01About this Privacy Policy
This Privacy Policy explains how Just Verify Limited collects and uses personal information in connection with our website, communications, products, services, verification activities, research, programmes and organisational relationships.
It may apply to website visitors; people who contact us; prospective and existing customers; suppliers; partners; Think Tank, event and roundtable participants; researchers; contributors; advisers; job applicants; representatives of organisations; and people whose information is included in material processed through an agreed activity. Personal information and personal data mean information relating to an identified or identifiable individual.
Additional privacy information may apply to a particular service, engagement, event, research project or product. Where we process information solely on a customer's documented instructions, we may act as a processor or service provider and the relevant controller's privacy information and contractual terms may also apply.
02Who we are
Just Verify Limited is the controller responsible for the personal information described in this Privacy Policy unless another notice or agreement explains otherwise. We are registered in England and Wales under company number 16356481.
Just Verify Limited82a James Carter Road
Mildenhall
United Kingdom
IP28 7DE
contact@justverify.ai
Where we act as a processor for another controller, requests concerning that processing may need to be directed to that controller.
03Personal information we may collect
Depending on the relevant relationship or activity, we may collect identity and contact information; organisation and professional information; enquiry, communication and meeting information; relationship, contract, billing and engagement records; Think Tank, event and programme participation information; and marketing preferences.
Where account-based products or services are introduced, this may include account identifiers, usernames, authentication information, access roles, permissions, account activity and support records. Depending on agreed verification work, we may process submitted evidence, system, provider, model, agent, workflow, log, governance, provenance, control, decision and assurance records, which may contain personal information about employees, customers, users or contractors.
We may also collect website and technical information, including IP address, browser, operating system, device information, pages viewed, referring source, session data, approximate location derived from technical data, cookie identifiers and security logs. Where applicable, recruitment information and public professional-source information may be collected. We may derive relationship status, areas of interest, engagement history, verification indicators or risk and evidence classifications relating to systems, organisations, controls or processes.
04Special-category and sensitive information
We do not ordinarily need special-category information through general website forms. This may include health, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade-union membership, genetics, biometrics used for identification, sex life or sexual orientation. Other laws may also treat precise location, government identifiers, financial-account credentials or certain communications as sensitive.
We may process sensitive information where valid explicit consent, an employment or social-protection obligation, legal claims, information clearly made public, another lawful condition, or agreed service material with appropriate safeguards permits it. Do not submit special-category information, confidential credentials or sensitive records through general forms unless necessary and an appropriate secure process has been agreed. Criminal-offence information requires an appropriate lawful basis and condition.
05How we collect personal information
We may collect information directly from you when you visit the website, complete a form, email us, attend a meeting or event, subscribe, submit an expression of interest, provide project material, enter an agreement or apply for a role.
We may also receive information from your organisation, customers, suppliers, project partners, event hosts, researchers, advisers, lawful public authorities, referrals, introductions, public websites, professional profiles, corporate records, public registers, publications, research and conference information. Technical information may be collected automatically through logs, cookies, similar technologies, analytics, security tools and browser interactions. Information from another source is handled consistently with applicable transparency requirements.
06How and why we use personal information
We use personal information to operate and protect the website; respond to enquiries; provide agreed products, services and verification activities; manage customer, supplier and partner relationships; operate Think Tank, event and programme activity; undertake research; improve products and methods; communicate about relevant work; meet legal obligations; and manage corporate administration or transactions.
- Website operation and security: delivery, functionality, misuse prevention, incident detection, troubleshooting and performance analysis. Lawful bases may include legitimate interests, legal obligations and consent for non-essential technologies where required.
- Enquiries and engagements: reviewing requests, arranging meetings, delivering agreed work, collecting and reviewing evidence, preparing reports and maintaining records. Lawful bases may include legitimate interests, steps before contract, performance of a contract, legal obligations and consent where specifically required.
- Programmes, research and communications: participation, research, reporting, improvements, newsletters and relevant updates. Lawful bases may include legitimate interests, consent, publicly available information, contract performance and applicable electronic-marketing rules.
- Legal, financial and corporate matters: accounting, tax, legal requests, disputes, insurance, audits, investment and restructuring. Lawful bases may include legal obligations, legitimate interests and legal claims.
