Privacy Policy

Veros Inc (operating as VeryAI)

Effective Date: 11 March 2025  |  Last Updated: 9 July 2026

PLEASE READ THIS PRIVACY POLICY CAREFULLY. This Privacy Policy describes how Veros Inc (operating as VeryAI) collects, uses, shares, retains and protects your personal data, including your Biometric Data. It supplements and is incorporated into our Terms of Use.

1. About this Policy; Who We Are

1.1  Veros Inc, an exempted company incorporated with limited liability in the Cayman Islands with registration number OS-420535, doing business as VeryAI ("VeryAI", "we", "our", "us"), takes the privacy of personal data, and Biometric Data in particular, very seriously. This Privacy Policy describes how we collect, use, share, store, retain and protect personal data in connection with our palm-recognition biometric authentication service, the Veros Identity Provider platform, our mobile applications, websites and APIs (collectively, the "Service").

1.2  This Policy supplements and is incorporated into our Terms of Use. Capitalised terms used but not defined in this Policy have the meanings given in the Terms of Use, including "Biometric Data", "Palm Image", "Palm Model", "Audit Images", "Pseudonymous Account Identifier", "Customer" and "Service".

2. Our Roles; When We Are Controller and When We Are Processor

2.1  VeryAI acts in different capacities depending on the context.

(a) Independent Controller. Where we operate the consumer-facing VeryAI application directly with you (i.e., not through an enterprise integration), we are the controller of your personal data, including your Biometric Data. We are also independent controller in respect of: (i) fraud prevention, abuse prevention, liveness detection and security; (ii) compliance with our legal obligations; (iii) establishment, exercise or defence of legal claims; and (iv) internal improvement of our fraud-detection, liveness-detection, abuse-prevention, quality-assurance, debugging, audit and security mechanisms, in each case to the extent disclosed in the Terms of Use, this Policy and the in-app consent flow and permitted by Applicable Law.

(b) Processor. Where you use the Service through a Customer (e.g., a fintech, gaming, social, community or government platform that has integrated the Service), the Customer is the controller for its relationship with you, and VeryAI processes personal data on the Customer's behalf in accordance with a written Data Processing Agreement. The Customer's privacy notice will apply to that relationship in addition to this Policy. Where a Customer uses VeryAI verification outputs to make onboarding, access, financial-services, gaming, community-membership or other eligibility decisions about you, the Customer (and not VeryAI) is responsible for that decision, for any human review process and for its own user-facing legal obligations. VeryAI will provide assistance to the Customer as required under the applicable Data Processing Agreement.

3. Categories of Personal Data We Process

3.1  We process the following categories of personal data.

(a) Palm Images (Biometric Data; special category / sensitive). Full-resolution images of your palm captured by your device camera during enrolment and re-enrolment. Palm Images are used to generate a Palm Model. A low-resolution audit image derived from your palm is retained for automated fraud, liveness and quality review — for up to one hundred eighty (180) days in our working store, and longer for enrolments flagged or rejected during review (see Section 9). Audit images are processed by third-party AI providers under contract (see Section 7, Sharing and Disclosure). Ordinary palm sign-in (verification of an existing Palm Model) does not capture or store an image.

(b) Palm Models (Biometric Data; special category / sensitive). Encrypted mathematical representations (feature vectors) derived from Palm Images. The Palm Model feature vector cannot be used to reconstruct a full-resolution image of your palm. A low-resolution audit image may be embedded in the stored Palm Model for fraud, liveness and quality review (see paragraph (a) above and Section 9). Used to authenticate you and stored in an isolated, encrypted biometric environment.

(c) Audit Images. Limited, low-resolution images, crops or derived visual records of a palm capture, retained solely for security, fraud prevention, liveness detection, quality assurance, debugging, audit and abuse-prevention purposes. Audit Images are not used to identify you independently of the Service. Even where VeryAI's technical assessment is that Audit Images are not, in isolation, capable of biometric identification, VeryAI treats Audit Images as Biometric Data and/or sensitive personal information where required by Applicable Law, and applies the same security, access-control and retention safeguards as for other Biometric Data. Retention is addressed in Section 9.

(d) Pseudonymous Account Identifier. A randomly generated alphanumeric string that does not directly identify you.

(e) Email Address (optional). If you choose to provide one, used for account recovery and important Service communications, including security and legal notifications.

(f) Authentication and Activity Logs. Timestamps and metadata of authentication events, account creation and settings changes. Used for security, audit, fraud prevention and compliance with legal obligations.

