Privacy Policy

Last updated: 3 June 2026  ·  Version: 2.0  ·  Applies to euverify.com, app.euverify.com, shop.euverify.com and gdpr.euverify.com

This Privacy Policy explains how Euverify Ltd and Euverify Limited (together “Euverify”, “we”, “us” or “our”) collect, use, share and protect personal data when you visit our websites, use our platform and tools, purchase from our marketplace, or engage our compliance services. It also explains your rights and how to exercise them.

1. Introduction

Euverify provides EU and UK regulatory compliance services, including acting as an Authorised Representative / Responsible Person for product compliance and as a GDPR Article 27 Representative for data protection. Because of the nature of these services, we act as a data controller for some personal data and as a data processor — handling data on behalf of our business customers — for other personal data. Section 3 explains the difference and which rules apply.

We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and the EU General Data Protection Regulation (Regulation (EU) 2016/679) (EU GDPR), together with the Privacy and Electronic Communications Regulations (PECR) and equivalent EU ePrivacy rules.

2. Who we are ↑ top

The Euverify entity responsible for your personal data (the “controller”, where we act as one) depends on where you are: Euverify Ltd for individuals in the United Kingdom, and Euverify Limited for individuals in the EU/EEA. Our registered entities are:

United Kingdom controllerEuverify Ltd, 3rd Floor, 86–90 Paul Street, London, EC2A 4NE, United Kingdom. Registered in England and Wales, company no. 16146525.
EU / EEA controllerEuverify Limited, Unit 3D North Point House, North Point Business Park, New Mallow Road, Cork, T23 AT2P, Ireland. Registered in Ireland, company no. 781168.
General enquiriesinfo@euverify.com
Data protection / privacygdpr@euverify.com

3. Our role: controller vs processor ↑ top

We are a controller — we decide why and how data is processed — for: visitors to our websites; prospective customers and leads; account holders and their users (account, contact and billing data); recipients of our marketing; and people who contact us for support.

We act as a processor, on your behalf, for the personal data contained in the information and documents you provide so we can deliver our services — for example, the names of signatories on declarations, manufacturer or supplier contacts, and personal data within test reports, risk assessments and technical files. Where we hold or handle that data to act as your Authorised Representative or GDPR Article 27 Representative, we do so on your documented instructions; you (our customer) remain the controller. This processing is governed by our Data Processing Agreement (DPA).

If you are an individual whose personal data appears in a customer’s documentation, please contact that customer (the controller) to exercise your rights. We will support them in responding.

4. Personal data we collect ↑ top

Depending on how you interact with us, we may collect the following categories of personal data:

CategoryExamples
Identity & contact dataName, job title, employer / company, email address, telephone or mobile number, business or postal address.
Account & login dataUsername, password (stored in hashed form), account settings, user role and authentication logs.
Billing & payment dataBilling name and address, plan, invoices and transaction history. Card payments are handled by our payment providers (Stripe, PayPal); we do not store full card numbers.
Service & compliance dataInformation and documents you upload to obtain our services — manufacturer / importer details, signatory names, declarations of conformity, test reports, risk assessments, technical files and product data — which may contain personal data.
CommunicationsEmails, support chat (Intercom), enquiry forms, and notes or recordings of calls and meetings (e.g. Zoom, Google Meet) where applicable.
Technical & usage dataIP address, device and browser type, operating system, referring pages, pages viewed and actions taken, dates and times, and approximate location derived from IP address.
Marketing & lead dataMarketing preferences, engagement with our emails and ads, and business contact data obtained from public sources and providers such as LinkedIn Sales Navigator.
Cookies & tracking dataIdentifiers and usage data collected via cookies and similar technologies (see Section 7 and our Cookie Policy).
We do not intentionally collect special category data (such as health, biometric or similar sensitive data). Please do not upload special category data unless it is necessary for the service and lawful for you to share.

5. How we collect your data ↑ top

  • Directly from you — when you register, start a trial, buy a plan or product, upload documents, complete forms, or contact us.
  • Automatically — through cookies and similar technologies and server logs when you use our websites and platform (see our Cookie Policy).
  • From third parties and public sources — colleagues who invite you to an account; referral and affiliate partners; sales-intelligence and enrichment providers (e.g. LinkedIn Sales Navigator); public registries and websites; and our sub-processors.

