VERA operates a talent intelligence platform that helps organizations evaluate candidates using structured reference data and AI-assisted analysis. This Privacy Policy explains what personal data we collect, where it comes from, why and how we use it, the roles we play (Controller and Processor), how we apply AI and profiling, how long we keep data, and the rights and choices available to you under the GDPR, UK GDPR, and other applicable data protection laws.
§ 01
01 — Who We Are & The Roles We Play
VERA ("VERA", "we", "us", "our") operates a talent intelligence platform that helps organizations evaluate candidates using structured reference data and AI-assisted analysis. Our role under data protection law depends on the data in question:
·Data Controller — for account, authentication, billing, platform usage, marketing, and support data, and for personal data of candidates who create their own VERA profile directly.
·Data Processor — for candidate and referee data processed on behalf of a recruiting organization (our customer), who is the Controller of that data.
·Joint arrangements — where responsibilities are shared, the relevant roles are set out in our customer agreement and Data Processing Agreement (DPA).
·Where we act as a Processor, we process personal data strictly on the documented instructions of the relevant recruiting organization and only for the purposes set out in our DPA.
·This Policy describes our practices as a Controller. Where a recruiting organization is the Controller, that organization's own privacy notice also applies and prevails for those activities.
§ 02
02 — Information We Collect
We collect the following categories of personal data depending on how you interact with the Service:
·Account Data — name, email address, password (stored only as a salted hash), role, organization, profile photo, and authentication identifiers (including Google or other single sign-on identifiers where applicable).
·Candidate Data — professional background, employment history, skills, role and seniority, self-assessments, and any information submitted as part of a candidate profile.
·Reference Data — the name and contact details of referees nominated by a candidate, the referee's stated relationship to the candidate, and structured responses, ratings, and written feedback submitted by referees.
·Derived & Inferred Data — behavioural insights, archetypes, confidence and consistency indicators, tradeoff maps, and comparison outputs generated by our analysis engine and AI systems from the data above.
·Usage & Device Data — IP address, approximate location derived from IP, device and browser information, operating system, log data, page and feature interactions, timestamps, and session/security event data.
·Billing Data — subscription, plan, and transaction records processed via third-party payment providers. We do not collect or store full payment card numbers.
·Communication Data — support requests, inquiry forms, and any communications you send to us.
·We do not intentionally collect special category data (see Section 16). Please do not submit it.
§ 03
03 — Where Personal Data Comes From
We obtain personal data from several sources. This Section satisfies our transparency duties under Articles 13 and 14 GDPR, including where we receive data about you from someone other than you:
·Directly from you — when you create an account, build a profile, complete a self-assessment, submit a reference, contact support, or otherwise use the Service.
·From candidates — referee names and contact details are provided to us by the candidate who nominates the referee. If you are a referee, you received a request because a candidate identified you as a past colleague, manager, or report.
·From referees — reference responses and feedback about a candidate are provided by the referees the candidate nominated.
·From recruiting organizations — customer administrators may add team members or candidates to a workspace.
·From authentication and integration providers — limited profile identifiers when you choose to sign in via a third party (e.g. Google).
·Automatically — usage, device, and log data generated as you interact with the Service.
§ 04
04 — How We Use Your Information
We use personal data for the following purposes:
·to provide, operate, and maintain the Service
·to create and authenticate accounts and manage organizational workspaces and seats
·to collect, validate, and structure reference data
·to generate candidate profiles, behavioural insights, and comparison views using our analysis engine and AI systems
·to support search, comparison, shortlisting, and evaluation workflows
·to process payments, subscriptions, badge unlocks, and enterprise seats
·to send service, transactional, security, and (where permitted) product communications
·to monitor, debug, secure, and improve platform performance and reliability
·to detect, investigate, and prevent fraud, abuse, and security incidents
·to comply with legal, regulatory, and contractual obligations and to establish, exercise, or defend legal claims
·We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not build advertising or marketing profiles.
§ 05
05 — Legal Bases for Processing (GDPR)
Where the GDPR or UK GDPR applies, we rely on one or more of the following legal bases, depending on the activity:
·Performance of a contract (Art. 6(1)(b)) — to provide the Service to account holders and recruiting organizations.
·Legitimate interests (Art. 6(1)(f)) — to operate, secure, debug, and improve the Service, to prevent fraud and abuse, to process referee data so candidates can build a verified profile, and to send relevant product communications to existing customers. We balance these interests against your rights and have carried out balancing assessments, available on request.
·Consent (Art. 6(1)(a)) — where required, for example certain reference collection flows, optional cookies/analytics, and non-essential marketing. You may withdraw consent at any time without affecting prior processing.
