Legal

Privacy Policy

Last updated July 19, 2026

§01Who We Are

Verndio is operated by We Are Contrast Limited, a company registered in England and Wales (company number 09564897), whose registered office is at 1 Sopwith Crescent, Wickford, Essex, United Kingdom, SS11 8YU. The Service is available to both individual and business customers.

We don't require a Data Protection Officer under the regulations, but our senior data controller can be contacted at [email protected].

§02Information We Collect

When you create an account, we collect your name, email address, password (stored as a salted hash), and team or company name. If you subscribe to a paid plan, our payment processor, Stripe, collects your billing details — Verndio itself never sees or stores full card numbers.

To provide the Service, we also store information about the servers and applications you connect, including hostnames, IP addresses, deployment activity logs, and SSH-related metadata, plus standard technical data such as IP address and browser type when you use the dashboard.

§04Special Categories of Personal Data

We don't store any "special category" personal data, such as data about health, race, or religion. We don't store government ID documents such as a driving licence, passport, or national insurance number, other than where you voluntarily provide a form of photo ID to verify your identity as part of a Subject Access Request (see below).

§05Cookies

We use a small number of essential cookies: one to keep you signed in, and one to remember your light/dark appearance preference. These are necessary for the Service to function and aren't used for advertising, analytics, or cross-site tracking.

§06Who We Share Your Data With

We don't sell your personal data, and we won't pass it to third parties without a lawful basis for doing so. The following sub-processors receive your personal data as part of running the Service:

ProcessorPurposeCountry
StripePayment processingUS / EU
DigitalOceanInfrastructure hosting for the Verndio dashboardUS / EU
ResendTransactional email deliveryUS

Servers and infrastructure you provision through Verndio — for example, a DigitalOcean Droplet you create to host your own application — are controlled by you, not by us, and fall outside the scope of this policy.

§07International Transfers

Some of our sub-processors are located outside the UK. Where personal data is transferred outside the UK, we rely on UK adequacy regulations (for countries the UK government has approved as offering an adequate level of data protection) or, where those don't apply, appropriate safeguards such as the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.

§08Data Retention

We retain account and billing information for up to 7 years, to coincide with HMRC and accounting record-keeping requirements. Server and deployment data — hostnames, IP addresses, deployment activity, and SSH-related metadata — is deleted when you remove the corresponding server or application, or when your account is closed, whichever is earlier.

§09Your Rights

As a data subject, you have the right to access, correct, erase, restrict, or export the personal data we hold about you, and to object to certain processing, including direct marketing and automated decision-making. You can update most account details yourself from your account settings, or contact us to make a request. All requests involving a third party processor will be forwarded to them as necessary.

§10Making a Subject Access Request

To protect your data from being disclosed to the wrong person, we verify your identity before fulfilling a Subject Access Request. We accept a passport, driving licence, or another form of photo ID that leaves no doubt as to the data owner's identity.

§11Complaints

Please send any initial complaints to [email protected]. If you're unhappy with how we've handled your data or your complaint, you have the right to lodge a complaint directly with the UK's supervisory authority, the ICO, at ico.org.uk/concerns.

§12Security

We use industry-standard measures — including encryption in transit and at rest for sensitive credentials — to protect your information. No method of transmission or storage is perfectly secure, and we can't guarantee absolute security.

§13Changes to This Policy

We may update this policy from time to time. If we make material changes, we'll update the date at the top of this page and, where appropriate, notify you directly.

§14Contact

Questions about this policy or your data? Contact us at [email protected].