Veracly
Privacy

Hoe Veracly omgaat met je gegevens.

RR Sols Pty Ltd, handelend als Veracly, is verwerkingsverantwoordelijke voor persoonsgegevens die via veracly.app en het platform worden verwerkt. Deze pagina legt uit wat we verzamelen, waarom en welke rechten je hebt.

Laatst bijgewerkt: 2026-08-21

Dit document wordt momenteel afgerond door onze juridisch adviseur.

De structuur en intentie hieronder geven aan wat elke sectie zal behandelen. Tot de juridisch adviseur de definitieve formulering goedkeurt, is dit puur informatief, niet juridisch bindend. Voor specifieke vragen schrijf naar legal@veracly.app.

Veracly is een B2B-SaaS die publiek toegankelijke webpagina's scant op compliance-issues. We verwerken beperkte persoonsgegevens, namen, zakelijke e-mails, factuuradressen en audit-logs. We verkopen je gegevens niet.

  1. 01

    Wie we zijn

    RR Sols Pty Ltd (ABN 56 672 722 486, ACN 672 722 486), handelend als Veracly. Statutaire zetel: 136 Arthur Allen Drive, Bardia, NSW 2565, Australië. Bestuurder en bevoegd vertegenwoordiger: Purushotham Reddy Pamuluru.

  2. 02

    AVG-vertegenwoordiger voor de EU en het VK

    Aangezien RR Sols Pty Ltd niet in de EU of het VK is gevestigd, hebben wij vertegenwoordigers aangesteld op grond van artikel 27 AVG en artikel 27 UK GDPR. EU-inwoners kunnen contact opnemen met onze EU-vertegenwoordiger: Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Wenen, Oostenrijk. Inwoners van het VK kunnen contact opnemen met onze UK-vertegenwoordiger: Prighter Ltd, 20 Mortlake High Street, Londen, SW14 8JN, Verenigd Koninkrijk. Om uw rechten als betrokkene uit te oefenen of een klacht in te dienen, kunt u een verzoek indienen via het Prighter-portaal: https://app.prighter.com/portal/11399422438. Vermeld a.u.b. ID-11399422438 in alle correspondentie.

  3. 03

    How we use personal data, five activities

    We process personal data in five distinct activities, each with its own legal basis, data categories, and retention window. The numbered sections below are the Art. 13/14 GDPR records for each activity, together with a note, among them, on personal data that appears on the sites we scan. Cross-cutting matters, automated processing, retention, your rights, international transfers, and security, come after those.

  4. 04

    Activity 1, veracly.app visitors

    Data processed: daily-rotated hashed IP address (not stored raw), browser metadata, page views, referrer, and contact-form submissions (name, email, message, only if you use the form). Purpose: serve the site, respond to enquiries, and monitor performance. Legal basis: Art. 6(1)(f) legitimate interest (site operation and cookieless aggregate analytics). We use first-party, server-side request logging only, no third-party analytics, no cookies, no device fingerprinting, no consent required. Our legal pages (this page, the imprint, and the DPA) display a certificate-of-representation badge loaded from app.prighter.com, so viewing one of them discloses your IP address and browser metadata to our Article 27 representative; no cookie is set. Contact-form data retained 24 months then deleted; performance logs rotated within 30 days. Recipients: Hetzner Online GmbH (hosting, Helsinki, Finland, EU); Prighter EU Rep GmbH and Prighter Ltd (our Article 27 representatives, Vienna and London), for that badge request and for anything you send through their portal. Complaint right: your national supervisory authority or the Austrian DSB (competent for our EU representative).

  5. 05

    Activity 2, free-scan requesters

    Data processed: email address you enter at scan time, scanned domain, scan timestamp, IP address at request time, and scan findings (public page content only, no account is created). Purpose: run the requested scan, enforce the one-free-scan-per-email-per-7-days rate limit, detect and prevent abuse. Legal basis: Art. 6(1)(f) legitimate interest in providing the scanning service you requested, for the scan itself; Art. 6(1)(f) legitimate interest for rate-limiting and abuse prevention. Retention: the ledger that enforces the rate limit (your email address and the request timestamp) is deleted after 30 days; the free PDF report and its verification record after 60 days; the scan record and its findings age out on the same 12-month window as any other scan. Recipients: Hetzner Online GmbH (hosting and worker compute, Helsinki, Finland, EU); Mistral AI (plain-English explanations for a limited number of findings, France, EU; we send only technical violation data and a short HTML snippet); Resend, Inc. (delivery of the report email, US, SCCs). If, and only if, you tick the optional marketing box when you request the scan, we send you one follow-up email about our paid plans, on the basis of your consent (Art. 6(1)(a)); you can withdraw at any time via the unsubscribe link or by emailing privacy@veracly.app, and nothing further is sent. We do not sell your data and we do not share it for advertising purposes.