(g) Device Information. Device information (operating system version, device model and manufacturer, hardware identifiers, and locale/timezone) and network metadata (IP address and user agent). This information is transmitted to our servers and used as an anti-fraud and anti-Sybil signal, and is retained in our fraud-review systems and logs. See Section 9 for retention.

(h) Cookies and Similar Technologies (website only). Strictly necessary, analytics and (if you consent) preferences cookies, as described in our Cookie Policy. Not used for cross-context behavioural advertising.

3.2  Sensitive Personal Information / Special Categories of Data. Palm Images and Palm Models are "biometric data" within the meaning of Article 4(14) GDPR and special category data under Article 9 GDPR; "sensitive personal information" under the CPRA § 1798.140(ae); and "biometric identifiers" and/or "biometric information" under BIPA, CUBI and equivalent state laws. Audit Images are treated as Biometric Data and/or sensitive personal information where required by Applicable Law. We treat all such data with the highest level of protection.

4. Purposes and Legal Bases for Processing

4.1  Where the GDPR or UK GDPR applies, we rely on the following legal bases. Where processing involves special category data under Article 9, VeryAI relies on an Article 9 basis (paragraph (a) or (b) below) in addition to the relevant Article 6 basis. Legitimate interests under Article 6(1)(f) is not relied on as a standalone basis for the processing of Article 9 special category data.

4.2  Outside the EEA/UK, we rely on equivalent lawful bases under Applicable Law, including informed, opt-in consent for Biometric Data and the necessity of processing to provide the Service or to comply with legal obligations.

5. How We Use Your Personal Data

5.1  We use personal data to:

5.2  We do not use Biometric Data (including Audit Images) for: (i) advertising, targeted marketing or cross-context behavioural advertising; (ii) profiling for purposes other than fraud detection, abuse prevention and security; (iii) sale, lease, rental, trade or commercial distribution to third parties; or (iv) training, fine-tuning or improvement of any third-party AI/ML model, except that Audit Images may be processed by third-party AI providers to perform fraud, liveness and quality review on our behalf as described in Section 7. We do not sell, lease, trade or otherwise profit from Biometric Data. We do use general product-analytics and mobile-analytics tools (see Section 7) to understand feature usage and app performance; this analytics activity does not involve Biometric Data and is not cross-context behavioural advertising. For clarity, this does not prevent VeryAI from charging Customers ordinary service fees for access to the Service, provided that those fees are not consideration for the sale, lease, trade or disclosure of Biometric Data.

6. Automated Decision-Making

6.1  Where VeryAI is controller and VeryAI's own automated processing produces legal or similarly significant effects on you (for example, denial of access to your VeryAI Account on fraud-related grounds), you have the right under Article 22 GDPR (and equivalent provisions of the UK GDPR and other Applicable Law) to obtain human intervention, to express your point of view and to contest the decision. To exercise this right, contact privacy@very.org.

6.2  Where you use the Service through a Customer and the Customer uses the VeryAI verification output to make a decision about access to a third-party service (including onboarding, access, financial-services, gaming, community-membership or other eligibility decisions), the Customer (and not VeryAI) is the controller of that decision, is responsible for any human review process, and is responsible for honouring any Article 22 GDPR (or equivalent) request directed at that decision. VeryAI will provide assistance to the Customer as required under the applicable Data Processing Agreement.

7. Sharing and Disclosure

7.1  We share personal data only as described below. We do not sell or share (as those terms are defined under the CPRA) personal information for cross-context behavioural advertising, and we do not sell, lease, trade or otherwise profit from Biometric Data.

(a) Sub-processors and service providers. We engage carefully selected sub-processors (e.g., cloud hosting, monitoring, security tooling) under written contracts that impose data protection obligations equivalent to ours. Our current sub-processor list is available upon request by contacting privacy@very.org.

We share data with the third-party providers listed in our sub-processor list, including: cloud hosting (Google Cloud); AI model providers that perform automated fraud, liveness and quality review of Audit Images (OpenRouter, OpenAI and Google); transactional email delivery (Amazon Web Services); wallet provisioning (Privy); push notifications and mobile analytics (Google Firebase); and product analytics (Mixpanel).

(b) Customer integrations / third-party applications. When you authorise a third-party application or Customer integration, we share only your Pseudonymous Account Identifier and limited verification metadata (timestamp, result, and any specifically authorised attributes). Palm Images, Palm Models and Audit Images are not shared with Customers or third-party applications, except as expressly authorised by you or required by Applicable Law. They may be processed by service providers acting on VeryAI's behalf, subject to appropriate contractual, security and confidentiality obligations, as described in this Policy.

(c) Affiliates. We may share personal data with current and future affiliates within the Veros corporate group, subject to the same standards as in this Policy.

