Privacy Policy
How VERONA AI LIMITED handles personal data on this website and in the mobile applications we publish.
1. Who we are (controller)
The controller of personal data described in this policy is:
VERONA AI LIMITED
Registered in Northern Ireland, Company No. NI738464
Registered office: 73 Boucher Crescent, Belfast, Northern Ireland, BT12 6HU
Email: ask@veronaai.co
“Verona AI”, “we”, “us” and “our” refer to VERONA AI LIMITED. Verona AI is a trading name of VERONA AI LIMITED.
2. Scope of this policy
This policy covers:
- the website at veronaai.co, including all of its pages; and
- the mobile applications published by VERONA AI LIMITED on the Apple App Store and Google Play, including the planned Verona AI companion app (together, the “apps”).
Where an app has features not described here at the time of its release, we will update this policy before that release and, where required, ask for your consent. It does not cover third-party websites or services we link to; their own privacy policies apply.
3. Data we process on the website
3.1 Email correspondence
The website contains no forms. Every contact route is an email link to ask@veronaai.co. If you email us, we process your email address, name (if given), and the content of your message in order to reply — including waitlist requests, general enquiries and data-protection requests.
3.2 Server and security logs
The website is served by Cloudflare, Inc. (“Cloudflare”). Cloudflare processes technical data — such as IP address, requested URL, browser type and timestamps — in server and security logs on our behalf, to deliver the site and protect it against attacks and abuse.
3.3 No analytics or advertising cookies
We do not run analytics scripts, advertising pixels or marketing cookies on this website. The only cookies that may be set are strictly necessary security cookies set by Cloudflare, described in our Cookie Policy.
4. Data we process in our apps
This section describes the data practices of the mobile applications we publish, including the Verona AI companion app. Where a specific app differs, its store listing and in-app notices will say so.
4.1 Account information
When you create an account we process your email address, display name, hashed password (or the token from a sign-in provider you choose), your business name and role, and your subscription status. We use this to operate your account, authenticate you, and provide support.
4.2 User content (and where it is stored)
The apps exist to let you set up and supervise your Verona AI agents. User content includes the business information you teach an agent (services, opening hours, policies, tone), documents you submit for processing, workflow definitions, and conversation content — both your conversations with your agents and, for business customers, the transcripts of conversations your agents hold with your customers.
User content is stored on our infrastructure hosted with Cloudflare, encrypted in transit and at rest. It is retained while your account is active and deleted as described in sections 8 and 12.
4.3 Device and technical data
We process device model, operating system version, app version, language and time-zone settings, and non-persistent technical identifiers needed to deliver push notifications you have enabled. We do not collect device advertising identifiers (such as the IDFA or Android Advertising ID).
4.4 Usage analytics
We collect limited, aggregated usage analytics — for example, which screens are used and which features are popular — to understand how the apps are used and improve them. This analytics data is not tied to advertising identifiers, is not shared with ad networks, and is not used to build profiles of you across other companies’ apps or websites.
4.5 Crash diagnostics
If the app crashes or malfunctions, we process crash logs and diagnostic information (device state, stack traces, app version) to find and fix the fault. Crash data is used only for stability and debugging.
4.6 App permissions
The apps request only the permissions they need, each for a stated purpose. Every permission is optional and can be revoked at any time in your device settings (iOS: Settings → Verona AI; Android: Settings → Apps → Verona AI → Permissions). The app keeps working without them, minus the related feature.
| Permission | Purpose | Required? | Revocable |
|---|---|---|---|
| Notifications | Alert you when an agent needs your approval or hands a conversation to you | Optional | Yes — device settings |
| Camera | Photograph a document (e.g. an invoice) to submit it to the Paperwork Agent | Optional | Yes — device settings |
| Photo library / files | Attach an existing document or image you choose | Optional | Yes — device settings |
| Microphone | Dictate a note or instruction to your agent instead of typing (processed only when you actively record) | Optional | Yes — device settings |
4.7 What we do not do
Across all of our apps, we do not:
- sell your personal data;
- include advertising SDKs or show third-party advertising;
- track you across other companies’ apps or websites;
- collect precise location data.
5. Purposes and lawful bases
Under UK GDPR, every purpose we process personal data for rests on a lawful basis:
| Purpose | Data used | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Replying to your emails, including waitlist and support requests | Email correspondence (3.1) | Legitimate interests — responding to people who contact us |
| Serving and securing the website | Server and security logs (3.2) | Legitimate interests — running and defending our website |
| Providing your account and the app’s core features | Account information (4.1), user content (4.2), device data (4.3) | Contract — performing our agreement with you |
| Sending service notifications you enable | Device data (4.3) | Contract; consent for the notification permission itself |
| Understanding and improving the apps | Aggregated usage analytics (4.4) | Legitimate interests — improving our products |
| Fixing crashes and faults | Crash diagnostics (4.5) | Legitimate interests — keeping the apps stable and safe |
| Training or fine-tuning models available to other customers | User content (4.2), only if you opt in | Consent — explicit and withdrawable at any time |
| Billing and account administration via the app stores | Subscription status (4.1) | Contract; legal obligation for tax and accounting records |
| Establishing, exercising or defending legal claims | Any of the above, as strictly necessary | Legitimate interests; legal obligation |
Where we rely on legitimate interests, we have balanced those interests against your rights and will explain the balancing on request.
