Using Veractly
Privacy notice
Veractly processes account and workflow information to provide its service. Your organization manages the workspace you use and determines which business data and connected systems it brings into Veractly.
Information processed
This includes your account identity, such as name and email address, organization membership and permissions, and the transactions, policies, connector settings and evidence submitted to your workspace. Service infrastructure also processes request and diagnostic information to deliver the site and investigate errors or misuse.
How information is used
Information is used to authenticate users, enforce access permissions, carry out authorized workflows, display and verify outcomes, maintain audit records, and operate and troubleshoot the service. Workspace access depends on your organization’s permissions and configuration.
Service providers and connected systems
Veractly uses AWS infrastructure and WorkOS authentication. Connecting another service allows the information needed for your authorized operations to pass to and from that service. Those providers have their own privacy terms and data practices.
Cookies and browser storage
Sign-in uses session mechanisms, including cookies and temporary browser storage, to complete authentication and return you to your requested page. The console also keeps workspace selections so you can navigate within the selected organization, project and environment.
Analytics and diagnostics
Public information pages use Google Analytics. Authentication pages and workspace pages do not load the Google tag. If you enter those pages after visiting a public page, Google Analytics collection is disabled for the rest of that browser document. Public page measurements use page paths rather than URL query values or document titles.
PostHog records selected product events and pseudonymous identifiers. Sentry records sanitized errors and performance information. Session replay is disabled. These tools help us understand service use and investigate problems; workspace evidence and form values are excluded from the event fields the application sends.
Workspace controls and requests
Contact your organization’s workspace administrator about your access or business data. Authorized administrators can review the available retention, export and deletion controls in workspace settings. Retention rules, legal holds, backups and unresolved safety work can affect what may be deleted and when. Submitting a request does not mean deletion has completed.