Privacy Policy
Last updated: 3 June 2026 · Version: 2.0 · Applies to euverify.com, app.euverify.com, shop.euverify.com and gdpr.euverify.com
This Privacy Policy explains how Euverify Ltd and Euverify Limited (together “Euverify”, “we”, “us” or “our”) collect, use, share and protect personal data when you visit our websites, use our platform and tools, purchase from our marketplace, or engage our compliance services. It also explains your rights and how to exercise them.
- Introduction
- Who we are
- Our role: controller vs processor
- Personal data we collect
- How we collect your data
- Purposes and legal bases
- Cookies and similar technologies
- Marketing and advertising
- How we share your data
- International data transfers
- How long we keep your data
- Security
- Your rights
- How to exercise your rights
- How to contact us
- Children’s data
- Third-party links
- Changes to this policy
1. Introduction
Euverify provides EU and UK regulatory compliance services, including acting as an Authorised Representative / Responsible Person for product compliance and as a GDPR Article 27 Representative for data protection. Because of the nature of these services, we act as a data controller for some personal data and as a data processor — handling data on behalf of our business customers — for other personal data. Section 3 explains the difference and which rules apply.
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and the EU General Data Protection Regulation (Regulation (EU) 2016/679) (EU GDPR), together with the Privacy and Electronic Communications Regulations (PECR) and equivalent EU ePrivacy rules.
2. Who we are ↑ top
The Euverify entity responsible for your personal data (the “controller”, where we act as one) depends on where you are: Euverify Ltd for individuals in the United Kingdom, and Euverify Limited for individuals in the EU/EEA. Our registered entities are:
| United Kingdom controller | Euverify Ltd, 3rd Floor, 86–90 Paul Street, London, EC2A 4NE, United Kingdom. Registered in England and Wales, company no. 16146525. |
|---|---|
| EU / EEA controller | Euverify Limited, Unit 3D North Point House, North Point Business Park, New Mallow Road, Cork, T23 AT2P, Ireland. Registered in Ireland, company no. 781168. |
| General enquiries | info@euverify.com |
| Data protection / privacy | gdpr@euverify.com |
3. Our role: controller vs processor ↑ top
We are a controller — we decide why and how data is processed — for: visitors to our websites; prospective customers and leads; account holders and their users (account, contact and billing data); recipients of our marketing; and people who contact us for support.
We act as a processor, on your behalf, for the personal data contained in the information and documents you provide so we can deliver our services — for example, the names of signatories on declarations, manufacturer or supplier contacts, and personal data within test reports, risk assessments and technical files. Where we hold or handle that data to act as your Authorised Representative or GDPR Article 27 Representative, we do so on your documented instructions; you (our customer) remain the controller. This processing is governed by our Data Processing Agreement (DPA).
If you are an individual whose personal data appears in a customer’s documentation, please contact that customer (the controller) to exercise your rights. We will support them in responding.
4. Personal data we collect ↑ top
Depending on how you interact with us, we may collect the following categories of personal data:
| Category | Examples |
|---|---|
| Identity & contact data | Name, job title, employer / company, email address, telephone or mobile number, business or postal address. |
| Account & login data | Username, password (stored in hashed form), account settings, user role and authentication logs. |
| Billing & payment data | Billing name and address, plan, invoices and transaction history. Card payments are handled by our payment providers (Stripe, PayPal); we do not store full card numbers. |
| Service & compliance data | Information and documents you upload to obtain our services — manufacturer / importer details, signatory names, declarations of conformity, test reports, risk assessments, technical files and product data — which may contain personal data. |
| Communications | Emails, support chat (Intercom), enquiry forms, and notes or recordings of calls and meetings (e.g. Zoom, Google Meet) where applicable. |
| Technical & usage data | IP address, device and browser type, operating system, referring pages, pages viewed and actions taken, dates and times, and approximate location derived from IP address. |
| Marketing & lead data | Marketing preferences, engagement with our emails and ads, and business contact data obtained from public sources and providers such as LinkedIn Sales Navigator. |
| Cookies & tracking data | Identifiers and usage data collected via cookies and similar technologies (see Section 7 and our Cookie Policy). |
5. How we collect your data ↑ top
- Directly from you — when you register, start a trial, buy a plan or product, upload documents, complete forms, or contact us.
- Automatically — through cookies and similar technologies and server logs when you use our websites and platform (see our Cookie Policy).