6. Who receives your data
We share personal data only with service providers who process it on our behalf under data-processing agreements, and with the app stores that distribute our apps:
- Cloudflare, Inc. — website hosting, content delivery, security and application infrastructure;
- Apple Inc. — App Store distribution, and subscription billing for purchases made through the App Store;
- Google LLC — Google Play distribution, and subscription billing for purchases made through Google Play.
We commit to keeping this list current: if we add processors (for example, an email provider or a model-hosting provider for the apps), we will update this policy before or at the time the change takes effect. We may also disclose data where the law requires it, or in a business transfer such as a merger — in which case this policy would continue to apply to your data unless you are told otherwise and given any choices the law requires.
7. International transfers
We are based in the United Kingdom. Our service providers (section 6) are headquartered in the United States and may process data there and elsewhere. Where personal data leaves the UK, we rely on one or more of the following safeguards:
- a UK adequacy decision covering the destination (including the UK Extension to the EU–US Data Privacy Framework, where the recipient is certified);
- the UK International Data Transfer Agreement (IDTA); or
- the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum.
You can ask us at ask@veronaai.co which safeguard applies to a particular transfer.
8. How long we keep data
| Data | Retention period |
|---|---|
| Email correspondence | Up to 24 months after our last exchange, then deleted — unless needed longer for an ongoing relationship or legal claim |
| Website server / security logs (held by Cloudflare) | Short rolling periods set by Cloudflare’s log retention, typically under 30 days |
| Account information | Life of the account, plus up to 30 days after deletion completes |
| User content (including conversation content) | Life of the account; deleted within 30 days of account deletion (section 12) |
| Aggregated usage analytics | Indefinitely — aggregated so it no longer identifies you |
| Crash diagnostics | Up to 12 months, then deleted |
| Billing and tax records | 6 years, as required by UK tax and company law |
9. Your rights
Under UK GDPR you have the following rights over your personal data:
- Access — a copy of the personal data we hold about you;
- Rectification — correction of inaccurate or incomplete data;
- Erasure — deletion of your data (“right to be forgotten”), subject to narrow legal exceptions;
- Restriction — limiting how we use your data while a dispute or check is resolved;
- Data portability — your data in a structured, commonly used, machine-readable format;
- Objection — objecting to processing based on legitimate interests, and to any direct marketing (we currently send none);
- Withdrawal of consent — at any time, where processing is based on consent (such as model-training consent), without affecting processing before withdrawal;
- Rights relating to automated decision-making — we make no solely automated decisions with legal or similarly significant effects about you; if that ever changes, you will have the right to human review.
To exercise any right, email ask@veronaai.co with the subject line “Data protection request”. We may need to verify your identity. We will respond within one month of receiving your request; if a request is complex we may extend by up to two further months, and we will tell you within the first month if so. Exercising your rights is free of charge except in the narrow cases where the law allows a reasonable fee.
10. Complaints to the ICO
We would welcome the chance to resolve any concern first — email ask@veronaai.co. You also have the right to complain at any time to the UK supervisory authority:
Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk
11. Children
Our website and apps are intended for adults running or working in businesses. They are not directed at children, and we do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal data, contact ask@veronaai.co and we will delete it promptly.
12. Account and data deletion
You can have your account and associated data deleted at any time, whichever way you signed up:
12.1 In the app
Once our apps are released, go to Settings → Account → Delete account. You will be asked to confirm; deletion then proceeds automatically.
12.2 By email
Email ask@veronaai.co with the subject line “Account deletion request” from the email address linked to your account. This route works whether or not you still have the app installed.
12.3 What happens next
We complete deletion of your account and associated personal data within 30 days of a verified request. A small subset of records may be retained beyond that only where the law requires it — for example, billing records kept for tax purposes (section 8) — and such records are kept isolated and used for no other purpose. Deleting the app from your device does not by itself delete your account; please use one of the routes above.
13. iOS App Tracking Transparency
Our apps do not track you across other companies’ apps or websites, and do not share your data with data brokers or advertising networks. Because there is no tracking as defined by Apple’s App Tracking Transparency framework, our apps do not need to show the ATT permission prompt. If any future feature ever involved tracking — which we do not plan — we would ask for your consent through the ATT prompt first, and update this policy before doing so.
14. Google Play Data Safety
The Data Safety section of each of our Google Play listings is prepared from this policy and is kept consistent with it. It declares the data described in section 4, states that we do not sell data, and describes our deletion route (section 12). If you ever spot a discrepancy between a store listing and this policy, this policy states our actual practice — and we will correct the listing. Please tell us at ask@veronaai.co.
15. Security
We apply technical and organisational measures proportionate to the risk, including: encryption of data in transit (TLS) and at rest; access to personal data restricted to those who need it, protected by strong authentication (including multi-factor authentication); separation of production data from development environments; logging and review of administrative access; a defined process for assessing and, where required, notifying personal-data breaches; and vendor due diligence with data-processing agreements for every processor. No system is perfectly secure, but if a breach affects your data and creates a risk to you, we will notify you and the ICO as UK GDPR requires.
16. Changes to this policy
We will update this policy as our products and legal obligations evolve — including before releasing any app whose data practices are not already described here. The effective date at the top always shows the current version. For material changes affecting app users, we will give notice in the app or by email, and where the change relies on consent, we will ask for it rather than assume it. Earlier versions are available on request.
17. Contact
Questions, requests and complaints about this policy or your personal data:
VERONA AI LIMITED
73 Boucher Crescent, Belfast, Northern Ireland, BT12 6HU
ask@veronaai.co — we reply within one business day.