Privacy & cookies
What data VÉRO keeps, why and for how long, when an advisor can see it, and how to use your rights.
Draft: this text will be reviewed by a lawyer before publication. Items in square brackets [ ] are to be completed by the operator of VÉRO.
Version 2026-10 · Last updated: 3 October 2026
At a glance
- The tools, guides, articles and Podcast are available without an account.
- We keep only what is needed for your account, your saved results, your appointments and your messages.
- We do not sell data and we do not use advertising cookies.
- An advisor sees your information only when you choose to share it, and you can withdraw that sharing at any time.
- You can download or delete your data from your account settings.
Who is responsible for your data
The controller for vero.cy is its operator: [legal name, address, registration number]. For anything about your data, contact us through the Contact page.
This policy applies the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and Cyprus Law 125(I)/2018.
What data we keep
- Account. Your name, e-mail address, password (stored only in a one-way hashed form), preferred language and, if you give it, your phone number. For advisors, also their company and registration number, so that their licence can be verified.
- Saved results. When you save a tool result to your account, we keep the figures you entered and the result.
- Appointments. Name, e-mail, phone, topic, date and time, and anything you add as a note.
- Messages. What you send through the contact and call-back forms: name, e-mail, phone, your message and the page you sent it from.
- Sharing with an advisor. Which information you chose to share, with which advisor, for what purpose and until when.
- Consent records. What you accepted or declined (for example this policy, newsletters or a sharing request), which version of the text, when, and from which form.
- Security log. Events such as sign-ins, password changes and failed sign-in attempts. IP addresses are never stored as they are, only as a one-way hash.
- Advisor subscriptions. Plan, subscription status and billing dates. You enter your card details directly with Stripe; they never reach VÉRO.
The tools do their calculations in your browser. What you type is not sent to us unless you choose to save the result to your account. If you copy the link to a result to send to someone, the figures you entered are contained in the link itself.
We do not need information about your health or other special categories of data for your account to work. Please do not enter them in free-text fields, such as messages or appointment notes, unless they are needed for what you are asking. If you share them with an advisor, that happens only with your explicit consent.
Why we use it and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Running your account and saving your results | Account, saved results | Contract (Article 6(1)(b) GDPR) |
| Appointments and replies to your messages | Appointments, messages | Steps you ask for before a contract, or performance of a contract (Article 6(1)(b)) |
| Sharing with an advisor you choose | Only what you select | Consent (Article 6(1)(a); for health data, explicit consent under Article 9(2)(a)) |
| Newsletters | Name, e-mail, language | Consent (Article 6(1)(a)), which you can withdraw at any time |
| Security and abuse prevention | Security log, hashed IP addresses | Legitimate interest (Article 6(1)(f)) |
| Proof of consent | Consent records | Legal obligation to be able to demonstrate consent (Articles 6(1)(c) and 7(1)) |
| VÉRO CRM subscriptions and invoicing | Subscription and billing details | Contract and legal obligation (tax records) |
We also send the service e-mails you need, such as verification codes, appointment confirmations and security notices. These are part of the service, not marketing.
Sharing with an advisor: only when you choose
Your account never becomes an advisor’s contact or client on its own. An advisor sees your information only when you send a sharing request from your account. Each time, you decide:
- who: one verified advisor whose licence has been checked;
- what: which saved results and which contact details (always your name; your e-mail and phone only if you tick them);
- why: for example a cover review, a quote, a question or a claim;
- for how long: 30, 90 or 365 days;
- whether the advisor may send documents or summaries back to your account.
If the advisor works in an agency that uses a shared VÉRO CRM workspace, what you share is also visible to the agency colleagues who handle clients (advisors, managers, administrators); office assistants do not see it. The advisor’s agency is shown on the sharing form.
You can withdraw sharing at any time from your account. From that moment the advisor no longer sees your information through VÉRO. Anything the advisor has already recorded in their own systems, such as their CRM, is their responsibility as a separate controller, and you can contact them directly about it.
