Legal

Privacy Policy

How VERONA AI LIMITED handles personal data on this website and in the mobile applications we publish.

1. Who we are (controller)

The controller of personal data described in this policy is:

VERONA AI LIMITED
Registered in Northern Ireland, Company No. NI738464
Registered office: 73 Boucher Crescent, Belfast, Northern Ireland, BT12 6HU
Email: ask@veronaai.co

“Verona AI”, “we”, “us” and “our” refer to VERONA AI LIMITED. Verona AI is a trading name of VERONA AI LIMITED.

2. Scope of this policy

This policy covers:

  • the website at veronaai.co, including all of its pages; and
  • the mobile applications published by VERONA AI LIMITED on the Apple App Store and Google Play, including the planned Verona AI companion app (together, the “apps”).

Where an app has features not described here at the time of its release, we will update this policy before that release and, where required, ask for your consent. It does not cover third-party websites or services we link to; their own privacy policies apply.

3. Data we process on the website

3.1 Email correspondence

The website contains no forms. Every contact route is an email link to ask@veronaai.co. If you email us, we process your email address, name (if given), and the content of your message in order to reply — including waitlist requests, general enquiries and data-protection requests.

3.2 Server and security logs

The website is served by Cloudflare, Inc. (“Cloudflare”). Cloudflare processes technical data — such as IP address, requested URL, browser type and timestamps — in server and security logs on our behalf, to deliver the site and protect it against attacks and abuse.

3.3 No analytics or advertising cookies

We do not run analytics scripts, advertising pixels or marketing cookies on this website. The only cookies that may be set are strictly necessary security cookies set by Cloudflare, described in our Cookie Policy.

4. Data we process in our apps

This section describes the data practices of the mobile applications we publish, including the Verona AI companion app. Where a specific app differs, its store listing and in-app notices will say so.

4.1 Account information

When you create an account we process your email address, display name, hashed password (or the token from a sign-in provider you choose), your business name and role, and your subscription status. We use this to operate your account, authenticate you, and provide support.

4.2 User content (and where it is stored)

The apps exist to let you set up and supervise your Verona AI agents. User content includes the business information you teach an agent (services, opening hours, policies, tone), documents you submit for processing, workflow definitions, and conversation content — both your conversations with your agents and, for business customers, the transcripts of conversations your agents hold with your customers.

User content is stored on our infrastructure hosted with Cloudflare, encrypted in transit and at rest. It is retained while your account is active and deleted as described in sections 8 and 12.

No training without consent. We do not use your user content — including conversation content — to train or fine-tune models made available to other customers, unless you have given us your explicit, opt-in consent. Withdrawing that consent stops any further such use.

4.3 Device and technical data

We process device model, operating system version, app version, language and time-zone settings, and non-persistent technical identifiers needed to deliver push notifications you have enabled. We do not collect device advertising identifiers (such as the IDFA or Android Advertising ID).

4.4 Usage analytics

We collect limited, aggregated usage analytics — for example, which screens are used and which features are popular — to understand how the apps are used and improve them. This analytics data is not tied to advertising identifiers, is not shared with ad networks, and is not used to build profiles of you across other companies’ apps or websites.

4.5 Crash diagnostics

If the app crashes or malfunctions, we process crash logs and diagnostic information (device state, stack traces, app version) to find and fix the fault. Crash data is used only for stability and debugging.

4.6 App permissions

The apps request only the permissions they need, each for a stated purpose. Every permission is optional and can be revoked at any time in your device settings (iOS: Settings → Verona AI; Android: Settings → Apps → Verona AI → Permissions). The app keeps working without them, minus the related feature.

PermissionPurposeRequired?Revocable
NotificationsAlert you when an agent needs your approval or hands a conversation to youOptionalYes — device settings
CameraPhotograph a document (e.g. an invoice) to submit it to the Paperwork AgentOptionalYes — device settings
Photo library / filesAttach an existing document or image you chooseOptionalYes — device settings
MicrophoneDictate a note or instruction to your agent instead of typing (processed only when you actively record)OptionalYes — device settings

4.7 What we do not do

Across all of our apps, we do not:

  • sell your personal data;
  • include advertising SDKs or show third-party advertising;
  • track you across other companies’ apps or websites;
  • collect precise location data.

5. Purposes and lawful bases

Under UK GDPR, every purpose we process personal data for rests on a lawful basis:

PurposeData usedLawful basis (UK GDPR Art. 6)
Replying to your emails, including waitlist and support requestsEmail correspondence (3.1)Legitimate interests — responding to people who contact us
Serving and securing the websiteServer and security logs (3.2)Legitimate interests — running and defending our website
Providing your account and the app’s core featuresAccount information (4.1), user content (4.2), device data (4.3)Contract — performing our agreement with you
Sending service notifications you enableDevice data (4.3)Contract; consent for the notification permission itself
Understanding and improving the appsAggregated usage analytics (4.4)Legitimate interests — improving our products
Fixing crashes and faultsCrash diagnostics (4.5)Legitimate interests — keeping the apps stable and safe
Training or fine-tuning models available to other customersUser content (4.2), only if you opt inConsent — explicit and withdrawable at any time
Billing and account administration via the app storesSubscription status (4.1)Contract; legal obligation for tax and accounting records
Establishing, exercising or defending legal claimsAny of the above, as strictly necessaryLegitimate interests; legal obligation

Where we rely on legitimate interests, we have balanced those interests against your rights and will explain the balancing on request.

