Legal

Privacy Policy

How Verityn Ltd collects, uses, shares, and protects personal data. We believe in being direct about this.

Last updated: 1 October 2025

1

Who we are and how to contact us

The data controller is Verityn Ltd, a company registered in England and Wales. Our registered office is Third Floor, 24 Wharfdale Road, King's Cross, London, N1 9RY.

For any privacy query, write to us at hello@verityn.ai or to the address above marked for the attention of the Privacy Officer. We aim to respond within five working days.

2

Personal data we collect

We collect personal data in the following categories:

  • Account data: name, job title, institutional affiliation, email address, and password (stored as a salted hash).
  • Usage data: log records of studies reviewed with Verityn, flags generated and acted upon, timestamps, and session identifiers.
  • Technical data: IP address, browser type and version, operating system, and device identifiers.
  • Communications data: the content of enquiries sent to us by email or through our contact forms.
  • Medical imaging data: de-identified DICOM studies uploaded for second-read processing. We do not request or accept studies that retain patient-identifying metadata.

3

Lawful basis for processing

We process personal data on the following lawful bases under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018:

  • Contract: processing necessary to perform our agreement with you or your institution, including providing access to the Verityn platform.
  • Legitimate interests: analysing aggregated and anonymised usage to improve the product, maintaining security logs, and detecting abuse, provided these interests are not overridden by your rights.
  • Legal obligation: retaining records where required by applicable law, including financial and audit obligations.
  • Consent: sending non-essential communications such as product updates and blog notifications, where you have opted in.

We do not rely on consent as the lawful basis for processing your account data or providing the core service.

4

Special category data and medical imaging

Medical imaging data may constitute special category data under Article 9 UK GDPR (data concerning health). We require all institutional customers to de-identify studies before upload and to confirm in their Data Processing Agreement that de-identification has been performed to an appropriate standard. Where we process special category data on behalf of a clinical institution, we do so as a processor under their lawful basis and in accordance with a signed Data Processing Agreement. We do not process identifiable patient data as a controller.

5

How we use your personal data

  • To provide and maintain your access to the Verityn platform.
  • To process second-read analyses and return flags, heatmaps, and confidence values.
  • To maintain audit logs required for medical device post-market surveillance.
  • To investigate and respond to security incidents.
  • To comply with legal, regulatory, and professional obligations.
  • To send service communications (account notices, security alerts, and material changes to these terms).
  • To send optional communications (blog posts, product updates) where you have consented.

6

Who we share data with

We do not sell personal data. We share data only with the following categories of recipient, and only to the extent necessary:

  • Cloud infrastructure providers hosting the Verityn platform and its databases, under data processing agreements.
  • Third-party AI model inference providers, where image analysis is performed by a sub-processor. A full list of sub-processors is available on request and in our Data Processing Agreement.
  • Professional advisers (lawyers, accountants, auditors) bound by confidentiality obligations.
  • Regulatory authorities and law enforcement where required by law.
  • Successors in a merger, acquisition, or asset sale, subject to appropriate safeguards.

7

International transfers

Some of our sub-processors operate outside the UK and the European Economic Area. Where personal data is transferred internationally, we ensure an appropriate safeguard is in place: an adequacy decision by the UK Secretary of State, or standard contractual clauses approved by the Information Commissioner's Office, supplemented by a transfer impact assessment where required. Details of the transfer mechanisms in place for each sub-processor are available on request.

8

How long we keep your data

We retain personal data only for as long as necessary for the purposes set out in this policy or as required by law. Our standard retention periods are:

  • Account data: for the duration of your account and for seven years after closure, to comply with financial and audit obligations.
  • Usage and audit logs: for seven years, to support post-market surveillance and any regulatory inspection.
  • De-identified imaging data: for no longer than ninety days after processing, unless a longer period is agreed in writing with the institution.
  • Communications data: for three years from the date of the communication, or until you request deletion.
  • Security logs: for two years.

9

Your rights

Under the UK GDPR you have the following rights. You can exercise any of them by writing to hello@verityn.ai. We will respond within one month.

  • Right of access: to receive a copy of the personal data we hold about you.
  • Right to rectification: to have inaccurate data corrected.
  • Right to erasure: to have your data deleted where we no longer have a lawful reason to hold it.
  • Right to restriction: to restrict our processing of your data in certain circumstances.
  • Right to data portability: to receive your data in a structured, machine-readable format.
  • Right to object: to object to processing based on legitimate interests, including for direct marketing.
  • Rights related to automated decision-making: we do not make solely automated decisions that produce legal or similarly significant effects.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

10

Cookies and tracking technologies

We use strictly necessary cookies to maintain your authenticated session and to provide security controls. We do not use advertising cookies or share data with advertising networks.

We use analytics cookies only where you have consented via the cookie notice on your first visit. Analytics data is aggregated and does not identify individual users. You may withdraw consent at any time by adjusting your cookie settings or by writing to us.

11

Security

We implement technical and organisational measures proportionate to the risks posed by our processing, including encryption in transit and at rest, access controls based on the principle of least privilege, penetration testing, and a documented incident response plan. Details of our security controls are available in the Security page. To report a security vulnerability, write to security@verityn.ai.

12

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and update the "last updated" date below. Continued use of the Verityn platform after the effective date of a revised policy constitutes acceptance of the revised terms.