Privacy Policy

Privacy Policy

1. Introduction

Welcome to Verumate (“Verumate”, “we”, “our”, or “us”).

Verumate is an AI-powered Virtual Business Analyst that helps organizations understand business performance by securely connecting to authorized Connected Services, analyzing Customer Data, and providing evidence-backed insights, investigations, recommendations, and reports.

We are committed to protecting your privacy and handling your information responsibly, transparently, and securely. This Privacy Policy explains what information we collect, how we use it, how we protect it, and the choices available to you.

This Privacy Policy applies to the Verumate website, application, APIs, and all related services unless otherwise stated.

By using Verumate, you agree to the collection and use of information as described in this Privacy Policy.


2. Definitions

For purposes of this Privacy Policy:

Customer means the individual or organization that creates or manages a Verumate Workspace.

Workspace means an isolated environment containing a Customer’s users, Connected Services, conversations, reports, and configuration.

Authorized User means a person granted permission to access a Workspace.

Connected Service means a third-party platform, application, database, API, or business system that a Customer explicitly authorizes Verumate to access through a Connector.

Connector means a secure integration between Verumate and a Connected Service.

Customer Data means data retrieved from Connected Services or provided directly by the Customer.

Google User Data means information obtained through Google APIs after a Customer grants authorization using Google OAuth.


3. Information We Collect

Depending on how you use Verumate, we may collect the following categories of information.

Account Information

  • Name

  • Email address

  • Organization name

  • Authentication information

  • Workspace configuration

  • User preferences

Customer Data

Customer Data includes information retrieved from Connected Services that you explicitly authorize.

Examples include:

  • Analytics metrics

  • Advertising performance

  • Search performance

  • Website traffic

  • Business KPIs

  • Reports

  • Uploaded spreadsheets

  • API responses

  • Business datasets

The categories of Customer Data available to Verumate depend on the Connected Services you choose to connect.

Conversation Data

When you interact with Verumate, we may store:

  • Questions you ask

  • AI-generated responses

  • Investigation results

  • Reports

  • Conversation history

Conversation history helps provide continuity, improve your experience, and support product functionality.

Technical Information

We may automatically collect:

  • IP address

  • Browser type

  • Device information

  • Operating system

  • Session information

  • Log files

  • Diagnostic information

  • Error reports


4. Information from Connected Services

Verumate retrieves information only from Connected Services that you explicitly authorize.

Depending on the Connector, this may include business metrics, reports, dimensions, configuration metadata, advertising performance, search performance, website analytics, and other information required to provide requested functionality.

Verumate does not access Connected Services unless authorization has been granted by the Customer.

Removing a Connector immediately prevents future data retrieval from that Connected Service.


5. Google API Services User Data

Verumate currently supports secure integrations with selected Google services using Google OAuth.

When authorized by you, Verumate may access Google API data solely to provide the functionality you request.

Google User Data is used only for purposes directly related to providing Verumate services, including retrieving Google Analytics and Google Search Console information, generating evidence-backed insights, answering business questions, producing reports, and supporting authorized investigations. Future Google integrations, such as Google Ads, will request only the minimum read-only permissions required when those features become available. For more information how Google API Data is used please visit https://verumate.com/google-api-data-usage/

Verumate does not use Google User Data for advertising, marketing, profiling unrelated to the requested service, or any unrelated commercial purpose.

Verumate does not sell Google User Data.

Verumate does not use Google User Data to train generalized artificial intelligence or machine learning models.

Additional information regarding Google’s data handling requirements is available in the Trust Center under Google API Data Usage & Limited Use Compliance.


6. OAuth Authorization

Where supported, Verumate uses OAuth 2.0 to securely connect to Connected Services.

OAuth authorization allows Customers to grant limited access without sharing passwords.

OAuth credentials are encrypted and stored securely.

Customers may revoke access at any time either within Verumate or through the Connected Service, where supported.

Verumate requests only the permissions necessary to provide requested functionality, following the Principle of Least Privilege.


7. How We Use Information

We use information to:

  • Provide Verumate services.

  • Authenticate users.

  • Connect authorized Connected Services.

  • Retrieve Customer Data.

  • Generate AI-assisted business insights.

  • Produce investigations and reports.

  • Improve platform reliability.

  • Detect security incidents.

  • Prevent fraud and abuse.

  • Comply with legal obligations.

  • Respond to customer support requests.

We do not use Customer Data for unrelated marketing purposes.


8. How AI Uses Your Data

Verumate combines deterministic investigation engines with artificial intelligence to analyze Customer Data and generate evidence-backed responses.

AI processing may include:

  • Summarization

  • Trend analysis

  • Business investigations

  • Recommendation generation

  • Natural language explanations

  • Report generation

AI responses are generated only using information available within your Workspace and authorized Connected Services.

Customer Data is not used to train generalized AI models.

AI-generated recommendations should be reviewed by Customers before making business decisions.


9. Data Sharing

We do not sell Customer Data or Google User Data.

We may share information only when necessary to:

  • Provide Verumate services through trusted subprocessors.

  • Comply with legal obligations.

  • Protect the security of Verumate.

  • Respond to lawful requests.

  • Enforce our Terms of Service.

All subprocessors are subject to appropriate contractual and security obligations.

A current list of subprocessors is available in the Trust Center.


10. Security

Protecting Customer Data is fundamental to Verumate.

We implement administrative, technical, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction.

These safeguards include:

  • Encryption in transit using HTTPS/TLS.

  • Encryption of sensitive credentials.

  • Secure OAuth authentication.

  • Access controls based on least privilege.

  • Infrastructure monitoring.

  • Audit logging.

  • Secure backup procedures.

Additional details are available in the Trust Center Security documentation.


11. Data Retention

We retain information only for as long as necessary to provide services, comply with legal obligations, resolve disputes, and enforce agreements.

Retention periods vary depending on the type of information.

Complete retention schedules are described in the Data Retention & Deletion Policy.


12. International Users

Verumate may process information in jurisdictions where our infrastructure or service providers operate.

Regardless of processing location, we apply appropriate safeguards designed to protect Customer Data consistent with this Privacy Policy.


13. Your Rights

Depending on applicable law, you may have rights to:

  • Access your personal information.

  • Correct inaccurate information.

  • Request deletion of your information.

  • Export your data.

  • Withdraw consent where applicable.

  • Object to certain processing activities.

Requests may be submitted using the contact information provided below.


14. Children’s Privacy

Verumate is intended for business use and is not directed toward children under the age required by applicable law.

We do not knowingly collect personal information from children.


15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or security practices.

Material changes will be communicated through appropriate channels before becoming effective where required by law.

The “Last Updated” date at the top of this document indicates the most recent revision.


16. Contact

If you have questions regarding this Privacy Policy or our privacy practices, please contact us:

Verumate

Email: privacy@verumate.com

Trust Center: https://verumate.com/trust


Google API Services User Data Policy Compliance

Verumate’s use and transfer of information received from Google APIs to any other application complies with the Google API Services User Data Policy, including the Limited Use requirements.

Verumate does not use Google User Data to develop, improve, or train generalized artificial intelligence or machine learning models.

Google User Data is accessed only to provide or improve user-facing functionality explicitly requested by the Customer.