Legal
Privacy Policy
How VertexY collects, uses, shares, retains, and protects personal information.
Overview
VertexY provides fraud detection, risk scoring, and graph intelligence services for business customers. This Privacy Policy explains how VertexY collects, uses, discloses, and protects personal information when organizations evaluate, buy, deploy, and use the platform.
It applies to our public website, the product interfaces and APIs, support channels, and related business operations. It does not override separate contractual commitments made in a subscription agreement, data processing addendum, or security exhibit; where those conflict with this policy, the agreement governs.
Controller and processor roles
These two roles are separate and it matters which one applies to a given piece of data:
- For our own website visitors, account holders, billing contacts, and support correspondents, VertexY acts as a controller and decides how that information is used.
- For the service data a customer sends us to assess — transaction, device, network and identity signals about their end users — VertexY acts as a processor, acting on that customer’s instructions. Requests from an end user about that data are directed to the customer who controls it.
Information We Collect
Account and business information
Names, work email addresses, job titles, company names, billing contacts, and administrative login details, collected when a customer registers or interacts with us.
Service data submitted for assessment
Data a customer sends through our APIs, dashboards, webhooks, and integrations. Depending on the customer’s implementation this may include device, network, transaction, behavioural, and identity-related signals needed to assess risk.
Indicator values such as email, phone, device and payment identifiers are stored as keyed hashes by default rather than as readable values. Readable storage is opt-in per field and controlled by the customer’s administrator.
Usage, diagnostic and security telemetry
Login events, feature usage, request metadata, browser details, IP addresses, audit events, and operational logs, used to secure the platform, monitor performance, prevent abuse, and improve the service.
Public sandbox
The interactive sandbox accepts only constrained synthetic aliases, documentation-reserved IP addresses, and structured demo values; personal-information fields are rejected. It stores no result and creates no assessment record tied to you. The browser may keep up to ten runs in page memory until you refresh or navigate away. We record anonymous aggregate run events and hashed IP counters for rate limiting and product analytics.
Do not send us special-category data, government identifiers, full payment card numbers, or authentication credentials. The service is not designed to receive them, and our ingestion path redacts values that resemble them.
How We Use Information
| Purpose | Categories used | Basis |
|---|---|---|
| Provide and maintain the platform | Account data, service data | Contract performance |
| Authenticate users and secure accounts | Account data, security telemetry | Contract performance; legitimate interests |
| Detect and prevent abuse of our own service | Security telemetry | Legitimate interests |
| Operate billing and enforce plan limits | Account data, usage metering | Contract performance |
| Provide support | Account data, support correspondence | Contract performance |
| Improve reliability and product features | Aggregate usage and diagnostics | Legitimate interests |
| Meet legal and audit obligations | Account data, audit logs | Legal obligation |
Where we use customer service data beyond delivering the service to that customer, we do so only as permitted by the applicable agreement and law.
Automated processing
The platform produces an automated risk score and a recommended action. VertexY does not execute the resulting business decision. The customer’s own systems and staff decide whether to allow, review, or decline, and retain responsibility for that outcome, including any human review they choose to apply.
AI assistance features
Optional AI features summarise evidence the platform already holds. They are read-only: they never alter a score, an action, a review outcome, or a policy. They run only on evidence assembled server-side within the customer’s own tenant, are disabled unless a company administrator enables them, and are configured so provider requests are not retained for provider model training.
Data Retention
| Data | Retention |
|---|---|
| Account and billing records | For the life of the account, then as required for tax and legal obligations |
| Risk assessments and evidence | For the retention window configured by the customer administrator |
| AI conversations and artifacts | Session-only, 7, 30, or 90 days, selected by the customer administrator |
| Audit logs | Retained to support security review and customer audit obligations |
| Operational and security logs | A short rolling window sized for incident investigation |
| Public sandbox runs | Not stored |
Customer administrators may request deletion or return of certain customer data in line with the applicable contract and the technical limits of the service. Backup copies and security logs may persist for a limited period until they are overwritten or expire on their normal schedule.
Security
- Encryption in transit for all API and dashboard traffic.
- Authenticated encryption at rest for sensitive stored fields, including AI evidence snapshots and artifact content.
- Keyed hashing of risk indicators, so stored identifiers are not readable by default.
- Tenant scoping enforced at every backend boundary, with the tenant identity taken from the authenticated session rather than the request body.
- Role and permission checks on privileged actions, with audit logging of administrative and export events.
- Signed, replay-protected ingestion for server-to-server event delivery.
No system is perfectly secure and we do not claim otherwise. We hold no third-party security certification at this time; where a page or document would normally cite one, it states the absence instead.
International Transfers
VertexY and its service providers may process information in countries other than the one where it was collected. Where we transfer personal information across borders, we rely on the safeguards required by applicable law, such as standard contractual clauses, and we contract our subprocessors to equivalent obligations.
Your Rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or object to processing of your personal information, to receive a portable copy, and to withdraw consent where we rely on it. You may also have the right to complain to your local supervisory authority.
If you are an end user of one of our customers, that customer controls the data submitted about you. We will refer your request to them and support them in responding.
To make a request, email support@getvertexy.com. We will verify the request appropriately before acting on it, and we will not treat you differently for exercising these rights.
Children
VertexY is a business-to-business service and is not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
Changes and Contact
We may update this policy as the service changes. When a change is material we will update the effective date above and, for customers, provide notice through the account or by email before it takes effect.
Questions about this policy, or a request to exercise your rights, can be sent to support@getvertexy.com.