Privacy Policy
Last updated: [insert date]
This Privacy Policy explains how Verdana – A Software Company LLC (“Verdana”, “we”, “us”, “our” or the “Platform”) collects, uses, stores, processes and protects personal data in connection with its website, SaaS platform and related services.
Verdana is a SaaS platform designed to support third-party management, supplier and contractor management, compliance workflows, documentation management, audit trails, approvals, procurement-related processes and business collaboration.
This Privacy Policy may be updated from time to time to reflect legal, technical, operational or commercial changes.
1. Company information and contact details
Company: Verdana – A Software Company LLC
Address: 770 NE 69TH ST UNIT 8, Miami, FL 33138, United States
Privacy contact: [email protected]
Phone: +54 11 6590 8284
For any questions, requests or concerns regarding privacy or personal data protection, please contact us at the email address above.
2. Scope of this Privacy Policy
This Privacy Policy applies to:
- visitors of Verdana’s website;
- customers, prospects and business contacts;
- authorized users of direct customers;
- users, employees, representatives or contacts of third parties created, invited or managed by customers through the Platform;
- other individuals whose personal data may be processed in connection with Verdana’s services.
When a customer uses Verdana to upload, manage or process information relating to its employees, suppliers, contractors, customers, representatives, beneficial owners or other third parties, the customer generally acts as the data controller or responsible party for such data. In those cases, Verdana generally acts as a data processor, service provider or equivalent role, processing personal data on behalf of the customer and in accordance with the customer’s instructions and the applicable contractual terms.
3. Personal data we may process
Verdana seeks to process only the personal data that is necessary to provide, operate, secure and improve its services.
Depending on the context, we may process the following categories of personal data.
3.1 Data relating to users of direct customers
- First name.
- Last name.
- Corporate email address.
- Company or organization.
- Role, permissions and user profile.
- Access credentials or user identifiers.
- Activity records within the Platform.
3.2 Data relating to users or representatives of third parties
Customers may create, invite or manage users, employees, representatives or contacts linked to third parties, such as suppliers, contractors, customers, service providers or other related organizations.
This data may include:
- First name.
- Last name.
- Corporate email address.
- Company or organization.
- Role or relationship with the customer.
- Activity records linked to processes managed within the Platform.
3.3 Documentary and operational data uploaded by customers
Depending on how each customer uses the Platform, customers may upload or process data contained in documents, forms, records or operational workflows, including:
- corporate, tax, employment, contractual, insurance or administrative documentation;
- information related to compliance, audits, third-party evaluations, risk assessments, approvals or traceability;
- purchase orders, invoices, payments or other transactional information;
- forms, statements, certificates, records or evidence of compliance;
- comments, tasks, approvals, rejections, observations and activity logs.
The customer is responsible for ensuring that it has a valid legal basis to upload, share and process such information through the Platform.
3.4 Technical and usage data
We may process technical information necessary to operate, secure and improve the Platform, including:
- IP address;
- date and time of access;
- browser and operating system;
- technical logs;
- usage events;
- security logs;
- session information;
- cookies or similar technologies, where applicable.
4. Purposes of processing
Personal data may be processed for the following purposes:
- enabling access and authentication to the Platform;
- managing users, roles, permissions and configurations;
- providing, operating, maintaining and improving Verdana’s services;
- supporting the management of relationships between customers and their third parties;
- recording compliance, audit, traceability and documentation activities;
- sending operational communications related to the service;
- providing technical support and customer service;
- preventing unauthorized access, fraud, security incidents or misuse;
- complying with legal, regulatory or contractual obligations;
- analyzing the performance of the Platform and improving the user experience;
- generating internal records, metrics or statistics, whenever possible in aggregated or non-identifiable form.
Verdana does not sell personal data of its customers or users uploaded to the Platform.
5. Legal bases for processing
Where the European Union General Data Protection Regulation, the UK GDPR or similar data protection laws apply, processing may rely on one or more of the following legal bases:
- Performance of a contract or steps prior to entering into a contract.
- Compliance with legal obligations.
- Legitimate interests of Verdana or its customers in operating, securing, auditing and managing business, contractual, documentary and compliance processes.
- Consent, where required by applicable law.
- Documented instructions from the customer, where Verdana acts as a data processor, service provider or equivalent role.
