Verigrey
Legal

Privacy Policy

This policy explains how Verigrey collects, uses, and protects the personal data we control as part of our website, marketing, sales, and account-management activities.

Effective date: August 18, 2026
This page is provided for general informational purposes and does not constitute legal advice. Personal data processed on behalf of customers when running the testing service is governed by the Data Processing Addendum in the customer contract, not this policy.

1. Who We Are

Verigrey Inc. ("Verigrey," "we," "our," or "us") provides an AI agent security and policy-compliance testing platform. This policy explains how we collect, use, and protect personal data for which we act as the data controller — meaning data we collect through our website, marketing, sales, and account-management activities.

We are committed to handling personal data in accordance with applicable data-protection laws, including Singapore's Personal Data Protection Act (PDPA), the EU and UK General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA/CPRA), as applicable to you.

Privacy contact: Privacy Team, legal@verigrey.com

2. Scope

This policy applies to personal data we collect as a controller. It does not apply to personal data contained in the systems, agents, or datasets that customers submit to our platform for testing — for that data, the customer is the controller and Verigrey acts as a processor under the Data Processing Addendum in the customer agreement.

3. Personal Data We Collect

CategoryExamplesRequired?
Identity dataFirst/last name, job title, companyYes, for account creation / demo requests
Contact dataBusiness email, phone numberYes, for communication
Authentication dataLogin credentials, session tokens, access logsAutomatic, for security
Technical & usage dataIP address, browser type, device, pages visited, timestamps, interaction dataAutomatic
Marketing & preference dataCommunication preferences, event/webinar registrationsOptional
Communication contentSupport tickets, sales enquiries, messages you send usOnly when you contact us

We do not intentionally collect special-category/sensitive personal data (e.g., health, race, religion, biometrics) through our website or sales process. Please do not submit such data to us via the Site.

4. How and Why We Use Your Data (and Legal Basis)

PurposeLegal basis (GDPR) / PDPA basisRetention
Create and manage accounts; authenticate usersContract / performance of serviceUntil deletion requested
Respond to demo requests, sales, and support enquiriesLegitimate interests / consent3 years after last activity
Send product updates and marketing (with opt-out)Legitimate interests / consent (opt-in where required)Until unsubscribe + 30 days
Analyze and improve the website and servicesLegitimate interests24 months rolling
Secure our systems; detect and respond to threatsLegitimate interests / legal obligation12 months
Comply with legal, accounting, and regulatory obligationsLegal obligationAs required by law

Where we rely on legitimate interests, our interest is in operating, improving, marketing, and securing our business, balanced against your rights. Where we rely on consent, you may withdraw it at any time. We do not use your personal data for automated decision-making that produces legal or similarly significant effects, and we do not sell your personal data.

5. Cookies and Tracking

We use cookies and similar technologies for essential site functionality, security, and analytics. You can manage non-essential cookies through our cookie banner or your browser settings at any time. We do not use third-party advertising cookies or engage in cross-context behavioral advertising.

6. Who We Share Data With

We share personal data with trusted third-party service providers ("subprocessors") who process it on our behalf under written agreements imposing appropriate data-protection obligations, including:

ProviderPurposeLocationSafeguard
Cloud infrastructure (Vercel, AWS)Hosting, compute, storageUSASCCs / DPF
Analytics providerProduct/website analyticsUSASCCs
CRM providerSales and marketingUSASCCs / DPF
Email providerTransactional & marketing emailUSASCCs
Support toolingCustomer supportUSASCCs / DPF

We may also disclose personal data where required by law, regulation, court order, or legal process, or to protect our rights, your safety, or the safety of others; and in connection with a merger, acquisition, financing, or sale of assets (subject to confidentiality).

7. International Data Transfers

We are based in the United States, with an affiliated office in Singapore, and may transfer and process your personal data in both jurisdictions and with subprocessors located elsewhere. Where we transfer personal data from the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards — including the EU Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum (IDTA), and/or subprocessors' Data Privacy Framework (DPF) certifications. For transfers under PDPA, we take reasonable steps to ensure a comparable standard of protection. You may request details of the safeguards in place.

8. Data Retention

We retain personal data only as long as necessary for the purposes described above (see the table in Section 4), after which we securely delete or anonymize it, unless a longer period is required by law (e.g., tax or accounting records). On a valid deletion request, we delete or anonymize your data within 30 days, subject to legal retention requirements.

9. Data Security

We implement appropriate technical and organizational measures to protect personal data, including encryption in transit and at rest, access controls, logging, and incident-response procedures. We are pursuing SOC 2 Type II and ISO 27001 certification. No system is completely secure; if we become aware of a personal-data breach that affects you, we will notify you and the relevant authorities as required by applicable law (including the PDPA and GDPR breach-notification requirements).

10. Your Rights

If you are in the EEA, UK, or Switzerland (GDPR): you have the rights of access, rectification, erasure, restriction, portability, objection (including to direct marketing), and withdrawal of consent. We respond within the statutory period (generally 30 days). You may lodge a complaint with your local supervisory authority.

If you are in Singapore (PDPA): you have the right to access and correct your personal data and to withdraw consent to its collection, use, or disclosure. You may contact our privacy contact above; you may also contact the Personal Data Protection Commission (PDPC).

If you are in California (CCPA/CPRA): you have the right to know, delete, correct, and opt out of the "sale" or "sharing" of personal information (we do not sell or share for cross-context behavioral advertising), and the right to non-discrimination for exercising your rights.

To exercise any right, contact legal@verigrey.com. We will verify your identity before responding.

11. Children

Our website and services are directed to businesses and professionals and are not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe we have, contact us and we will delete it.

12. Changes to This Policy

We may update this policy to reflect changes in our practices or applicable law. Material changes will be posted here with a revised "Last updated" date and, where required, notified to you directly.

13. Contact

Privacy questions or to exercise your rights: legal@verigrey.com

Complaints (EEA/UK): your local supervisory authority. Singapore: the PDPC. California: as set out above.