Privacy Policy
Veru Legal AI
This is the privacy policy, a document in which you will find all information on the processing of personal data carried out by verulabs d.o.o. (hereinafter: “Controller”).
The Controller pays special attention to the security of your personal data. All personal data provided are treated as confidential and are used only for the purposes for which they were provided.
1. Personal Data Controller
The processing of personal data is carried out by the personal data controller.
Controller details:
Name: verulabs d.o.o.
Address: Miklošičeva cesta 30, Ljubljana
You may contact the Controller at: contact@veru.legal
2. Definitions
“Personal data” means any information relating to an identified or identifiable individual (this includes name, surname, e-mail address and telephone number, as well as identifiers specific to the physical, physiological, genetic or mental identity of the individual, etc.)
“Controller” means a legal or natural person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing.
“Processor” means a natural or legal person, public authority or other body which processes personal data on behalf of the controller.
“Processing” means collection, storage, access and all other forms of use of personal data.
“Veru” or “service” means Veru Legal AI application provided as software as a service (SaaS) utilizing artificial intelligence technologies.
“Subscriber” means a legal person or a sole practitioner pursuing an activity, with whom the Controller has entered into a subscription relationship for access to Veru, in accordance with the General Terms and Conditions applicable at the Controller.
“User” means a natural person who is granted access to Veru in accordance with the Subscriber’s instructions.
3. Subject Matter of the Privacy Policy
The subject matter of this privacy policy is the personal data collected and processed by the Controller for the purposes of providing Veru.
Personal data collected and processed by the Controller:
- Basic personal data (name and surname, company details, address);
- Contact details (e-mail, telephone number);
- Data on the selected service (selected package);
- Data required to create a user account (user details)
- Data required to process payments,
- Data required to perform security functions (time and type of activity in the application, IP address).
When using the services, personal data may be contained within content that Veru users enter or create when using the services (hereinafter: “User Content”). The entry and creation of User Content falls within the exclusive domain of the individual Subscriber to the service. In relation to the data created (or made available) by an individual User when using Veru, the Controller acts in the role of a user of personal data. Any questions addressed to the Controller that relate to User Content fall outside the Controller’s competence. Upon receipt of such a question, the Controller will notify the Subscriber, provided that it can be established with certainty from the question itself to which Subscriber the question relates. Otherwise, such questions will be dismissed.
We obtain your personal data directly from you, e.g. when you submit an enquiry or order our services. We also obtain your personal data through the use of our website.
4. Purposes of Processing
This privacy policy is intended for:
- Subscribers,
- Website visitors.
All personal data collected by the controller are processed only where we have an appropriate legal basis for doing so and for the specific purposes defined in the table below. All personal data are processed on an appropriate legal basis, as defined below. Should we process the data for a purpose not defined in this policy, we will inform you thereof in advance.
| Purpose | Types | Legal basis | Retention period |
|---|---|---|---|
| Provision of our services | Name and surname of the User, e-mail, telephone number, Subscriber details, including payment details and details of the selected package. | Contractual relationship | 5 years after termination of the provision of the service |
| Communication with you based on your enquiries | Name and surname, e-mail address, telephone number, content of the message, date and time of the 30-minute video call | Pre-contractual relationship | 6 months after the end of the communication |
| Enforcement of legal claims and protection of our rights | The set of data depends on the situation | The law | In accordance with legislation |
| Sending e-newsletters to existing Subscribers | Name and surname, e-mail address | The law | Until withdrawal |
| Sending e-newsletters to the general public | Name and surname, e-mail address | Consent | Until withdrawal |
| Prevention of fraud and online scams | e-mail address, IP address, time and type of activity in the application | Legitimate interest in ensuring a secure user experience | Until withdrawal, but no longer than one year |
The provision of personal data is voluntary, except where the provision of personal data is required by legislation. In that case, you are obliged to provide the personal data. We need certain personal data in order to provide you with the service. If you decide not to provide us with the data, we will be unable to offer you certain services.
We process personal data only for as long as necessary to fulfil the purpose for which the data were collected. Upon expiry of the retention period, the data are erased or anonymised in such a way that reconstruction of the data is no longer possible.
