Privacy Policy

Effective Date: January 1, 2026

1. Introduction

Verilock ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our compliance guidance platform at verilock.ai.

2. Information We Collect

We collect the following types of information:

  • Contact Information: Your name and work email address
  • Company Information: Your company name and business details
  • Wizard Responses: Answers you provide in our compliance assessment wizard (21 questions about your business, data handling, security practices, and compliance goals)
  • Payment Information: Billing details processed through our payment provider, Paddle
  • Usage Data: Information about how you interact with our service

3. How We Store Your Information

Your data is securely stored in MongoDB databases. We implement appropriate technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction.

4. How We Use Your Information

We use the information we collect to:

  • Generate personalized compliance roadmaps and policy documents
  • Provide and improve our compliance guidance service
  • Process your subscription payments
  • Communicate with you about your account and our services
  • Analyze usage patterns to improve product features
  • Comply with legal obligations

5. Third-Party Services

We share your information with the following third-party service providers:

  • Paddle: For payment processing. Your payment information is handled directly by Paddle and subject to their privacy policy.
  • Anthropic (Claude API): Your wizard responses and company information are processed through Claude to generate compliance content. This data is used only for generation and not stored by Anthropic.

6. Your Rights

Under GDPR and CCPA, you have the following rights:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data
  • Portability: Request transfer of your data to another service
  • Objection: Object to processing of your personal data
  • Restriction: Request restriction of processing

To exercise any of these rights, please contact us at hello@verilock.ai.

7. Cookies and Tracking

We use minimal, essential cookies to maintain your session and provide basic functionality. We do not use tracking cookies or third-party advertising cookies. We use PostHog for basic product analytics to understand how our service is used and improve user experience.

8. Data Retention

We retain your personal data for as long as your account is active or as needed to provide you services. If you request deletion of your data, we will delete it within 30 days, except where we are required to retain it for legal compliance.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place to protect your data in accordance with this Privacy Policy and applicable law.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the effective date.

11. Contact Us

For any privacy-related questions or requests, please contact us at: hello@verilock.ai