Privacy Policy

Effective date: July 16, 2026 · Last updated: July 16, 2026

This Privacy Policy explains how Veriteos, Inc. (“Veriteos,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal information when you visit veriteos.com, communicate with us, subscribe to updates, or use the Veriteos enterprise workforce platform as an authorized user (collectively, the “Services”).

1. Scope and our role

For information collected through our Website, business communications, and direct account administration, Veriteos generally determines the purposes and means of processing and acts as a controller or business under applicable privacy law.

A customer organization may provide operational, workforce, or healthcare data to the platform (“Customer Data”). For Customer Data, the customer generally determines why and how the information is processed, and Veriteos acts as its service provider or processor under the applicable customer agreement. When Customer Data includes Protected Health Information (“PHI”), Veriteos processes it only under an applicable Business Associate Agreement (“BAA”).

This Privacy Policy does not replace a customer’s Notice of Privacy Practices, BAA, data processing agreement, or other contractual privacy terms. If you have a question or request about Customer Data or PHI, contact the customer organization that controls that information.

2. Information we collect

The information we collect depends on how you interact with the Services and may include:

  • Contact and business information. First and last name, work email address, company or organization, communications and message content, and newsletter subscription status.
  • Website and device information. Internet Protocol (IP) address, referrer, user agent, browser and device information, pages viewed, interactions, approximate location derived from IP address, timestamps, analytics identifiers, and similar usage information.
  • Account and authentication information. Name, work contact information, authentication identifiers, login and session information, account status, customer organization, assigned role and permissions, security events, audit logs, feature activity, and support communications.
  • Customer Data. Operational, workforce, financial, healthcare, or other data that a customer chooses to provide or connect to the platform. Depending on the customer’s configuration, Customer Data may include sensitive personal information or PHI.

We collect information directly from you, from the customer organization that authorizes your account, automatically from your browser or device, and from service providers and integrations used to operate the Services. Do not submit PHI, medical details, or patient data through our public contact or newsletter forms.

3. How we use information

We use personal information to:

  • provide, operate, maintain, support, and improve the Services;
  • authenticate users, administer accounts and permissions, and support customer organizations;
  • respond to inquiries, arrange demonstrations, manage business relationships, and send requested updates;
  • monitor performance, understand use of our Website and platform, troubleshoot issues, and develop features;
  • protect the security, integrity, and availability of the Services; prevent fraud, misuse, and unlawful activity; and enforce our agreements;
  • comply with law, respond to lawful requests, and establish, exercise, or defend legal claims; and
  • evaluate or complete a financing, merger, acquisition, reorganization, sale, or other business transaction.

We use Customer Data to provide, support, and secure the Services and as otherwise instructed by the customer. We may use only Customer Data that is both aggregated and de-identified so that it does not reasonably identify a person or customer for broader analytics, benchmarking, and service improvement. We apply the de-identification standards required by applicable law, take reasonable measures to prevent re-identification, do not attempt to re-identify the information, and require recipients to keep it in de-identified form and not re-identify it. Any such use involving PHI occurs only when and to the extent authorized by the applicable BAA. We do not use identifiable Customer Data to train any artificial intelligence or machine learning model without the customer’s separate written authorization.

4. How we disclose information

We may disclose personal information to the following categories of recipients for the purposes described in this Policy:

  • Customer organizations. Account information, activity, and Customer Data may be available to the customer’s authorized administrators and users according to assigned permissions.
  • Infrastructure and platform providers.Supabase provides authentication, database, and storage services. Hosting, cloud, monitoring, and security providers help us operate and protect the Services.
  • Communications providers. Resend supports transactional email, inquiry notifications, and requested communications.
  • Analytics providers. Google Analytics and PostHog process device, usage, and analytics identifier data to help us measure and improve our own Website. Their technologies collect information when you use the Website and may recognize a browser or device over time. We use these providers as processors for first-party analytics, not for targeted or cross-context behavioral advertising.
  • Mapping providers. Mapbox may process location, address, or device information when an authorized user uses a platform feature that depends on maps or geocoding.
  • Professional advisers. Lawyers, accountants, auditors, insurers, and other advisers may receive information when reasonably necessary to provide professional services.
  • Authorities and other legal recipients. We may disclose information when we reasonably believe it is required by law or necessary to protect rights, safety, and the integrity of the Services.
  • Transaction participants and successors.Parties to a proposed or completed financing, merger, acquisition, reorganization, sale, or similar transaction may receive information subject to appropriate safeguards.

We do not sell personal information or “share” it as those terms are defined by applicable US state privacy laws. We do not use personal information for targeted or cross-context behavioral advertising. We require service providers and processors to handle information for specified business purposes and subject to contractual restrictions appropriate to their role.

Other than the service providers collecting information on our behalf as described above, we do not authorize third parties to collect personal information through the Services about your activities over time and across unrelated websites or online services.

