Verdatum privacy policy

Last updated: 11 August 2026

This policy explains what personal data Verdatum processes, why we process it, where it goes and how long we keep it.

Who we are

Verdatum is a trading name of The Coln Group Ltd. The company is registered in England and Wales under company number 09788225. Its registered office is 3rd Floor, 86–90 Paul Street, London, EC2A 4NE.

The Coln Group Ltd is the data controller for the processing in this policy. Our data protection officer handles privacy matters at privacy@verdatum.ai. For general support, email support@verdatum.ai.

What Verdatum does

Verdatum is a hosted service for durable organization profiles. It connects AI agents to source-backed organization intelligence through the Model Context Protocol. A profile can include organization identity, ownership and governance, filings and financials, public markets, sanctions, patents, and entitled life sciences intelligence.

One profile describes one confirmed organization. People and other organizations can appear as source-backed intelligence inside its projections. They do not become the subject of that profile.

The short version

Sign-in and entitlement data

Access is contracted at organisation level. WorkOS, Inc. verifies your work email, either directly or through your organisation's identity provider. It then issues an access token. Verdatum validates the token and your organisation's contract before serving profile data.

WorkOS holds your email address and organisation membership as our processor. For profile requests, Verdatum receives pseudonymous user and organisation identifiers. When you sign in to the Verdatum account page, Verdatum also receives your email address and name from the verified WorkOS identity token. It keeps those account details in a signed, Secure and HttpOnly browser session cookie until you sign out or the verified sign-in expires. Verdatum has no separate user database, and its account logs contain the pseudonymous identifiers rather than your email address or name.

Every customer organization (the tenant) is entitled to the core intelligence domain. It may additionally be entitled to life_sciences across every profile in that tenant. Domain entitlement is separate from source and record coverage. Verdatum derives both rights from WorkOS Organization metadata before deployment. It does not call WorkOS during a profile request.

Purpose: authenticate you and enforce your organisation's entitlement.

Lawful basis: our legitimate interests and your organisation's contract under UK GDPR and EU GDPR article 6(1)(f), and article 6(1)(b) where you act for the contracting organisation.

Organization clues and profile creation

Your agent can send a name, identifier, website or ticker to identify one organization. Verdatum processes this clue to return a resolved organization, possible candidates or an unresolved outcome. It does not silently choose when the evidence requires your decision.

When your agent creates a profile, the confirmed organization scope and its supporting evidence become durable profile data. The original conversation remains with your AI assistant platform. Verdatum does not create a separate copy of it.

Purpose: identify the organization you selected and create the contracted profile.

Lawful basis: your organisation's contract and our legitimate interests under article 6(1)(b) and article 6(1)(f).

Profile data

A profile contains a concise envelope and immutable revisions. Each revision records the exact projection revisions it uses. A projection can contain normalized source-backed claims, coverage, freshness, limitations and evidence links.

Verdatum stores:

Raw provider payloads, documents, tables or licensed excerpts are never persisted in the profile store. Verdatum retains only approved normalized structured records, claims and provenance. Separately governed response and public filing extraction caches can hold public source content under their own bounded operational policies; those caches are not profile evidence.

Disabling monitoring stops future scheduled assessments. It does not delete the profile, revisions, evidence, execution records or audit records. When a contract ends, the tenant offboarding procedure revokes access and stops work at termination, then removes live profile and execution data within 24 hours. A minimal payload-free purge audit remains for its stated retention period.

Purpose: provide a coherent profile, refresh it, show its evidence and report source-backed changes.

Lawful basis: your organisation's contract and our legitimate interests under article 6(1)(b) and article 6(1)(f).

Service logs

Service logs can contain the tool name, status, timing, error category and pseudonymous WorkOS identifiers. They never contain tool arguments, profile content, evidence content, document content, access tokens or email addresses. Code and automated tests enforce this allowlist.

Purpose: operate and secure the service, plan capacity and prevent abuse.

Lawful basis: legitimate interests under article 6(1)(f).

Public-source caches

Verdatum uses bounded caches to avoid repeating provider work:

These caches do not contain your conversation or user identity.

Personal data in profile evidence

Public company registers can publish names, service addresses, appointments and control interests for officers and persons with significant control. Sanctions authorities publish identifying details about designated people. Patent offices publish applicants, inventors and recorded assignment parties. Life sciences and research sources can publish investigators and publication authors. Verdatum does not persist clinical-trial participants or patient-level health data under this product policy.