  6. 06

    Activity 3, outbound prospects (Art. 14 disclosure)

    If you receive an outreach email from puru@veracly.app: your contact details were collected from your organisation's own website or from a publicly accessible business directory, not from you. We contact business addresses only — a named work address at an organisation, or a generic inbox such as info@ or office@. We do not send outreach to personal email addresses, and we do not send outreach to recipients in Germany. Data processed: business email address, organisation name, publicly visible domain, and one or more compliance findings from a crawl of your publicly accessible pages. Legal basis: Art. 6(1)(f) UK GDPR, and Art. 6(1)(f) GDPR where EU law applies — our legitimate interest in telling a business operator about a technical compliance finding on their own public website. Because we write to you at a business address for which your organisation, not you personally, is the subscriber, regulation 22 of the UK Privacy and Electronic Communications Regulations does not require your prior consent. Balancing test: the finding is self-verifiable in your browser's developer tools; you are contacted in your business capacity, not as a private individual; and the processing is limited to publicly available contact details and the findings themselves. Recipients: Microsoft (our mailbox provider, which carries the message); Hetzner Online GmbH (the unsubscribe endpoint and the suppression list, Helsinki, Finland, EU); and Prighter, if you raise your objection as a data-subject request through our Article 27 representative. Right to object (Art. 21): reply with any refusal wording, use the unsubscribe link carried in every outreach email, or email privacy@veracly.app. We stop immediately and remove you from the working list for that campaign. To make that permanent we add you to a suppression list we keep indefinitely. If you use the unsubscribe link, that list holds only a one-way cryptographic fingerprint of your address, not the address itself — enough to recognise it and drop it from every future list, but not enough for us to read it back or to contact you. If you object by reply or by email, we also keep the address, so that we can evidence that your objection was honoured. If you would like the rest of what we hold about you erased, or written confirmation, email privacy@veracly.app and we will do it. Retention: prospect records are held until you object, or 6 months from collection, whichever is earlier. That window is enforced by us purging the campaign working files, not by an automated job — prospect details are not stored in the Veracly application. Suppression-list entries are kept indefinitely, as described above. No profiling; no automated decision-making with legal or similarly significant effects. Historical note: an earlier outreach campaign to German recipients ceased on 11 June 2026; the prospect database and working files for it were erased on 11–12 June 2026, and the sent messages themselves are retained in our mailbox as a legal-defence record.

  7. 07

    Activity 4, account holders and paid customers

    Data processed: name, work email, organisation name, billing address, VAT ID, subscription tier, scan history, PDF reports, invoices, and payment-method metadata (Stripe handles card data; we never store raw card numbers). Purpose: deliver the scanning service, bill you, send service notifications, comply with tax obligations. Legal basis: Art. 6(1)(f) legitimate interest in providing our service to our customers; Art. 6(1)(c) legal obligation (tax records, Australian Corporations Act 2001). Retention: account data for the life of the account (you can delete at /account/profile); scan results 12 months after each scan; billing records 7 years (Australian tax-record obligation). Recipients: Hetzner Online GmbH (hosting, database, and object storage, Helsinki, Finland, EU); Mistral AI (report text generation, France, EU); Clerk, Inc. (authentication, US, SCCs); Resend, Inc. (transactional email, US, SCCs); Stripe Payments Europe, Ltd. (billing, Ireland/US, SCCs); Revenue Commissioners, Ireland (VAT OSS reporting, name, country, transaction amount only, no scan content). When you verify ownership of a domain we look up its DNS TXT record, and if our own resolver has not yet seen the record we repeat the query against the public resolvers operated by Cloudflare (1.1.1.1) and Google (8.8.8.8); those queries disclose the domain name you are verifying, and nothing else. If you enable Slack alerts on a Growth, Pro, or Agency plan, we post scan results to the Slack webhook you configure, and they are received by Slack Technologies LLC in the United States under Standard Contractual Clauses. The post contains the scanned domain, its per-jurisdiction scores and any drop since the last scan, and a time-limited link to the full PDF report — so anyone with access to that Slack channel can open the report, including any personal data the scanned pages contained. We stop posting as soon as you clear the webhook or your plan no longer includes Slack alerts. Complaint right: your national DPA or the Austrian DSB.

