Privacy Policy
What personal data Verinten processes, why, on what basis, for how long, and the rights you can exercise.
- Version
- 1.0
- Effective
- Contact
- Privacy team
In counsel review — not yet binding. This document is published for transparency while Verinten prepares for launch. It is not yet the binding version of this policy.
The short version
- Verinten never collects, stores, or infers patient data. Submitting it is prohibited.
- It reads public sources only. Nothing behind a login is collected.
- Product analytics is off until you consent, and session replay is a separate choice that never follows analytics consent automatically.
- Export and deletion are self-service.
1. Who is responsible
Kollekting Apps LLC is the controller for the personal data described in sections 2 and 3. Where Verinten processes personal data on your instructions as part of the service, it acts as a processor and the Data Processing Addendum applies.
2. Account and workspace data
| Data | Why | Basis |
|---|---|---|
| Email address, display name, locale | Authentication, notifications, interface language | Performance of the contract |
| Session records and sign-in events | Keeping accounts secure and revocable | Legitimate interest in security |
| Organisation name, country, time zone, billing email | Operating the workspace and issuing invoices | Performance of the contract; legal obligation |
| Consent records | Proving what you chose and when | Legal obligation |
| Support correspondence | Answering your request | Performance of the contract |
3. Public source data
To produce reputation intelligence, Verinten reads publicly available material about the businesses in your workspace. That material may contain personal data published by its author — a reviewer’s display name, for example. Verinten processes it on the basis of legitimate interest in analysing public business reputation, and applies the following minimisation:
- Reviewer names are minimised or masked in analytical screens, and shown only where you need them to respond to a specific public item.
- No attempt is made to identify a reviewer, link reviews across platforms to one person, or build a profile of any individual.
- Special-category data is not sought. Where a public item happens to contain it, that item is treated as evidence of a reputation theme and is never used to characterise the individual.
4. Product analytics
Verinten uses PostHog for product analytics, reached through a first-party proxy on our own domain. It is disabled until you accept analytics in the consent manager, automatic capture of clicks and page content is switched off entirely, and every event is an explicit, reviewed event from a fixed catalogue.
- You are identified only by an internal Verinten user identifier — never your email, name, or any billing identifier.
- URLs are reduced to route templates before being recorded, so no workspace name, clinic identifier, token, or query string is ever transmitted.
- The content of forms, evidence, and support messages is never transmitted.
- Session replay is a separate preference, off by default, and records with all text and inputs masked.
- IP addresses are discarded at ingestion.
You can change or withdraw either choice at any time from the consent manager or from Account → Privacy, and withdrawal takes effect immediately.
5. Cookies
See the Cookie Policy. Only strictly necessary cookies are set before consent.
6. Who else processes your data
The full list, with each party’s role and location, is in Subprocessors.
7. How long data is kept
Retention periods per data category are published in the Data Retention Policy.
8. Your rights
You may request access, correction, export, deletion, restriction, or objection, and you may withdraw consent at any time. Export and deletion are available self-service inside the product; anything else can be requested from the privacy contact above. We respond within one month and will tell you if we need longer and why. You may also complain to your supervisory authority.
9. Security
Controls are summarised on the security page and in more detail in the Security Overview.
Change history
- 1.0
First published version.