Legal
Privacy Policy
Last updated: 20 May 2026
This Privacy Policy explains how VeraKey (“VeraKey”, “we”, “us”) collects, uses, discloses, and protects personal data when you use the VeraKey compliance platform and related websites (the “Service”). We handle personal data in accordance with the Singapore Personal Data Protection Act 2012 (“PDPA”).
By using the Service, you agree to the collection and use of personal data as described here. If you do not agree, please do not use the Service.
1. Data we collect
- Account data — your name, email address, password (stored hashed), organisation name, and role within an organisation.
- Content you provide — compliance evidence, files, control statuses, remarks, framework adoptions, and any other data you or your organisation uploads to the Service.
- Usage and log data — audit events, IP address, browser type, device information, and timestamps of actions taken within the Service.
- Cookies — session and preference cookies needed to keep you signed in and remember your settings (see Section 7).
2. How we use data
- To provide, operate, and maintain the Service.
- To authenticate you and secure your account and organisation.
- To maintain an append-only audit log for your organisation’s compliance needs.
- To send service-related communications (e.g. invitations, sign-in links, account notices).
- To respond to your enquiries and support requests.
- To detect, prevent, and address security incidents, fraud, or technical issues.
- To comply with legal obligations.
3. Consent and legal basis
We collect, use, and disclose personal data with your consent, or where permitted or required under the PDPA and other applicable laws. You may withdraw consent at any time by contacting us (see Section 10); note that withdrawing consent may mean we can no longer provide parts of the Service.
4. Storage and security
Personal data and your content are hosted in Singapore (the ap-southeast-1 region) and encrypted at rest and in transit. Access between organisations is isolated by row-level security, and every change to tenant data is recorded in an append-only audit log. We apply reasonable administrative, technical, and physical safeguards, but no method of transmission or storage is completely secure.
5. Disclosure to third parties
We do not sell personal data. We share data only with service providers who process it on our behalf to operate the Service, under appropriate confidentiality and data-protection obligations. These include:
- Supabase — database, authentication, and file storage.
- Vercel — application hosting and delivery.
- Mailtrap — transactional email delivery.
- Stripe — payment processing (when paid plans are enabled).
- Anthropic — AI processing for the optional compliance assistant and AI-drafting features (see Section 6).
We may also disclose data where required by law, regulation, legal process, or a valid governmental request.
6. Artificial intelligence
VeraKey offers optional AI-assisted features powered by Anthropic (Claude): a compliance assistant that answers questions about your own organisation’s compliance data, and AI-drafted starter documents generated to help you begin populating evidence. These features are off by default in the sense that they only run when you choose to use them.
- Scope is your organisation only. The assistant can access only the data belonging to your active organisation. The organisation is determined from your authenticated session — never from anything you type — and the same row-level security that isolates tenants applies as a backstop. The AI cannot reach another organisation’s data.
- What is sent to Anthropic. To generate a response we send your questions and the relevant data from your organisation (such as compliance metrics, control details, and evidence metadata). When you ask about the contents of a document, the text of that evidence file (Markdown, plain text, or Word documents) may be sent as well. The assistant is read-only — it cannot change your data — and has no access to the internet.
- How Anthropic handles it. Anthropic processes this data solely to return a response to you. Under Anthropic’s commercial terms, your inputs and the generated outputs are not used to train Anthropic’s models. Anthropic may retain these inputs and outputs for a limited period under its commercial terms (for example, to monitor for misuse) before deleting them.
- What VeraKey stores. We do not store your assistant conversations. Our audit log records only a one-way cryptographic hash of your question plus which data the assistant accessed — not the question text or the answer. AI-drafted documents are saved as draft evidence in your workspace, marked as AI-generated and unreviewed until you review them.
- Your responsibility. AI output may be inaccurate or incomplete. Always review AI-drafted content and AI answers before relying on them for any compliance, audit, or legal purpose.
We may introduce additional AI-assisted features over time. We will update this Privacy Policy and, where required, seek your consent before doing so.
7. Data retention and deletion
We retain personal data for as long as your account is active or as needed to provide the Service and meet legal obligations. Some records use soft deletion and remain recoverable for a limited period before permanent erasure. On organisation closure or a verified erasure request, data is scheduled for permanent deletion. Audit-log entries may be retained as required for compliance and security purposes.
8. Cookies
We use strictly necessary cookies to keep you signed in (session cookies) and to remember preferences such as your active organisation and theme. We do not use cookies for third-party advertising. You can control cookies through your browser, but disabling necessary cookies will prevent you from signing in.
9. Your rights under the PDPA
Subject to the PDPA, you may request access to the personal data we hold about you and ask us to correct it if it is inaccurate or incomplete. You may also withdraw consent to our continued collection, use, or disclosure of your personal data. To make a request, contact us at hello@verakey.io. We will respond within the time limits set by the PDPA.
10. International transfers
Your data is stored in Singapore. Where a service provider processes data outside Singapore, we take reasonable steps to ensure it is afforded a standard of protection comparable to that under the PDPA.
11. Contact us
For questions about this Privacy Policy or to exercise your rights, contact our data protection contact at hello@verakey.io.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date above. Your continued use of the Service after an update constitutes acceptance of the revised policy.
See also our Terms of Service.