  8. 08

    Personal data on the sites we scan

    When you instruct the Service to scan a URL, the crawler reads publicly accessible pages and may incidentally encounter personal data published there — for example the names and contact details of employees on a contact page. We do not seek out personal data, and we do not build profiles from it. Be aware that we do retain part of what we find. Where a page fails a check, the finding keeps the offending HTML snippet and a CSS selector, and on paid scans sometimes a cropped screenshot of the element, because that evidence is what makes the report reproducible and independently verifiable. Where we cannot find a cookie banner, we also store a short diagnostic extract of those elements on the page whose markup or text mentions consent or a known consent tool, so a missed detection can be investigated. All of this is stored with the scan record and deleted on the same 12-month window. While a scan is running we capture page images so you can watch its progress; those are deleted as soon as the scan finishes. We do not retain a general copy of the pages we crawl. Where you are our customer and the scanned site is yours, we process this category of data as your processor under the Data Processing Addendum. Legal basis: Art. 6(1)(f), our legitimate interest in producing reports that are reproducible and independently verifiable. Source of the data: the publicly accessible page that was scanned. You may object at any time under Art. 21 by emailing privacy@veracly.app.

  9. 09

    Activity 5, subprocessor list

    Current subprocessors: Clerk, Inc. (authentication, US, DPA, SCCs); Hetzner Online GmbH (compute, database, and object storage, Helsinki, Finland, EU, processed in the EEA only); Mistral AI (AI text generation in scan reports, France, EU; we send only technical violation data and a short HTML snippet, no account or billing data); Prighter EU Rep GmbH and Prighter Ltd (our Article 27 GDPR and UK GDPR representative, Vienna and London; receives data-subject requests and hosts the certificate-of-representation badge shown on our legal pages); Resend, Inc. (transactional email, US, DPA, SCCs); Stripe Payments Europe, Ltd. (payment processing, Ireland/US, DPA, SCCs). Separately, and not as a subprocessor, we report your name, country, and transaction amount to the Revenue Commissioners in Ireland for OSS VAT filing, because a legal obligation requires it. Full list with effective dates is published at veracly.app/subprocessors. Changes to this list are published there and reflected in this policy; see “Wijzigingen aan dit beleid” below. Contractual notice and objection rights for subprocessor changes are set out in the Data Processing Addendum, which forms part of our Terms of Service.

  10. 10

    Geautomatiseerde verwerking en AI

    Een deel van de tekst in uw compliance-rapport, de uitleg in gewone taal bij overtredingen, de samenvatting, de aanbevolen oplossingen en de vertalingen naar de ondersteunde talen, wordt gegenereerd door een AI-model van Mistral AI (gevestigd in Frankrijk, EU), dat optreedt als sub-verwerker namens ons. We sturen de AI de technische gegevens van de overtreding en een kort HTML-fragment van het betrokken element; we sturen niet de naam van uw organisatie, contactgegevens of andere persoonsgegevens die wij van u bewaren. AI-gegenereerde teksten worden afgedekt door een deterministische fallback-tekst en als de AI niet beschikbaar is, vallen we automatisch terug op die tekst. Wij nemen geen besluiten met juridische of vergelijkbaar aanzienlijke gevolgen voor u (art. 22 AVG); u kunt menselijke beoordeling van een door AI geschreven passage aanvragen via privacy@veracly.app.

  11. 11

    How long we keep it

    We keep personal data only as long as it's needed for the purpose it was collected. Scan results, including findings, the underlying raw data, jurisdiction verdicts, and generated PDF reports, are deleted 12 months after the scan completed. Free-scan PDF reports and their cryptographic verification record are kept for 60 days (2 months) from issuance, then removed. AI-usage records (model name, token counts, cost) are kept for 24 months so we can answer billing or audit questions. Free-scan history (used to enforce the one-free-scan-per-email-per-7-days limit) is kept for 30 days. Public contact-form submissions are kept for 24 months for sales follow-up, then deleted. Account data, your profile, your organization, and the link to your authentication provider, is kept for the life of the account; you can delete it yourself any time from /account/profile or by emailing privacy@veracly.app. Billing records held by Stripe and our accounting software are retained for 7 years to meet Australian tax-record obligations on RR Sols Pty Ltd. A daily automated job enforces these windows. One record deliberately outlives them: the verification anchor for an issued paid report, which holds the report’s hash, its language, the issue date, and our signing-key identifier, but no page content and no personal data. It is kept with no expiry so that a report you have already shared stays independently verifiable, and it survives erasure of the underlying scan. Closed accounts: if you close your account rather than delete it, we keep its data so you can reopen, and erase it 12 months after closure. We email you before that happens.

