Legal // Effective 19 June 2026

Privacy Policy.

How VeritasLedger Global handles personal data in connection with our forensic and compliance services — including GDPR and UK GDPR rights.

Policy Document // Public
Jurisdiction
EU/UK
Framework
GDPR
Status
ACTIVE
Document // Full Text

1. Who we are

VeritasLedger Global ("VeritasLedger", "we", "us", "our") provides blockchain forensic, transaction verification, and compliance advisory services to institutional clients. For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR / Data Protection Act 2018, VeritasLedger acts as a data controller for personal data submitted through our website, intake forms, and direct correspondence, and as a data processor when handling personal data on behalf of an engaged client under a written services agreement.

Privacy enquiries can be sent through the secure intake form on our contact page or through the in-app support chat.

2. Personal data we collect

  • Intake and engagement data: company name, contact name, business email, jurisdiction, transaction type and value, and any notes you choose to share when requesting a consultation.
  • Payment data: payer name, email, cryptocurrency network, amount, package selected, and transaction hash for verification and accounting.
  • Support data: messages exchanged with our AI assistant or escalated to a human agent, including any contact details you provide for follow-up.
  • Technical data: IP address, user agent, and basic request metadata captured by our hosting and security infrastructure for fraud prevention and service integrity.
  • Matter data: information you share during a paid engagement (wallet addresses, transaction records, documents). This is processed under our engagement contract.

We do not knowingly collect special-category data (health, race, religion, biometrics) and ask that you not submit it through the intake form. We do not collect data from children under 16.

3. How and why we process your data (legal bases)

  • To respond to enquiries and deliver services — legal basis: performance of a contract or steps taken at your request prior to entering one (Art. 6(1)(b) GDPR).
  • To process payments and keep accounting records — legal basis: contract and legal obligation (Art. 6(1)(b) and (c) GDPR).
  • To prevent fraud, secure our systems, and meet AML / sanctions obligations — legal basis: legal obligation and legitimate interests (Art. 6(1)(c) and (f) GDPR).
  • To operate and improve the website and chat support — legal basis: legitimate interests in running a secure, useful service (Art. 6(1)(f) GDPR).

We do not sell personal data and we do not use it for advertising or behavioural profiling.

4. Who we share data with

We share personal data only with vetted processors that support our service, under written data processing terms:

  • Hosting and database: our managed cloud backend provider, which stores intake submissions, payment records, and support escalations.
  • Transactional email: our email delivery provider, used to send payment notifications and escalation alerts to our operations inbox.
  • AI assistant: our model gateway provider, which processes chat messages to generate replies. Conversations are not used to train third-party models.
  • Professional advisers and authorities: where required by law, regulation, court order, or to investigate suspected fraud or abuse.

5. International transfers

Some of our processors are located outside the EEA and the UK. Where personal data is transferred internationally, we rely on adequacy decisions where available, and otherwise on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary technical and organisational measures.

6. Retention

  • Intake submissions not converted into engagements: retained for up to 24 months, then deleted or anonymised.
  • Engagement / matter files: retained for 7 years after the close of the engagement to meet professional, AML, and tax record-keeping obligations.
  • Payment and accounting records: retained for the period required by applicable tax and AML law (typically 7 years).
  • Support chat transcripts and escalations: retained for up to 12 months for quality and dispute purposes.
  • Security and request logs: retained for up to 90 days, then rotated.

When a retention period ends we delete the data or irreversibly anonymise it. Backups are purged on their normal rotation cycle.

7. Security

We apply technical and organisational measures appropriate to the sensitivity of the data we handle, including encryption in transit (TLS), encryption at rest at the database layer, role-based access control with least privilege, row-level security on customer-data tables, audit logging, and dedicated service accounts for server-side data access. Access to client matter data is limited to the engagement team on a need-to-know basis.

8. Your rights under GDPR and UK GDPR

If you are located in the EEA, the UK, or Switzerland, you have the following rights with respect to your personal data:

  • Access — obtain confirmation that we process your data and a copy of it.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure ("right to be forgotten") — request deletion where one of the GDPR grounds applies and no overriding legal obligation requires us to keep it.
  • Restriction of processing in defined circumstances.
  • Portability — receive data you provided to us in a structured, machine-readable format.
  • Objection — object to processing based on our legitimate interests.
  • Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.
  • Lodge a complaint with your local supervisory authority — for example the UK Information Commissioner's Office (ICO), the Irish Data Protection Commission, or the supervisory authority of your EU member state.

To exercise any of these rights, submit a request via our contact page. We respond within one month and may extend by up to two further months for complex requests, as permitted by Art. 12(3) GDPR. We may need to verify your identity before acting on a request.

9. Cookies and analytics

The site uses only the strictly necessary cookies and local storage required to run the application, maintain a session for authenticated areas, and protect against abuse. We do not use third-party advertising cookies or cross-site tracking.

10. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Our AI support assistant provides informational replies and routes unresolved questions to a human team member.

11. Changes to this policy

We may update this policy from time to time. Material changes will be reflected in the effective date at the top of the page and, where appropriate, communicated to active clients directly.

12. Contact

For privacy questions, data subject requests, or to raise a concern, please use our secure intake form and mark your message "Privacy request". We treat all such requests as priority.