Legal

Privacy Policy

How Verisa collects, uses, and protects information on this website.

This privacy policy describes how Verisa ("we", "our", "us") collects, uses, and protects information when you visit verisa.ai.

Information we collect

We collect information you voluntarily provide through our contact form: name, email address, company, role, and message content. With your explicit consent, we use Google Analytics 4 with IP anonymization, no Google Signals, and no ad personalization. We honour browser-level Do-Not-Track and Global Privacy Control signals — if either is set, analytics never loads regardless of banner state.

Functional storage

The public pages of this website set no HTTP cookies. We use the browser's localStorage API for two functional purposes: remembering whether you have dismissed the consent banner, and remembering your chosen light or dark theme. These entries contain no personal data and can be cleared at any time via your browser's site-data controls.

The authenticated partner portal under /portal is the one exception. Signing in sets two strictly necessary cookies, which carry no analytics or profiling function and therefore require information rather than consent: verisa_portal, the session identifier, httpOnly, SameSite=Lax, Secure over HTTPS, valid for at most 12 hours and expiring after 60 minutes of inactivity; and verisa_csrf, a cross-site request forgery token readable by the page and valid for the same period. Signing out deletes both. No cookie is set for a visitor who does not sign in.

How we use information

Contact form submissions are used solely to respond to your inquiry and provide information about our products. We do not sell, share, or transfer your personal data to third parties. Analytics data is aggregated and used to improve the website.

Third-party processors

When deployed behind Cloudflare's CDN, Cloudflare processes connection metadata (IP addresses, request URLs, user agents) on our behalf as a data processor under their standard Data Processing Addendum and Standard Contractual Clauses.

When you have consented to analytics, Google processes anonymized analytics events on our behalf under Google's Data Processing Terms.

Data retention

We retain contact form data for as long as necessary to fulfill the purpose for which it was collected. You may request deletion of your data at any time.

Partner directory

Controller. For the data published in the Verisa partner directory the controller is ENTEL Műszaki Fejlesztő Kft. (in English-language materials: Entel Engineering Research & Consulting Ltd.), registered office 1025 Budapest, Szépvölgyi út 32. 1. em. 1., Hungary, company registration number 01-09-065978. We and each listed reseller determine the purposes and means of this publication independently of one another and are therefore independent controllers; no joint controllership under Article 26 GDPR arises between us. This section describes our own processing in full — for it, we do not refer you to the reseller's privacy notice.

Purpose. To publish, in a verifiable form, which resellers are authorised to sell and support Verisa products, in which contractual territory, for which product range and with which evidenced service capability, so that public-sector and other buyers can check a reseller's status before contracting.

Categories of data. Company name, approved logo, registered office, country, website, public organisational contact details, partner tier, contractual territory, covered product range, evidenced service capability. No further data point is published without the reseller's prior written consent, and that consent is recorded before publication.

Legal bases. Organisational data — including a functional email address or telephone number that is not attributable to an individual — is published on the basis of our legitimate interest in a transparent and verifiable sales channel (Article 6(1)(f) GDPR); the balancing assessment is documented and available on request. The name or contact details of a natural person are published only where the reseller has designated them in advance and expressly in writing, the individual has been properly informed, and the individual has consented (Article 6(1)(a) GDPR). Consent may be withdrawn at any time with effect for the future, and withdrawal does not affect the lawfulness of processing before it.

Retention. Data remains published while the reseller agreement is in force. On termination we remove the entry within 15 working days — from the directory page, from page and CDN caches, from any downloadable partner catalogue, from the sitemap and from our search index. After removal we retain only the version history evidencing when an entry was published, amended and removed, as the audit trail for these obligations.

Recipients. The directory is public: published data is accessible to any visitor and may be indexed by search engines. We do not pass partner directory data to third parties for their own purposes. Content delivery involves the CDN provider named elsewhere in this notice, acting as our processor under the safeguards stated there.

Your rights. You may request access to your personal data, its rectification or erasure, restriction of processing, and you may object to processing; where processing rests on consent you may withdraw it and exercise the right to data portability. You may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH, 1055 Budapest, Falk Miksa utca 9–11., Hungary) or with the supervisory authority of your habitual residence, and you may seek a judicial remedy.

Contact. support@verisa.ai

Partner portal

The partner portal is a separate processing operation from the directory above. The directory deliberately avoids naming individuals; the portal necessarily processes the data of named employees of a reseller.

Purpose and legal basis. We operate the portal to provide the electronic submission and tracking channel the reseller framework agreement requires, and to evidence when a submission was made. Account data — email address, display name, the partner organisation, the function assigned within it, and a password hash — is processed to perform the agreement with the reseller (Article 6(1)(b) GDPR) and, in respect of the employee as data subject, on our legitimate interest in an identified and accountable channel (Article 6(1)(f)). The append-only audit log, which records who submitted what and when, rests on our legitimate interest in evidence and on the contractual commitment that the portal log proves the time of submission. Login attempts and session metadata (IP address, user agent) are processed on our legitimate interest in defending against authentication attacks. The balancing assessments are documented and available on request.

Categories of data. Account data as above; submissions and support tickets filed by the user; correction requests concerning the partner's own directory entry; session metadata; and audit log entries. The audit log stores a pseudonymous user identifier and a hash of the submitted content, not the content itself.

Retention. Audit log entries and submissions are retained for the term of the agreement and 8 years thereafter, as evidence. Session records are deleted 30 days after expiry; login attempt records after 90 days. An account is retained until it is closed; 30 days after closure the email address and display name are anonymised and the password hash is deleted.

Erasure and the audit log. The audit log is deliberately immutable: each entry carries the hash of the previous one, so deleting or altering an entry would destroy the evidential value the whole log exists for. We therefore do not delete audit entries on request. Instead, the identifier they contain is a pseudonym, and anonymising the account breaks the link between that pseudonym and the individual in our systems. Where an erasure request cannot be met for this reason we say so in writing, with the ground and the retention period.

Recipients. No third party. The portal database is held on our own infrastructure and is not shared with any processor beyond the hosting and CDN arrangements named elsewhere in this notice.

Rights. The rights listed for the partner directory apply here too, including the right to lodge a complaint with NAIH or with the supervisory authority of your habitual residence.

Contact. support@verisa.ai

Contact

For privacy-related inquiries, please contact us at entel@entel.hu.

Last updated: 2026-08-12