6. Purposes and legal bases ↑ top

We only process personal data where we have a lawful basis to do so. The table below sets out what we do and the legal basis under the UK GDPR / EU GDPR:

PurposeLegal basis
Create, administer and provide your account, platform access and the services you requestPerformance of a contract
Provide our compliance services and act as your Authorised Representative / GDPR Article 27 RepresentativePerformance of a contract; for third-party data within your documents we act as your processor on your instructions
Hold and retain technical documentation, declarations and related records as your Authorised RepresentativeCompliance with a legal obligation and performance of a contract
Process payments and keep accounting and tax recordsPerformance of a contract and compliance with a legal obligation
Provide customer support and respond to enquiriesPerformance of a contract and our legitimate interests
Secure our websites, platform and data, and prevent fraud and abuseOur legitimate interests and compliance with a legal obligation
Send service and transactional messages (account, billing, security)Performance of a contract and our legitimate interests
Send direct marketing to business contacts and customers about our servicesOur legitimate interests (B2B), or your consent where required by law. You can object or unsubscribe at any time
Use cookies and similar technologies for analytics, advertising and audience profiling for marketingYour consent (via our cookie banner)
Analyse usage to maintain, improve and develop our websites, platform and servicesOur legitimate interests
Publish reviews and testimonialsYour consent
Establish, exercise or defend legal claims, enforce our terms and handle disputesOur legitimate interests and compliance with a legal obligation
Comply with legal obligations and respond to lawful requests, including data subject requests and requests from authoritiesCompliance with a legal obligation
Transfer data as part of a merger, acquisition or other corporate transactionOur legitimate interests

Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. You can ask us for more information about this assessment using the contact details in Section 15.

7. Cookies and similar technologies ↑ top

Our websites use cookies and similar technologies for necessary, functional, analytics, performance and advertising purposes. Non-essential cookies — including analytics and advertising cookies — are only set with your consent, which you give through our cookie banner and can change or withdraw at any time via “Cookie Settings”. For the full list of cookies, their purposes and durations, and how to manage them, see our Cookie Policy.

8. Marketing and advertising ↑ top

We may send you marketing about our services where we are permitted to do so. For prospective customers we rely on consent or the business-to-business “soft opt-in” where it applies; for existing customers we rely on our legitimate interests. Every marketing email includes an unsubscribe link, and you can opt out at any time by unsubscribing or emailing info@euverify.com.

We and our advertising partners — including Google, Microsoft (Bing), Meta (Facebook), LinkedIn, X (Twitter) and Taboola — use cookies and similar technologies to deliver and measure advertising, including showing you tailored ads on other websites and platforms. This involves profiling for marketing purposes based on your interactions with our sites and ads. We carry out this activity on the basis of your consent, which you manage through our cookie banner. You can object to profiling for direct marketing at any time and manage advertising cookies through “Cookie Settings” and the privacy settings of the relevant platforms.

We do not make decisions that produce legal or similarly significant effects about you using solely automated processing.

9. How we share your data ↑ top

We do not sell your personal data. We share it only as described below:

Who we share withWhy
Sub-processors (service providers)We use vetted providers to host our platform, process payments, send communications, provide support, analyse usage, enable e-signature, and supply sales, AI and other operational tools. They act only on our instructions and under contract. See our Sub-processor List.
Advertising & analytics partnersTo deliver and measure advertising and understand how our sites are used, subject to your cookie consent.
Professional advisers & auditorsLawyers, accountants, insurers and auditors where necessary.
Regulators, authorities & courtsWhere required by law, or to establish, exercise or defend legal rights. Where we act as your Authorised Representative or Article 27 Representative and an authority requests documentation, we will, wherever possible, come back to you for the specific document rather than releasing your supplier or commercial detail directly.
AcquirersIn connection with a merger, acquisition, financing or sale of assets, subject to appropriate confidentiality.
With your consentAny other sharing you direct or agree to.

10. International data transfers ↑ top

We are based in the UK and the EU (Ireland). Some of our sub-processors are located outside the UK and the European Economic Area (EEA), including in the United States. Where we transfer personal data to a country that is not covered by a UK or EU “adequacy” decision, we put appropriate safeguards in place — such as the European Commission’s Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement or Addendum, together with any additional measures required. Where a provider is certified under the EU–US Data Privacy Framework (and its UK Extension), we may rely on that. You can request a copy of the relevant safeguards using the contact details in Section 15.

