The Trust Operations Platform — compliance automation that doesn’t stop at SOC 2. See how it opens deals →
Legal

PRIVACY POLICY

Version 2.0 · Effective 1/1/2025 · Last updated 5/18/2026

Verisq Inc. ("Verisq," "we," "us," or "our") respects your privacy. This Privacy Policy describes how we collect, use, disclose, and protect personal information when you interact with us through our website at verisq.ai and related domains (the "Site"), our enterprise software products (the "Services"), and our business operations.

This Policy applies to two distinct relationships:

  • As a controller of personal information you share with us directly — for example, when you request a demo, sign up as a customer, contact us, or visit our website. The bulk of this Policy addresses this relationship.
  • As a processor of personal information our customers configure within our Services on behalf of their own end users. When Verisq acts as a processor, our customer is the controller and their privacy notice governs their end users. The Verisq Data Processing Agreement governs that relationship; see § 13.

If you are an end user of a website or service that uses Verisq products (such as a website displaying a CookiePLUS consent banner), please refer to that website's own privacy notice. We process your information only as instructed by that operator.

1. Who we are

Verisq Inc. is a Delaware corporation with principal offices in Alpharetta, Georgia, United States. We provide governance, risk, compliance, third-party risk management, privacy operations, and threat intelligence software products including the Verisq platform, LiveThreat, CookiePLUS, and DNBL.

Contact information:

2. Personal information we collect

We collect personal information in three principal ways: information you provide to us, information collected automatically, and information from third parties.

2.1 Information you provide

  • Account and contact information: name, business email address, business phone number, job title, company name, and the contents of any messages you send us.
  • Demo and sales inquiry information: company size, role, technology stack, areas of interest, and any other information you choose to share during sales conversations.
  • Customer relationship information: billing contact, technical contact, security contact, contract terms, and payment information processed through our payment processor (we do not store full card numbers).
  • Support and feedback: information you provide when contacting support, submitting feedback, or participating in surveys.
  • Event participation: if you attend our webinars, conferences, or trainings, we receive registration information and attendance records.

2.2 Information collected automatically

When you visit the Site or use the Services, we collect information automatically through cookies and similar technologies. See our Cookie Policy for the complete list of cookies and tracking technologies used. The categories include:

  • Device and browser information: IP address, browser type, operating system, device identifiers, and screen resolution.
  • Usage information: pages visited, time on page, navigation paths, referring URLs, and search terms used to find us.
  • Service usage: within our Services, we collect logs of feature usage, errors encountered, and configuration choices made by your administrator users.

2.3 Information from third parties

  • Marketing and enrichment data: we may receive company-level firmographic data (industry, size, location) from B2B data enrichment providers to qualify prospects.
  • Publicly available sources: professional networking platforms (LinkedIn), company websites, and industry publications.
  • Referrals and partners: if you are referred to us by a partner or existing customer, we may receive your contact information from them.
  • Authentication providers: if you sign in with single sign-on, we receive the information your identity provider releases (typically name and email).

We do not knowingly collect special categories of personal data (such as health information, biometric data, or information about religious or political beliefs) about visitors to our Site or contacts in our sales pipeline. Our Services may process such data on behalf of our customers when configured by them; that processing is governed by our Data Processing Agreement.

3. How we use your information

We use personal information for the following purposes, each tied to a specific legal basis where required by law (see § 4).

PurposeExamples
Providing the ServicesAuthenticating users, delivering features, processing transactions, maintaining records
Customer supportResponding to inquiries, troubleshooting, providing training
Sales and marketingResponding to demo requests, sending product updates and newsletters (with consent where required), running events and webinars, measuring marketing effectiveness
Improving our productsAnalyzing usage patterns, prioritizing features, fixing defects, improving documentation
Security and fraud preventionDetecting and preventing unauthorized access, abuse, malware, and other security incidents
Legal and complianceComplying with our legal obligations, responding to lawful requests, enforcing our agreements, defending against claims
Business operationsBilling, accounting, auditing, financial reporting, corporate transactions

We do not sell personal information for monetary consideration. We do not engage in cross-context behavioral advertising. We may share aggregated, de-identified, or anonymized data publicly without restriction.

4. Legal bases for processing (EEA, UK, Switzerland)

Where the General Data Protection Regulation (GDPR), UK GDPR, or Swiss FADP applies, we rely on the following legal bases:

  • Contract — to provide the Services to customers and respond to their requests (Art. 6(1)(b))
  • Legitimate interests — to operate our business, market to prospects in a B2B context, secure our systems, and improve our products, provided those interests are not overridden by your rights (Art. 6(1)(f))
  • Consent — for non-essential cookies, marketing emails where required, and any optional features clearly marked as consent-based (Art. 6(1)(a))
  • Legal obligation — to comply with applicable laws (Art. 6(1)(c))

You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal. For processing based on legitimate interests, you have the right to object (see § 6).