·Legal obligation (Art. 6(1)(c)) — where processing is required to comply with applicable law (e.g. tax, accounting, lawful requests).
·Where we act as a Processor, the relevant recruiting organization is responsible for establishing the legal basis for its processing.
§ 06
06 — Reference Data & Referees
Reference data is central to VERA and is handled with specific safeguards. References are nominated by the candidate and submitted voluntarily by referees who choose to respond.
·Candidates nominate their own referees and are responsible for ensuring they have a basis to share a referee's contact details with us.
·Referees are informed of who is collecting the data and why before they submit, and participation is voluntary.
·Reference responses are processed to generate structured, decision-support insights for the relevant organization.
·Reference data is accessible only to authorized users within the relevant organization and is never made publicly visible.
·Access is restricted using workspace isolation, role-based access controls, and audit logging.
·Referees may contact us to access, correct, or request deletion of the response they submitted (see Sections 13–14).
§ 07
07 — AI Processing, Profiling & Automated Decisions
VERA uses artificial intelligence systems, including large language models provided by third parties (such as Anthropic), to process reference and profile data into structured outputs such as summaries, behavioural insights, archetypes, and comparison views.
·These outputs are decision-support tools only. They are designed to assist human recruiters, not to replace human judgement.
·The analysis may involve profiling based on professional and reference data within the meaning of Article 4(4) GDPR.
·VERA does not make solely automated decisions that produce legal or similarly significant effects about a person within the meaning of Article 22 GDPR. Every hiring or evaluation decision is made by a human within the recruiting organization, who remains responsible for that decision.
·You may contact us or the relevant organization to obtain meaningful information about the logic involved at a general level, to express your point of view, and to contest an insight you believe is inaccurate.
·Personal data processed by these AI systems is used solely to provide platform functionality. We have contractual commitments that your personal data is NOT used to train third-party providers' general-purpose models.
§ 08
08 — Sub-processors & Data Sharing
We share personal data only with the categories of recipients necessary to operate the Service, and only to the extent required for their function:
·AI / LLM processing providers (e.g. Anthropic) — to generate insights from reference and profile data.
·Cloud hosting, database, and infrastructure providers — to host and operate the platform.
·Payment processors (e.g. SumUp) — to process subscriptions and one-off purchases.
·Authentication providers (e.g. Google, where you enable single sign-on) — to verify identity.
·Email and communication providers (e.g. Resend) — to send transactional and permitted product emails.
·Analytics and security/error-monitoring providers — to keep the Service reliable and secure.
·Professional advisers, auditors, and authorities — where required by law, or to establish, exercise, or defend legal claims, or in connection with a merger, acquisition, or asset sale (subject to this Policy).
·All sub-processors are bound by written data protection agreements imposing confidentiality and security obligations. A current list of sub-processors is available on request. We do not share personal data with data brokers or for advertising purposes.
§ 09
09 — International Data Transfers
We are based in, and primarily process data within, the European Economic Area (EEA). Some sub-processors may process data outside the EEA or UK.
·Where data is transferred outside the EEA/UK, we rely on an adequacy decision by the European Commission (or UK equivalent) where one exists.
·In the absence of adequacy, we implement appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), together with supplementary technical and organizational measures where needed.
·You may request a copy of the relevant safeguards by contacting us using the details in Section 21.
§ 10
10 — Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, after which it is deleted or anonymized. Our retention is guided by the following principles:
·Account & profile data — retained while the account is active.
·Candidate & reference data — retained for the duration of the relevant organization's use, or, for candidate-owned profiles, while the candidate maintains the profile.
·Deletion requests — after a deletion request, data is permanently removed following a 30-day grace period (during which the request can be cancelled by logging in), unless longer retention is legally required.
·Billing & tax records — retained for the period required by applicable financial and tax law (typically up to 6–10 years).
·Security, log, and audit data — retained for a limited period proportionate to security and fraud-prevention needs.
·Backups — residual copies in encrypted backups are overwritten on our standard backup rotation cycle.
·We may retain anonymized or aggregated data that can no longer identify you for analytics and product improvement without time limit.
§ 11
11 — Security
We implement appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, alteration, or disclosure, including:
·encryption in transit (TLS)
·passwords stored only as salted hashes; we never store plaintext credentials
·role-based access control and least-privilege access principles
·workspace isolation between organizations
·centralized authorization checks with deny-audit logging of sensitive actions
·regular review of access, dependencies, and security configuration
·internal access on a need-to-know basis under confidentiality obligations
·No method of transmission or storage is completely secure, so while we strive to protect your data, we cannot guarantee absolute security.
§ 12
12 — Cookies & Analytics
We use cookies and similar technologies to operate and improve the Service.
·Strictly necessary cookies — required to run the Service (e.g. authentication sessions, security, load balancing). These cannot be switched off.
