← Back to home
Privacy Policy

Verifica Data Protection

Last updated: September 2026

This Privacy Policy explains how VERICASA INC ("the Company", "we", "us" or "our") collects, uses and shares personal data when you use Verifica: the marketing website at www.verifica.co and the KYC and AML platform (together, the "Service"). It also explains your privacy rights.

By using the Service, you acknowledge this Privacy Policy. If you do not agree, do not use the Service.

Who is responsible

Verifica is operated by VERICASA INC. That is the contracting entity for the website, the platform and related services.

When a client firm uses Verifica to verify an investor, buyer, seller or other counterparty, that firm is typically the controller of the verification file. VERICASA INC processes that file to provide the Service. For this marketing website, demo and assessment requests, and the firm's own Verifica account, VERICASA INC is the controller.

Definitions

  • Account means an account created to access the platform or parts of it.
  • Company means VERICASA INC, the operator of Verifica.
  • Personal data means any information relating to an identified or identifiable natural person.
  • Service means the Verifica website and the Verifica KYC and AML platform, including screening powered by LSEG World-Check.
  • Service Provider means a processor that handles personal data on our behalf to run the Service (for example hosting, document verification or screening).
  • Usage Data means data collected automatically from use of the Service or its infrastructure.
  • User means the individual using the Service, or the firm on whose behalf they act.

Personal data we collect

Marketing website

On www.verifica.co we may collect:

  • Name, email and message when you use the contact form or request a demo
  • Assessment answers and, if you ask us to follow up, the contact details you provide
  • Usage Data such as IP address, browser type, pages visited, time on page and device identifiers
  • Cookie and similar data, as described under Cookies on this website below

We do not ask website visitors for identity documents or biometrics.

Verifica platform

When a firm or an invited counterparty uses the platform, we may collect whatever the requested checks need, including:

  • Account data: name, email, organisation and login data
  • Identity documents and data read from them
  • Biometric liveness images or recordings used to match a person to a document
  • Due-diligence answers (for example source of funds, occupation or ownership)
  • Names and identifiers of connected persons and entities, including beneficial owners
  • Screening inputs and results against sanctions, PEP and adverse-media sources

Usage Data

Usage Data is collected automatically when you use the Service. It may include IP address, browser type and version, pages or screens viewed, date and time, time spent, device type, operating system and diagnostic data.

How we use personal data

We use personal data to:

  • Provide, maintain and secure the Service
  • Run the identity, document, biometric, ownership and screening checks a client firm requests
  • Produce the timestamped, exportable audit file
  • Manage accounts, contracts, billing and support
  • Respond to website enquiries and, where you have asked us to, contact you about Verifica
  • Monitor usage, fix errors and improve the Service
  • Measure marketing on this website only after you accept marketing cookies
  • Comply with law, including retaining records a regulated firm or we must keep

We do not sell personal data. We do not share identity documents, biometrics or verification files with third parties for marketing or advertising.

Who we share data with

We share personal data only when it is needed to run the Service or required by law:

  • Screening and verification processors. Names, identifiers and related data are sent to LSEG World-Check and to official document-verification sources so the requested checks can run. This is part of the Service, not a marketing disclosure.
  • Infrastructure providers. Hosting, security and operations processors. The Services are hosted in Spain, Germany and, where needed, other EU locations.
  • Professional advisers and public authorities when required by law or to protect legal rights, users or the public.
  • Business transfers. If VERICASA INC is involved in a merger, acquisition or asset sale, we will give notice before personal data is transferred and becomes subject to a different privacy policy.

We do not share personal data with business partners for promotions. The Service has no public user-to-user areas.

Retention

We keep personal data only as long as needed for the purposes in this policy, including legal and audit obligations.

  • Website enquiry and assessment data is kept long enough to handle the request and any follow-up you asked for.
  • Verification files are retained for as long as the client firm's regulatory purpose and our legal obligations require, then deleted or anonymised.
  • Platform data is segregated per client.

International transfers

Personal data is processed at our operating locations and at those of the processors above. Where a transfer outside the European Economic Area is required (for example a screening query), we use Standard Contractual Clauses (EU Model Clauses) or another lawful transfer mechanism, and we take steps reasonably necessary to keep the data protected.

Your rights

Under the GDPR, you may have the right to access your personal data, correct it, delete it, restrict or object to processing, export it, and withdraw consent where processing is based on consent. You may also lodge a complaint with a supervisory authority.

You can ask us at DPO@vericasa.com or contact@vericasa.com. If your data was submitted as part of a firm's verification, we may need to route the request through that firm, because it is typically the controller of that file.

We have appointed a Data Protection Officer. Contact DPO@vericasa.com.

Security

Identity documents are among the most sensitive data a firm handles. Data is encrypted in transit and at rest and segregated per client. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Cookies on this website

This marketing website uses cookies that are necessary for the site to function (for example locale). It also uses the LinkedIn Insight Tag, a marketing cookie, to measure LinkedIn ads and understand which professional audiences visit the site. That tag is not loaded until you accept marketing cookies in the banner, and it is not loaded on the assessment or contact forms. You can change your choice at any time from Cookie settings in the footer.

When you accept, LinkedIn may process visit data (page URL, referrer, device and a LinkedIn cookie) under LinkedIn's own terms. Rejecting marketing cookies does not affect use of the site.

Children's privacy

The Service is for business users aged 18 or over. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided personal data, contact us and we will delete it.

Links to other websites

The Service may contain links we do not operate. Their privacy practices are their own. Review the policy of every site you visit.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will post the new policy on this page and, when the change is material, give notice by email and/or a notice on the Service before it takes effect.

Contact us

Questions about this Privacy Policy:

See a full check run
on a real file.

Identity, documents, and screening in one engine, start to report.

Request a demo