Legal
Privacy Policy
Draft v0.1·Last updated 2026-07-31
1. Overview
This Privacy Policy describes how Saintrac, the company behind Verela, handles data when a customer uses the Verela platform. Verela is a synthetic identity verification platform. Self-serve signup provisions a workspace for synthetic data only. The platform does not process real identity, biometric, repayment, or customer data in the sandbox environment. Processing real identity data requires a separate review and approval that is not available through self-serve signup.2. Data categories handled
- Account dataThe name, email, role, and organization membership of each team member invited to the workspace.
- Synthetic identity dataSynthetic identities, synthetic evidence files, and synthetic verification sessions created for testing and demonstration. No real identity documents or biometric data are processed in the sandbox.
- Operational telemetryVerification session status, policy decisions, review outcomes, audit events, and API request metadata. These records use safe identifiers and allowlisted metadata only.
- Billing dataOrganization name, billing email, tax country, and payment method summary. Full card numbers are handled by the payment provider and never reach Verela's servers.
3. Data the platform does not process
The sandbox environment is designed for synthetic data only. The platform does not process the following categories of data in the sandbox:- Real identity and biometric dataReal identity documents, real biometric data, or real facial images are not processed in the sandbox. Facial verification in production is vendor-provided liveness plus one-to-one comparison only, with no searchable embeddings.
- Real repayment and credit-bureau dataReal repayment records, real credit-bureau data, or real registry data are not processed in the sandbox. The platform does not claim connectivity to any credit bureau or registry authority.
- Real customer dataReal customer records belonging to the institution's end customers are not processed in the sandbox. Only synthetic fixtures are used.
4. Purposes of processing
- Service provisionTo operate the verification workflows, policy engine, review queue, and audit trail that constitute the platform.
- Authentication and accessTo authenticate team members, manage organization membership, and enforce role-based access control.
- BillingTo manage subscriptions, record usage, process payments, and issue invoices.
- CommunicationTo communicate with the organization owner about account status, security notices, and product changes.
5. Retention
The customer configures retention periods for evidence and verification records. Evidence is stored in encrypted, S3-compatible object storage with configurable deletion schedules and legal-hold controls. Metadata history is retained separately from evidence files. When a retention period expires, the associated evidence is deleted; the metadata history remains for audit purposes.After subscription cancellation, the customer's data remains accessible. The customer may request export of its data before termination takes effect. Saintrac does not retain customer data beyond the period necessary to comply with legal obligations or to provide the audit trail the customer configured.6. Data-subject correction paths
For synthetic verification sessions, the applicant whose synthetic identity is being verified can request a correction through the in-session correction flow. The institution controls the correction review process and decides whether to uphold or reject the request.For team members, the organization owner or admin can update member roles, suspend access, or remove members. A team member may contact their organization owner to request changes to their account information.For billing data, the organization owner can update the billing email and tax country through the billing page. Payment method updates are handled through the payment provider's customer portal.7. Subprocessors
Saintrac engages subprocessors to provide the infrastructure and services that operate the platform. Each subprocessor is engaged under a data processing agreement. The current list of subprocessors, including the processing purpose and region for each, is published on the Subprocessors page.8. Security measures
Saintrac applies technical and organizational measures to protect data, including encrypted evidence storage, hashed API keys, server-resolved organization scope, role-based access control, audit history, and configurable retention. Identity evidence receives the highest protection. Operational telemetry uses safe identifiers and allowlisted metadata only. See the Trust and security page for the full security model.9. Changes to this policy
This Privacy Policy is a draft and may change pending qualified legal review. Saintrac will provide notice of material changes through the platform or by email to the organization owner. See the Terms of Service and the Data Processing Addendum for related terms.Related documents
Other legal documents
- Terms of ServiceDraft terms of service for the Verela synthetic identity verification platform. Pending qualified legal review.
- Data Processing AddendumDraft data processing addendum identifying controller and processor roles for Verela. Pending qualified legal review.
- SubprocessorsDraft list of subprocessors used by Verela with processing purpose and region. Pending qualified legal review.
- Acceptable Use PolicyDraft acceptable use policy for the Verela synthetic identity verification platform. Pending qualified legal review.
- Trust and securityUnderstand the security model, evidence protection, and controlled-pilot boundaries that shape these documents.