Privacy Policy
This Privacy Policy describes how Verify Solutions, S.L. processes personal data when you use the platform, applications, dashboards and related services (hereinafter, the Service).
1. Data Controller
- Controller: Verify Solutions, S.L.
- Tax ID: B27661099
- Address: Carrer Riera Garrap, 37, 17007 Girona, Spain
- Contact email: clientes@ecomverify.email
- Security email: security@ecomverify.email
2. Applicable regulations
- Regulation (EU) 2016/679 (GDPR).
- Spanish Organic Law 3/2018 (LOPDGDD).
- Spanish Law 34/2002 (LSSI-CE) on Information Society Services.
- ePrivacy regulations applicable to cookies and similar technologies.
- Where applicable, anti-money laundering (AML/CFT) and regulatory compliance rules.
3. Principles applied
The Controller applies the GDPR principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.
4. Categories of data subjects
- Registered users (business/self-employed customers and authorised internal users).
- Customer contacts (representatives, administrators, attorneys, authorised employees).
- Prospects and information requesters.
- Suppliers and partners.
- Website visitors (cookies and analytics, subject to consent).
5. Categories of data processed
- Identification and contact data: name, surname, email, phone, role, company, country, addresses.
- Account data: credentials, roles/permissions, preferences, access logs.
- Professional / commercial data: business information, activity, corporate structure, submitted documentation.
- Economic and transactional data: billing, sales metrics, statements or movements when integrations are connected with consent.
- Tax / accounting data provided by the customer: records and information necessary to provide the Service.
- KYC and verification data (where applicable): ID document, proof of address, proof of authority, anti-fraud verification.
- Technical data: IP, device identifiers, logs, browser, security events.
6. Source of the data
- Data provided directly by the user or their company.
- Data generated by the use of the Service (logs, auditing, security).
- Data obtained through integrations authorised by the user (for example, payment gateways, e-commerce, open banking) when the user connects such sources and grants consent.
- Data from third parties designated by the customer (accountants, advisors, platforms) when enabled by the customer.
7. Purposes of processing and legal bases
We process personal data for the following purposes, with their legal bases:
- Sign-up, registration and account management (create user, authenticate, manage permissions). Legal basis: performance of contract and pre-contractual measures (art. 6.1.b GDPR).
- Service provision (certification, report generation, dashboards, tracking, customer support). Legal basis: contract (art. 6.1.b).
- Identity verification and anti-fraud controls (KYC where applicable, document validation, abuse prevention). Legal basis: legitimate interest (art. 6.1.f) and, where applicable, legal obligation (art. 6.1.c) when AML/CFT rules apply.
- Integrations and third-party connections (e.g. open banking, online stores, accounting tools), always activated by the user. Legal basis: contract (art. 6.1.b) and consent for specific accesses when required (art. 6.1.a).
- Legal obligations (accounting, tax, authority requests). Legal basis: legal obligation (art. 6.1.c).
- Security and maintenance (monitoring, logs, auditing, incident detection). Legal basis: legitimate interest (art. 6.1.f) and legal security obligation (art. 32 GDPR).
- Operational communications (service notices, incidents, relevant changes, confirmations). Legal basis: contract (art. 6.1.b).
- Marketing communications (news, offers). Legal basis: consent (art. 6.1.a) or legitimate interest towards existing customers where permitted by LSSI-CE, always offering an easy opt-out.
- Analytics and product improvement (usage metrics). Legal basis: legitimate interest (art. 6.1.f) and, when it involves non-technical cookies, consent (ePrivacy).
8. Processing on behalf of the customer (Processor vs Controller)
In certain services, Verify Solutions, S.L. may process data on behalf of the customer (for example, when the customer uploads documentation or connects business data for analysis). In such cases, the customer may act as Controller and Verify Solutions, S.L. as Processor, formalising a data processing agreement pursuant to GDPR art. 28 where applicable.
9. Recipients and processors
Data may be disclosed to or accessed by:
- Technology providers (hosting, email, storage, monitoring, support) under processing and confidentiality agreements.
- Verification / KYC providers if identity controls are activated.
- Payment providers if payment services are contracted.
- Public authorities (Spanish Data Protection Agency, courts, tax administration, others) when there is a legal obligation or valid request.
We do not sell personal data to third parties.
10. International transfers
If any provider is located outside the European Economic Area, appropriate safeguards will be applied (for example, Standard Contractual Clauses of the European Commission or other valid mechanisms). The user may request additional information about the applied safeguards at the email indicated above.
11. Retention periods
- Account and customer data: during the contractual relationship and, after termination, blocked for the legal statute-of-limitations and obligation periods (e.g. commercial and tax) as applicable.
- Support and communications: the time needed to manage the request and, afterwards, during liability and control periods.
- Logs and security: the time strictly necessary for security, auditing and fraud prevention, in line with best practices and legal needs.
- Marketing: until the user withdraws consent or opts out.
12. User rights
You may exercise the rights of:
- Access
- Rectification
- Erasure
- Objection
- Restriction
- Portability
- Withdraw consent at any time (without affecting prior lawfulness)
To exercise them, contact clientes@ecomverify.email. If you believe we have not properly handled your rights, you may lodge a complaint with the Spanish Data Protection Agency (AEPD).
13. Automated decisions and profiling
We may generate metrics, scores or indicators (for example, ratings or scores based on provided and verified data) for certification and fraud prevention purposes. Should automated decisions with legal or significant effects exist, the user will be informed and applicable rights will be enabled, including human intervention, expressing their point of view and contesting the decision, pursuant to GDPR art. 22.
14. Security measures
We apply appropriate technical and organisational measures, including, where applicable: encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access control, activity logging, strong authentication, environment segregation, backups, least-privilege policies and incident management procedures.
15. Data breaches
In the event of a personal data breach, the Controller will apply the notification procedures to the supervisory authority and, where applicable, to those affected, pursuant to arts. 33 and 34 GDPR.
16. Third-party data provided by the user
If the user provides data of third parties (for example, representatives, employees or partners), they guarantee that they have a legitimate basis for doing so and that they have informed those third parties of this Privacy Policy.
17. Changes to this policy
We may update this Policy to adapt it to legal or technical changes. The current version will be published in the Service.
Last updated: 2026-08-03. Verify Solutions, S.L. — Tax ID B27661099 · Girona Companies Register (Registro Mercantil), Sheet GI-79107 — Carrer Riera Garrap, 37, 17007 Girona, Spain.