Privacy
Privacy policy
VERIS is a product operated by Recrucial AB, Sweden. This policy explains how we handle personal data when you visit or use VERIS.
Effective 4 August 2026
Who is responsible
Recrucial AB is the controller for account, billing, website, and support data used to operate VERIS. When customers send AI request data through VERIS, the customer determines the purpose of that processing and Recrucial AB acts as a service provider or processor. Contact privacy@veris.digital for privacy matters.
Data we collect
We collect account and profile details, organization membership, billing and subscription records, support messages, security and audit events, provider configuration metadata, and technical request records such as model, token count, cost, latency, outcome, and timestamps. Provider credentials are stored in protected systems and are not displayed again after entry. AI request content may be processed when you configure VERIS to proxy it.
For single AI requests routed through VERIS, we store request metadata rather than prompt or response content. For multi-step and document workflows, intermediate execution data, which can include extracted text, model output and generated vectors, is stored so a run can complete and be inspected afterwards. We are actively reducing what those workflows retain.
Why we use it
We use data to provide and secure the service, authenticate users, process payments, route AI requests, calculate usage and costs, generate recommendations, respond to support, prevent abuse, and meet legal obligations.
Our principal legal bases in the UK and EEA are performance of a contract, legitimate interests in operating and protecting VERIS, compliance with law, and consent where required.
Providers and international processing
VERIS relies on infrastructure, authentication, email, payment, and customer-selected AI providers. Data may be processed outside your country. Where required, Recrucial AB uses appropriate transfer safeguards. A customer controls which AI providers receive its request data and should review those providers' terms and regional settings.
Retention and deletion
VERIS does not currently run an automated retention or purge schedule. Account records, billing records, AI request metadata, execution records, support messages and security events remain stored until they are deleted on request or until we introduce a published retention schedule. We are not stating a fixed retention period for any of these categories, because no mechanism enforces one today.
Deletion is handled manually. Email privacy@veris.digital to request deletion of a workspace, an organization or an account. We do not currently commit to a completion timeframe, and some records must be kept where law, financial obligations, fraud prevention or dispute resolution require it. This section will be updated when automated retention and deletion are in place.
Cookies and local storage
VERIS uses necessary browser storage for authentication, theme, interface preferences, and application context. We do not currently use third-party advertising or behavioral analytics cookies. If that changes, this policy and any required consent controls will be updated first.
Your rights
Depending on your location, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent. Email privacy@veris.digital. We may verify identity before acting. You may also complain to the Swedish Authority for Privacy Protection or your local regulator.
Changes
Material changes will be dated on this page and communicated where required. Continued use after an effective change is governed by the updated policy, subject to rights that cannot legally be waived.