5. How we share information

We do not sell personal information. We share personal information only as described below.

5.1 Sub-processors and service providers

We engage trusted third parties to operate our business. Each is contractually bound to confidentiality and security obligations consistent with this Policy. Categories include:

  • Cloud hosting and infrastructure (Microsoft Azure)
  • Email delivery (Azure Communication Services)
  • Customer relationship management (HubSpot)
  • Marketing automation (HubSpot)
  • Analytics (Google Analytics 4)
  • Payment processing (Stripe, PayPal)
  • Customer support tooling (Zoho)

Our complete and current sub-processor list is published at verisq.ai/sub-processors and updated when changes occur.

5.2 Business transfers

If Verisq is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction. We will notify affected individuals where required by law.

5.3 Legal requirements

We may disclose personal information to comply with legal obligations, respond to lawful requests by public authorities, protect our rights and safety, prevent fraud or abuse, or enforce our terms. We push back on overbroad government demands and publish transparency information when permitted.

5.4 With your direction

Where you direct us to share information — for example, when you connect a Verisq product to a third-party integration — we share according to your direction.

6. Your rights

Depending on where you live, you may have rights regarding your personal information. Verisq honors these rights for all individuals regardless of jurisdiction, except where local law specifies otherwise.

6.1 Rights available

  • Access — request a copy of the personal information we hold about you
  • Rectification / correction — request correction of inaccurate or incomplete information
  • Deletion / erasure — request deletion of your personal information, subject to legal retention requirements
  • Portability — receive your personal information in a structured, commonly used, machine-readable format
  • Restriction — request limitation of processing in specific circumstances
  • Objection — object to processing based on legitimate interests, including direct marketing
  • Withdraw consent — withdraw consent at any time for processing based on consent
  • Opt out of sale or sharing — under US state laws, opt out of "sale" or "sharing" of personal information (we do not sell or share for cross-context behavioral advertising, but you may submit a request to confirm)
  • Limit use of sensitive personal information — under California law, request limitation on use of sensitive personal information
  • Non-discrimination — exercise your rights without discriminatory treatment
  • Right to appeal — appeal our decisions on your rights requests under applicable US state laws

6.2 How to exercise your rights

Submit a request through our Privacy Portal at verisq.ai/privacy-portal. The portal supports four primary request types: Access, Correction, Erasure, and Consent Management.

You may also email privacy@verisq.ai. We will verify your identity before fulfilling any request and respond within the timeframes required by applicable law (typically 30 days under GDPR, 45 days under CCPA, with extensions where permitted).

You may designate an authorized agent to submit requests on your behalf. We will require evidence of the agent's authority.

6.3 Global Privacy Control and other universal opt-out signals

We honor Global Privacy Control (GPC) signals received via your browser. When we detect a GPC signal from a resident of California, Colorado, Connecticut, Texas, Oregon, Delaware, New Jersey, New Hampshire, or other states recognizing universal opt-out signals, we treat it as a valid opt-out request for sale and sharing under those laws.

6.4 Complaints

If you believe we have not addressed your concerns, you have the right to lodge a complaint with a supervisory authority. In the EEA, this is typically your local Data Protection Authority. In the United Kingdom, the Information Commissioner's Office (ico.org.uk). In Switzerland, the Federal Data Protection and Information Commissioner (edoeb.admin.ch). For California residents, the California Privacy Protection Agency (cppa.ca.gov).

We encourage you to contact us first so we can address your concerns directly.

7. International transfers

Verisq is headquartered in the United States and our Services are hosted in Microsoft Azure data centers, principally in the United States. When we transfer personal information from the European Economic Area, United Kingdom, or Switzerland to the United States or other countries, we rely on:

  • EU-US Data Privacy Framework and its UK Extension and Swiss-US framework
  • Standard Contractual Clauses (EU Commission Decision 2021/914) and the UK International Data Transfer Addendum, supplemented by appropriate technical and organizational measures
  • Transfer Impact Assessments conducted in accordance with EDPB guidance

A copy of the relevant Standard Contractual Clauses is available on request to privacy@verisq.ai. EU customers operating through our Services should consult the Data Processing Agreement for transfer mechanisms applicable to processor-side processing.

8. Data retention

We retain personal information only as long as necessary for the purposes for which it was collected, plus any period required by law or our legitimate business needs.