For advisors who use VÉRO CRM
When an advisor records their clients in VÉRO CRM, the advisor is the controller for that data. VÉRO acts as a processor: it hosts and processes the data only to provide the service and only on the advisor’s instructions, under a Data Processing Agreement (see the Terms of use, Part B).
If you are an advisor’s client and want to use your rights over what they hold about you, please contact the advisor first. We will help them respond.
Service providers we use
We do not sell or rent data. We use a small number of providers who process data on our behalf, under contract and only for the purpose we set:
- Hosting of the VÉRO CRM platform (app.vero.cy): Hetzner Online GmbH (Germany), on a server in Finland, inside the European Union.
- Hosting of the website vero.cy: WordPress.com (Automattic). [Storage location: to be confirmed.]
- E-mail delivery (verification codes, password resets, invitations, appointment confirmations, notices): the Titan e-mail service, from info@vero.cy. [Processing location: to be confirmed.]
- AI text drafts, only when an advisor asks for one in VÉRO CRM: Anthropic, which receives the text of the request only to return the draft.
- Stripe, for VÉRO CRM subscription payments. You enter your card details on Stripe’s payment page and they never reach VÉRO; we receive only the payment and subscription status. For some purposes, such as fraud prevention, Stripe acts as a separate controller under its own privacy policy.
If a provider processes data outside the European Economic Area, this happens only with the safeguards the GDPR requires, such as the European Commission’s standard contractual clauses. [To be completed for each provider.] We may also disclose data to public authorities where the law requires it.
How long we keep data
| Data | How long |
|---|---|
| Account and saved results | Until you delete them or delete your account |
| Messages and appointments | 24 months, then anonymised |
| Sharing with an advisor | Until they expire or you withdraw them |
| Consent records | As long as needed to prove consent; after account deletion, in pseudonymised form |
| Security log | 180 days |
| Subscription billing records | As long as tax law requires |
When you delete your account, your saved results are deleted, all active sharing is withdrawn, and your messages and appointments are anonymised. Backups of the VÉRO CRM platform are replaced automatically, so anything deleted is also gone from them within 21 days at the latest. [Website backups: to be completed.]
Your rights
- Access and portability: download all your account data as a JSON file from Account settings.
- Correction: update your details in your settings, or ask us to correct them.
- Erasure: delete your account from your settings by confirming your password. If you are an advisor with an active subscription, cancel it first; your data stays available for export.
- Withdrawing consent: stop newsletters in your settings and withdraw sharing from your account. Withdrawal does not affect what happened before it.
- Objection and restriction: object to processing based on our legitimate interest, or ask us to restrict processing.
- Complaint: you can complain to the Cyprus Commissioner for Personal Data Protection (www.dataprotection.gov.cy).
For any request, write to us through the Contact page. We reply without undue delay and within one month at the latest. We may ask you to confirm that the request is yours.
Cookies
We use only cookies that are strictly necessary for the website to work. These do not need consent, because the service you ask for cannot work without them.
| Cookie | Purpose |
|---|---|
| Sign-in | Keeps you signed in to your account. It ends when you close your browser or, if you choose to stay signed in, after up to 14 days. |
| Security | Checks that your browser accepts cookies and protects sign-in and forms against unauthorised requests. |
| VÉRO CRM sign-in (advisors only) | Lets you move securely from the Advisor Hub to VÉRO CRM and keeps your session there. |
We do not use advertising cookies, social media cookies or third-party tracking tools.
The hosting platform may collect anonymous visitor statistics; details: [to be completed].
How we protect your data
- Connections to the website are encrypted (HTTPS).
- Passwords and verification codes are stored only in one-way hashed form.
- IP addresses are stored only as hashes.
- Sign-in attempts and forms are rate-limited to prevent abuse.
- Advisors are listed on VÉRO and can receive shared information only after their licence has been verified.
If a breach occurs that may affect you, we will inform you and the Commissioner as the law requires.
Children
VÉRO accounts are intended for adults. We do not knowingly create accounts for children.
Changes to this policy
When this policy changes, we update the version at the top of the page. For significant changes, we will let you know by e-mail or in your account before they apply.