Legal

Privacy Policy

At Verifrs, we understand that handling financial data requires the highest level of trust and security. This Privacy Policy outlines how we collect, use, and protect your information when you use our IFRS compliance platform.

Last updated: July 18, 2026

Privacy at a glance
01

We process account, usage and customer-provided reporting data to operate the service.

02

Data is used for contracted services, security, support and legitimate product operations.

03

Customers retain ownership and control of uploaded financial information.

04

Privacy requests are reviewed under the law applicable to the requester.

01

Scope and responsible entity

This notice explains how Verifrs handles personal data through its public website, access programme and hosted reporting workspace. It applies alongside any signed order form, data-processing agreement or design-partner agreement.

  • Verifrs acts as controller for website visits, access requests, account administration, security and direct business communications.
  • The contracting customer generally acts as controller for personal data contained in customer-uploaded reporting information.
02

Controller and processor roles

The legal role depends on why and how data is processed. When Verifrs processes customer content only to provide the contracted service, it acts as a processor on the customer’s documented instructions.

  • Customers determine whether uploaded data may lawfully be processed and are responsible for notices to their personnel and data subjects.
  • A separate data-processing agreement may define instructions, assistance, deletion, audit information and subprocessor terms.
03

Data we collect

We limit collection to information reasonably needed to provide, secure and improve the service and manage the business relationship.

  • Identity and account data, business contact details, organisation membership, roles, authentication events, support communications and access requests.
  • Customer content such as trial balances, ledgers, mapping decisions, evidence files and report metadata, plus technical usage, device, diagnostic and security events.
04

Purposes and legal bases

We process personal data only for identified operational, contractual, security and legal purposes. The applicable legal basis depends on the relationship and jurisdiction.

  • To provide and support the service, authenticate users, administer accounts, deliver requested communications and perform the contract or pre-contract steps.
  • To protect the platform, prevent misuse, improve reliability, comply with law and pursue legitimate business interests where those interests are not overridden.
05

Financial data and AI-assisted processing

Customer-uploaded financial information is treated as customer content and processed to deliver the configured reporting workflow. AI-assisted suggestions remain subject to customer review and approval.

  • We do not sell customer content and do not use identifiable customer financial data to train general-purpose models without explicit documented authorization.
  • Customers should not upload personal data that is unnecessary for the reporting purpose and must have authority to provide all uploaded information.

Verifrs produces audit-supporting workpapers, not an audit opinion, legal advice or a certification of IFRS compliance.

06

Recipients and subprocessors

We disclose data only where needed to operate the service, comply with law, protect rights or complete an approved corporate transaction.

  • Infrastructure, authentication, communications, monitoring, storage and AI service providers may process limited data under contractual and access restrictions.
  • We may disclose information to professional advisers, authorities or transaction counterparties where legally required or subject to appropriate confidentiality safeguards.
07

International data transfers

Service providers and users may operate in different countries. Where law requires, cross-border transfers must rely on a recognized transfer mechanism and appropriate safeguards.

  • Hosting region and transfer requirements may be documented in the applicable order form or data-processing agreement.
  • Customers may contact us for current transfer and subprocessor information relevant to their deployment.
08

Retention, export and deletion

We retain information only while reasonably necessary for the service, security, contractual records and applicable legal obligations, then delete or de-identify it according to operational procedures.

  • Customer-content retention and return are governed by the workspace status and any signed agreement; customers should export required records before termination.
  • Limited backups, audit events, billing, dispute and security records may remain for defined operational or legal periods before scheduled deletion.

Retention periods vary by data category and contract. Request the deployment-specific schedule before relying on Verifrs as a record-retention system.

09

Security and incident handling

We apply technical and organisational measures designed to protect confidentiality, integrity and availability in proportion to the product’s maturity and risk profile.

  • Controls include organisation-scoped authorization, managed encrypted infrastructure, secure transport, activity records and controlled deployment secrets.
  • No system is completely secure. Confirmed incidents are investigated, contained and communicated according to contractual and legal notification duties.
10

Your privacy rights

Depending on applicable law, individuals may have rights to information, access, correction, deletion, restriction, objection, portability, consent withdrawal and complaint to a supervisory authority.

  • Submit a request to privacy@verifrs.com. We may verify identity, authority and the relevant customer relationship before responding.
  • For customer-controlled content, we may direct the request to the relevant customer or assist that customer as processor.

Rights are not absolute and may be limited by lawful exemptions, recordkeeping obligations or the need to protect other people.

11

Cookies and service telemetry

The website and application may use necessary storage for authentication, language, security and session continuity, plus limited diagnostics for reliability.

  • Essential technologies are used to provide requested functions and protect the service.
  • Where consent is legally required for non-essential analytics or communications, the relevant control or notice will be presented before activation.
12

Children, changes and contact

The service is intended for authorised business users and not directed to children. We may update this notice as the service, providers or law changes.

  • Material updates will be identified by a revised date and, where appropriate, an in-product or direct notice.
  • Questions, complaints and requests may be sent to the privacy contact below; security reports should be sent through the security contact.

Privacy questions or rights requests

Contact us with the relevant organisation, account email, request type and jurisdiction. Do not include unnecessary financial or identity documents in the initial email.

privacy@verifrs.com