GDPR Compliance
Data controller
Verified Workflows Inc. is the data controller for personal data collected through the Service. Our EU representative can be reached at eu-rep@verifiedworkflows.com.
Legal bases for processing
We process personal data on the following legal bases under the GDPR: contract (to provide the Service you signed up for), legitimate interest (to secure and improve the Service, prevent fraud, and maintain accurate business records), legal obligation (to comply with applicable law), and consent (for cookies that are not strictly necessary, which you can withdraw at any time).
Your rights under the GDPR
You have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data, and the right to lodge a complaint with your supervisory authority. To exercise any of these rights, email privacy@verifiedworkflows.com. We respond within 30 days.
International data transfers
Personal data may be transferred to and processed in the United States. We use Standard Contractual Clauses (SCCs) approved by the European Commission to ensure an adequate level of protection. A copy of the SCCs is available on request.
Data Protection Officer
Our DPO can be reached at dpo@verifiedworkflows.com.
Sub-processors
We use the following sub-processors to provide the Service. Each is bound by a data processing agreement:
- Stripe (payments, US)
- Wise (reviewer payouts, UK)
- AWS (hosting, US and EU)
- Google Cloud Platform (hosting, US and EU)
- Resend (transactional email, US)
- PostgreSQL managed services (database, US)
- Redis Labs (caching, US)
Data breach notification
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.