With respect to data uploaded by customers to the Platform, the customer is responsible for determining, documenting and maintaining the applicable legal basis for the processing.
6. Roles and responsibilities
6.1 Verdana
Verdana may act as:
- a data controller or equivalent role with respect to data relating to its own customers, prospects, business contacts, website visitors, internal users and direct communications; and
- a data processor, service provider or equivalent role with respect to data that customers upload, manage or process through the Platform.
When Verdana acts as a data processor or service provider, Verdana undertakes to:
- process personal data in accordance with the customer’s documented instructions;
- implement reasonable technical and organizational measures;
- restrict access to authorized personnel;
- maintain confidentiality regarding the information processed;
- reasonably assist the customer in responding to data subject requests;
- cooperate in connection with security incidents where applicable;
- delete, return or retain data in accordance with the applicable contractual terms and applicable law.
6.2 Direct customers
Direct customers generally act as data controllers or responsible parties with respect to the data they upload, invite, manage or process through the Platform.
In particular, customers are responsible for:
- having a valid legal basis for the processing;
- informing their employees, users, suppliers, contractors or other third parties where required;
- obtaining consents, authorizations or notices where required;
- keeping information under their control accurate and up to date;
- managing requests for access, rectification, deletion, objection, portability or other rights;
- providing instructions to Verdana regarding the processing of data uploaded to the Platform.
6.3 Third parties and data subjects
Employees, representatives, contacts or users of third parties whose personal data is uploaded to the Platform may exercise their rights in accordance with applicable law.
Where personal data has been uploaded by a customer, Verdana may redirect, coordinate or validate the request with the relevant customer, as such customer generally acts as the data controller or responsible party. Verdana will reasonably cooperate with the customer in handling such requests.
7. Data retention
We retain personal data for as long as necessary to fulfill the purposes described in this Privacy Policy, provide the contracted services, comply with legal or contractual obligations, resolve disputes, maintain audit records and protect the security of the Platform.
As a general criterion:
- data relating to customer users will be retained while the account remains active or while necessary to provide the service;
- data relating to users or representatives of third parties will be retained while they maintain a relationship with the customer or while the customer instructs us to retain such data;
- activity and security logs may be retained for up to 12 months, unless a longer retention period is required for legal, contractual, audit or security reasons;
- after termination of the service, data may be deleted, exported, anonymized or retained for a reasonable period in accordance with the applicable contract.
Where contractually applicable, Verdana will seek to delete customer data within 30 days following termination of the service or a valid deletion instruction, unless a legal, technical or contractual reason justifies a different retention period.
8. Data subject rights
Depending on the applicable law, data subjects may have the right to:
- access their personal data;
- request correction of inaccurate or incomplete data;
- request deletion of their data;
- object to the processing;
- request restriction of processing;
- request data portability;
- withdraw consent, where processing is based on consent;
- lodge a complaint with a competent supervisory authority.
Requests may be sent to [email protected].
Where Verdana processes personal data on behalf of a customer, the request may require validation, coordination or instruction from the relevant customer, in its role as data controller or responsible party.
Verdana will respond to requests within the timeframes required by applicable law and will reasonably cooperate with its customers in responding to requests relating to data processed on their behalf.
9. Information security
Verdana implements reasonable technical, organizational and administrative measures designed to protect information against unauthorized access, loss, alteration, improper disclosure or destruction.
These measures may include, as applicable:
- encryption in transit using TLS;
- encryption at rest using robust encryption mechanisms;
- role-based access controls;
- two-factor authentication where enabled or required;
- password policies;
- session timeouts;
- access attempt logging;
- access revocation processes;
- logical segregation by customer;
- separation between development and production environments;
- backups;
- audit logs;
- monitoring of technical and security events;
- internal access restrictions based on the need-to-know principle;
- confidentiality obligations applicable to personnel and providers.
If Verdana detects a security incident that may affect personal data, Verdana will take reasonable steps to investigate, mitigate and, where applicable, notify affected customers or competent authorities in accordance with applicable law and contractual commitments.
10. Sub-processors and technology providers
Verdana uses technology providers to provide, host, secure, monitor and improve the Platform. These providers may act as sub-processors where they process personal data on behalf of Verdana for the provision of the service.
