Privacy Policy
Effective date: 4 August 2026
This Privacy Policy explains how VERIFIT LIMITED collects, uses and protects personal data. We have written it to be readable, and we have not padded it with rights we don’t exercise: we do not sell personal data, we do not run advertising, and we collect the minimum we need.
1. Who we are (data controller)
The data controller for the personal data described in this policy is:
- VERIFIT LIMITED, a company registered in Northern Ireland, Company No. NI736605
- Registered office: 12-16 Bridge Street, Belfast, Northern Ireland, BT1 1LU
- Email: support@verifit.uk
Where business customers use the Verifit platform to run checks on their own candidates, suppliers or clients, the customer is normally the controller of that check data and VERIFIT LIMITED acts as processor under a data processing agreement. This policy covers the processing for which we are the controller.
2. Scope of this policy
This policy applies to:
- the website verifit.uk; and
- the mobile applications published by VERIFIT LIMITED on the Apple App Store and Google Play (together, the “apps”), including the Verifit companion capture app currently in development.
Where an app has behaviour not described here, its store listing and in-app notices will say so and this policy will be updated before release.
3. Data we collect on the website
The website is deliberately quiet:
- Email correspondence. All calls to action on this site are email links. If you email us, we receive your email address, the content of your message and any details you choose to include. We use this only to respond and to keep a record of the correspondence.
- Server and security logs. The website is served through Cloudflare, which processes technical data (IP address, user agent, requested URL, timestamps) in server logs for security, abuse prevention and performance.
- No analytics or advertising cookies. We do not use analytics tools, advertising pixels or tracking cookies on this website. See our Cookie Policy for the small number of strictly necessary cookies Cloudflare may set.
4. Data we collect in the apps
The following describes the apps as designed. Anything materially different will be reflected here before an app ships.
4.1 Account information
Name, work email address, organisation and role, used to create and secure your account and to link your actions to your organisation’s workspace.
4.2 User content
Documents, images and check records you create or capture in the apps are stored on our UK-based infrastructure (hosted on Cloudflare services) within your organisation’s workspace. User content remains under the control of your organisation and is not used for any purpose other than providing the service.
4.3 Device and technical data
Device model, operating system version, app version and language settings, used for compatibility, support and security.
4.4 Usage analytics
Aggregated, privacy-preserving usage metrics (for example, which features are used and how often) to improve the product. These metrics contain no advertising identifiers and are not used to profile individuals.
4.5 Crash diagnostics
If the app crashes, we collect diagnostic reports (stack trace, device model, OS version, app version) to identify and fix the fault. Crash reports are not used for any other purpose.
4.6 App permissions
| Permission | Why we ask | Revocable? |
|---|---|---|
| Camera | To capture documents (for example an ID document or certificate) during a check. Requested only when you start a capture; never used in the background. | Yes — iOS Settings → Privacy → Camera, or Android Settings → Apps → Permissions. The app continues to work; you can upload files instead. |
| Photos / files (read, user-selected) | To let you attach an existing document or image to a check. | Yes — via the same settings paths. Attachment upload is optional. |
| Notifications | To alert you to checks awaiting review or documents nearing expiry. | Yes — decline the prompt or disable in device settings at any time. |
The apps do not request microphone, location, contacts or background-tracking permissions.
4.7 Document and ID capture
Because identity documents deserve particular care:
- Purpose. Camera capture exists solely to photograph documents for the verification workflow initiated by you or your organisation.
- On-device processing. Quality checks (edge detection, glare, blur) run on your device; only the final capture is transmitted, encrypted in transit.
- Special category caution. Identity documents may incidentally reveal special category data (for example, a photograph may indicate ethnic origin). We process document images only as necessary for the verification purpose, restrict access to them, and apply the retention rules in section 8.
- No biometric templates without consent. We do not create biometric templates or perform facial-recognition matching from captured images unless and until we introduce a feature that does so with your explicit, separate consent — clearly requested at the point of use and refusable without losing access to the rest of the service.
- Retention. Captured documents are retained according to the controlling organisation’s configured retention policy and deleted on schedule (see section 8).
4.8 What we do not do
- We do not sell personal data.
- We do not use advertising SDKs in our apps.
- We do not track you across other companies’ apps or websites.
- We do not collect precise location data.
5. Purposes and lawful bases
| Purpose | Data | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Responding to enquiries | Email correspondence | Legitimate interests (responding to people who contact us) |
| Providing and securing the website | Server and security logs | Legitimate interests (security, abuse prevention, service integrity) |
| Providing the apps and platform | Account information, user content, device data | Contract (performing our agreement with you / your organisation) |
| Running verification workflows for business customers | Check records, captured documents | Processed on the customer’s instructions as processor; the customer’s basis is typically legal obligation or legitimate interests |
| Improving the product | Aggregated usage analytics | Legitimate interests (understanding aggregate feature use) |
| Fixing faults | Crash diagnostics | Legitimate interests (maintaining a working, safe product) |
| Any future biometric feature | Facial images / templates | Explicit consent (Art. 9(2)(a)) — not currently offered |
| Legal compliance | Records we are required to keep | Legal obligation |
6. Recipients of your data
We share personal data only with service providers who help us run the service:
- Cloudflare, Inc. — website hosting, content delivery, security and application infrastructure.