More than one lawful basis may apply. Consent may be withdrawn where relied upon, without affecting earlier lawful processing. We will consider legal requirements before using information incompatibly with the original purpose.
07Marketing communications
We may send relevant communications about research, events, Think Tank programmes, products, services and organisational updates where consent, applicable electronic-marketing rules or another lawful basis permits and the communication is reasonably expected in the professional relationship.
Electronic marketing should provide a clear way to unsubscribe. You can also change preferences through contact@justverify.ai. Opting out does not prevent service, legal, security, project, enquiry-response or other non-marketing messages. We may retain a minimal suppression record to respect an opt-out.
08Cookies and similar technologies
The website may use cookies and similar technologies to operate essential features, maintain security, remember preferences, understand performance, measure engagement and improve the website. Where required, non-essential technologies should not be activated until an appropriate choice has been made.
Visitors should be able to accept or reject non-essential technologies, adjust available preferences, withdraw consent and use browser controls. Further information is in the Cookie Policy. Before publication, cookie categories, scripts, analytics disclosures and consent controls should be checked against the live implementation.
09When we share personal information
We may disclose personal information to service providers and processors supporting hosting, cloud infrastructure, email, communications, document storage, security, analytics, relationship management, event management, payment processing, collaboration or technical services; and to professional advisers such as lawyers, accountants, auditors, insurers and consultants.
We may share information with customers, partners, project participants, event hosts, programme collaborators, authorities or corporate-transaction recipients where necessary and lawful for an agreed engagement, project, event, programme, research, legal requirement or transaction. Appropriate notice, confidentiality and contractual arrangements should be used where required. Providers and processors should protect information and use it only for agreed purposes.
10International transfers
Some providers, partners or recipients may be outside the United Kingdom or access personal information from another country. Where a transfer is restricted, we should use an appropriate mechanism, which may include UK adequacy regulations, an applicable European adequacy decision, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, approved standard contractual clauses, binding corporate rules or another legally permitted safeguard or exception.
Where required, we should assess protection and apply supplementary measures. You may contact us for information about safeguards relevant to a transfer. We do not state that all information is stored exclusively in the United Kingdom.
11How long we retain personal information
We retain personal information only for as long as reasonably necessary for its purpose and related legal, accounting, security or reporting requirements. Decisions consider the purpose, sensitivity, amount, relationship, contractual obligations, limitation periods, tax requirements, security needs, dispute risks and whether information can be anonymised.
Examples include retaining enquiry records for a reasonable period after communication; project and contract records during a relationship and an appropriate period afterwards; financial records as required by law; marketing preferences until withdrawal with a limited suppression record; programme records for administration and reporting; and logs according to operational and security needs. We do not specify fixed periods unless verified. Information no longer required should be deleted, securely destroyed or anonymised.
12Security
We use reasonable technical and organisational measures designed to protect personal information from unauthorised access, accidental loss, misuse, alteration, disclosure and destruction. Measures may include access controls, authentication, role-based permissions, encryption, secure configuration, backups, logging, monitoring, confidentiality, supplier due diligence, incident processes, minimisation and secure deletion.
Access should be limited to authorised people with a legitimate need. No system, transmission method or storage environment can be guaranteed completely secure. We should assess a personal-data breach and notify individuals or regulators where required by law.
13Your data-protection rights
Rights depend on applicable law, circumstances and lawful basis. They may include rights to be informed, access personal information, rectify inaccuracies, request erasure, restrict processing, receive portable information, object to processing based on legitimate interests or public-interest grounds, withdraw consent, and rights relating to solely automated decisions with legal or similarly significant effects.
You have the right to object at any time to the use of your personal information for direct marketing.
To exercise a right, contact contact@justverify.ai. We may need to verify identity. No fee is normally charged, although law may allow a reasonable fee or refusal for manifestly unfounded, excessive or repetitive requests. Some rights are subject to legal exemptions.
14Complaints
Please contact us first at contact@justverify.ai so we can review a concern. You may also complain to the Information Commissioner's Office, the United Kingdom's data-protection regulator, through its official complaint service. People outside the United Kingdom may also have a right to complain to their local authority. A complaint does not affect other legal rights.
