VVerifagent
ProductHow it worksGuidesPricing
Sign inGet startedGet started
  • Product
  • How it works
  • Guides
  • Pricing
  • Sign in

Language

← Home
TermsPrivacyCookiesLegal noticeDPA

On this page

Data controllerData we processPurposes and legal basesController vs processorSubprocessorsRetentionYour GDPR rightsSecurityInternational transfersChildrenChanges
Legal

Privacy policy

Last updated: 30 July 2026

This document is a generated draft. It does not replace review by a qualified lawyer or DPO.

Data controller

The controller of account and billing-related personal data will be identified upon registration of the publishing company. Until then, for any request relating to your personal data (access, rectification, erasure, restriction, portability, objection) or to lodge a complaint with the CNIL or another competent supervisory authority, contact contact@verifagent.com. You may also use in-product account deletion at /app/settings/account when that meets your request.

Data we process

Depending on how you use Verifagent, we may process:

  • Account: email address, password hash (handled by Supabase Auth), preferred language (preferred_locale / verifagent_locale).
  • Organization: organization name, members and roles.
  • Monitors: name, expected period, grace period, ping tokens/URLs.
  • Signals (pings): timestamps, durations, error messages and JSON metadata sent by your workflows.
  • Incidents: open/resolve times and related status.
  • Notification channels: destination emails, chat/webhook URLs (Slack, Discord, Teams), Telegram chat IDs, and PagerDuty routing keys. Bot tokens and routing keys are stored as secrets and redacted in the UI for non-managers.
  • Billing (once payments open): Stripe customer/subscription identifiers and related status fields. Card data will be processed by Stripe, not stored by Verifagent.
Important: ping metadata and error messages are stored as received. Do not put passwords, secrets, health data, government IDs or other sensitive personal data in workflow payloads sent to Verifagent.

Purposes and legal bases

  • Providing the monitoring service and account (performance of a contract).
  • Security, abuse prevention and service integrity (legitimate interests / legal obligations).
  • Billing and tax records for paid plans (contract / legal obligation).
  • Transactional emails — auth, alerts, billing reminders (contract / legitimate interests).
  • Product analytics via Vercel Analytics in a privacy-oriented mode (legitimate interests; see Cookies policy).

Controller vs processor

For your account profile and our billing relationship, Verifagent acts as controller.

For personal data contained in your monitors’ ping metadata, incident context and notification destinations that you configure, you are typically the controller. A Data Processing Agreement (DPA) will be made available when the service opens for business customers who need one.

Subprocessors

We use the following providers to operate Verifagent:

  • Supabase — database and authentication; data hosted in the European Union (Stockholm, Sweden), region eu-north-1.
  • Vercel — application hosting and delivery.
  • Resend — sending transactional and alert emails.
  • Stripe — payment processing and customer billing portal.
  • cron-job.org — external cron calling our notification dispatch endpoint.

Retention

Visible history follows plan limits: about 7 days on Solo and about 12 months on Studio for incident/history views, subject to product changes.

Operational logs and backups may retain residual data for a short additional period for security and continuity.

After account deletion (available in the product at /app/settings/account), your memberships are removed. Organizations you alone owned may be deleted with their monitors and channels. Stripe may retain invoicing records as required by law once billing is active.

Your GDPR rights

Where GDPR applies, you may request access, rectification, erasure, restriction, portability and objection, and you may lodge a complaint with a supervisory authority.

To exercise rights, contact contact@verifagent.com or use in-product account deletion at /app/settings/account when that meets your request.

Security

We use measures appropriate to a SaaS monitoring service (encrypted transport, access controls, hashed passwords via Supabase Auth, secret ping tokens). No method of transmission or storage is perfectly secure.

International transfers

If a provider processes data outside the EEA/UK, we rely on appropriate safeguards (such as Standard Contractual Clauses) offered by that provider, unless an adequacy decision applies.

Children

Verifagent is intended for professional use and is not directed at children.

Changes

We may update this policy. The “Last updated” date will change.

VVerifagent

Product

How it worksPricingSign inGet started

Resources

Guidesn8nMakeZapiercron

Legal

TermsPrivacyCookiesLegal notice
Verifagent