5. Contractual Processors
We will disclose your personal data to third parties where this is strictly necessary to ensure the operation of our services.
Third parties may not use your personal data for their own purposes, and we have concluded a personal data processing agreement with each of them, governing the protection and processing of the data.
Certain third parties export your personal data outside the EEA. In such cases, we have put in place additional safeguards in the form of standard contractual clauses, ensuring that the protection of your personal data is adequate.
Third parties with whom we share your personal data:
- The provider of the “backend” system (the server-side part of our application, which ensures the provision of the services);
- Providers granting access to the generative artificial intelligence models available as part of the provision of the services;
- Providers enabling the operation of the document editor;
- The provider of subscription management systems;
- The provider of payment system management;
- Providers of application performance analysis (so-called crash reporting);
- The hosting provider;
- The bulk e-mail sending provider.
6. Further Processing of Personal Data in Automated Form
The Controller does not carry out automated decision-making or profiling in the processing of personal data.
7. How Do We Protect Your Personal Data?
We ensure the security of your personal data by having adopted various technical and organisational measures, including:
- Regular updating of our hardware and software;
- Protection of hardware and software with security software;
- Protection of our business premises;
- Training of employees and external associates in the field of personal data protection;
- Ensuring that access to personal data by unauthorised persons is restricted.
We are aware that, despite the security mechanisms we have put in place, a security incident may occur. To this end, we have established a protocol under which such incidents will be handled promptly, effectively and in accordance with legislation.
In the event of a security incident where it is likely that the rights and freedoms of individuals have been jeopardised, we will notify the competent supervisory authority of such an incident without delay, and no later than within 72 hours. In the event of a security incident likely to result in a high risk to the rights and freedoms of individuals, we will also notify the individuals concerned without delay.
8. What Rights Do You Have?
With regard to the processing of your personal data that we carry out, the following rights are available to you:
- Right of access to and a copy of personal data: this right enables you to obtain information about the processing of personal data, and also gives you the possibility to inspect or obtain a copy of the personal data we hold about you.
- Right to rectification of personal data: you have the right to request the rectification of inaccurate or incomplete data we hold about you.
- Right to restriction of processing of personal data: this right enables you to restrict processing, e.g. for the duration of the controller’s decision-making on a rectification request or an objection.
- Right to erasure of personal data: this right enables you, in certain cases, to request the erasure of the data we hold about you. Where the legal basis for the processing of personal data is the law or a valid contract, we cannot erase your personal data.
- Right to withdraw consent: where we process your personal data on the basis of consent, you may withdraw that consent at any time. Withdrawal of consent entails no negative consequences for you. Please note that, after withdrawal of consent, we will no longer be able to provide you with certain services.
- Right to object to the processing of personal data: this right is available to you where personal data are processed on the basis of legitimate interests. It enables you to request that the controller cease the processing. Please note that in certain cases the controller may refuse such an objection. In any event, the controller will cease the processing if you object to direct marketing. You may withdraw consent by sending us an e-mail at contact@veru.legal.
- Right to data portability: this right enables you to request that we transmit your personal data to another controller in a machine-readable format. This is only possible where we process your data by automated means and where the data were collected on the basis of consent or a contractual relationship.
If you believe that a breach of personal data protection has occurred, you may at any time lodge a complaint with the competent supervisory authority, which in Slovenia is the Information Commissioner.
We will process your requests relating to the rights defined above as soon as possible, and no later than within 30 days of receipt. If a request is so extensive that its resolution will take longer, we will inform you thereof in advance and give you an indicative deadline for the preparation of the response.
We reserve the right to identify you when you submit a request to exercise any of your rights. If your request does not include personal data on the basis of which we can reliably identify you, we will ask you for additional personal data. If you fail to provide us with the additional personal data within the deadline, your request will be dismissed.
You may exercise your rights by writing to us at contact@veru.legal.
9. Amendments
Any amendment to our privacy policy will be published on this website. You are deemed to agree to the new version of the policy if, after the policy has been amended, you continue to use our website or other services covered by this policy.
10. Do You Have a Question?
You can contact us at any time with additional questions regarding personal data protection by writing to us at: contact@veru.legal.