(d) Legal and regulatory disclosures. We may disclose personal data where required by law, regulation, legal process or enforceable governmental request, where necessary to investigate or prevent fraud, security breaches or violations of our Terms of Use, or to protect the rights, safety or property of VeryAI, our Users or others.

(e) Corporate transactions. In the event of a merger, acquisition, financing, reorganisation, bankruptcy or sale of all or part of our assets, personal data may be transferred to the relevant counterparty, subject to the same protections.

8. International Data Transfers

8.1  VeryAI is incorporated in the Cayman Islands. Our personnel, service providers, sub-processors and technical infrastructure may be located in the United States, the European Economic Area, the United Kingdom and other jurisdictions, as updated from time to time.

8.2  For EEA, UK and Swiss users, international transfers of personal data (including Biometric Data) are made primarily under the EU Standard Contractual Clauses and, for UK transfers, the UK International Data Transfer Addendum (or the UK International Data Transfer Agreement), in each case with supplementary measures and a transfer impact assessment as appropriate. We rely on the following transfer mechanisms under Applicable Law, as applicable:

8.3  Copies of the relevant transfer mechanisms (other than third-party-published instruments) are available on request from privacy@very.org.

9. Data Retention

9.1  We retain personal data only for as long as necessary for the purposes set out in this Policy, taking into account legal, regulatory, accounting and reporting requirements. We avoid open-ended retention.

(a) Palm Images: the full-resolution Palm Image captured during enrolment or re-enrolment is not separately retained beyond Palm Model generation. However, a low-resolution audit image derived from your palm is embedded in the Palm Model and separately retained in our working store for up to one hundred eighty (180) days for automated fraud, liveness and quality review. Where an enrolment is flagged or rejected during review, the associated audit image is instead retained in accordance with paragraph (c) below (Audit Images: fraudulent, invalid or security-flagged).

(b) Audit Images (valid / authentic): retained for no longer than one hundred eighty (180) days from capture, after which they are permanently destroyed or anonymised.

(c) Audit Images (fraudulent, invalid or security-flagged): retained only for as long as reasonably necessary for investigation, fraud prevention, abuse prevention, legal defence or security purposes, and in any event no longer than twelve (12) months from the date of flagging, unless a longer period is required by Applicable Law or legal process.

(d) Palm Models: retained until the earliest of (i) closure of your Account, (ii) your use of the in-app "Erase" function, and (iii) your withdrawal of consent, unless a longer period is required by Applicable Law, legal process or a documented security investigation. Erasing your Palm Model schedules it for permanent deletion; see Section 9.2 for the applicable grace period.

(e) Authentication and activity logs: generally for up to three (3) years for fraud, audit and legal-defence purposes, deleted or anonymised in the ordinary course thereafter, subject to any longer period required by Applicable Law, legal process or a documented investigation.

(f) Email address (optional): until you delete your Account or request deletion, plus a backup retention period not exceeding ninety (90) days.

9.2  Erasing your Palm Model using the in-app "Erase" function schedules it for permanent deletion. During a grace period of up to ninety (90) days, you may cancel the erasure by reactivating your Account. After the grace period expires, the Palm Model is purged from our systems and cannot be recovered.

10. Security

10.1  We implement physical, organisational and technical safeguards proportionate to the risk associated with Biometric Data, including:

10.2  Personal data breach notification. Where a personal data breach is likely to result in a high risk to your rights and freedoms, we will notify you in accordance with Article 34 GDPR (and equivalent provisions of the UK GDPR and applicable state notification laws). Where required by Applicable Law, we will also notify the relevant supervisory authority.

11. Your Rights

11.1  Subject to and in accordance with Applicable Law, you have the following rights:

11.2  How to exercise your rights. Submit a request through the in-app account management features, including the in-app "Erase" function for withdrawal of consent and erasure, or by emailing privacy@very.org. We will respond within the time required by Applicable Law (one month under the GDPR, extendable by two further months for complex requests; 45 days under the CCPA/CPRA, extendable by an additional 45 days). We may need to verify your identity using your Pseudonymous Account Identifier and, where appropriate, additional verification consistent with the sensitivity of the request.

11.3  Authorised agents. If you appoint an authorised agent to act on your behalf, we may require written authorisation and may verify your identity directly, in accordance with CPRA § 1798.135(c) and equivalent provisions.

11.4  No discrimination. We will not discriminate against you for exercising any privacy right.

11.5  Customer-controlled decisions. Where a Customer is the controller of a decision made using the Service (see Sections 2 and 6), you may need to direct certain rights requests to that Customer. We will assist as required under the applicable Data Processing Agreement.

