Trust & Transparency

How we handle your data.

Verdaio operates on EU-hosted infrastructure, processes the minimum data required, and documents every processor, control, and commitment below. If your procurement team needs something, it is probably here. Otherwise, ask at privacy@verdaio.ai.

From questionnaire to report, nothing is kept beyond delivery
๐Ÿ“‹
1

You answer

Structured questionnaires collect company-level business data: sector, size, policies, and practices. No sensitive personal data is required.

โšก
2

AI processes

Your answers are sent to Claude (by Anthropic, hosted on Amazon Bedrock in EU) for analysis. Processing is ephemeral: inputs are not stored by Verdaio and are not used for model training.

๐Ÿ“„
3

Report delivered

A structured compliance report is generated and a secure download link is delivered to your email. Reports are stored temporarily (up to 48 hours) for download, then automatically deleted.

Where your data goes, and where it doesn't
๐ŸŒ

Your browser

Form data submitted over TLS 1.2+ encrypted connection.

๐Ÿ‡ช๐Ÿ‡บ

AWS Ireland

Serverless Lambda processes your request in eu-west-1. No persistent servers.

๐Ÿค–

Amazon Bedrock (EU)

Claude model hosted in eu-west-1. Ephemeral processing. No data stored. No model training.

๐Ÿ“ฌ

Your inbox

Secure download link delivered via email. Report auto-deleted after 48 hours.

Built for privacy from the ground up
๐Ÿ‡ช๐Ÿ‡บ

EU-hosted

All infrastructure runs in AWS eu-west-1 (Ireland) and Supabase eu-central-2 (Switzerland). Your data stays in the EU.

๐Ÿ”’

Encrypted

TLS 1.2+ for all data in transit. AES-256 encryption at rest. Row-Level Security on all database tables.

๐Ÿ—‘๏ธ

Minimal data stored

Assessment inputs are processed and discarded. AI-generated reports are stored temporarily (up to 48 hours) for download, then automatically deleted.

๐Ÿช

No tracking cookies

We use Plausible Analytics, an EU-hosted, open-source analytics tool that uses no cookies and collects no personal data. No analytics information is stored on your device.

๐Ÿค–

AI transparency

All AI-generated reports clearly disclose that they are produced by AI (Claude by Anthropic, hosted in EU via Amazon Bedrock) and do not constitute legal advice. EU AI Act Art. 50 compliant.

๐Ÿ›ก๏ธ

GDPR-compliant

Privacy by design. Data minimization. DPAs with all sub-processors. Transfer Impact Assessment documented for all non-EEA transfers.

Where each data category actually lives

Every category of data we process, the provider that hosts it, the region it sits in, and how long it is retained. For the authoritative version see our ROPA.

Data category Provider Region Retention
Account authentication (email, hashed password)SupabaseZurich (Switzerland, EU adequacy)Until account deletion
Subscription + single-purchase recordsSupabaseZurich (Switzerland, EU adequacy)Until deletion; invoice link retained 10 years (PT fiscal law)
AI-generated reportsAWS S3Ireland (EU)48 hours, then auto-deleted
Server access logsAWS CloudWatchIreland (EU)90 days (security)
CDN edge access logsAWS CloudFrontN/ANot captured (data minimisation, since 2026-04-10)
Transactional email (report links, notifications)Brevo (Sendinblue SAS)France + Germany + GCP Belgium (EU)100 days (Brevo default)
Invoices + credit notesInvoiceXpressPortugal (EU)10 years (CIRC Art. 123, DL 28/2019)
Payment recordsStripeIreland (EU primary) + United States (SCCs + DPF)Per Stripe retention policy
Website analytics (cookieless, aggregated)PlausibleEstonia (EU)Aggregated indefinitely; no individual-level data
Controller inbox (privacy@, support@, legal@)Google WorkspaceUnited States (SCCs + DPF)Per mailbox settings

Full data-category map and lawful bases documented in our ROPA.

Exactly how the AI layer works

Verdaio reports are generated by an AI model. Because we sell compliance, we document the AI layer to the same standard we expect from the companies we assess.

