Legal CentreDocument
Privacy Notice
verinex.dev, the Verinex platform, and the Console at console.verinex.dev. It is written to the transparency expectations of the General Data Protection Regulation (Regulation (EU) 2016/679) and Irish data-protection law.Data controller
#The controller of personal data described in this notice is Prodia Systems Limited, established in Ireland. Where Prodia Systems Limited processes personal data on behalf of a customer of the Verinex platform as a processor, the customer is the controller and the terms of the Data Processing Addendum apply.
Scope of this notice
#This notice covers processing carried out in connection with the marketing website, access to the Console and use of the Verinex platform. It does not cover the practices of third parties whose services may be linked from the website or which a customer may configure alongside Verinex.
Categories of personal data
#Depending on the interaction, we may process the following categories:
- Contact and access-request information: name, organisation, work email address, role and information you provide when requesting access to Verinex or contacting us.
- Account and Console usage data: identifiers assigned to Authorised Users, authentication events, permission changes, actions taken in the Console and configuration values.
- Technical data: IP address, user-agent, device and browser characteristics, referrer, request logs, error diagnostics and similar telemetry collected when you interact with our systems.
- Cookies and similar storage: as described in our Cookie Policy.
- Customer-controlled data: personal data contained in Customer Inputs and Outputs handled by Verinex on behalf of a customer as a processor.
- Correspondence: content and metadata of enquiries and any related files you send us.
We do not intentionally collect special-category personal data through the website and do not use Verinex for such data without written agreement and safeguards.
Purposes and lawful bases
#We process personal data for the following purposes and on the following bases:
- To operate the marketing website — legitimate interests (Article 6(1)(f) GDPR) in publishing accurate information about Verinex and operating a functional website.
- To respond to enquiries and access requests — steps taken at the request of the person prior to entering a contract (Article 6(1)(b)) or legitimate interests in evaluating and progressing prospective business relationships.
- To provide and administer the Verinex platform — performance of a contract with the customer (Article 6(1)(b)) and, in respect of Authorised Users, legitimate interests in operating and securing the service.
- To secure our systems and prevent misuse — legitimate interests in security, service integrity and prevention of fraud and abuse.
- To comply with law — compliance with a legal obligation (Article 6(1)(c)).
- Cookies and analytics — consent where required, or legitimate interests for strictly necessary storage. See the Cookie Policy.
Sources of personal data
#We primarily receive personal data directly from you or from your organisation. We may also receive personal data from our processors, from public sources and, in respect of Customer Inputs, from the customer that has instructed us to process the data.
Recipients and processors
#We share personal data only where necessary for the purposes described above, including with: hosting, infrastructure, communications and analytics providers engaged as processors; professional advisers under confidentiality obligations; public authorities where required by law; and successors in the context of a corporate transaction, subject to appropriate protections. Our processors are listed in the Subprocessor Register as they are confirmed.
International transfers
#Where personal data is transferred outside the European Economic Area, we take steps to ensure that an appropriate level of protection is in place, using transfer mechanisms recognised under Chapter V of the GDPR (for example, standard contractual clauses and, where relevant, supplementary measures). Details of specific transfers and mechanisms will be published in the Subprocessor Register as they are confirmed.
Retention
#We retain personal data only for as long as necessary for the purposes for which it was collected, to comply with legal obligations, to resolve disputes and to enforce agreements. Retention periods vary by category of data and are being finalised.
Security
#We take appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing. See the Security and Trust statement for more information.
Automated decisions and profiling
#Verinex does not use personal data collected via the marketing website to make decisions with legal or similarly significant effects about individuals based solely on automated processing. Automated processing that forms part of the Verinex platform is carried out on behalf of the customer under the customer's control, in accordance with the Data Processing Addendum and the Responsible AI Policy.
Your rights
#Subject to conditions in law, you may have the following rights in relation to your personal data: access, rectification, erasure, restriction of processing, portability, objection to processing based on legitimate interests, objection to direct marketing, and withdrawal of consent where processing is based on consent. Exercising a right does not adversely affect other rights.
How to exercise your rights
#To exercise a right, please contact us using the details in the contact block below. We may need to verify your identity before responding, and we will respond within the statutory timeframe. If we are acting as a processor on behalf of a customer, we may direct your request to the relevant controller.
Right to complain
#You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. Our lead supervisory authority is the Data Protection Commission (Ireland) — https://www.dataprotection.ie.
Children
#Verinex is intended for use by organisations and their personnel, not by children. We do not knowingly collect personal data of children through the website or Console. If you believe a child has provided us with personal data, please contact us so we can take appropriate action.
Changes to this notice
#We may update this notice from time to time. The current version and effective date are shown at the top of this page and recorded in the Legal change log. Material changes will be signalled in an appropriate manner.
Contact
#Operator
Prodia Systems Limited
Public brand: Verinex — https://verinex.dev
Registered office
Pending verification
Company number
Pending verification
VAT number
Pending verification
Privacy contact
Pending verification