Privacy Policy
How verrou collects, uses, and protects information when you visit this website or contact us — and where engagement material, including project repositories, is stored. Last updated: .
Who we are
verrou is a boutique cybersecurity consultancy providing Post-Quantum Cryptography Readiness, AI Security, and Product Penetration Testing services. This policy explains how we handle personal information collected through this website. It does not cover data we process under a signed engagement or services agreement — that handling is governed by the terms of the applicable contract and any data processing addendum.
For the purposes of data protection law, the data controller is verrou, Inc., a Delaware corporation. Questions about this policy or your personal information can be sent to hello@verrou.ai.
Information we collect
We keep collection to a minimum. Through this website, we collect:
- Contact form submissions. When you complete our contact form, we receive the information you choose to provide — typically your name, email address, company, and the message describing your inquiry. This is used solely to respond to you.
- No analytics, no tracking cookies, no third-party requests. We run no analytics and set no cookies. Every asset on this site — fonts included — is served from our own infrastructure, so no third party sees your visit.
- No web server request logs. Access logs are written to
/dev/nullrather than to disk, so the pages you visit are never recorded in the first place. - No IP addresses. Your address is never stored — not on disk, and not in memory. To rate-limit the contact form against abuse we need to recognize a repeat sender, not to know who they are, so we keep only a one-way cryptographic digest of the address, computed with a secret that is generated fresh each time the service starts and never leaves memory. The digest cannot be turned back into your address, cannot be matched against one taken before the last restart, and is discarded once the rate-limit window expires. Your address itself is never written to a file, never included in the notification email we receive, and never appears in any log.
We do not knowingly collect sensitive categories of personal data through this website, and we ask that you not include confidential technical details about your environment in an initial contact message.
How we use it, and on what legal basis
We use the information above to:
- Respond to inquiries and provide the services you request;
- Operate, maintain, secure, and improve the website;
- Detect, prevent, and investigate fraud, abuse, and security incidents;
- Comply with legal obligations and enforce our agreements.
We do not sell your personal information, and we do not use contact form submissions to send marketing unless you have separately asked to hear from us.
Under the EU/UK GDPR our lawful basis is legitimate interests (Article 6(1)(f)) — answering someone who has deliberately contacted us about our services is what both sides expect, involves the minimum data needed to reply, and does not override your rights. Where your message concerns a possible engagement, processing also serves steps taken at your request before entering a contract (Article 6(1)(b)). We do not rely on consent, so there is no consent for you to withdraw — and nothing to click through on arrival.
Cookies & analytics
This site sets no cookies at all — not for analytics, not for preferences, not for anything else. We use no third-party analytics service, and no third-party assets load when you visit, so nothing here follows you around the web.
Because we set no cookies and run no tracking, there is no banner to click through on arrival and no cookie consent for you to give, manage, or withdraw.
Third-party processors
We keep this list deliberately short:
- Contact form — the form is handled by our own software running on the same server as this website. No third-party form service is involved; what you type goes directly to us.
- Hosting — 1984 hosts this website and the contact form that receives your message, in Iceland, acting as our processor.
- Email — our mail is operated by Proton in Switzerland; your submission reaches us as email and is stored there.
- Project & code hosting — engagement material, including project repositories, is held on our own server in Iceland. No third-party code-hosting provider is involved.
Each processor is bound to appropriate confidentiality and security obligations. We review this list periodically and update it as our providers change.
Data retention
We keep personal information only for as long as needed for the purpose it was collected, or as required by law. Contact form submissions are retained for as long as necessary to handle your inquiry and any resulting relationship, then deleted or anonymized. When the form is submitted successfully, your message reaches us as email and nothing at all is stored on the web server. Only if that delivery fails does the server keep a copy, so your message is not simply lost — and that copy is rotated out within roughly three months. There is nothing else to retain: no request logs, no IP addresses, no cookies. Specific retention periods for client engagement data are set out in the applicable engagement agreement; our standard period is 30 days after the final invoice is paid.
Your rights
Depending on where you live, you may have rights over your personal information. Under the EU/UK GDPR these include the right to access, correct, delete, restrict, or object to processing, the right to data portability, and the right to withdraw consent where processing is based on consent. Under the California Consumer Privacy Act (CCPA/CPRA) these include the right to know what personal information we hold, the right to deletion, the right to correction, and the right not to be discriminated against for exercising your rights. We do not sell or share personal information as those terms are defined under California law.
To exercise any of these rights, email hello@verrou.ai. We will verify your request and respond within the timeframe required by applicable law. You also have the right to lodge a complaint with your local data protection authority.
International transfers
All of our infrastructure sits inside the European Economic Area or in a country the European Commission has recognized as offering an adequate level of data protection. This website and the contact form that receives your message are hosted in Iceland, which is part of the EEA; our email is operated in Switzerland, which holds an EU adequacy decision; and engagement material sits on that same Icelandic infrastructure. Because of this, no personal data is transferred to a country that would require Standard Contractual Clauses or an equivalent safeguard. If you contact us from outside these regions, your submission travels to that infrastructure.
Legal requests
If we receive a legally binding demand for your data, we will comply with the law. We will also tell you it happened, unless we are legally prohibited from doing so. We will not volunteer your data to anyone who has not compelled it.
You should also know where we sit. verrou, Inc. is a US company, so a US court can compel us to produce what we hold, wherever in the world it is stored. That is ordinary jurisdiction rather than the CLOUD Act — which reaches providers of communication and remote-computing services, and we are neither. The providers we use are Icelandic and Swiss. We would rather state this plainly than let non-US hosting imply a protection it does not give. The practical mitigation is that we hold very little: no request logs, no IP addresses, and engagement material deleted on a defined schedule.
Children’s privacy
This website and our services are intended for businesses and are not directed to children. We do not knowingly collect personal information from anyone under the age of 16. If you believe a child has provided us with personal information, please contact us at hello@verrou.ai and we will delete it.
Changes to this policy
We may update this policy from time to time to reflect changes in our practices, technology, or legal requirements. When we do, we will revise the "Last updated" date at the top of this page. Material changes will be highlighted where appropriate. We encourage you to review this page periodically.
Contact
If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, reach us at hello@verrou.ai. We read every message and will respond as promptly as we can.