Legal

Privacy Policy

Last updated: 17 March 2026

This policy explains how VIAIS Group Limited collects, uses, and protects your personal data when you use VeroReport. We are committed to handling your data responsibly and in compliance with UK GDPR and the Data Protection Act 2018.

1. Who We Are

VeroReport is a trading name of VIAIS Group Limited, a company registered in England and Wales. We operate the VeroReport platform at www.veroreport.online. For the purposes of UK GDPR and the Data Protection Act 2018, VIAIS Group Limited is the data controller for personal data collected through this platform.

Contact: [email protected]

2. What Data We Collect

We collect and process the following categories of personal data:

Account data: your name, email address, and password (stored as a one-way hash) when you register for an account.

Usage data: pages visited, features used, session timestamps, and browser/device information collected automatically via server logs and analytics.

Content data: job descriptions, candidate CVs, interview notes, and hiring decision rationale that you upload or generate within the platform. This data is processed solely to provide the service and is never used to train AI models or shared with third parties.

Communications: if you contact us by email, we retain that correspondence.

3. How We Use Your Data

We process your personal data for the following purposes and legal bases:

To provide the VeroReport service — performance of a contract (Article 6(1)(b) UK GDPR).

To maintain account security and prevent fraud — legitimate interests (Article 6(1)(f) UK GDPR).

To send service-related communications (e.g. password resets) — performance of a contract.

To comply with legal obligations — legal obligation (Article 6(1)(c) UK GDPR).

We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.

4. Data Retention

Account data is retained for as long as your account is active. If you delete your account, your personal data is permanently deleted within 30 days, except where we are required to retain it by law (e.g. for tax or legal compliance purposes).

Hiring decision records and exports you create are retained until you delete them or close your account. We recommend you export and store records you need for compliance purposes before closing your account.

5. Data Sharing

We do not sell, rent, or trade your personal data. We may share data with:

Infrastructure providers: cloud hosting and database services used to operate the platform, bound by data processing agreements.

Payment processors: if you subscribe to a paid plan, payment is handled by our payment provider. We do not store full card details.

Legal authorities: where required by law, court order, or to protect the rights and safety of users or third parties.

We do not share candidate data, CVs, or hiring decision content with any third party for any purpose.

6. International Transfers

Your data is stored and processed within the United Kingdom and the European Economic Area. Where any transfer outside these regions is necessary, we ensure appropriate safeguards are in place in accordance with UK GDPR requirements, including standard contractual clauses.

7. Your Rights

Under UK GDPR, you have the following rights:

Right of access — to request a copy of the personal data we hold about you.

Right to rectification — to correct inaccurate or incomplete data.

Right to erasure — to request deletion of your personal data ("right to be forgotten").

Right to restriction — to request that we limit how we process your data.

Right to data portability — to receive your data in a structured, machine-readable format.

Right to object — to object to processing based on legitimate interests.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

8. Cookies

We use a single session cookie to keep you logged in. This cookie is strictly necessary for the service to function and does not track you across other websites. We do not use advertising cookies or third-party tracking cookies.

9. Security

We implement appropriate technical and organisational measures to protect your personal data, including encrypted data transmission (HTTPS), hashed password storage, and access controls. No system is completely secure; if you believe your account has been compromised, contact us immediately at [email protected].

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes by email. The date of the most recent revision is shown at the top of this page. Continued use of the platform after changes constitutes acceptance of the updated policy.

Questions or Requests

To exercise your data rights, raise a concern, or ask a question about this policy, contact our data team directly.

[email protected]