Legal

Privacy Policy

Last updated: May 2026

1. Who we are

Verra is operated by SME Digital ("SME Digital", "we", "us"), the legal entity providing the Verra workspace. SME Digital is the data controller responsible for personal data processed through Verra and is the seller of the Verra service. Contact: info@smedigital.biz

2. Information we collect

Account data (name, email, company, login credentials); workspace content you add to Verra (contacts, marketing audiences and campaign content, deals, proposals, invoices, notes, files); marketing engagement data generated when you send campaigns from Verra (delivery, open, click, bounce, complaint and unsubscribe events for your recipients); connected-account data where you link a third-party account such as LinkedIn (profile identifier, name, email, profile image and encrypted access tokens); support communications; and technical/usage data (IP address, browser type, device identifiers, log and telemetry data, cookies).

3. How we use your information and legal basis

We use your data to (a) provide and operate the Verra workspace and your account — legal basis: performance of a contract; (b) process payments and manage subscriptions via our payment provider — legal basis: performance of a contract; (c) secure the service and prevent fraud or abuse — legal basis: legitimate interests; (d) provide customer support and service communications — legal basis: performance of a contract / legitimate interests; (e) improve the product and analyse usage — legal basis: legitimate interests; (f) comply with legal obligations — legal basis: legal obligation; (g) send marketing where permitted — legal basis: consent, which you may withdraw at any time. We never sell your personal data.

4. Who we share your data with

We share personal data only with: (a) Paddle.com Market Ltd, our Merchant of Record and payment processor, which handles checkout, billing, tax, subscription management, invoicing, and refunds for all Verra orders; (b) cloud hosting, database, and infrastructure providers that store and serve your workspace; (c) email sending, delivery, analytics, and customer support tooling used to operate the service and to deliver campaigns you send; (c1) social platforms you choose to connect, such as LinkedIn, which receive the posts you publish; (d) professional advisers (legal, accounting); and (e) law enforcement or regulators where required by law. These recipients act as processors on our behalf, except Paddle which acts as an independent controller for payment data as Merchant of Record.

4a. Marketing you send from Verra

Verra provides tools that let you send email campaigns to your own contacts and publish posts to social accounts you connect. For that content you are the controller of your recipients' personal data and we act as your processor. You are responsible for having a lawful basis to contact each recipient, for honouring consent and unsubscribe requests, and for complying with anti-spam and marketing laws that apply to you (for example GDPR, PECR, CAN-SPAM and CASL). Verra adds an unsubscribe link to every marketing email, records unsubscribes, bounces and complaints, and permanently suppresses those addresses across your workspace — this suppression cannot be overridden. Sending, delivery and engagement events are processed by our email infrastructure providers on our behalf.

4b. Connected accounts

If you connect a third-party account such as LinkedIn, we store the profile details that account returns and an encrypted access token so Verra can publish on your behalf when you instruct it to. Tokens are encrypted at rest, never exposed to the browser, and are deleted when you disconnect the account. Verra publishes only the content you create and approve, and your use of the connected platform remains subject to that platform's own terms and privacy policy.

5. Data retention

Account and workspace data are retained for the lifetime of your account and for up to 90 days after account closure to allow recovery, after which they are deleted or anonymised. Billing and tax records retained by Paddle and by us are kept for up to 7 years to meet legal and accounting obligations. Support and security logs are typically retained for 12–24 months.

6. Security

We protect your data with industry-standard technical and organisational measures, including encryption in transit (TLS) and at rest, role-based access controls, row-level security so only your workspace members can read your data, audit logging, least-privilege access for staff, hardened cloud infrastructure, regular dependency and vulnerability updates, secure secret management, and backups. No system is perfectly secure, but we work continuously to protect your information.

7. Cookies

We use essential cookies required to run the service (e.g. authentication and session) and limited analytics cookies to understand usage. You can manage cookies via your browser settings; disabling essential cookies will break parts of the service.

8. Your rights

You may access, correct, export, or delete your personal data, restrict or object to certain processing, withdraw consent where processing is based on consent, and lodge a complaint with your local data protection authority. Use your account settings or contact info@smedigital.biz — we will respond within one month.

9. International transfers

Your data may be processed in countries outside your own, including by Paddle and our cloud providers. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.

10. Changes to this policy

We may update this policy from time to time. Material changes will be communicated through the product or by email. The "Last updated" date above reflects the latest revision.

11. Contact

Questions about this policy or your data? Contact SME Digital at info@smedigital.biz