This policy explains how Verigrey collects, uses, and protects the personal data we control as part of our website, marketing, sales, and account-management activities.
Verigrey Inc. ("Verigrey," "we," "our," or "us") provides an AI agent security and policy-compliance testing platform. This policy explains how we collect, use, and protect personal data for which we act as the data controller — meaning data we collect through our website, marketing, sales, and account-management activities.
We are committed to handling personal data in accordance with applicable data-protection laws, including Singapore's Personal Data Protection Act (PDPA), the EU and UK General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA/CPRA), as applicable to you.
Privacy contact: Privacy Team, legal@verigrey.com
This policy applies to personal data we collect as a controller. It does not apply to personal data contained in the systems, agents, or datasets that customers submit to our platform for testing — for that data, the customer is the controller and Verigrey acts as a processor under the Data Processing Addendum in the customer agreement.
| Category | Examples | Required? |
|---|---|---|
| Identity data | First/last name, job title, company | Yes, for account creation / demo requests |
| Contact data | Business email, phone number | Yes, for communication |
| Authentication data | Login credentials, session tokens, access logs | Automatic, for security |
| Technical & usage data | IP address, browser type, device, pages visited, timestamps, interaction data | Automatic |
| Marketing & preference data | Communication preferences, event/webinar registrations | Optional |
| Communication content | Support tickets, sales enquiries, messages you send us | Only when you contact us |
We do not intentionally collect special-category/sensitive personal data (e.g., health, race, religion, biometrics) through our website or sales process. Please do not submit such data to us via the Site.
| Purpose | Legal basis (GDPR) / PDPA basis | Retention |
|---|---|---|
| Create and manage accounts; authenticate users | Contract / performance of service | Until deletion requested |
| Respond to demo requests, sales, and support enquiries | Legitimate interests / consent | 3 years after last activity |
| Send product updates and marketing (with opt-out) | Legitimate interests / consent (opt-in where required) | Until unsubscribe + 30 days |
| Analyze and improve the website and services | Legitimate interests | 24 months rolling |
| Secure our systems; detect and respond to threats | Legitimate interests / legal obligation | 12 months |
| Comply with legal, accounting, and regulatory obligations | Legal obligation | As required by law |
Where we rely on legitimate interests, our interest is in operating, improving, marketing, and securing our business, balanced against your rights. Where we rely on consent, you may withdraw it at any time. We do not use your personal data for automated decision-making that produces legal or similarly significant effects, and we do not sell your personal data.
We use cookies and similar technologies for essential site functionality, security, and analytics. You can manage non-essential cookies through our cookie banner or your browser settings at any time. We do not use third-party advertising cookies or engage in cross-context behavioral advertising.
We share personal data with trusted third-party service providers ("subprocessors") who process it on our behalf under written agreements imposing appropriate data-protection obligations, including:
| Provider | Purpose | Location | Safeguard |
|---|---|---|---|
| Cloud infrastructure (Vercel, AWS) | Hosting, compute, storage | USA | SCCs / DPF |
| Analytics provider | Product/website analytics | USA | SCCs |
| CRM provider | Sales and marketing | USA | SCCs / DPF |
| Email provider | Transactional & marketing email | USA | SCCs |
| Support tooling | Customer support | USA | SCCs / DPF |
We may also disclose personal data where required by law, regulation, court order, or legal process, or to protect our rights, your safety, or the safety of others; and in connection with a merger, acquisition, financing, or sale of assets (subject to confidentiality).
We are based in the United States, with an affiliated office in Singapore, and may transfer and process your personal data in both jurisdictions and with subprocessors located elsewhere. Where we transfer personal data from the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards — including the EU Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum (IDTA), and/or subprocessors' Data Privacy Framework (DPF) certifications. For transfers under PDPA, we take reasonable steps to ensure a comparable standard of protection. You may request details of the safeguards in place.
We retain personal data only as long as necessary for the purposes described above (see the table in Section 4), after which we securely delete or anonymize it, unless a longer period is required by law (e.g., tax or accounting records). On a valid deletion request, we delete or anonymize your data within 30 days, subject to legal retention requirements.
We implement appropriate technical and organizational measures to protect personal data, including encryption in transit and at rest, access controls, logging, and incident-response procedures. We are pursuing SOC 2 Type II and ISO 27001 certification. No system is completely secure; if we become aware of a personal-data breach that affects you, we will notify you and the relevant authorities as required by applicable law (including the PDPA and GDPR breach-notification requirements).
If you are in the EEA, UK, or Switzerland (GDPR): you have the rights of access, rectification, erasure, restriction, portability, objection (including to direct marketing), and withdrawal of consent. We respond within the statutory period (generally 30 days). You may lodge a complaint with your local supervisory authority.
If you are in Singapore (PDPA): you have the right to access and correct your personal data and to withdraw consent to its collection, use, or disclosure. You may contact our privacy contact above; you may also contact the Personal Data Protection Commission (PDPC).
If you are in California (CCPA/CPRA): you have the right to know, delete, correct, and opt out of the "sale" or "sharing" of personal information (we do not sell or share for cross-context behavioral advertising), and the right to non-discrimination for exercising your rights.
To exercise any right, contact legal@verigrey.com. We will verify your identity before responding.
Our website and services are directed to businesses and professionals and are not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe we have, contact us and we will delete it.
We may update this policy to reflect changes in our practices or applicable law. Material changes will be posted here with a revised "Last updated" date and, where required, notified to you directly.
Privacy questions or to exercise your rights: legal@verigrey.com
Complaints (EEA/UK): your local supervisory authority. Singapore: the PDPC. California: as set out above.