Legal

Privacy Policy

Effective date: 2026-01-29

1. Who we are

Verity (feedback.mom) is operated from Norway ("Verity", "we", "us"). If we incorporate or restructure (for example to a Norwegian AS or other entity), we may transfer this service and its data to a successor entity and will update this policy accordingly.

Contact for privacy requests: [email protected]

2. Scope

This policy explains how we process personal data in connection with:

  • • our marketing site,
  • • our customer admin application (accounts, billing, security), and
  • • feedback submitted through customer-configured widgets ("End User submissions").

If you submit feedback through a widget embedded on a customer's website/app, that customer is typically responsible for determining what is collected and why.

3. Roles (controller / processor)

Customer content (processor): If you use Verity for your organization, you are typically the data controller for End User submissions (reports and evidence), and Verity acts as your data processor for that customer content.

Account & operations (controller): Verity is the data controller for account, billing, and security/operational data necessary to operate the service.

Where required, we provide a Data Processing Agreement ("DPA") governing our processor obligations.

4. What we collect

Depending on configuration and use, we may process:

  • • Account and billing data: admin email, authentication/session data, subscription and billing records, and related security data (such as IP address and user agent for login security and abuse prevention).
  • • Report data: message content and report metadata (such as reported URL, environment/type/status, and optional identity fields if you enable them).
  • • Evidence (optional, customer-controlled): screenshots and attachments, annotation data, session replay data (event-based recordings), technical diagnostics (such as console/network information), and derived artifacts generated when enabled.
  • • Operational data: logs and telemetry used for reliability, fraud prevention, security, and debugging.

5. Why we collect it (purposes)

We process personal data to:

  • • provide the service (collect, display, and manage feedback),
  • • secure the service (authentication, abuse prevention, incident response),
  • • maintain and improve reliability and performance (monitoring, debugging, error tracking),
  • • deliver integrations you enable (e.g., ticketing/chat/dev tools and webhooks),
  • • send product/marketing communications only if you opt in (where applicable).

6. Legal bases (GDPR/EEA/UK)

For EEA/UK contexts where Verity acts as controller, we process personal data based on one or more of: performance of a contract, legitimate interests (security, fraud prevention, reliability), compliance with legal obligations, and consent (where required, such as certain marketing communications).

Where Verity acts as processor for Customer Content, the customer determines the lawful basis and provides required notices/consents to End Users.

7. Cookies and similar technologies

  • • The admin application uses strictly necessary cookies and/or similar technologies for authentication and session management.
  • • The widget may use strictly necessary local storage or similar technologies to function (for example to store temporary configuration or session state). The widget does not use cookies by default.
  • • The widget is not designed to perform device fingerprinting.

We may update this section with a more detailed breakdown as the product evolves.

8. Sharing and subprocessors

We do not sell personal data.

We may share data with:

  • • service providers used to run the service (such as payment processing, email delivery, cloud infrastructure/storage, and error monitoring), and
  • • third-party services you connect via integrations/webhooks, according to your configuration.

A current list of our subprocessors is available to customers via our DPA and/or upon request.

9. Data retention

Retention depends on plan and configuration. We keep data only as long as necessary for the purposes described above, including operating the service and customer workspaces, security and incident response, meeting legal and accounting obligations, and resolving disputes and enforcing our terms.

Customers may be able to configure retention for certain types of Customer Content.

10. International transfers

Some service providers may process data outside Norway/EEA. Where applicable, we rely on appropriate transfer mechanisms (such as Standard Contractual Clauses) and vendor commitments.

11. Your rights

Depending on your location, you may have rights to access, correct, delete, or export your personal data, and to object or restrict certain processing.

End Users: If you submitted feedback through a customer's widget, contact that organization first, as they typically control the data and can instruct us as processor.

To exercise rights related to Verity's controller data (account/billing/security), contact [email protected].

12. Security

We use reasonable technical and organizational measures designed to protect personal data. No method of transmission or storage is 100% secure.

13. Changes

We may update this policy as the service changes. We will post the updated policy on this page and update the effective date.