12. Cookies and Similar Technologies

12.1  Our website uses cookies and similar technologies as described in our Cookie Policy. Where required by Applicable Law, we obtain consent before setting non-essential cookies. The Service mobile application does not use cookies; it uses local device storage strictly necessary to operate the application.

13. Children

13.1  The Service is not directed to, and we do not knowingly collect personal data from, individuals under the age of 18 (or the age of majority in your jurisdiction, if higher). If we become aware that we have inadvertently collected personal data from a person under that age, we will delete that data without undue delay and terminate the affected Account. If you believe we may have inadvertently collected personal data from a minor, please contact privacy@very.org.

14. EU AI Act and Other Emerging Regulation

14.1  The classification and regulation of the Service under Regulation (EU) 2024/1689 (the "EU AI Act") depends on the actual deployment context, Customer use case, technical configuration and applicable guidance from competent authorities. This Section is provided for transparency only and is not a legal determination or an admission of any classification under the EU AI Act.

14.2  VeryAI's current understanding is that one-to-one biometric verification used solely to confirm that a specific person is who they claim to be is generally treated differently under the EU AI Act from remote biometric identification, and that pure one-to-one verification scenarios may fall outside the "remote biometric identification" category referenced in Annex III. Customer deployments in contexts such as critical infrastructure, essential public or private services, financial onboarding, law enforcement, migration / border / asylum, or one-to-many identification scenarios may, however, still trigger additional provider or deployer obligations under the EU AI Act.

14.3  The allocation of responsibility between VeryAI and a Customer under the EU AI Act (including any allocation between "provider" and "deployer" roles) will be addressed in the applicable Enterprise Agreement and any associated Data Processing Agreement. VeryAI will comply with applicable obligations under the EU AI Act in accordance with the timetable for entry into application of those obligations.

15. Changes to this Policy

15.1  We may update this Policy from time to time. The "Last Updated" date at the top will reflect the date of the most recent revision. Where changes are material, we will provide reasonable notice through in-app notification, by email (if you have provided one) and by posting the updated Policy with a new effective date, in each case no fewer than thirty (30) days before the change takes effect, except where a shorter period is required by Applicable Law or to address a security or legal risk. For changes that materially expand our use or sharing of Biometric Data, we will obtain your fresh affirmative consent.

16. Contact Us

16.1  Veros Inc, legal@very.org or privacy@very.org.


Annex — Jurisdiction-Specific Disclosures

1. California Notice at Collection (CCPA/CPRA)

The categories of personal information we collect, the purposes for which they are used, and our retention periods, are set out in Sections 3, 5 and 9 of this Policy. We do not sell or share (as those terms are defined under the CPRA) your personal information, and we do not sell, lease, trade or otherwise profit from Biometric Data. You have the right to limit our use and disclosure of sensitive personal information; see Section 11. To exercise California rights, contact privacy@very.org or use the in-app controls. For our "Shine the Light" disclosure (California Civil Code § 1798.83), please contact us at the same address.

2. Illinois Disclosure (BIPA)

VeryAI is collecting, capturing or otherwise obtaining your biometric identifiers and biometric information for the purposes set out in Section 5. Retention and destruction of biometric identifiers and biometric information is addressed in Section 9. We will not sell, lease, trade or otherwise profit from your biometric identifiers or biometric information.

3. EU/EEA, UK and Swiss Disclosures

This Policy serves as our notice for the purposes of Articles 13 and 14 GDPR and equivalent provisions of the UK GDPR and the Swiss FADP. You have the right to lodge a complaint with your local supervisory authority.

4. Other US States

If you are a resident of a state with a comprehensive privacy law (including Virginia, Colorado, Connecticut, Utah, Oregon, Texas, Montana, Tennessee, Iowa, Indiana, Delaware, New Jersey, New Hampshire, Kentucky, Rhode Island, Maryland or Minnesota), you have similar rights of access, deletion, correction and opt-out as those described in Section 11, exercisable through the same channels.

5. Quebec (Law 25)

If you reside in Quebec, the provisions of Quebec's Law 25 (Act respecting the protection of personal information in the private sector) apply. You may exercise your rights of access, rectification, erasure and de-indexing by contacting privacy@very.org.

6. Relationship to the Terms of Use

This Policy is read together with, and incorporated into, the Terms of Use. Capitalised terms used but not defined in this Policy have the meanings given in the Terms of Use. The Terms of Use are governed by the laws of the Cayman Islands and contain a binding arbitration agreement (LCIA, seat: Cayman Islands) and class action waiver, subject to mandatory consumer-protection laws and the jurisdiction-specific provisions in those Terms.

VeryAI

Get the VeryAI app

Scan the QR code to download the app