users and enforcing tenant isolation between organisations.
To respond to support, sales and security enquiries.
To send essential account and service communications (for example, security alerts or changes to this policy).
With your consent, to send product updates or marketing communications, which you may opt out of at any time.
To monitor, investigate and prevent misuse, fraud or security incidents.
4. Data ownership and confidentiality
Audit content you create in the Service belongs to your organisation. We do not use your audit content — risk assessments, working papers, issues or reports — to train models, for marketing, or share it with other customers.
We access audit content only where necessary to provide support you request, to investigate a security or technical issue, or where required by law.
7. Security
We apply a defense-in-depth approach: strict multi-tenant data isolation, encryption in transit and at rest, two-factor authentication, hardened file uploads and least-privilege access controls. No system is perfectly secure, and we continually review and improve these protections. See our Security page for more detail.
8. Data retention
We retain account and audit content for as long as your organisation maintains an active subscription, plus a reasonable period afterward to allow for account recovery, unless a shorter period is requested and legally permitted. You may request deletion of your organisation's data by contacting us, subject to any legal retention obligations.
9. Your rights
Depending on your location, you may have rights to access, correct, export or delete your personal information, and to object to or restrict certain processing. To exercise these rights, contact us using the details below; we will respond within a reasonable timeframe.
10. International data transfers
Verity may process and store data in countries other than your own. Where required, we rely on appropriate safeguards for international transfers of personal information.
11. Children's privacy
The Service is intended for business use by adults and is not directed to children. We do not knowingly collect personal information from children.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "last updated" date, and where appropriate we will provide additional notice.
13. Contact us
Questions about this Privacy Policy or how we handle your data can be sent to [email protected].