This service is provided by Veraxus Ltd ("we", "us", "our"), a company registered in England and Wales (company number 17093059), registered office 6 Meteor Crescent, Warrington, WA2 0DU. We are registered with the UK Information Commissioner's Office (ICO) under reference 00014402595. For data-protection matters, contact contact@veraxus.co.uk. We are the controller for personal data we hold about you as a user of the app. This policy is written to meet the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
It covers how we handle personal data when you create an account, use the Veraxus Contractor Hub app, share a public profile, or contact us. Where you store information about your own clients in the app, you are the controller of that data and we are your processor (see section 9).
| Category | Examples |
|---|---|
| Account data | Email address; a securely hashed password; account creation and sign-in records. |
| Profile data | Business name, your name, trade, company registration number and status, short bio, business logo. |
| Compliance documents | Insurance certificates, qualifications, IDs and other documents you upload, plus issuer and expiry details. |
| Your clients' / jobs data | If you add client or job details, that information (for which you are the controller — section 9). |
| Usage & analytics | Actions you take in the app, pages viewed, time spent in the app, device and browser type, and approximate location derived from your IP address — collected via privacy-friendly, cookieless analytics. These product analytics are linked to your account so we can understand how the Service is used, improve it, and support you better. |
| Technical & security | IP address, log and audit data used to keep the Service secure and diagnose problems. |
| Communications | Emails we send you (verification, reminders, service notices) and any messages you send us. |
| Payment data (future) | If paid plans are introduced, payments are handled by Stripe; we receive limited records (e.g. that a payment succeeded), not your full card number. |
We do not intentionally collect special-category data (such as health). Please don't upload documents containing more personal data than necessary.
Location (journey screen). If you use the journey screen, your device location is read only when you tap to use it while that screen is open, and never in the background. It is used on your device to estimate distances to your stops and is not stored by us; you can enter a postcode instead. The app can also send you an optional morning brief notification, which you can switch on or off in the app at any time.
Site access passes. If you issue a site access pass, the pass page at its secret link shows the name (and any trade or company you add) of the person the pass is for, the site, the access window, and a plain-English summary of the compliance documents you had on file when the pass was issued. It also names you as the issuer: your business name, or your own name if you have not set a business name. It does not show the documents themselves, your account, your contact details, or anyone else’s data. Anyone holding the link or scanning the QR code can view it, so share it only with the site, and the pass page is not indexed by search engines. The pass expires by itself at the end of its window and you can revoke it at any time. Where the pass is for someone other than you (an employee, a subcontractor or a delivery driver), you are the controller for their details and you should tell them the pass is being issued (section 9).
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| Create and run your account; store and display your documents and profile; send expiry reminders and essential service emails; provide features you use (e.g. company look-up). | Performance of our contract with you. |
| Keep the Service secure, prevent and investigate abuse and fraud, diagnose and fix problems, and understand and improve how the app is used. | Our legitimate interests in running and improving a safe, reliable service (balanced against your rights). |
| Take payments and manage subscriptions (if paid plans are introduced). | Performance of our contract. |
| Send optional product or marketing updates. | Your consent — which you can withdraw at any time. |
| Meet legal, tax, accounting and regulatory obligations. | Legal obligation. |
You have an absolute right to object to direct marketing at any time.
We never sell or rent your data. We share it only with service providers ("processors") who help us run the app, under contracts requiring them to protect it and use it only on our instructions:
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication, file storage | EU (London / Ireland) |
| Vercel | App and website hosting / content delivery | Global edge; US-headquartered |
| Resend | Sending our emails | EU / US |
| PostHog | Privacy-friendly, cookieless usage analytics | EU |
| Companies House | Company look-up when you use that feature | UK |
| Anthropic (Claude AI) | Vera AI features — reading documents or receipts you choose to scan, and drafting text, only when you use them | US (with UK/EU safeguards) |
| Stripe | Payment processing (only if paid plans launch) | EU / US |
We may also disclose data where required by law, to enforce our terms, or to protect rights, safety or property; and to a buyer or successor if we sell or reorganise our business (subject to this policy).
AI features (Vera) — only when you choose to use them. Some optional features use a third-party AI provider (Anthropic). When you scan a document or receipt, or ask Vera to draft or answer something, the relevant content — for example the photo you scan, or the text of your request — is sent to the AI provider to process, and the result is returned to you. Vera reads the content to extract or draft; we do not keep the scanned image as a separate AI record, and what is retained is only what you choose to save (for example a document you add to your Passport). Our AI provider does not use your content to train its models. Using AI is entirely optional: the Hub works fully without it, and you confirm each scan or request yourself.
We aim to keep data in the UK or EU. Some providers are based in, or may process data in, the United States or other countries. Where data is transferred outside the UK, we rely on UK-approved safeguards — such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision — to ensure your data has an equivalent level of protection.
Your data is held in secure, access-controlled databases and storage hosted in the UK/EU. We protect it with measures including encryption in transit (HTTPS/TLS) and at rest (AES-256), database row-level security so each contractor can only access their own data, private document storage accessible only via short-lived, signed links, access controls, and audit logging. No system can be guaranteed perfectly secure, but we take protection seriously and have a process to respond to incidents, including notifying the ICO within 72 hours, and you where required, in the event of a personal-data breach likely to result in a risk to your rights.
We keep your data for as long as your account is active. If you delete your account, we delete your profile, documents, uploaded files and reminders. We may keep limited records for a reasonable period afterwards where we need to for legal, tax (for example, six years for tax records), accounting, dispute or security reasons. Analytics data is kept in aggregated or limited form for service improvement.
If you use the app to store information about your own customers or jobs, you are the data controller for that information and we are your processor. We will: process it only to provide the Service to you and on your instructions; keep it secure; assist you, where reasonable, with requests from your clients and with your own obligations; and delete or return it when you close your account. You are responsible for having a lawful basis to hold your clients' data and for giving them their own privacy information.
Under UK data protection law you have the right to: be informed; access a copy of your data; have inaccurate data corrected; have your data erased; restrict or object to processing; data portability; and to withdraw consent where we rely on it. You can exercise most of these directly in the app (for example by editing your profile or deleting your account) or by emailing contact@veraxus.co.uk. We will respond within one month. There is normally no charge. If we can't act on a request, we'll explain why.
We do not make decisions that produce legal or similarly significant effects about you using solely automated processing. Our analytics are used to understand and improve the Service, not to evaluate individuals.
We use a small number of essential cookies / browser local storage to keep you signed in and make the app work. Our analytics are configured to be cookieless. Because we do not use advertising or non-essential tracking cookies, we don't show an intrusive cookie banner — but you can clear your browser's local storage at any time.
We will only send you marketing if you have agreed to it, and you can opt out at any time via the unsubscribe link in our emails or by emailing us. You will still receive essential service messages (such as security and reminder emails) while you have an account.
The app is for business users aged 18 and over. It is not intended for, and we do not knowingly collect data from, children.
We may update this policy as the Service or the law changes (including changes under the Data (Use and Access) Act 2025). We'll post the new version here with an updated date and, for material changes, notify you.
Please contact us first at contact@veraxus.co.uk — we'd like the chance to help. You also have the right to complain to the ICO: ico.org.uk or 0303 123 1113.
Veraxus Ltd, 6 Meteor Crescent, Warrington, WA2 0DU — contact@veraxus.co.uk.