6. Who receives your data

We share personal data only with service providers who process it on our behalf under data-processing agreements, and with the app stores that distribute our apps:

  • Cloudflare, Inc. — website hosting, content delivery, security and application infrastructure;
  • Apple Inc. — App Store distribution, and subscription billing for purchases made through the App Store;
  • Google LLC — Google Play distribution, and subscription billing for purchases made through Google Play.

We commit to keeping this list current: if we add processors (for example, an email provider or a model-hosting provider for the apps), we will update this policy before or at the time the change takes effect. We may also disclose data where the law requires it, or in a business transfer such as a merger — in which case this policy would continue to apply to your data unless you are told otherwise and given any choices the law requires.

7. International transfers

We are based in the United Kingdom. Our service providers (section 6) are headquartered in the United States and may process data there and elsewhere. Where personal data leaves the UK, we rely on one or more of the following safeguards:

  • a UK adequacy decision covering the destination (including the UK Extension to the EU–US Data Privacy Framework, where the recipient is certified);
  • the UK International Data Transfer Agreement (IDTA); or
  • the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum.

You can ask us at ask@veronaai.co which safeguard applies to a particular transfer.

8. How long we keep data

DataRetention period
Email correspondenceUp to 24 months after our last exchange, then deleted — unless needed longer for an ongoing relationship or legal claim
Website server / security logs (held by Cloudflare)Short rolling periods set by Cloudflare’s log retention, typically under 30 days
Account informationLife of the account, plus up to 30 days after deletion completes
User content (including conversation content)Life of the account; deleted within 30 days of account deletion (section 12)
Aggregated usage analyticsIndefinitely — aggregated so it no longer identifies you
Crash diagnosticsUp to 12 months, then deleted
Billing and tax records6 years, as required by UK tax and company law

9. Your rights

Under UK GDPR you have the following rights over your personal data:

  1. Access — a copy of the personal data we hold about you;
  2. Rectification — correction of inaccurate or incomplete data;
  3. Erasure — deletion of your data (“right to be forgotten”), subject to narrow legal exceptions;
  4. Restriction — limiting how we use your data while a dispute or check is resolved;
  5. Data portability — your data in a structured, commonly used, machine-readable format;
  6. Objection — objecting to processing based on legitimate interests, and to any direct marketing (we currently send none);
  7. Withdrawal of consent — at any time, where processing is based on consent (such as model-training consent), without affecting processing before withdrawal;
  8. Rights relating to automated decision-making — we make no solely automated decisions with legal or similarly significant effects about you; if that ever changes, you will have the right to human review.

To exercise any right, email ask@veronaai.co with the subject line “Data protection request”. We may need to verify your identity. We will respond within one month of receiving your request; if a request is complex we may extend by up to two further months, and we will tell you within the first month if so. Exercising your rights is free of charge except in the narrow cases where the law allows a reasonable fee.

10. Complaints to the ICO

We would welcome the chance to resolve any concern first — email ask@veronaai.co. You also have the right to complain at any time to the UK supervisory authority:

Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk

11. Children

Our website and apps are intended for adults running or working in businesses. They are not directed at children, and we do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal data, contact ask@veronaai.co and we will delete it promptly.

12. Account and data deletion

You can have your account and associated data deleted at any time, whichever way you signed up:

12.1 In the app

Once our apps are released, go to Settings → Account → Delete account. You will be asked to confirm; deletion then proceeds automatically.

12.2 By email

Email ask@veronaai.co with the subject line “Account deletion request” from the email address linked to your account. This route works whether or not you still have the app installed.

12.3 What happens next

We complete deletion of your account and associated personal data within 30 days of a verified request. A small subset of records may be retained beyond that only where the law requires it — for example, billing records kept for tax purposes (section 8) — and such records are kept isolated and used for no other purpose. Deleting the app from your device does not by itself delete your account; please use one of the routes above.

13. iOS App Tracking Transparency

Our apps do not track you across other companies’ apps or websites, and do not share your data with data brokers or advertising networks. Because there is no tracking as defined by Apple’s App Tracking Transparency framework, our apps do not need to show the ATT permission prompt. If any future feature ever involved tracking — which we do not plan — we would ask for your consent through the ATT prompt first, and update this policy before doing so.

14. Google Play Data Safety

The Data Safety section of each of our Google Play listings is prepared from this policy and is kept consistent with it. It declares the data described in section 4, states that we do not sell data, and describes our deletion route (section 12). If you ever spot a discrepancy between a store listing and this policy, this policy states our actual practice — and we will correct the listing. Please tell us at ask@veronaai.co.

15. Security

We apply technical and organisational measures proportionate to the risk, including: encryption of data in transit (TLS) and at rest; access to personal data restricted to those who need it, protected by strong authentication (including multi-factor authentication); separation of production data from development environments; logging and review of administrative access; a defined process for assessing and, where required, notifying personal-data breaches; and vendor due diligence with data-processing agreements for every processor. No system is perfectly secure, but if a breach affects your data and creates a risk to you, we will notify you and the ICO as UK GDPR requires.

16. Changes to this policy

We will update this policy as our products and legal obligations evolve — including before releasing any app whose data practices are not already described here. The effective date at the top always shows the current version. For material changes affecting app users, we will give notice in the app or by email, and where the change relies on consent, we will ask for it rather than assume it. Earlier versions are available on request.

17. Contact

Questions, requests and complaints about this policy or your personal data:

VERONA AI LIMITED
73 Boucher Crescent, Belfast, Northern Ireland, BT12 6HU
ask@veronaai.co — we reply within one business day.