- Apple Inc. — app distribution, and crash/diagnostic reporting where you have enabled sharing with developers on iOS.
- Google LLC — app distribution via Google Play, and Android crash/diagnostic reporting where enabled.
We commit to keeping this list current: if we engage additional sub-processors, we will update this policy before they process personal data. We may also disclose data where required by law or to protect our legal rights, and to professional advisers under confidentiality.
7. International transfers
We store and process customer data in the UK by default. Some providers listed in section 6 are headquartered outside the UK and may process limited technical data internationally. Where personal data is transferred outside the UK, we rely on one or more of: a UK adequacy regulation for the destination country; the UK International Data Transfer Agreement (IDTA); or the UK Addendum to the EU Standard Contractual Clauses, together with any supplementary measures needed.
8. How long we keep data (retention)
| Data | Retention period |
|---|---|
| Email correspondence | Up to 24 months after the matter is closed, then deleted |
| Cloudflare server/security logs | Short rolling periods set by Cloudflare (typically less than 30 days) |
| Account information | Life of the account, plus 30 days after deletion (section 12) |
| User content & captured documents | Per the controlling organisation’s configured retention policy; deleted on schedule, and in any event on verified deletion request subject to section 12 |
| Aggregated usage analytics | Indefinitely (contains no personal identifiers) |
| Crash diagnostics | Up to 12 months |
| Invoicing and accounting records | 6 years, as required by UK tax law |
9. Your rights
Under UK GDPR you have the right to:
- Be informed — this policy;
- Access — a copy of the personal data we hold about you;
- Rectification — correction of inaccurate or incomplete data;
- Erasure — deletion of your data in certain circumstances;
- Restriction — limiting how we process your data;
- Data portability — receiving data you provided in a structured, machine-readable format;
- Object — to processing based on legitimate interests; and
- Rights related to automated decision-making — we do not make solely automated decisions with legal or similarly significant effects; review decisions in Verifit workflows are made by your organisation’s human reviewers.
To exercise any right, email support@verifit.uk with the subject “Data rights request”. We will respond within one month of receiving your request (extendable by two further months for complex requests, in which case we will tell you). We may need to verify your identity before acting. Where your data is held in a business customer’s workspace and we act as processor, we will refer your request to that organisation and assist them in responding.
10. Complaints to the ICO
If you are unhappy with how we handle your personal data, please contact us first — we take complaints seriously. You also have the right to complain to the UK supervisory authority:
- Information Commissioner’s Office (ICO)
- Website: ico.org.uk
- Address: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
- Telephone: 0303 123 1113
11. Children
Our website and apps are business tools and are not directed at children. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal data, contact support@verifit.uk and we will delete it promptly.
12. Account & data deletion
You can request deletion of your account and associated personal data at any time:
- In-app (once our apps are available): go to Settings → Account → Delete account and confirm. This starts deletion of your account and associated personal data.
- By email: send a request to support@verifit.uk with the subject line “Account deletion request” from the email address linked to your account.
We complete deletion within 30 days of a verified request. A minimal set of records may be retained where the law requires it (for example, invoicing records under UK tax law, or evidence a controller customer is legally obliged to keep) — we retain only what is necessary, for only as long as required, and we will tell you what is retained and why. Where we act as processor for your organisation, deletion of check records may need to be routed through your organisation as controller; we will assist.
13. iOS App Tracking Transparency
Our apps do not track users across apps or websites owned by other companies, and do not share personal data with data brokers. Accordingly, no App Tracking Transparency (ATT) prompt is required and none is shown. If this ever changed, we would ask for your consent through the ATT framework before any tracking occurred — a consent-first commitment.
14. Google Play Data Safety
The Data Safety declarations on our Google Play listings are prepared from this policy and are kept consistent with it. If you spot any inconsistency between a store listing and this policy, this policy governs and we would appreciate a note to support@verifit.uk so we can correct the listing.
15. Security
We apply technical and organisational measures proportionate to the sensitivity of the data we handle, including: encryption in transit (TLS) and at rest; role-based, least-privilege access controls; append-only audit logging of access to sensitive records; environment separation; and security review of changes. We are an early-stage company and do not claim third-party certifications we do not hold; our security documentation is available to customers on request and will mature with the company. No system is perfectly secure — if we become aware of a personal data breach creating risk to you, we will notify the ICO and affected individuals as required by law.
16. Changes to this policy
We may update this policy as the product develops. The effective date at the top will change, and for material changes affecting app users we will provide notice in the app or by email before the change takes effect. Earlier versions are available on request.
17. Contact
Questions about this policy or our data practices: support@verifit.uk, or write to VERIFIT LIMITED, 12-16 Bridge Street, Belfast, Northern Ireland, BT1 1LU. We reply within one business day.