·Analytics cookies — used, where permitted, to understand aggregate usage and improve the product.
·We do not use advertising or cross-site tracking cookies.
·You can control non-essential cookies through your browser settings or any cookie controls we provide. Disabling strictly necessary cookies may affect functionality.
§ 13
13 — Your Rights
Subject to applicable law (including the GDPR and UK GDPR), you have the following rights in respect of your personal data:
·Access — to obtain confirmation of, and a copy of, the personal data we hold about you.
·Rectification — to have inaccurate or incomplete data corrected.
·Erasure — to request deletion of your data ("right to be forgotten"), subject to legal retention requirements.
·Restriction — to limit how we process your data in certain circumstances.
·Portability — to receive certain data in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
·Objection — to object to processing based on legitimate interests, and to object at any time to any processing for direct marketing.
·Withdraw consent — at any time, where processing is based on consent, without affecting prior processing.
·Rights related to automated decision-making — as described in Section 07.
·Complaint — to lodge a complaint with a supervisory authority (see Section 22).
·We will not discriminate against you for exercising any of these rights.
§ 14
14 — How to Exercise Your Rights
We make it easy to exercise your rights:
·Self-service — candidates can export their data, delete their account, and remove individual references directly from within the Service.
·By contacting us — using the details in Section 21. We may need to verify your identity before acting on a request.
·Where VERA is a Processor — requests relating to data we process on behalf of a recruiting organization should be directed to that organization; we will assist them in responding as required by our DPA.
·Timing — we respond to verified requests within one month, which may be extended by two further months for complex or numerous requests, in which case we will inform you.
·Cost — requests are free unless they are manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or decline, as permitted by law.
§ 15
15 — Marketing & Communications
We send different categories of communication, with different controls:
·Service & transactional messages — account, security, billing, reference-request, and support messages. These are necessary to provide the Service and cannot be opted out of while you hold an account.
·Product & marketing messages — where permitted by law or with your consent, about features and offers. You can unsubscribe at any time via the link in each message or by contacting us.
·Opting out of marketing does not affect service or transactional messages.
§ 16
16 — Special Category & Sensitive Data
VERA is not designed to collect special category data (such as data revealing racial or ethnic origin, political opinions, religious beliefs, trade-union membership, health, sex life, sexual orientation, or biometric/genetic data) or data about criminal convictions.
·Candidates and referees should not submit special category or sensitive data in free-text fields.
·If such data is provided voluntarily and unsolicited, we process it only as necessary to operate the Service and will delete it where appropriate.
·We do not use special category data to generate insights or profiles.
§ 17
17 — Children's Privacy
The Service is intended for working professionals and is not directed to children. We do not knowingly collect personal data from individuals under 16 (or the applicable digital-consent age in your jurisdiction). If we become aware that we have collected data from a child without an appropriate legal basis, we will delete it promptly.
§ 18
18 — Data Breach Notification
We maintain procedures to detect, investigate, and respond to personal data breaches. Where a breach is likely to result in a risk to individuals' rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware where required, and we will notify affected individuals (or the relevant Controller, where we act as Processor) without undue delay where the law requires.
§ 19
19 — Anonymized & Aggregated Data
We may create anonymized and aggregated data that cannot reasonably be used to identify you (for example, platform-wide statistics, benchmarks, and product analytics). This data is no longer personal data and may be used and retained for any lawful business purpose, including improving and promoting the Service.
§ 20
20 — Changes to This Policy
We may update this Privacy Policy to reflect operational, legal, regulatory, or technical changes. The "Effective date" below indicates when it was last revised. Where changes are material, we will provide additional notice (for example, by email or an in-product notice) before they take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy where permitted by law.
§ 21
21 — Contact, DPO & EU Representative
For privacy inquiries, to exercise your rights, or to contact our Data Protection Officer:
·Email: privacy@vera-analysis.com
·Data Protection Officer: dpo@vera-analysis.com
·Postal and EU/UK representative details (where applicable under Article 27 GDPR) are available on request via the email above.
·We aim to resolve all inquiries promptly and in any event within the statutory timeframes.
§ 22
22 — Supervisory Authority & Complaints
If you are in the EEA or the UK and believe our processing of your personal data does not comply with data protection law, you have the right to lodge a complaint with your local supervisory authority. We would, however, appreciate the opportunity to address your concerns first — please contact us using the details in Section 21 before doing so.
Version history
Every change to this document is logged below for full transparency.
Version 1effective 2026-06-20
Initial publication.
addedInitial Privacy Policy published.
Effective date: June 16, 2026 · Privacy enquiries: privacy@vera-analysis.com · Data Protection Officer: dpo@vera-analysis.com