11. How long we keep your data ↑ top

We keep personal data only for as long as we need it for the purposes set out in this policy, or for as long as the law requires. Typical periods are:

Type of dataHow long we keep it
Account and contact dataFor the duration of your relationship with us, then typically up to 6 years after your account closes, to handle queries and exercise or defend legal claims.
Billing, payment and tax recordsUsually 6 years from the relevant financial year, to meet accounting and tax law.
Compliance documentation, declarations and technical files held as your Authorised RepresentativeFor the period required by the applicable product legislation — commonly up to 10 years after the last product is placed on the market — or as otherwise instructed by you under our DPA.
Service & compliance data processed on your behalf (as processor)For the duration of the service, then returned or deleted in line with our DPA and your instructions.
Support and communicationsTypically 2–3 years.
Marketing dataUntil you unsubscribe or object, after which we keep minimal data on a suppression list to honour your choice.
Cookies and tracking dataFor the durations set out in our Cookie Policy.
As your Authorised Representative we are legally required to retain technical documentation and declarations for the periods above. When we no longer need personal data we securely delete or anonymise it; anonymous and aggregated data that does not identify you may be kept indefinitely.

12. Security ↑ top

We take the security of personal data seriously and maintain appropriate technical and organisational measures to protect it against loss, misuse and unauthorised access, alteration or disclosure. These include encryption of data in transit and at rest, access controls and least-privilege access, network and application monitoring, secure development practices, and contractual data-protection terms with our sub-processors.

Euverify is Cyber Essentials certified and is working towards SOC 2. We treat the personal data and documentation you entrust to us as confidential and make it available only to authorised personnel who need it to provide our services. Despite our measures, no method of transmission or storage is completely secure, so we cannot guarantee absolute security; please use a strong, unique password and keep your login credentials confidential.

13. Your rights ↑ top

Depending on where you are and the law that applies, you have the following rights over your personal data:

  • Access — a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — delete your data in certain circumstances.
  • Restriction — limit how we use your data in certain circumstances.
  • Portability — receive certain data in a portable format, or have it sent to another provider.
  • Object — object to processing based on legitimate interests, and to direct marketing at any time (which we will always honour).
  • Withdraw consent — where we rely on consent, withdraw it at any time, without affecting processing already carried out.
  • Automated decisions — not to be subject to decisions with legal or similarly significant effects based solely on automated processing. We do not carry out such decision-making.
  • Complain — lodge a complaint with a supervisory authority (see Section 15).

Where we process your data on behalf of a customer (as processor or representative), please direct your request to that customer (the controller); we will assist them in responding.

14. How to exercise your rights ↑ top

To make a request, email us at gdpr@euverify.com. To protect your data, we may need to verify your identity before we act. We will respond within one month. If your request is complex, or you have made several requests, we may extend this by up to two further months and will tell you within the first month if so. Requests are normally free; we may charge a reasonable fee, or decline to act, if a request is manifestly unfounded or excessive, and we will explain why.

15. How to contact us ↑ top

If you have any questions, concerns or complaints about this policy or how we handle personal data, please contact us:

United Kingdom

Euverify Ltd
3rd Floor, 86–90 Paul Street
London, EC2A 4NE
United Kingdom
Company no. 16146525

European Union (Ireland)

Euverify Limited
Unit 3D North Point House
North Point Business Park, New Mallow Road
Cork, T23 AT2P, Ireland
Company no. 781168

General enquiries: info@euverify.com
Data protection & privacy requests: gdpr@euverify.com

You also have the right to lodge a complaint with a supervisory authority:

Supervisory authorityContact
United Kingdom — Information Commissioner’s Office (ICO)Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, UK · ico.org.uk · 0303 123 1113
Ireland / EU — Data Protection Commission (DPC)21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland · dataprotection.ie · +353 1 765 0100

If you are in another EU/EEA country, you may also contact your local supervisory authority.

16. Children’s data ↑ top

Our websites, platform and services are intended for businesses and are not directed at children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.

17. Third-party links ↑ top

Our websites and platform may link to third-party sites and services that we do not control. This policy does not apply to them and we are not responsible for their practices. Please review their own privacy notices.

18. Changes to this policy ↑ top

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date and post the new version on our website. If the changes are material, we will give reasonable notice — for example, by email or a notice on our website — before they take effect. Please review this policy periodically.