15California privacy information
Where applicable, California residents may have rights to know categories and specific pieces of personal information collected, sources, purposes and recipients; request deletion or correction; opt out of sale or sharing where applicable; limit certain sensitive-information uses; and avoid discriminatory treatment for exercising rights. The relevant categories, sources, purposes and recipients are described above.
Requests may be made through contact@justverify.ai. An authorised agent may submit a request where California law permits, subject to appropriate verification. We do not make an unverified statement about sale or sharing as defined by California law. The live cookies, analytics, advertising and disclosures must be checked before publishing any further California-specific claim.
16Canadian privacy information
Where Canadian federal or provincial privacy law applies, individuals may have rights to understand use, request access or correction, withdraw consent where processing depends on it, challenge compliance and complain to the relevant regulator. Withdrawing consent can affect our ability to provide a requested product, service, programme or communication where necessary information is withdrawn. Send requests to contact@justverify.ai. Individuals may also complain to the Office of the Privacy Commissioner of Canada or the appropriate provincial authority.
17Rights in other jurisdictions
People elsewhere may have additional rights, including access, correction, deletion, objection, restriction, portability, withdrawal of consent, opt out, appeal and complaint rights. We will consider requests under the law applying to the relevant processing. Not every right applies worldwide or in every circumstance. Where the EU GDPR applies, individuals may also complain to the supervisory authority where they live, work or believe an infringement occurred.
18AI-assisted tools and automated decision-making
Our work concerns AI verification, evidence, trust, governance, assurance and monitoring. We may use AI-assisted tools for appropriate internal or service-related activities such as organising information, summarising material, supporting research, identifying patterns, classifying evidence, reviewing technical information, administrative workflows, verification or assurance activity, and improving products and methods.
Where personal information is involved, we should identify a lawful purpose and basis, use information proportionately, apply access and security controls, assess accuracy and limitations, provide human review where appropriate, avoid unsupported output and meet contractual and confidentiality obligations. Products or systems may generate evidence indicators, verification signals, trust records, assurance findings, risk or control observations and monitoring alerts.
We do not intend to make decisions about individuals solely through automated processing where they produce legal or similarly significant effects unless lawful, necessary, proportionate and accompanied by required information and safeguards. We do not claim that confidential customer or project information is used to train general-purpose AI models unless specifically authorised and accurately disclosed.
19Confidential and third-party information
Only provide another person's information where you have an appropriate legal basis, authority or permission. Submitted material can include employee, customer, supplier, system-user and project information, logs, evidence, internal documents and confidential business information. The submitting organisation is responsible for authorisation and any required privacy information.
Do not use general website forms for passwords, access credentials, secret keys, highly confidential records, unrestricted datasets containing personal information, special-category information or legally privileged material unless an appropriate secure process has been agreed. A general enquiry does not automatically create a confidential, client, partnership, research or advisory relationship. Separate confidentiality or data-processing terms may apply to a formal engagement.
20Third-party websites and services
The website may link to third-party websites, services, platforms, reports, event systems or social-media pages. A link does not mean that we endorse a third party, control its processing, accept responsibility for its privacy practices, or guarantee its security or availability. Review the relevant third party privacy policy before submitting personal information. Where we embed or integrate a third-party service, the website and Cookie Policy should explain the relevant processing accurately.
21Children's privacy
The website, products, services and programmes are directed primarily to organisations, professionals and adult participants. We do not knowingly seek personal information from children through general website forms. A person under 18 should not submit personal information without appropriate permission and supervision from a parent, guardian, school or responsible organisation.
If we become aware that a child's information has been collected inappropriately, we will take reasonable steps to review and delete or otherwise handle it as required by law. Contact contact@justverify.ai.
22Changes to this Privacy Policy
We may update this Privacy Policy for changes in law, regulatory guidance, website changes, products, services, processing activities, technology, security or organisational developments. The revised version will be published here with an updated effective or last-updated date. Where a change materially affects use of personal information, we may provide additional notice where required or appropriate. Earlier versions may be retained for legal, accountability or record-keeping purposes.
23Contact Just Verify
Questions, requests or concerns about this Privacy Policy or our use of personal information should be sent to:
Just Verify Limited82a James Carter Road
Mildenhall
United Kingdom
IP28 7DE
Company number: 16356481
Email: contact@justverify.ai