CategoryTypical retention
Customer account recordsTerm of the customer relationship plus 7 years
Sales inquiry records24 months from last interaction
Marketing contact recordsUntil you unsubscribe or request deletion
Website analytics26 months (Google Analytics default)
Support tickets5 years from closure
Financial and tax records7 years (US tax law)
Security logs13 months
Backups90 days

After retention periods expire, we delete or de-identify personal information using methods designed to prevent recovery.

9. Security

We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, alteration, disclosure, and destruction. These include:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Multi-factor authentication for employee access to production systems
  • Role-based access control and least-privilege principles
  • Continuous security monitoring and incident response procedures
  • Annual penetration testing and security audits
  • Employee security awareness training
  • Background checks for employees with access to sensitive data
  • SOC 2 Type II audited controls (Security, Privacy, Confidentiality, Availability)

No method of transmission or storage is 100% secure. We work hard to protect your information but cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and applicable regulators as required by law.

10. Children

Our Site and Services are intended for business use and not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe we have inadvertently collected such information, please contact privacy@verisq.ai so we can delete it.

11. California-specific disclosures

If you are a California resident, the California Consumer Privacy Act (as amended by the California Privacy Rights Act) provides specific rights and requires specific disclosures. The categories of personal information we collect, the purposes for which we use them, and the categories of third parties to whom we disclose information are described throughout this Policy. The following table summarizes for California purposes:

CCPA CategoryCollected?SourcesPurposesDisclosed to
IdentifiersYesDirect, automatic, third partiesService delivery, marketing, securitySub-processors
Customer recordsYesDirectService delivery, billingSub-processors
Commercial informationYesDirect, automaticService delivery, billing, analyticsSub-processors
Internet/network activityYesAutomaticAnalytics, securitySub-processors
Geolocation (approximate)YesAutomatic (IP-derived)Localization, securitySub-processors
Professional/employment informationYesDirect, third partiesSales and marketingSub-processors
InferencesLimitedDerivedMarketing, segmentationSub-processors
Sensitive personal informationNo
Biometric, genetic, healthNo

We do not sell personal information and do not share personal information for cross-context behavioral advertising. We retain personal information for the periods described in § 8.

To exercise your rights, submit a request through verisq.ai/privacy-portal. To exercise the right to opt out of sale and sharing (which we already do not engage in), submit a request labeled "Do Not Sell or Share My Personal Information" via the same portal or email privacy@verisq.ai. We also honor Global Privacy Control signals automatically.

Right to appeal: If we decline your request, you may appeal by emailing privacy-appeals@verisq.ai. We will respond within 60 days.

Authorized agent: A person you designate may submit requests on your behalf. We will verify the agent's authority and your identity before fulfillment.

12. Other US state privacy laws

We provide equivalent rights to residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Tennessee, Indiana, Florida, Delaware, New Hampshire, New Jersey, Maryland, Minnesota, Rhode Island, Nebraska, Kentucky, and other states with applicable privacy laws. Requests are processed through verisq.ai/privacy-portal under the framework most protective of your rights.

13. When Verisq acts as a processor

For our customers, Verisq processes personal information about their end users only on the customer's instructions. The Verisq Data Processing Agreement governs that processing and includes:

  • Defined processing purposes limited to delivering the contracted Services
  • Sub-processor obligations with flow-down requirements
  • Standard Contractual Clauses for international transfers where applicable
  • Security obligations consistent with industry standards
  • Breach notification obligations
  • Assistance with data subject rights requests directed to the customer
  • Audit rights

End users of customer services should direct privacy inquiries to the customer (the controller). Verisq will redirect end-user requests received directly to the appropriate customer where we can identify them, or respond with general guidance otherwise.

14. Cookies and tracking

For details on the cookies and similar technologies used on our Site, see our Cookie Policy. You can manage your cookie preferences at any time through our cookie banner. We honor Global Privacy Control signals as described in § 6.3.

15. Third-party links

Our Site may contain links to third-party websites or services not controlled by Verisq. We are not responsible for the privacy practices of those third parties. Please review their privacy notices before providing information to them.

16. Changes to this Policy

We may update this Policy from time to time. The "Last updated" date at the top reflects the most recent revision. We will post material changes on our Site and, where required by law, notify you directly. Continued use of the Site or Services after the effective date of changes constitutes acceptance, except where applicable law requires renewed consent.

17. Contact us

For any questions about this Privacy Policy or our privacy practices:

Email: privacy@verisq.ai
Privacy Portal: verisq.ai/privacy-portal
DPO inquiries: dpo@verisq.ai

We aim to respond to all inquiries within 5 business days.