5. Cookies and online tracking

The platform uses essential technologies, including authentication and session cookies, to sign users in, maintain security, and provide requested functionality. It may also use a preference cookie to remember interface choices. Blocking these technologies may prevent the platform from working correctly.

The Website uses Google Analytics and PostHog scripts, cookies, or similar identifiers to understand visits and interactions. These providers collect information directly through their technologies when the Website loads. Your browser may let you block or delete cookies, and analytics providers may offer their own controls. Blocking analytics technologies may reduce our ability to measure Website use but should not prevent basic Website access.

Because there is no consistently applied industry standard for browser “Do Not Track” signals, our Website does not currently respond to them. We do not sell or share personal information or use it for targeted advertising, so a Global Privacy Control or similar opt-out preference signal does not change our current practices. If our practices change and applicable law requires recognition of such a signal, we will honor it as required and update this Policy.

6. Customer Data and PHI

Customer Data is processed on behalf of and under instructions from the relevant customer organization. The customer is responsible for determining the lawful basis and purposes for that processing, providing required notices, managing permissions, and responding to individual requests. Veriteos assists customers in meeting their obligations as required by contract and applicable law.

Veriteos accepts PHI only under an applicable BAA and uses and discloses it as permitted by that BAA. This Policy is not a Notice of Privacy Practices and does not create or replace a BAA. If your request concerns Customer Data or PHI, contact the healthcare organization, employer, health plan, or other customer that collected or controls it. If you contact us directly, we may refer the request to that customer and assist it under our contract.

7. Retention

We retain personal information only for as long as reasonably necessary and proportionate for the disclosed purpose, taking into account the type and sensitivity of the information, the duration of our relationship, customer instructions, contractual requirements, security needs, legal obligations, limitation periods, and whether information is maintained in routine backups. Our principal retention criteria are:

  • Contact and newsletter information is retained while needed to respond, manage the business relationship, or provide requested communications, and afterward as needed for legal records. We may retain a minimal suppression record after an unsubscribe request so that we continue to honor it.
  • Website, device, and analytics information is retained while useful for security, troubleshooting, trend analysis, and service improvement, subject to the settings and retention cycles of our systems and analytics providers.
  • Account, authentication, and audit informationis retained during the customer relationship and afterward as needed to secure the Services, document authorized activity, comply with contracts and law, and resolve disputes.
  • Customer Data and PHI is retained and deleted according to customer instructions, the Customer Agreement, any applicable BAA, legal requirements, and routine backup cycles.

When personal information is no longer needed, we delete or de-identify it, subject to applicable legal and operational requirements. We may retain aggregated or de-identified information that cannot reasonably identify a person or customer, subject to the de-identification commitments above.

8. US state privacy rights

Depending on where you reside, how you interact with Veriteos, and whether a state privacy law applies to Veriteos and the information at issue, you may have rights to:

  • confirm whether we process your personal information and access or know the categories and specific pieces we hold;
  • correct inaccurate personal information;
  • delete personal information, subject to exceptions;
  • obtain a portable copy of personal information you provided;
  • opt out of a sale, statutory sharing, targeted advertising, or certain profiling or automated decision-making, where applicable;
  • limit certain uses or disclosures of sensitive personal information or withdraw consent where the law provides that right;
  • appeal our decision on a request where an appeal right applies; and
  • receive equal service and not be discriminated against for exercising a privacy right.

These rights are not available in every state or in every circumstance. Nothing in this Policy creates a right where applicable law does not require one. Veriteos does not currently sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising.

To submit a request concerning information Veriteos controls, email contact@veriteos.com and describe the request and your state of residence. To appeal a decision, reply to our response or send a new message with “Privacy Appeal” in the subject line. We may request information reasonably necessary to verify your identity, authority, and the information involved. We will use verification information only for the request and related recordkeeping.

An authorized agent may submit a request where permitted by law. We may require proof of the agent’s authority and may ask you to verify your identity or confirm the request directly. If a request concerns Customer Data or PHI, submit it to the relevant customer organization; Veriteos will assist that organization as required.

9. Security

We maintain administrative, technical, and organizational safeguards designed to protect personal information in light of its nature and the risks of processing. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for protecting your credentials and promptly reporting suspected account misuse.

10. United States processing

Veriteos is a United States company, and the Services are directed to organizations operating in the United States. Personal information may be processed and stored in the United States and in other locations where our service providers operate. If you access the Services from another country, its laws may provide different protections than the laws where you live.

11. Children

The Services are intended for business use by adults and are not directed to children under 13. We do not knowingly collect personal information from children under 13 through the Website or workforce platform. If you believe a child has provided us personal information, contact us so we can review and address it.

12. Changes to this Policy

We may update this Policy to reflect changes in our practices, Services, or legal obligations. We will post the updated Policy here and change the “Last updated” date. If a change is material, we will provide additional notice when required by law or a Customer Agreement.

13. Contact

Questions or requests about this Policy may be sent to:
Veriteos, Inc.
contact@veriteos.com