Sub-processors may include providers of cloud infrastructure, hosting, storage, document processing, artificial intelligence, email delivery, monitoring, technical support, security, operational analytics or other tools necessary for the operation of the Platform.
Verdana currently uses Amazon Web Services (AWS) as its primary cloud infrastructure and data storage provider.
In addition, for certain customers, features or configurations, Verdana may use specialized providers for document processing, information extraction, OCR, automation or artificial intelligence assistance, including OpenAI, where such features have been contracted, enabled or are necessary to provide the service.
Verdana seeks to maintain appropriate contractual arrangements with its providers and sub-processors, including obligations regarding confidentiality, security, limited use of information and personal data protection.
Where applicable, Verdana will inform customers of relevant sub-processors or material changes that may affect the processing of personal data.
11. Amazon Web Services
Verdana uses Amazon Web Services as its primary cloud infrastructure provider.
- Provider: Amazon Web Services.
- Main location: AWS EU Region, Ireland, unless a different contractual or technical configuration applies.
- Purpose: Cloud infrastructure, hosting, processing and data storage.
- Relevant certifications reported by AWS: ISO 27001, ISO 27017, ISO 27018, SOC 1, SOC 2, SOC 3, among others.
- Applicable safeguards: encryption, access controls, logical isolation, monitoring, backups and security tools provided by AWS.
Verdana seeks to maintain appropriate contractual and technical safeguards with AWS, including data processing terms, security obligations and international transfer mechanisms where applicable.
12. Artificial intelligence, automation and document processing
The Platform may include automation, extraction, classification, document analysis, report generation, OCR processing or artificial intelligence-assisted features.
These features may be used, depending on the configuration contracted or enabled by each customer, to assist with tasks such as:
- extracting information from documents;
- reading and classifying documents;
- detecting expiration dates, inconsistencies or missing fields;
- generating preliminary observations;
- assisting with document audits, compliance, procurement or third-party management processes.
In certain cases, and only where necessary to provide features contracted or enabled by the customer, Verdana may use external artificial intelligence providers, including OpenAI, to process documents, text or information uploaded to the Platform.
When such services are used, Verdana seeks to apply configurations and contractual terms designed to protect the confidentiality of customer information. In particular, with respect to the use of the OpenAI API, Verdana uses configurations under which the information submitted is not used to train or improve OpenAI’s public models, unless expressly authorized or otherwise agreed in writing.
Automated or artificial intelligence-assisted features are intended to provide operational assistance. Outputs may contain errors, omissions or incomplete interpretations and must be reviewed, validated and approved by the customer before being used for legal, regulatory, contractual, commercial, operational or critical decision-making purposes.
Verdana does not use customer information uploaded to the Platform to train its own models or third-party models, unless expressly authorized by the customer or otherwise agreed in writing.
13. International data transfers
Personal data may be stored or processed in countries other than the country of residence of the data subject, customer or user.
Where applicable, Verdana will take reasonable measures to ensure that such transfers are subject to appropriate safeguards, such as contractual clauses, data processing agreements or other mechanisms recognized by applicable data protection laws.
14. Cookies and similar technologies
Verdana’s website may use cookies or similar technologies to operate properly, remember preferences, analyze website usage, improve the browsing experience or perform measurement activities.
Users can configure their browser to reject or delete cookies. However, some website or Platform features may be affected.
Where required by applicable law, Verdana will request prior consent for the use of non-essential cookies.
15. Confidentiality
Information uploaded by customers to the Platform is treated as confidential.
Verdana does not sell such information or share it with third parties for purposes unrelated to the provision of the service, except where instructed by the customer, required by law, necessary for operations through authorized providers or otherwise permitted under the applicable contract.
16. Children
The Platform is not directed to children. Verdana does not knowingly collect personal data from children without valid authorization.
If Verdana becomes aware that personal data from a child has been processed without the required authorization, Verdana will take reasonable steps to delete it or regularize the processing as appropriate.
17. Changes to this Privacy Policy
Verdana may update this Privacy Policy from time to time.
The current version will be published on Verdana’s website with the corresponding “Last updated” date. Where changes are material, Verdana may notify customers or users through reasonable means.
18. Contact
For privacy or personal data protection questions, requests or complaints, please contact:
Verdana – Southapps S.A.
Address: Paraná 562, Buenos Aires, Argentina
Email: [email protected]
Phone: +54 11 6590 8284