Page 1. Scope, Principles, and Information We Collect
1.1 Purpose of this policy
VeralogicLabs is focused on digital content verification, suspicious content review, and risk-based assessment workflows. To operate these services, we need to process certain categories of information. This policy is designed to help users, customers, investigators, compliance teams, and casual visitors understand what we collect, why we collect it, and how we manage it in a way that is proportionate to the services provided.
We aim to collect only the information reasonably required to run the service, maintain security, respond to support requests, meet legal obligations, improve product performance, and document case activity. We also aim to avoid using personal data in ways that are unexpected, excessive, or unrelated to a legitimate operational need.
1.2 Who this policy applies to
This policy applies to website visitors, registered users, organizations that deploy or trial the platform, individuals who contact us, and people whose data may appear in submitted screenshots, documents, URLs, images, or related evidence. It also applies to prospective customers, business contacts, and anyone receiving communications from us about our products or services.
1.3 Information you provide directly
When you fill out forms, create an account, log in, submit a suspicious URL, upload a file, or contact our team, you may provide information such as your name, email address, organization name, password credentials, support inquiry details, uploaded media, screenshots, written notes, and any contextual information you choose to include with a submission.
If you submit content for analysis, that content may contain personal data, images of individuals, usernames, social media handles, business identifiers, conversations, web addresses, or visual evidence connected with a suspected scam, impersonation attempt, or manipulated media incident. You should submit only the material that is relevant to the review you want us to conduct.
1.4 Information collected automatically
We may automatically collect technical and usage information when you access the service. This may include IP address, approximate location inferred from network data, browser type, operating system, device identifiers, access timestamps, pages visited, referring links, error logs, session activity, request metadata, and diagnostic events used to secure and maintain the platform.
We may also use cookies or similar technologies to keep you signed in, remember interface preferences, support security checks, measure performance, understand traffic patterns, and improve the reliability of key workflows such as content submission, authentication, and account recovery.
Page 2. How We Use Information and Legal Bases
2.1 Service delivery and case handling
We use information to provide access to the platform, authenticate users, receive suspicious content, process uploads, run analysis workflows, document findings, produce trust reports, support case tracking, and present results back to authorized users. We may also use information to troubleshoot submission failures, detect malformed or unsafe files, and preserve submission integrity.
Where organizations use our services for internal review or investigative purposes, we may process case-related content on their instructions. In such situations, our role may differ depending on the arrangement, and the organization may be responsible for determining whether a particular submission is appropriate and lawful.
2.2 Security, fraud prevention, and abuse monitoring
Because the platform deals with high-risk content, we use information to detect misuse, unauthorized access, malicious uploads, credential abuse, spam, automated attacks, policy violations, and other behaviors that could endanger users or the service. This includes using logs, metadata, rate controls, and review signals to protect the platform and those relying on it.
We may suspend, quarantine, block, or preserve submissions when required to protect system integrity, investigate suspicious activity, respond to legal requests, or enforce our platform rules. Some review actions may occur automatically when a file or request appears unsafe.
2.3 Communications and support
We use contact details to respond to inquiries, confirm account actions, deliver operational notices, provide support, communicate about investigations or account issues, and share important policy or product updates. If you contact us, we may retain the correspondence and related metadata so our team can continue the conversation, improve support quality, and maintain an accurate service record.
2.4 Legal bases for processing
Depending on the context, we may process information because it is necessary to perform a contract, because we have a legitimate interest in operating and securing the platform, because the law requires us to do so, or because you have provided consent for a particular activity. Where consent is relied upon, you may withdraw it, though this may affect the availability of some features or communications.
- Contractual necessity may apply when we create accounts, enable logins, and deliver requested analysis workflows.
- Legitimate interests may apply to platform security, product improvement, support, and business administration.
- Legal obligations may apply to record keeping, law enforcement cooperation, and compliance investigations.
- Consent may apply to optional communications or certain region-specific processing requirements.
Page 3. Sharing, Retention, and International Data Handling
3.1 When information may be shared
We do not sell personal data. We may share information with service providers and infrastructure partners who help us host the platform, store files, send transactional communications, monitor uptime, or support security and maintenance. These providers are expected to process information only for permitted purposes and under appropriate safeguards.
We may also disclose information to professional advisers, auditors, insurers, regulators, law enforcement bodies, courts, or other authorities when we believe disclosure is necessary to comply with law, protect rights and safety, investigate fraud, or respond to a valid legal process. In a merger, acquisition, restructuring, financing, or asset sale, relevant information may be disclosed as part of due diligence or transferred as part of the transaction subject to applicable protections.
3.2 Customer-directed sharing
If a customer account includes multiple authorized users, case information may be visible to those users based on account permissions. Organizations using the platform are responsible for configuring internal access appropriately and ensuring that only properly authorized personnel can view sensitive reports, uploads, or case histories.
3.3 Retention periods
We retain information for as long as reasonably necessary for the purposes described in this policy, including to provide the service, maintain security records, resolve disputes, enforce agreements, and comply with legal or regulatory obligations. Retention periods may vary depending on account status, type of submission, operational necessity, legal hold requirements, or customer agreements.
For example, authentication data may be retained to manage accounts, support records may be retained to respond to recurring issues, and case-related materials may be retained for historical review, reporting continuity, or audit purposes. When data is no longer needed, we aim to delete, anonymize, or securely isolate it according to our internal controls and technical limitations.
3.4 Cross-border processing
Your information may be processed in jurisdictions different from the country where it was collected. When this occurs, we take steps that are reasonably intended to preserve appropriate protections for personal data, taking into account contractual safeguards, access restrictions, and the nature of the information involved. By using the service where such processing is necessary, you acknowledge that your information may be transferred and processed across borders.
Page 4. Rights, Choices, Security, and Contacting Us
4.1 Your rights and choices
Depending on your location and the laws that apply, you may have rights relating to the personal data we hold about you. These may include the right to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent in certain circumstances. We may need to verify your identity before fulfilling a request, and some requests may be limited by legal obligations, security requirements, or the rights of others.
If you are submitting a request on behalf of an organization, another individual, or a case subject, we may ask for additional documentation demonstrating your authority to act. We may also decline requests that would compromise ongoing investigations, reveal protected internal review methods, or unlawfully interfere with evidence preservation duties.
4.2 Security measures
We use administrative, technical, and organizational measures intended to protect information against unauthorized access, misuse, loss, alteration, or disclosure. These measures may include access controls, authentication checks, transport protections, file validation, submission quarantine processes, audit logging, least-privilege practices, and controlled support access. No internet-based platform can guarantee absolute security, but we work to reduce risk and respond promptly when issues are identified.
4.3 Third-party content and links
Submissions may include links or references to third-party websites, social media platforms, messaging tools, or online marketplaces. Our service may also link out to third-party resources for convenience. We are not responsible for the privacy practices, content, or security of those third-party environments. You should review their policies separately before sharing information with them.
4.4 Updates to this policy
We may update this Privacy Policy from time to time to reflect product changes, legal developments, or operational improvements. When material changes are made, we may revise the effective date, publish the updated policy on the site, and where appropriate provide additional notice through the service or by email.
4.5 Contact details
If you have questions, privacy concerns, or rights requests, you may contact us at jesvin@businessmetrics-ai.com, via WhatsApp at +60 11-1302 1017, or by post to 2nd Floor, Menara PJH, 2, Jalan Tun Abdul Razak, Presint 2, 62000 Putrajaya, Wilayah Persekutuan Putrajaya.