Notice Details
Track the current public policy version and contact path.
Scope
This policy covers public sites, hosted service use, and customer-facing support paths.
- VeridataOps public websites and product pages.
- Hosted VeridataOps application environments operated by VeridataOps.
- Customer communications, account administration, and support interactions.
- Customer-facing documentation and review packets that explain how data is handled.
Roles
Controller and processor roles depend on the service surface.
- VeridataOps generally acts as controller for website visitors, sales contacts, billing contacts, and support contacts whose data it collects directly.
- VeridataOps generally acts as processor or service provider for tenant data processed inside the hosted service on behalf of a customer.
- Customer-managed and OEM deployments shift more processing control to the operating customer or partner outside VeridataOps-hosted support or release work.
Data Categories
The public privacy notice should identify the main data categories involved.
- Account and profile data such as name, email address, role, tenant association, and authentication state.
- Commercial and support data such as company, billing contact, support requests, meeting notes, and product-review context shared directly with VeridataOps.
- Service and operational data such as logs, job history, review activity, release evidence, audit artifacts, and tenant configuration records needed to operate the hosted service.
- Customer-authorized source, destination, and estate data that a hosted tenant chooses to collect, review, commit, or export through the product.
Data Use
VeridataOps uses data only for documented service purposes.
- Providing and securing the hosted service.
- Authenticating users and enforcing tenant access controls.
- Collecting, reviewing, and presenting customer-authorized operational evidence.
- Providing support, release, billing, security, and service communications.
- Meeting legal, contractual, security, accounting, or audit obligations.
Security And Transfers
Public privacy wording should describe the protection boundary and transfer caveats.
- VeridataOps uses tenant-aware access controls, authenticated access paths, review provenance, and deployment-appropriate infrastructure protections to reduce unauthorized access and misuse.
- International transfers, region choices, and subprocessor locations depend on the active hosted package or customer deployment and may require contract-specific terms such as SCCs or equivalent transfer safeguards.
- Formal security guarantees still depend on the exact audited deployment, release version, and enabled infrastructure controls.
Rights And Requests
Rights requests should have a named route on the public notice.
Controller-side privacy questions and rights requests can be routed through privacy@veridataops.com. VeridataOps may need to verify identity, confirm the relevant service surface, and distinguish controller-side data from tenant data processed on a customer's behalf before action is taken.
Where VeridataOps acts as processor, the request may need to route through the customer controller first so the customer can instruct the action on the relevant tenant data.
- Controller-side requests may include access, rectification, erasure, restriction, objection, portability, or a request to withdraw a previously given consent where consent is the lawful basis.
- VeridataOps may need enough information to locate the relevant records, verify identity, and determine whether the request concerns controller-side records or tenant data processed for a customer.
- Individuals in the EEA, UK, or other applicable regions may also have the right to complain to their local supervisory authority if they believe controller-side handling is unlawful.
Profiling And Automation
Public privacy wording should disclose the limited profiling and automated-decision position.
VeridataOps does not use public-site, account-contact, or hosted-service support data for solely automated decisions that produce legal or similarly significant effects on an individual.
Controller-side analytics, abuse prevention, and product-usage review may involve limited segmentation or event analysis, but those activities are used to operate, secure, and improve the service rather than to build advertising profiles or automated eligibility decisions.
Next Step
Use the live public surface as the review artifact.
When a customer or reviewer needs product-safe wording, point them at these URLs on veridataops.com and then attach deployment-specific evidence separately.