Verdatum can store the normalized, source-backed parts of those records inside an organization profile. It keeps the source and limitations attached. A sanctions candidate is not a designation decision. A patent party is not proof of current ownership.

Verdatum does not create profiles whose scope is an individual. If a source record is wrong, the source that published it remains the effective correction route. A later profile refresh can publish the corrected record. Retained older revisions remain a record of what the source reported at their assessment time, until their retention expires.

Lawful basis: legitimate interests under article 6(1)(f), including providing source-backed organization intelligence from records published for public, regulatory or research purposes.

This policy is our public transparency notice for indirect collection under article 14(5)(b). Individual notice to every person named across the public records would involve disproportionate effort. This policy explains the data classes, sources, purpose and rights in one stable place.

Support correspondence and website visitors

If you contact support, we process what you send to resolve the issue and keep the correspondence for as long as needed to evidence how we handled it.

The Verdatum website is static. It sets no cookies and runs no analytics or tracking. Hosting infrastructure records standard request logs, including IP addresses, for security and operations.

Lawful basis: legitimate interests under article 6(1)(f).

Where your data goes

Our processors

Processor Role Location
Google Cloud, Google Ireland Ltd hosting, databases, logging and source caches in europe-west1 EEA
WorkOS, Inc. authentication, email verification and organisation membership United States
Mistral AI optical character recognition of public registry filings; it receives the filing document, not your identity or conversation France, EEA

Data sources

Verdatum sends only the organization or record terms needed for a profile assessment. Depending on coverage, it can query:

The source receives no Verdatum user identity. It can receive an organization name, registry number, security identifier, patent reference, or another source-specific record key. Each source remains responsible for the records it publishes.

Your AI assistant platform

Your AI assistant platform processes your conversation and the profile data it receives under its own terms and privacy policy. Verdatum's commitments apply only to Verdatum infrastructure.

International transfers

The service runs in Belgium in the EEA, which the UK recognizes as adequate. Transfers to WorkOS in the United States use the standard contractual clauses and the UK international data transfer addendum in the WorkOS data processing agreement. For any other transfer outside the UK and EEA, we use an adequacy decision or appropriate contractual safeguards.

How long we keep data

Data Retention
Active profile, current revision and monitoring configuration While the organisation's contract remains active; access is revoked and work stops at termination, with live-store purge completed within 24 hours
Superseded profile and projection revisions, profile change sets and related evidence Up to 12 months after supersession
Private profile execution and idempotency records 30 days after completion or recording
Payload-free profile purge audit records 400 days
Encrypted database backups after deletion Up to 7 days; recovery use only
Service request logs with pseudonymous identifiers 30 days
WorkOS sign-in and membership records For the contract life, then deleted under the WorkOS data processing agreement
Public filing extraction and source caches While operationally useful and permitted by the source policy
Support correspondence As long as needed to resolve and evidence the matter

Backups are for recovery only. Before a restored database can serve traffic, Verdatum reapplies every completed tenant deletion after the restore point and verifies that the deleted tenant's live profile and execution data remain absent.

The profile retention policy is versioned. The most restrictive applicable source licence, legal requirement, customer contract or product limit governs each stored item.

Your rights

Under the UK GDPR and, where applicable, the EU GDPR, you can ask to access, correct or erase your personal data. You can also ask us to restrict processing, object to it, or provide portable data where the law requires this.

Verdatum makes no automated decision about you that has legal or similarly significant effect.

Email privacy@verdatum.ai to exercise a right. We respond within one month. You can complain to the Information Commissioner's Office at ico.org.uk, or to your local EEA supervisory authority.

For source-published data, correction at the source is usually the effective route. We can explain our processing and apply the profile retention and purge controls that govern our copy.

Security

We encrypt traffic in transit. Google Cloud encrypts stored profile data and backups at rest. Provider credentials live in Secret Manager rather than code. Production access follows least privilege. Our cloud provider ensures that administrative access is logged.

This service is for organisations

Verdatum is a business-to-business service for contracted organisations. It is not directed at children, and we do not knowingly process children's personal data as users.

Changes to this policy

We will publish changes here and update the date at the top. We notify contracted organisations before a material change takes effect.