Model
Claude Sonnet 4.6 (Anthropic), hosted via Amazon Bedrock EU inference profile in eu-west-1 (Ireland). No data leaves the EU during inference.
Temperature
0.3 in production (slight variability across identical inputs, intentional to balance consistency and contextual phrasing). Benchmark suite runs at 0 for deterministic regression testing.
Training data
Your inputs are never used to train AI models. Anthropic's Bedrock terms contractually prohibit training on customer inputs. No fine-tuning, no RAG ingestion of your answers.
Human oversight
Reports are decision-support, not legal advice. Every report carries an AI Act Art. 50 disclosure footer. Users are expected to review outputs and validate with qualified counsel before acting on them.
AI I/O logging
Prompt and response logs are stored in AWS CloudWatch (Ireland) for 90 days, used for service reliability and abuse prevention. Not used for model training or shared with third parties.
Output quality
Quarterly benchmark suite across all 16 tools. Latest internal score: 92/100. We publish material benchmark regressions in the changelog.
AI Act classification
Verdaio is not a high-risk AI system under Annex III (no decisions on natural persons in employment, credit, law enforcement, etc.). We are subject to Art. 50 transparency obligations, which we meet via report-footer disclosure and this page.
Clear commitments
We don't sell your data
We don't train AI models on your inputs
We don't place tracking or advertising cookies
We don't share your data with data brokers
We don't retain your assessment inputs after processing
We don't store your AI-generated reports
Every third party we work with
ProviderPurposeLocation
Amazon Web ServicesHosting, compute, AI compliance analysis (Amazon Bedrock, Claude model)Ireland (EU)
SupabaseDatabase and authenticationSwitzerland (EU adequacy)
StripePayment processingIreland (EU, primary) + United States (SCCs + DPF)
Brevo (Sendinblue SAS)Transactional emailFrance (EU)
Google WorkspaceController inbox hosting (@verdaio.ai email)United States (SCCs + DPF)
PlausiblePrivacy-first analyticsEstonia (EU)
InvoiceXpressInvoice generationPortugal (EU)

For full legal details, see our Data Processing Agreement.

How long we keep each type of data
CategoryDurationLawful basis
User accountsUntil deletionContract (Art. 6(1)(b))
AI-generated reports48 hours, then auto-deletedContract + minimisation (Art. 5(1)(e))
Assessment inputsNot retained (processed ephemerally)Data minimisation (Art. 5(1)(c))
Invoices + credit notes10 yearsLegal obligation (CIRC Art. 123, DL 28/2019)
Server access logs (CloudWatch)90 daysLegitimate interest (Recital 49, security)
Transactional email logs (Brevo)100 daysProcessor default; legitimate interest (deliverability)
Website analyticsAggregated indefinitely; no individual dataNot personal data
Consent recordsUntil account deletion + 3 yearsAccountability (Art. 7(1))
Breach notification records3 yearsAccountability (Art. 33(5))

Full policy in Privacy Policy ยง7. Internal retention procedure documented in DATA-RETENTION-POLICY and available under NDA.

How we stay accountable
AreaStatus
Data Protection OfficerNot required under GDPR Art. 37 (we are not a public authority, we do not perform large-scale systematic monitoring, and we do not process special categories of data at large scale). Analysis documented in our ROPA and available on request.
Data Protection Impact AssessmentNecessity analysis completed under GDPR Art. 35(3); no DPIA required at current scope. Analysis documented in our DPIA necessity assessment and available on request.
Incident responseCNPD notification within 72 hours under Art. 33 GDPR. Enterprise customers notified within 48 hours per DPA. Full runbook maintained internally and available under NDA for enterprise due diligence.

For access to any of the above artefacts, email privacy@verdaio.ai.

Public record of incidents
No customer-data incidents to date

No security incident affecting customer personal data has occurred since Verdaio launched in 2026.

One internal credential-handling incident is on record: on 2026-04-14 the deploy script briefly printed provider API keys (Brevo, Anthropic) to its own output stream during a routine Lambda redeploy. No customer data was exposed, no external access attempt was detected in the rotation window, and the affected keys were rotated the same day. The deploy script was patched to suppress secret fields on the same day.

If a qualifying breach ever occurs, we will post a detailed postmortem on this page within 72 hours of CNPD notification under GDPR Art. 33. Enterprise customers are notified within 48 hours per our DPA, with or without a CNPD filing.

What we hold, what we inherit, what we don't

Verdaio's own certifications

Verdaio is a sole-operator EU SaaS. We do not currently hold ISO 27001 or SOC 2 certifications; at this scale the overhead outweighs the benefit versus a documented controls pack. Our Technical and Organisational Measures (TOMs) per GDPR Art. 32 are fully documented and available under NDA for enterprise due diligence.

Inherited from our infrastructure

  • AWS (eu-west-1 hosting + Bedrock): ISO 27001, ISO 27017, ISO 27018, SOC 1/2/3, PCI DSS, C5, and more.
  • Supabase (auth + database): SOC 2 Type II, HIPAA-ready.
  • Stripe (payments): PCI DSS Level 1, SOC 1 Type II, SOC 2 Type II.
  • Brevo (email): ISO 27001.
  • Google Workspace (controller inbox): ISO 27001, ISO 27018, SOC 1/2/3.

Self-attested compliance

  • GDPR: controller obligations met; ROPA, DPIA necessity, LIAs, TIA, TOMs documented.
  • EU AI Act: Art. 50 transparency obligations met via report-footer disclosure and this page; not a high-risk system under Annex III.
  • ePrivacy / cookies: no tracking or advertising cookies placed; EU Cookie Law not triggered.

Internal controls in force

  • Annual supplier DPA register review.
  • Quarterly AI output benchmark.
  • Weekly regulatory scan to detect material change in laws we depend on.
  • Principle of least privilege on all AWS IAM roles; MFA enforced on the owner account.
All our policies in one place

Questions about security or data handling?

We are happy to answer any questions about how Verdaio handles your data.