Vera
Back to home

Legal

Privacy Policy

Last updated:

This policy explains how Vera IT PTY LTD, trading as Vera (“we”, “us”, and “our”), handles personal information through our website, IT Checkup, and IT asset and software management app. App-specific processing applies when you or your organisation use those features.

1. Who this policy covers

Vera is operated by Vera IT PTY LTD. You can contact us at hello@verait.io. This policy covers website visitors, people who contact us or register interest, app users, and people whose information an organisation adds to Vera.

We manage information used to operate our own website, accounts, communications, and billing. When an organisation adds employee or business records to its workspace, we process those records to provide the service to that organisation. Its administrators control workspace access and how the records are used. For requests about employer-managed records, contact your organisation first; we can help route your request.

2. Information we collect

  • Contact details: your email address, messages you send us, signup source and time, browser user agent, and a hashed version of your IP address recorded with a signup. Hosting services may also process IP addresses in connection and security logs.
  • IT Checkup: answers are used in your browser to calculate results. If you request an emailed report, your email address, result scores, identified gaps, and selected recommendations are sent to our server and email provider. Requesting a report does not create a Vera account or subscribe you to marketing emails.
  • Account and workspace details: names, email addresses, authentication identifiers, organisation details, roles, invitations, preferences, and account activity.
  • Business records: team names, work emails, departments and job titles; device names, serial numbers, operating systems, assignments and warranties; software licences, costs and renewals; domains, tasks, notes, and documents you upload or import.
  • Connected services: authorised directory, device, licence, profile and task information from Microsoft or Google, connection identifiers, and access and refresh tokens needed to maintain the connection.
  • Security and AI features: email addresses submitted for breach checks and returned findings; prompts and relevant context used by AI features; and access records for connected assistants.
  • Billing and technical information: subscription status, customer and transaction identifiers, billing contact details, page views, product events, browser and device characteristics, performance measurements, and error reports. Payment details entered in Stripe checkout are handled by Stripe.

We collect information from you, your organisation and its authorised users, connected services, and your use of Vera. Please only provide information you are authorised to share. Do not put passwords, payment card details, or unnecessary sensitive personal information in notes, tasks, documents, or AI prompts.

3. How we use information

We use information to provide and maintain Vera, authenticate users, manage workspaces and subscriptions, import and organise records, sync tasks, check breach exposure, deliver requested reports, respond to enquiries, and send product updates you requested. We also use it to diagnose errors, understand product use, improve the service, prevent misuse, and meet applicable legal obligations.

You can browse the website without creating an account. If you choose not to provide information needed for a report, account, or integration, that feature may be unavailable. You can ask us to stop marketing emails at any time by emailing hello@verait.io; this does not stop necessary service or security messages for an active account.

4. Analytics and browser storage

The public website uses Vercel Web Analytics and Speed Insights to measure visits and performance. IT Checkup events include step completion, time spent, result bands, and report-request interactions. These events do not include the email address you enter in the report form.

The app uses PostHog for optional product analytics and technical exception reporting. You can decline optional app analytics in its banner and change your preference in Settings under notifications. The app analytics setup does not use session replay. This app preference is separate from the public website's analytics.

The app and its authentication provider use browser storage or cookies for sign-in and preferences. You can manage storage through your browser, although blocking essential storage can affect sign-in or saved preferences. Technical error reports may include page and browser context.

5. Integrations, breach checks, and AI

Connecting Microsoft 365 or Google Workspace lets Vera retrieve the directory and device information covered by the permissions you grant; supported Microsoft connections can also retrieve licence information. Personal Google Tasks and Microsoft To Do connections let you send tasks to those services, and Google task completion status can sync back. Connections may refresh in the background while authorised.

You can disconnect integrations in Vera or revoke access with the provider. Disconnecting does not automatically delete records already imported into your workspace or tasks sent to another service. Manage those records separately or contact us for help.

When breach monitoring is used, Vera sends team email addresses to Have I Been Pwned and stores the returned findings. An organisation should inform its team about this processing and ensure it has authority to request checks.

Where AI features are enabled, prompts and relevant document or workspace context may be processed by OpenAI to produce answers or document search results. If you authorise an external assistant through Vera's MCP connection, permitted workspace information can be sent to that assistant, including team, asset, software, task, domain, and breach information. The assistant provider handles received information under its own terms and privacy policy. Review its data-use settings before connecting it.

6. Who receives information

Information is available to authorised members of your workspace according to their access, and to providers that support the features you use. These include:

  • Vercel for website hosting, analytics, and performance monitoring; Convex for app data storage and backend services; and Clerk for app authentication.
  • Cloudflare for delivering IT Checkup emails. Where signup notifications are enabled, the email address and signup source are also sent to the Vera team through Discord.
  • Stripe for subscriptions and payments, and PostHog for app analytics and error reporting.
  • Microsoft, Google, Have I Been Pwned, OpenAI, and assistants you authorise, for the connections and features described above.

We may also disclose information when reasonably necessary to comply with law or a valid legal request, protect people or the service, obtain professional advice, or complete a business transfer subject to appropriate confidentiality and privacy protections.

7. International processing

Vera uses cloud services with international operations. Your information may be processed outside your country, including in the United States, depending on the provider and feature. Connecting an external service can also transfer information to the locations used by that provider. Vera does not promise that all information stays in Australia or in a single region.

Where applicable law requires safeguards for an international transfer, those requirements apply to our handling of the transfer. Contact us for information about the providers and processing locations relevant to your workspace.

8. Security and retention

Vera uses authentication, workspace access controls, and encryption for stored integration tokens to protect information. No online system can guarantee absolute security. Tell us promptly if you suspect unauthorised access to your account.

We retain information for as long as needed for the purposes described here, taking account of active accounts and connections, support needs, security investigations, and legal recordkeeping requirements. Different records have different lifetimes; cancellation or disconnection does not necessarily erase them immediately. Copies may remain in backups and provider records until their applicable retention periods end.

You can request deletion of your personal information or contact record by contacting us. For workspace data, an authorised administrator can use available account controls or contact us. We may need to retain some records for legal obligations or legitimate security needs and will explain any applicable limitation when responding.

9. Your choices, requests, and complaints

To request access, correction, or deletion, withdraw a consent, or raise a privacy concern, email hello@verait.io. Include the email or organisation associated with your request, but do not send passwords or unnecessary identity documents. We may need to verify your identity and authority before providing or changing records.

Depending on where you live and which laws apply, you may also have rights to object to or restrict processing, receive a portable copy, or appeal a decision. We assess requests under applicable law and explain our response. Withdrawing consent does not affect processing that was lawful before withdrawal.

We will review privacy complaints, investigate the circumstances, and respond using the contact details you provide. If you are dissatisfied, you can contact your local privacy regulator. In Australia, this is the Office of the Australian Information Commissioner.

10. Children and policy changes

Vera is a business service and is not directed at children. If you believe a child has provided personal information directly to us, contact us so we can investigate and take appropriate action.

We may update this policy as Vera or its data practices change. We will publish the updated version here and revise the date above, and provide additional notice where required by law. Our Terms of Service explain the conditions for using Vera.