Privacy Policy (GDPR)

Privacy Policy

This Privacy Policy describes how Verify Solutions, S.L. processes personal data when you use the platform, applications, dashboards and related services (hereinafter, the Service).

1. Data Controller

2. Applicable regulations

3. Principles applied

The Controller applies the GDPR principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.

4. Categories of data subjects

5. Categories of data processed

6. Source of the data

7. Purposes of processing and legal bases

We process personal data for the following purposes, with their legal bases:

8. Processing on behalf of the customer (Processor vs Controller)

In certain services, Verify Solutions, S.L. may process data on behalf of the customer (for example, when the customer uploads documentation or connects business data for analysis). In such cases, the customer may act as Controller and Verify Solutions, S.L. as Processor, formalising a data processing agreement pursuant to GDPR art. 28 where applicable.

9. Recipients and processors

Data may be disclosed to or accessed by:

We do not sell personal data to third parties.

10. International transfers

If any provider is located outside the European Economic Area, appropriate safeguards will be applied (for example, Standard Contractual Clauses of the European Commission or other valid mechanisms). The user may request additional information about the applied safeguards at the email indicated above.

11. Retention periods

12. User rights

You may exercise the rights of:

To exercise them, contact clientes@ecomverify.email. If you believe we have not properly handled your rights, you may lodge a complaint with the Spanish Data Protection Agency (AEPD).

13. Automated decisions and profiling

We may generate metrics, scores or indicators (for example, ratings or scores based on provided and verified data) for certification and fraud prevention purposes. Should automated decisions with legal or significant effects exist, the user will be informed and applicable rights will be enabled, including human intervention, expressing their point of view and contesting the decision, pursuant to GDPR art. 22.

14. Security measures

We apply appropriate technical and organisational measures, including, where applicable: encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access control, activity logging, strong authentication, environment segregation, backups, least-privilege policies and incident management procedures.

15. Data breaches

In the event of a personal data breach, the Controller will apply the notification procedures to the supervisory authority and, where applicable, to those affected, pursuant to arts. 33 and 34 GDPR.

16. Third-party data provided by the user

If the user provides data of third parties (for example, representatives, employees or partners), they guarantee that they have a legitimate basis for doing so and that they have informed those third parties of this Privacy Policy.

17. Changes to this policy

We may update this Policy to adapt it to legal or technical changes. The current version will be published in the Service.


Last updated: 2026-08-03. Verify Solutions, S.L. — Tax ID B27661099 · Girona Companies Register (Registro Mercantil), Sheet GI-79107 — Carrer Riera Garrap, 37, 17007 Girona, Spain.