  12. 12

    Your rights (Art. 15 - 22 GDPR)

    Access (Art. 15): obtain a copy of personal data we hold about you. Rectification (Art. 16): correct inaccurate data. Erasure (Art. 17): delete your data where no legal obligation requires retention, self-serve at /account/profile for account data. Restriction (Art. 18): pause processing while a dispute is resolved. Portability (Art. 20): receive account data in a machine-readable format. Object (Art. 21): object to processing on legitimate-interest grounds; we will cease unless we demonstrate compelling overriding grounds. Withdraw consent (Art. 7(3)): where consent is the legal basis, withdraw at any time without affecting prior processing. No solely automated decisions (Art. 22): we do not make decisions about you based solely on automated processing with legal or similarly significant effects. Lodge a complaint: contact your national supervisory authority, or for EU subjects the Austrian DSB (Datenschutzbehörde) as the authority competent for our EU representative Prighter EU Rep GmbH. To exercise any right, email privacy@veracly.app or use the self-service tools at /account. We respond within one month, extendable by two months for complex requests.

  13. 13

    International transfers and safeguards

    Veracly's application, API, background processing, database, object storage, and AI text generation all run within the European Union on infrastructure provided by Hetzner Online GmbH (Helsinki, Finland) and Mistral AI (France), both EU-based providers. EU customer data is stored in the EU. Australia does not have an EU adequacy decision. Where personal data of EEA data subjects is transferred outside the EEA to a third country lacking adequate data protection laws (including to RR Sols Pty Ltd's systems in Australia, for engineering access, audit, and finance), we use data processing and data sharing agreements that include the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), supplemented where necessary by further safeguards following a transfer impact assessment. Where personal data of UK data subjects is transferred outside the UK, we use data processing and data sharing agreements that include either the UK International Data Transfer Addendum to the EU SCCs or the UK International Data Transfer Agreement (IDTA), in either case supplemented where necessary by further safeguards following a transfer risk assessment. The remaining US-based subprocessors, Clerk (authentication) and Resend (transactional email), are covered by controller-to-processor SCCs under 2021/914 Module 2; payments contract through Stripe Payments Europe, Ltd. in Ireland, whose onward US transfers are covered by Module 3 of the same clauses. Our UK representative, Prighter Ltd, receives data in the United Kingdom, which benefits from a European Commission adequacy decision. Transfer impact assessments are conducted before engaging each non-adequate-country subprocessor. Copies of applicable SCCs and IDTAs are available on request from legal@veracly.app. For EU VAT compliance, RR Sols Pty Ltd is registered under the Non-Union OSS scheme in Ireland (EU372098920); transaction records required for VAT returns are reported to the Irish Revenue Commissioners as the OSS Member State of Identification.

  14. 14

    Hoe we gegevens beveiligen

    Versleuteling onderweg en in rust, rolgebaseerde toegangscontrole, audit-logging en periodieke pentesten. SOC 2 Type II is in voorbereiding.

  15. 15

    Wijzigingen aan dit beleid

    Materiële wijzigingen worden minstens 30 dagen vooraf per e-mail aangekondigd. Kleine wijzigingen worden weerspiegeld in de datum hierboven.

Geverifieerde vertegenwoordiging

Klik op een badge om onze aanstelling als vertegenwoordiger op grond van artikel 27 AVG en UK GDPR via Prighter te verifiëren.

GDPR Certification: Art 27 representation by PrighterUK-GDPR Certification: Art 27 representation by Prighter

powered by Prighter

Vragen over dit document?

Praat met ons juridisch contact.

Klant, prospect of FG met een specifieke vraag, of iets opgemerkt dat we moeten corrigeren? Stuur ons een bericht en we sturen het door naar het juiste team.

Hoe Veracly omgaat met je gegevens.