- From third parties and public sources — colleagues who invite you to an account; referral and affiliate partners; sales-intelligence and enrichment providers (e.g. LinkedIn Sales Navigator); public registries and websites; and our sub-processors.
6. Purposes and legal bases ↑ top
We only process personal data where we have a lawful basis to do so. The table below sets out what we do and the legal basis under the UK GDPR / EU GDPR:
| Purpose | Legal basis |
|---|---|
| Create, administer and provide your account, platform access and the services you request | Performance of a contract |
| Provide our compliance services and act as your Authorised Representative / GDPR Article 27 Representative | Performance of a contract; for third-party data within your documents we act as your processor on your instructions |
| Hold and retain technical documentation, declarations and related records as your Authorised Representative | Compliance with a legal obligation and performance of a contract |
| Process payments and keep accounting and tax records | Performance of a contract and compliance with a legal obligation |
| Provide customer support and respond to enquiries | Performance of a contract and our legitimate interests |
| Secure our websites, platform and data, and prevent fraud and abuse | Our legitimate interests and compliance with a legal obligation |
| Send service and transactional messages (account, billing, security) | Performance of a contract and our legitimate interests |
| Send direct marketing to business contacts and customers about our services | Our legitimate interests (B2B), or your consent where required by law. You can object or unsubscribe at any time |
| Use cookies and similar technologies for analytics, advertising and audience profiling for marketing | Your consent (via our cookie banner) |
| Analyse usage to maintain, improve and develop our websites, platform and services | Our legitimate interests |
| Publish reviews and testimonials | Your consent |
| Establish, exercise or defend legal claims, enforce our terms and handle disputes | Our legitimate interests and compliance with a legal obligation |
| Comply with legal obligations and respond to lawful requests, including data subject requests and requests from authorities | Compliance with a legal obligation |
| Transfer data as part of a merger, acquisition or other corporate transaction | Our legitimate interests |
Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. You can ask us for more information about this assessment using the contact details in Section 15.
7. Cookies and similar technologies ↑ top
Our websites use cookies and similar technologies for necessary, functional, analytics, performance and advertising purposes. Non-essential cookies — including analytics and advertising cookies — are only set with your consent, which you give through our cookie banner and can change or withdraw at any time via “Cookie Settings”. For the full list of cookies, their purposes and durations, and how to manage them, see our Cookie Policy.
8. Marketing and advertising ↑ top
We may send you marketing about our services where we are permitted to do so. For prospective customers we rely on consent or the business-to-business “soft opt-in” where it applies; for existing customers we rely on our legitimate interests. Every marketing email includes an unsubscribe link, and you can opt out at any time by unsubscribing or emailing info@euverify.com.
We and our advertising partners — including Google, Microsoft (Bing), Meta (Facebook), LinkedIn, X (Twitter) and Taboola — use cookies and similar technologies to deliver and measure advertising, including showing you tailored ads on other websites and platforms. This involves profiling for marketing purposes based on your interactions with our sites and ads. We carry out this activity on the basis of your consent, which you manage through our cookie banner. You can object to profiling for direct marketing at any time and manage advertising cookies through “Cookie Settings” and the privacy settings of the relevant platforms.
We do not make decisions that produce legal or similarly significant effects about you using solely automated processing.
9. How we share your data ↑ top
We do not sell your personal data. We share it only as described below:
| Who we share with | Why |
|---|---|
| Sub-processors (service providers) | We use vetted providers to host our platform, process payments, send communications, provide support, analyse usage, enable e-signature, and supply sales, AI and other operational tools. They act only on our instructions and under contract. See our Sub-processor List. |
| Advertising & analytics partners | To deliver and measure advertising and understand how our sites are used, subject to your cookie consent. |
| Professional advisers & auditors | Lawyers, accountants, insurers and auditors where necessary. |
| Regulators, authorities & courts | Where required by law, or to establish, exercise or defend legal rights. Where we act as your Authorised Representative or Article 27 Representative and an authority requests documentation, we will, wherever possible, come back to you for the specific document rather than releasing your supplier or commercial detail directly. |
| Acquirers | In connection with a merger, acquisition, financing or sale of assets, subject to appropriate confidentiality. |
| With your consent | Any other sharing you direct or agree to. |
10. International data transfers ↑ top
We are based in the UK and the EU (Ireland). Some of our sub-processors are located outside the UK and the European Economic Area (EEA), including in the United States. Where we transfer personal data to a country that is not covered by a UK or EU “adequacy” decision, we put appropriate safeguards in place — such as the European Commission’s Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement or Addendum, together with any additional measures required. Where a provider is certified under the EU–US Data Privacy Framework (and its UK Extension), we may rely on that. You can request a copy of the relevant safeguards using the contact details in Section 15.
