Legal
Privacy Policy
How Verasity™ collects, uses, stores, and protects personal data.
Last updated: August 2026
What data we collect
We collect account information (name, work email, role), workspace configuration data, simulation and training activity (events, completions, reports), brand monitoring inputs (domains, executive names, keywords), and standard usage telemetry needed to operate the service.
How customer employee data is used
Employee data is processed solely to deliver the awareness, simulation, training, and risk-scoring services contracted by the customer. Verasity™ acts as a data processor under the customer's instructions and does not sell employee data. Employee data is disclosed only to the subprocessors that operate the service on our behalf, under contract.
AI usage and data processing
Verasity™ uses AI to generate simulations, training content, and threat-intelligence summaries. Customer-identifying data and employee content are not used to train shared or third-party foundation models. Enterprise customers can opt in to additional model isolation and data residency controls.
Data residency options
Verasity™ is designed to support global enterprise deployment models, including regional hosting and data residency options where configured and contractually agreed. Customers with specific data residency, privacy, or regulatory requirements can request a data residency brief and security documentation.
Subprocessors
Verasity™ uses a vetted list of subprocessors for hosting, email delivery, voice synthesis, and analytics. The current list is available under NDA and is updated when material changes occur.
Retention and deletion
Customer data is retained for the duration of the agreement plus the retention period defined in your order form. On termination, customer data is deleted within 60 days unless a longer period is required by law.
Security safeguards
Verasity™ applies encryption in transit and at rest, role-based access control, MFA, audit logging, and a documented vulnerability management and incident response program. See our security page for details.
Customer rights
Customers and their employees may request access, correction, or deletion of personal data through their workspace administrator. Requests are honored consistent with applicable law (e.g., GDPR, pipeda, ccpa).
Website visitors: what this site collects
- • Form submissions: the name, work email, company and any optional phone number, area of interest or message you type into a demo, assessment, contact, partner or resource-download form.
- • Request context: the page you submitted from, the referring URL, and campaign parameters (utm_source, utm_medium, utm_campaign, utm_content) carried in the link you arrived on.
- • Consent record: whether you ticked the optional marketing box, the version of the wording you were shown, the time of the decision, and the page it was made on.
- • First-party interaction events: page and form events such as views, starts, validation errors, submissions, CTA and download clicks, tied to an anonymous ID that lives only in the current browser tab.
- • Server logs: standard request logs kept by our hosting provider, including IP address and user agent, used for security, abuse prevention and rate limiting.
How website data is used
- • To respond to the request you submitted, and to route it to the right team.
- • To send you a confirmation that we received the request. That confirmation is transactional only and contains no marketing content.
- • To protect the forms against automated abuse (rate limiting, bot heuristics, duplicate-submission checks).
- • To measure which pages and campaigns lead to enquiries, using the anonymous event data described above.
- • Marketing updates are sent only if you ticked the optional box. The box is never pre-ticked, and no demo, assessment or resource request depends on it.
Processors that receive website data
- • Cloudflare — hosting and delivery of this website and its server endpoints; processes request metadata and server logs.
- • Supabase — database hosting for website enquiries and first-party interaction events.
- • Resend — email delivery for internal enquiry notifications and for your confirmation email.
- • These providers process the data on our instructions, under contract, and only to provide those services. We do not sell personal data and we do not share it with advertising networks.
Cookies and analytics
This website sets no advertising or cross-site tracking cookies and uses no third-party analytics product. Interaction measurement is first-party only and uses a random identifier stored in your browser tab's session storage, which is discarded when the tab is closed. Because there are no non-essential cookies, no cookie banner is displayed; if that ever changes, the relevant storage will be blocked until a consent choice is made.
Website data retention
Enquiry records are kept while we act on them and for the period needed to answer follow-up questions and meet our record-keeping obligations. A specific retention period for website enquiries is under review and will be published here once approved; no automated deletion runs until it is. You can ask us to delete your enquiry at any time using the contact address below.
Access and deletion requests
Email hello@verasity.ai with the subject "Data request" from the address you used on the form, stating whether you want a copy of the data we hold or its deletion. We locate records by email address, confirm the outcome to you, and act within the timeframe required by applicable law.
Website search and interaction analytics
Verasity™ may collect website search queries and interaction analytics (such as pages viewed, cTAs clicked, and search terms entered into our site search) to improve site experience and content relevance. We do not intentionally collect sensitive personal information through site search. Search queries are treated as analytics data subject to this privacy policy. Do not enter passwords, government identifiers, or other sensitive personal data into the site search field.
Contact
Privacy questions and data subject requests: hello@verasity.ai.
Questions? Contact hello@verasity.ai.