Log inBook a walkthrough

Privacy Policy

Version: 2.0 · Last updated: 2026-08-17 · Effective from: 2026-05-01

Table of contents

  • Data controller
  • What personal data we process
  • Purpose and legal basis
  • Automated decision-making
  • Storage period
  • Sharing with third parties
  • Data security
  • Incident management
  • Data subject rights
  • Cookies
  • Contact and complaints
  • Changes

Data controller

Verca AB is the data controller for personal data collected in connection with visits to the website, account administration and communication. For personal data that Customers create or upload in the Platform, Verca AB acts as data processor on behalf of the Customer (see our DPA).

Verca AB
Organization number: 559564-2629
Registered office: Malmö
Email: support@verca.se

What personal data we process

Verca AB processes the personal data required to provide the service. The processing covers the following categories:

CategoryExamplesSource
Contact detailsName, job title, email address, phone numberCustomer at registration
Account dataLogin information, role, permissionsPlatform at account creation
Technical dataIP address, browser, device, session dataAutomatic collection
Billing dataOrganization number, billing address, payment referencesCustomer at contract signing
Customer dataDocuments and files uploaded by UsersCustomer during use

We do not process special categories of personal data (Article 9 GDPR) unless this is expressly required and approved by the Customer.

Data from third parties (Article 14 GDPR). If Verca AB receives personal data about you from sources other than yourself — such as from your employer at account creation, from a partner during collaborations, or from a supplier in the Customer's supply chain — you will be informed of this without undue delay and no later than within 30 days of receipt, in accordance with Article 14 GDPR. Information is provided by email to the registered address or, if no such address exists, at first contact.

Purpose and legal basis

PurposeLegal basisDescription
Providing the serviceContractAccount, login, storage of documents and product information, classification and requirement management
Customer supportLegitimate interestTroubleshooting, system maintenance, communication
Platform improvementLegitimate interestAnalysis of usage patterns in aggregated form, performance optimization
Billing and administrationLegal obligation / ContractBilling, accounting, contract management
Security and abuse preventionLegitimate interestLogging, incident management, access control

Verca AB never processes personal data for purposes incompatible with the above. Personal data is not used for marketing to third parties.

Automated decision-making

The Platform contains a rule engine (Requirements Engine) that automatically identifies applicable regulations based on product data. This automation constitutes decision support — not automated decision-making with legal effect within the meaning of Article 22 GDPR. The Customer always makes the final decision.

Profiling. Verca AB does not profile individual Users' classification decisions or product data. Usage patterns are analysed only in aggregated and pseudonymised form for product improvement and performance analysis, never for marketing or sharing with third parties.

Storage period

Data typeStorage period
Customer account dataContract term
Customer data (documents, files)Contract term + 30 days export window + 30 days deletion
Technical data (logs, sessions)Maximum 12 months
Billing and accounting data7 years under Swedish accounting law
Audit logs12 months

After termination of the Agreement, the Customer has 30 days to export data. Thereafter, Customer data is permanently deleted within an additional 30 days, in accordance with the Data Processing Agreement (DPA) § 8. Data subject to statutory requirements (e.g. Swedish accounting law) is retained in accordance with law.

Sharing with third parties

Verca AB never shares personal data for marketing purposes.

Personal data may be processed by sub-processors within the following categories:

CategoryPurposeLocation
Infrastructure and operationsServer hosting, data storageEU
AuthenticationLogin and access controlEU
BillingPayment processingEU
EmailTransactional messagesEU
E-signingDigital document signingEU
Error trackingApplication monitoringEU
SecurityRate limiting and performance monitoringEU
Web analyticsAnalytics on public pages (consent-based)EU
AI servicesAI chat, document analysis, and semantic search, only after organization activationUnited States

All processing takes place under data processing agreements in accordance with GDPR. A current list of sub-processors is available in the Data Processing Agreement (DPA).

No transfer of personal data to countries outside the EU/EEA takes place without a legal basis (e.g. EU Commission adequacy decision or standard contractual clauses).

Data security

Verca AB takes technical and organizational measures to protect personal data:

  • Encryption at rest and in transit
  • Role-based access control
  • Tenant isolation — each organization's data is strictly separated at database level
  • Complete audit log with timestamp and user
  • Secure server environment within the EU
  • Continuous security updates and testing

Only authorized personnel with documented need have access to personal data.

Audit log content. Logs record timestamp, user ID, IP address, type of action (creation, edit, deletion) and the resource concerned. Logs are available for the Customer's own internal reviews and may, upon official request, be provided to supervisory authorities (e.g. the Swedish Authority for Privacy Protection or the Swedish Consumer Agency). Logs are not used for marketing or sharing with third parties.

Incident management

In case of suspected personal data incident, Verca AB notifies the Customer without undue delay and no later than within 36 hours, in accordance with the Data Processing Agreement (DPA). Incidents that pose a risk to data subjects' rights and freedoms are reported to the Swedish Authority for Privacy Protection (IMY) within 72 hours in accordance with Article 33 GDPR.

Data subject rights

As a data subject, you have the right to:

  • Access your personal data (Article 15)
  • Request rectification of incorrect data (Article 16)
  • Request erasure of data no longer needed (Article 17)
  • Request restriction of processing (Article 18)
  • Object to processing based on legitimate interest (Article 21)
  • Request data portability in machine-readable format (Article 20)
  • Lodge a complaint with the supervisory authority (Article 77) — Swedish Authority for Privacy Protection (IMY), imy.se

Requests are responded to without undue delay and no later than within 30 days.

Contact: support@verca.se

Cookies

Verca AB uses cookies to provide the Platform's functionality and improve the user experience. Detailed information about which cookies are used and how they are managed is available in our separate cookie policy.

Contact and complaints

Verca AB (reg. no. 559564-2629) is the data controller for the processing described in this policy.

Verca AB
Skomakaregatan 6-8
211 34 Malmö
Sweden

Questions about personal data processing: dataskydd@verca.se

Verca AB does not currently have a designated Data Protection Officer (DPO). Inquiries and complaints concerning personal data processing are answered by Verca AB's data protection function at the email address above.

Complaints to the supervisory authority:
If you believe Verca AB is processing your personal data in violation of the GDPR, you have the right to lodge a complaint with:
Swedish Authority for Privacy Protection (IMY)
Website: imy.se

Changes

Verca AB may update this privacy policy. In case of material changes, Customers are notified at least 30 days in advance. The latest version is always published at verca.se/integritetspolicy.

Previous versions of the privacy policy are retained internally and may be provided upon request.

Product

PlatformVerca AITiersLog in

Resources

GuidesHow to CE Mark a ProductTechnical DocumentationEU Declaration of ConformityProduct Risk AssessmentFAQ

Regulations

General product safety (GPSR)Machinery RegulationCyber Resilience Act (CRA)Digital Product Passports (DPP)Packaging and Packaging Waste RegulationREACHRoHS

Company

About VercaPartnersCareersContactCalmplexity

Governance

Corporate policyImpartiality and independenceInformation security

Legal

Terms of UsePrivacy policyCookie policyData Processing AgreementService Level Agreement
© 2026 Verca AB. All rights reserved.
·