11. How long we keep your data ↑ top
We keep personal data only for as long as we need it for the purposes set out in this policy, or for as long as the law requires. Typical periods are:
| Type of data | How long we keep it |
|---|---|
| Account and contact data | For the duration of your relationship with us, then typically up to 6 years after your account closes, to handle queries and exercise or defend legal claims. |
| Billing, payment and tax records | Usually 6 years from the relevant financial year, to meet accounting and tax law. |
| Compliance documentation, declarations and technical files held as your Authorised Representative | For the period required by the applicable product legislation — commonly up to 10 years after the last product is placed on the market — or as otherwise instructed by you under our DPA. |
| Service & compliance data processed on your behalf (as processor) | For the duration of the service, then returned or deleted in line with our DPA and your instructions. |
| Support and communications | Typically 2–3 years. |
| Marketing data | Until you unsubscribe or object, after which we keep minimal data on a suppression list to honour your choice. |
| Cookies and tracking data | For the durations set out in our Cookie Policy. |
12. Security ↑ top
We take the security of personal data seriously and maintain appropriate technical and organisational measures to protect it against loss, misuse and unauthorised access, alteration or disclosure. These include encryption of data in transit and at rest, access controls and least-privilege access, network and application monitoring, secure development practices, and contractual data-protection terms with our sub-processors.
Euverify is Cyber Essentials certified and is working towards SOC 2. We treat the personal data and documentation you entrust to us as confidential and make it available only to authorised personnel who need it to provide our services. Despite our measures, no method of transmission or storage is completely secure, so we cannot guarantee absolute security; please use a strong, unique password and keep your login credentials confidential.
13. Your rights ↑ top
Depending on where you are and the law that applies, you have the following rights over your personal data:
- Access — a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — delete your data in certain circumstances.
- Restriction — limit how we use your data in certain circumstances.
- Portability — receive certain data in a portable format, or have it sent to another provider.
- Object — object to processing based on legitimate interests, and to direct marketing at any time (which we will always honour).
- Withdraw consent — where we rely on consent, withdraw it at any time, without affecting processing already carried out.
- Automated decisions — not to be subject to decisions with legal or similarly significant effects based solely on automated processing. We do not carry out such decision-making.
- Complain — lodge a complaint with a supervisory authority (see Section 15).
Where we process your data on behalf of a customer (as processor or representative), please direct your request to that customer (the controller); we will assist them in responding.
14. How to exercise your rights ↑ top
To make a request, email us at gdpr@euverify.com. To protect your data, we may need to verify your identity before we act. We will respond within one month. If your request is complex, or you have made several requests, we may extend this by up to two further months and will tell you within the first month if so. Requests are normally free; we may charge a reasonable fee, or decline to act, if a request is manifestly unfounded or excessive, and we will explain why.
15. How to contact us ↑ top
If you have any questions, concerns or complaints about this policy or how we handle personal data, please contact us:
United Kingdom
Euverify Ltd3rd Floor, 86–90 Paul Street
London, EC2A 4NE
United Kingdom
Company no. 16146525
European Union (Ireland)
Euverify LimitedUnit 3D North Point House
North Point Business Park, New Mallow Road
Cork, T23 AT2P, Ireland
Company no. 781168
General enquiries: info@euverify.com
Data protection & privacy requests: gdpr@euverify.com
You also have the right to lodge a complaint with a supervisory authority:
| Supervisory authority | Contact |
|---|---|
| United Kingdom — Information Commissioner’s Office (ICO) | Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, UK · ico.org.uk · 0303 123 1113 |
| Ireland / EU — Data Protection Commission (DPC) | 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland · dataprotection.ie · +353 1 765 0100 |
If you are in another EU/EEA country, you may also contact your local supervisory authority.
16. Children’s data ↑ top
Our websites, platform and services are intended for businesses and are not directed at children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
17. Third-party links ↑ top
Our websites and platform may link to third-party sites and services that we do not control. This policy does not apply to them and we are not responsible for their practices. Please review their own privacy notices.
18. Changes to this policy ↑ top
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date and post the new version on our website. If the changes are material, we will give reasonable notice — for example, by email or a notice on our website — before they take effect. Please review this policy periodically.